What is true if a network administrator needs to configure port - ProProfs Discuss
Advertisement

What is true if a network administrator needs to configure port security on a switch?

Asked by Rapbondoc, Last updated: Mar 26, 2024

+ Answer
Request
Question menu
Vote up Vote down

1 Answer

rapbondoc

rapbondoc

rapbondoc
Rapbondoc

Answered Sep 26, 2018

The sticky learning feature allows the addition of dynamically learned addresses to the running configuration.
When dynamic mac address learning is enabled on an interface, the switch can learn new addresses up to the maximum defined.

Follow these guidelines when configuring port security: + Port security can only be configured on static access ports, trunk ports, or 802.1Q tunnel ports. -> A is not correct. + A secure port cannot be a dynamic access port. + A secure port cannot be a destination port for Switched Port Analyzer (SPAN). + A secure port cannot belong to a Fast EtherChannel or Gigabit EtherChannel port group. -> D is not correct + You cannot configure static secure or sticky secure MAC addresses on a voice VLAN. -> B is not correct. + When you enable port security on an interface that is also configured with a voice VLAN, you must set the maximum allowed secure addresses on the port to at least two. + If any type of port security is enabled on the access VLAN, dynamic port security is automatically enabled on the voice VLAN. + When a voice VLAN is configured on a secure port that is also configured as a sticky secure port, all addresses seen on the voice VLAN are learned as dynamic secure addresses, and all addresses seen on the access VLAN (to which the port belongs) are learned as sticky secure addresses. + The switch does not support port security aging of sticky secure MAC addresses. + The protect and restrict options cannot be simultaneously enabled on an interface. (Reference: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3550/software/release/12-1_19_ea1/configuration/guide/3550scg/swtrafc.html#wp1038546) Note: Dynamic access port or Dynamic port VLAN membership must be connected to an end station. This type of port can be configured with the switchport access vlan dynamic command in the interface configuration mode. Please read more about Dynamic access port here: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3550/software/release/12-1_19_ea1/configuration/guide/3550scg/swvlan.html#wp1103064
upvote downvote
Reply 

Advertisement
Advertisement
Search for Google images Google Image Icon
Select a recommended image
Upload from your computer Loader
Image Preview
Search for Google images Google Image Icon
Select a recommended image
Upload from your computer Loader
Image Preview
Search for Google images Google Image Icon
Select a recommended image
Upload from your computer Loader

Email Sent
We have sent an email to your address "" with instructions to reset your password.