Cisco 2970 - Catalyst Switch Especificaciones Pagina 384

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 674
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 383
19-6
Catalyst 2970 Switch Software Configuration Guide
78-15462-03
Chapter 19 Configuring Port-Based Traffic Control
Configuring Port Blocking
This example shows how to configure Gigabit Ethernet interface 0/1 as a protected port:
Switch# configure terminal
Switch(config)# interface gigabitethernet0/1
Switch(config-if)# switchport protected
Switch(config-if)# end
Configuring Port Blocking
By default, the switch floods packets with unknown destination MAC addresses out of all ports. If
unknown unicast and multicast traffic is forwarded to a protected port, there could be security issues. To
prevent unknown unicast or multicast traffic from being forwarded from one port to another, you can
block a port (protected or nonprotected) from flooding unknown unicast or multicast packets to other
ports.
Default Port Blocking Configuration
The default is to not block flooding of unknown multicast and unicast traffic out of a port, but to flood
these packets to all ports.
Blocking Flooded Traffic on an Interface
Note The interface can be a physical interface (for example, Gigabit Ethernet 0/1) or an EtherChannel group
(for example, port-channel 5). When you block multicast or unicast traffic for a port channel, it is
blocked on all ports in the port channel group.
Beginning in privileged EXEC mode, follow these steps to disable the flooding of multicast and unicast
packets out of an interface:
To return the interface to the default condition where no traffic is blocked and normal forwarding occurs
on the port, use the no switchport block {multicast | unicast} interface configuration commands.
This example shows how to block unicast and multicast flooding on Gigabit Ethernet interface 0/1:
Switch# configure terminal
Command Purpose
Step 1
configure terminal Enter global configuration mode.
Step 2
interface interface-id Enter interface configuration mode, and enter the type and
number of the interface to configure, for example
gigabitethernet0/1.
Step 3
switchport block multicast Block unknown multicast forwarding out of the port.
Step 4
switchport block unicast Block unknown unicast forwarding out of the port.
Step 5
end Return to privileged EXEC mode.
Step 6
show interfaces interface-id switchport Verify your entries.
Step 7
copy running-config startup-config (Optional) Save your entries in the configuration file.
Vista de pagina 383
1 2 ... 379 380 381 382 383 384 385 386 387 388 389 ... 673 674

Comentarios a estos manuales

Sin comentarios