Cisco Certified Support Technician (CCST) NetworkingNetwork AccessMedium
A network administrator is configuring a new Cisco switch. The administrator wants to ensure that specific MAC addresses are allowed on a port, and any other MAC addresses attempting to connect will be immediately shut down, requiring manual intervention to re-enable the port. Which port security violation mode should be configured?
- ATrap
- BProtect
- CShutdown
- DRestrict
Show answer & explanationAnswer & explanation
Correct answer: C. Shutdown
The 'Shutdown' violation mode disables the port immediately upon a security violation, placing it in an error-disabled (err-disable) state, and requiring manual intervention (or an auto-recovery timer) to bring it back up. This matches the requirement for immediate shutdown and manual re-enabling.
Why the other options are wrong
- A. Trap is not a standard port security violation mode on Cisco switches; it's an action taken by 'Restrict' mode.
- B. Protect mode drops packets from unauthorized MACs but does not send an SNMP trap or disable the port.
- D. Restrict mode drops packets from unauthorized MACs and sends an SNMP trap, but does not disable the port.
Port Security Violation Modes
Actions a switch takes when an unauthorized device or too many MAC addresses are detected on a port configured with port security.
- Protect: drops unauthorized traffic.
- Restrict: drops unauthorized traffic, sends SNMP trap, increments counter.
- Shutdown: disables the port and puts it in err-disable state.
Memory trick: P-R-S: Protect, Restrict, Shutdown – each more severe.