【正文】
erfaces Switchshow portsecurity Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action (Count) (Count) (Count) Fa5/1 11 11 0 Shutdown Fa5/5 15 5 0 Restrict Fa5/11 5 4 0 Protect Total Addresses in System: 21 Max Addresses limit in System: 128 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 924 PortBased Authentication ? Restricts unauthorized clients from connecting to a LAN through publicly accessible ports 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 922 ? Port security is a MAC address lockdown that disables the port if the MAC address is not valid. Network Access Port Security 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 920 Configuring Authorization Switch(config)aaa authorization {authproxy | work | exec | mands level | reverseaccess | configuration | ipmobile} {default | listname} [method1 [method2...]] ? Creates an authorization method list and enables authorization Switch(config)interface interfacetype interfacenumber ? Enters interface configuration mode Switch(configif)ppp authorization {default | listname} ? Applies the named authorization method list to the interface 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 918 AAA Network Configuration ? Authentication – Verifies a user’s identify ? Authorization – Specifies the permitted tasks for the user ? Accounting – Provides billing, auditing, and monitoring 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 916 Objectives Upon pleting this lesson, you will be able to: ? Explain basic security concepts for the multilayer switched work ? Configure authentication, authorization, and accounting on Catalyst switches ? Configure port security and portbased authentication with ? Verify the work access security configuration ? Configure VLAN access lists ? Verify the VLAN access list security configuration 169。 2022, Cisco Systems, Inc. All rights reserved. 915 Securing Multilayer Switched Networks 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 913 Verifying NAM Switchshow module ? Displays information about installed modules Switchshow module Mod Ports Card Type Model Serial No. 2 2 Catalyst 6000 supervisor 2 (Active) WSX6KSUP22GE SAD0410050B 3 48 48 port 10/100 mb RJ45 ether WSX6248RJ45 SAD03080485 5 2 Network Analysis Module WSX6380NAM SAD05130AXB 7 2 Intrusion Detection System WSX6381IDS SAD05100HPT Switchshow interface Gigabi