首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The network security policy for Ezonexam requires that only one host be permitted to attach dynamically to each switch interface
The network security policy for Ezonexam requires that only one host be permitted to attach dynamically to each switch interface
admin
2009-05-19
27
问题
The network security policy for Ezonexam requires that only one host be permitted to attach dynamically to each switch interface. If that policy is violated, the interface should be automatically disabled. Which two commands must the Ezonexam network administrator configure on the 2950 Catalyst switch to meet this policy? (Choose two)
选项
A、SWEzonexam1(config-if)# switchport port-security maximum 1
B、SWEzonexam1(config)# mac-address-table secure
C、SWEzonexam1(config)# access-list 10 permit ip host
D、SWEzonexam1(config-if)# switchport port-security violation shutdown
E、SWEzonexam1(config-if)# ip access-group 10
答案
A,D
解析
Explanation
Catalyst switches offer the port security feature to control port access based on MAC addresses. To configure port security on an access layer switch port, begin by enabling it with the following interface configuration command:
Switch(config-if)# switchport port-security
Next, you must identify a set of allowed MAC addresses so that the port can grant them access. You can explicitly configure addresses or they can be dynamically learned from port traffic. On each interface that uses port security, specify the maximum number of MAC addresses that will be allowed access using the following interface configuration command:
Switch(config-if)# switchport port-security maximum max-addr
Finally, you must define how each interface using port security should react if a MAC address is in violation by using the following interface configuration command:
Switch(config-if)# switchport port-security violation {shutdown | restrict | protect}
A violation occurs if more than the maximum number of MAC addresses are learned, or if an unknown (not statically defined) MAC address attempts to transmit on the port. The switch port takes one of the following configured actions when a violation is detected:
shutdown-The port is immediately put into the errdisable state, which effectively shuts it down. It must be re-enabled manually or through errdisable recovery to be used again.
restrict-The port is allowed to stay up, but all packets from violating MAC addresses are dropped. The switch keeps a running count of the number of violating packets and can send an SNMP trap and a syslog message as an alert of the violation.
protect-The port is allowed to stay up, as in the restrict mode. Although packets from violating addresses are dropped, no record of the violation is kept.
转载请注明原文地址:https://jikaoti.com/ti/JoO7FFFM
本试题收录于:
思科640802题库思科认证分类
0
思科640802
思科认证
相关试题推荐
Writealettertorecommendyourstudent,DavidSmith,whoishuntingforajobandinterestedintheSalesManagerposition.Yo
Writeanessayof160-200wordsbasedonthefollowingdrawing.Inyouressay,youshouldfirstdescribethedrawing,theninte
Theideaisasaudaciousasitaltruistic:provideapersonallaptopcomputertoeveryschoolchild—particularlyinthepoorestp
"Deadpool",whichsofarhastakenmorethan$500mincinemasworldwide,isanatypicalblockbuster,afoul-mouthedanti-herofi
"Deadpool",whichsofarhastakenmorethan$500mincinemasworldwide,isanatypicalblockbuster,afoul-mouthedanti-herofi
InParagraphs1and2,thetextshowsPTK’s______.Anappropriatetitleforthetextismostlikelytobe______.
Couldahugadaykeepthedoctoraway?Theanswermaybearesounding"yes!"【B1】______helpingyoufeelcloseand【B2】______to
TodayweliveinaworldwhereGPSsystems,digitalmaps,andothernavigationappsareavailableonoursmartphones.【B1】______
Inthemoviesandontelevision,artificialintelligence(AI)istypicallydepictedassomethingsinisterthatwillupendourwa
随机试题
初三学生雷鸣因抢劫判处有期徒刑。根据《中华人民共和国义务教育法》,其服刑期间接受义务教育所需经费应由()。
简述集权制和分权制的优缺点。
阿司匹林中毒时可采取的措施是
A.清热燥湿B.清热燥湿,泻火解毒C.清热燥湿,泻火除蒸,解毒疗疮D.清热燥湿,泻火解毒,利尿E.清热燥湿,泻肝胆火龙胆草具有的功效是
社区构成的要素有
个人教育贷款签约和发放中的风险包括()。
风险预警程序是()。①风险处置;②后评价;③信用信息的收集和传递;④风险分析。
根据《未成年人保护法》规定,国家保障未成年人的()和其他合法权益不受侵害。
某地方性法规规定,企业终止与职工的劳动合同的,必须给予相应的经济补偿。某企业认为该规定与《中华人民共和国劳动法》相抵触,可以维护自身权益的途径是()。
在教育的本质问题上,杨贤江认为教育是()。
最新回复
(
0
)