<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Layer 2 port channel security in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/layer-2-port-channel-security/m-p/3216562#M547355</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have 2 Cisco switches connected via a layer 2 port channel (trunk). LACP. 1 Catalyst 9300, 1 Catalyst 3650.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to configure authentication between the switches on the port channel so that the 9300 will only allow that specific 3650 to connect on that port channel. This is because the 3650 is not in a secure location and anyone may be able to connect to that uplink.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The switches won't let me do switchport port-security.&lt;/P&gt;
&lt;P&gt;What would be the best way to do this? I was thinking 802.1x with local authentication but I don't know if that would work or how to configure it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Waqas&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:39:03 GMT</pubDate>
    <dc:creator>waqas gondal</dc:creator>
    <dc:date>2020-02-21T18:39:03Z</dc:date>
    <item>
      <title>Layer 2 port channel security</title>
      <link>https://community.cisco.com/t5/network-access-control/layer-2-port-channel-security/m-p/3216562#M547355</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have 2 Cisco switches connected via a layer 2 port channel (trunk). LACP. 1 Catalyst 9300, 1 Catalyst 3650.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to configure authentication between the switches on the port channel so that the 9300 will only allow that specific 3650 to connect on that port channel. This is because the 3650 is not in a secure location and anyone may be able to connect to that uplink.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The switches won't let me do switchport port-security.&lt;/P&gt;
&lt;P&gt;What would be the best way to do this? I was thinking 802.1x with local authentication but I don't know if that would work or how to configure it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Waqas&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/layer-2-port-channel-security/m-p/3216562#M547355</guid>
      <dc:creator>waqas gondal</dc:creator>
      <dc:date>2020-02-21T18:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 port channel security</title>
      <link>https://community.cisco.com/t5/network-access-control/layer-2-port-channel-security/m-p/3216938#M547356</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Waqas,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Your switches are the latest generation, you can use MACSec between the two switches. MACSec provides per-link authentication and encryption between the switches. I haven't tried this myself yet, but you should be able to do this. Have a look at this &lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/37e/consolidated_guide/b_37e_consolidated_3850_cg/b_37e_consolidated_3850_cg_chapter_01110101.html#task_CCBD6C0C4B07493BB5531708AE622C61" target="_self"&gt;document&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Alternatively you could use NEAT, if you have ISE/ACS infrastructure and you authenticate your users with dot1x. Check this guide on &lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/15-e/sec-usr-8021x-15-e-book/sec-ieee-neat.pdf" target="_self"&gt;NEAT&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Agris&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please rate if helpful&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 11:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/layer-2-port-channel-security/m-p/3216938#M547356</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-11-15T11:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2 port channel security</title>
      <link>https://community.cisco.com/t5/network-access-control/layer-2-port-channel-security/m-p/3217283#M547357</link>
      <description>Thanks</description>
      <pubDate>Wed, 15 Nov 2017 21:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/layer-2-port-channel-security/m-p/3217283#M547357</guid>
      <dc:creator>waqas gondal</dc:creator>
      <dc:date>2017-11-15T21:45:17Z</dc:date>
    </item>
  </channel>
</rss>

