Solved

Port based security on Cisco Switches

Posted on 2012-03-29
5
368 Views
Last Modified: 2012-06-27
I need to find out which Cisco switches support port based security. I have a network with Cisco voice and data along with their respective vlans, however I need to create some additional vlans and be able to allow access on ports only to specified MAC addresses so that under no circumstances can anyone connect a device and have access to the network. Can someone please offer suggestions and maybe shed some light on what that config would look like.
0
Comment
Question by:ryanva
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 5

Expert Comment

by:andrew1812
ID: 37782170
0
 
LVL 10

Expert Comment

by:mat1458
ID: 37782580
Any IOS switch can do that: 2960, 3560, 3750, 4500, 6500. Also the older ones like 2950, 3550, 4000, 6000 do that. And some of the SMB switches support it as well.

Do yu already have any type of switches?
0
 

Author Comment

by:ryanva
ID: 37782605
I have a Cisco 2960-24PC-L for the voice vlan and two Linksys SGE2000P switches for the data vlan
0
 
LVL 10

Accepted Solution

by:
mat1458 earned 500 total points
ID: 37784027
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 37786705
Config looks like:

 switchport port-security
 switchport port-security violation restrict

with the addition of a "switchport port-security mac-address sticky" statement.

Please be aware that MAC addresses can be cloned, so 802.1x is a better security tool.

Tamas
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ASA RADIUS Authetication for Management Access 13 58
Domain administrator account is locked out 31 102
Edge switch problems cisco 2960 25 83
Expand Verizon 3G to LTE - possible? 4 58
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Is your computer hacked? learn how to detect and delete malware in your PC
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question