Hello and welcome back to I see anyone interconnecting Cisco networking devices are one. This is episode 334 Troubleshooting poor security
in Trenton. Hero and I will be restructured for this course.
US video went over kind of how this switch determines where to send frames and how it actually does send frames of this video. We look at control shooting a poorly configured switch with port security enabled and look at those violation molds once again.
So learning objectives were gonna learn these show commands to troubleshoot support security.
A quick pre assessment question. Get your brain thinking which violation mode will not shut down the porter logging messages but will discard a funding traffic.
All right, it is the protect mode. I've gone ahead and configured FAA 06 already with protecting and I have shut down set on F A 02 and we'll go through what each of those look like again.
So Charles shouldn't port security here. If you guys can show running configures a phenomenal resource, you can look att tthe e port security mode. Show port security is going to show you the few port security settings and I'll show you the
port said it's enabled on along with their violation modes show interfaces F A zero to will show if it's, um, every disabled or not. Remember the show I p interface brief will not show our disable those or say it's down
the show Port security interface FAA Zahra to is going to show, you know, the last Mac, it's actually gonna show the violation. Mom is going to show your counters if you have counter, if you have enabled gonna show your port status. You know, secure ops here, here, down.
So remember, restrict will send log messages as an MP messages and create increment that violation counter, whereas protect is not going to do that.
Both modes air. Still gonna ford the good traffic and discard the bad traffic. Where I shut down is gonna kill that port and put it into air disabled mode.
He's gonna bring up the party session here
so I'm gonna show you the show run commands a quick half a zero to.
So we still have our description on their Kelly where you are, mode enabled, and I have a Mac address sticking on there
just because I love sticky, and it's so much easier and typing it up.
So remember where this is under the shutdown mode, because that is the default mode for port security. As if if we go to weaken just to get the Pharaoh, go to six.
You see the violation motors under protect
both Somerset. Both enabled.
Now, if we do, I'll show you show ports security.
We're gonna see 02 is under shut down 06 under protect.
And both, um, have zero violations.
Remember, the protect is not gonna show violation counts.
It's gonna make it a lot more difficult to troubleshoot.
show. Interfaces FAA 02
So we're connected. It's working.
We have not pop for security yet.
And lastly, we'll do a show port security interface at 02
We are secure up for violation of is shut down.
We have one total Mac address for maximum with one on there. We have zero security violation. What I'm doing to go ahead and pop on and our device on the FAA zero to and we'll watch this
All right. So hopefully should be. Let's see, we got up and we'll give it a second. It should go to Port Security or disable soon.
Alright, there we go.
So now we air disabled. So let's go back through. See what changed? So we would show it Run interface FAA 02
So that still shows the same thing. That hasn't changed at all. So if we do a show Port Security,
the only thing that really changed is we haven't we have a violation count? It doesn't say the status of the port, but we do have a violation count. Now
let's run a show interfaces F A's or two status.
Boom. Here we go. They're disabled.
So we have something now. We have no something to chase,
So show ports security interface. FAA 02
and we have one violation counts.
I'm gonna go ahead and just shut the interface down.
Shoot. I'm gonna go ahead and remove that
offending device from
best Ethan. That too. And go ahead and plug it into fast. He's in at six, and we'll see what the difference looks like. They're
all right. So we're back.
So I'm gonna run a no Shut up on that phaser. What's useful? Get that one back up,
And let's see if anything changed for F A 06 where this one is under the restrict or protect mode. Excusing,
and nothing changed. Let's do a show. Port Security.
Remember, we're not going to see a violation count on this one.
We'll see if we have anything under show interface, a vase or two. Status
still says connected. Show
port Security interface. FAA 02
Okay, and where you are? Still secure up in violation count zero.
But there is a defending her elf offending device. Flooded, eh? Phase or six. This is why this one's particular player difficult to troubleshoot.
So let's try the show run interface F A 06 while we have this one up here.
So here is the way you can tell. Look at the two Mac addresses.
Your last source. Mac was here, whereas this is the one that's actually enables for the poor.
That's how you're going to tell in this one.
It's a lot more difficult, whereas if we were to go into
here a phaser six, how much we're going to shut it down.
Bridget Swissport Port Security violation to restrict.
And we'll do a no shuts. Wash how fast it goes up and down.
No, that one won't go down. Remember?
But we do have violation counters.
I'm actually gonna stop the pink so these aren't going off like crazy.
Clear why? That's just gonna keep sending violations. So we'd run a show. Ron Interface, FAA 06
now we're getting violation counters
and show her face phase or two status.
We're still connected. So remember, it's not gonna It's only discarding that offending traffic. It's still gonna love that good traffic all through. So I could plug in Mylar device and pink right through without an issue that wouldn't have to shut. No. Shut the port.
And if we do a show port security interface. FAA 06
and we'll see what Mac addresses show run interface. If a 06
we had different Mac addresses as well.
So it's another way to check.
All right, we're gonna go ahead and move on to the post assessment here.
What is the violation mode if he status of the port has error disabled. Hopefully, you get this one by now.
Yes, it is the shutdown mode
in the next episode in the last episode for this module. Actually, we're gonna go ahead and look a troubleshooting dealings and villain trunks.
As always, If you have any questions, need any help? Feel free to shoot a message. Otherwise, thank you for washing this lesson. And I look forward to seeing the next one.