On which interface can port security be configured?

QuestionsCategory: 300-115On which interface can port security be configured?
Admin Staff asked 3 months ago
On which interface can port security be configured?

A. static trunk ports

B. destination port for SPAN

C. EtherChannel port group

D. dynamic access ports








 

Suggested Answer: A

Port Security and Port Types -
You can configure port security only on Layer 2 interfaces. Details about port security and different types of interfaces or ports are as follows:
✑ Access ports  You can configure port security on interfaces that you have configured as Layer 2 access ports. On an access port, port security applies only to the access VLAN.
✑ Trunk ports  You can configure port security on interfaces that you have configured as Layer 2 trunk ports. VLAN maximums are not useful for access ports.
The device allows VLAN maximums only for VLANs associated with the trunk port.
✑ SPAN ports  You can configure port security on SPAN source ports but not on SPAN destination ports.
✑ Ethernet Port Channels  Port security is not supported on Ethernet port channels.
Reference: http://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/4_1/nx-os/security/configuration/guide/sec_nx-os-cfg/sec_portsec.html

These are some other guidelines for configuring port security:
Port security can only be configured on static access ports. A secure port cannot be a dynamic access port or a trunk port. A secure port cannot be a destination port for Switch Port Analyzer (SPAN). A secure port cannot belong to an EtherChannel port group. A secure port cannot be an 802.1X port. You cannot configure static secure MAC addresses in the voice VLAN.
Reference: https://supportforums.cisco.com/t5/network-infrastructure-documents/unable-to-configure-port-security-on-a-catalyst-2940-2950-2955/ta-p/3133064

This question is in 300-115 Implementing Cisco IP Switched Networks (SWITCH) Exam
For getting Cisco Certified Network Professional (CCNP) Routing and Switching Certificate





Disclaimers:
The website is not related to, affiliated with, endorsed or authorized by Cisco.
Trademarks, certification & product names are used for reference only and belong to Cisco.
The website does not contain actual questions and answers from Cisco's Certification Exam.

Recommended

Welcome Back!

Login to your account below

Create New Account!

Fill the forms below to register

Retrieve your password

Please enter your username or email address to reset your password.