Cisco CCNA (200-301)Network AccessMedium
A network administrator is reviewing the configuration of a Cisco Catalyst switch for security best practices. The administrator notices that several access ports are configured with 'switchport mode dynamic auto'. The security policy dictates that ports connected to end devices should not negotiate trunking. Which command should the administrator use on these access ports to prevent them from potentially forming a trunk link, while still allowing them to function as access ports?
- Aswitchport mode dynamic desirable
- Bswitchport mode access
- Cswitchport mode trunk
- Dswitchport nonegotiate
Show answer & explanationAnswer & explanation
Correct answer: B. switchport mode access
Configuring 'switchport mode access' explicitly sets the port to permanent access mode, preventing it from forming a trunk. This addresses the security policy to ensure ports connected to end devices do not negotiate trunking.
Why the other options are wrong
- A. This command sets the port to actively attempt to form a trunk, which violates the security policy.
- C. This command forces the port into trunking mode, which violates the security policy.
- D. The 'switchport nonegotiate' command prevents DTP from sending/receiving, but the port remains in its current mode (e.g., 'dynamic auto' would still be access but wouldn't negotiate a trunk if connected to another switch in 'desirable' or 'auto'). However, 'switchport mode access' is more explicit for end-device ports.
Switchport Mode Access
The 'switchport mode access' command configures an interface as a permanent non-trunking Layer 2 access port. It will not attempt to negotiate a trunk link.
- Prevents DTP negotiation.
- Ensures the port operates in a single VLAN.
- A security best practice for end-device ports.
Memory trick: A.C.C.E.S.S. - Always Control Connections, Especially Security-Sensitive.