cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
364
Views
0
Helpful
2
Replies

Port-security is not sending snmp messages on 2960x with ip source guard port-sec enabled

Victor Bidnenko
Level 1
Level 1

We have 2960x switch (WS-C2960X-48LPS-L  15.0(2)EX4   C2960X-UNIVERSALK9-M) and have configured on access ports port-security, ip source guard (IPSG) and also DAI and DHCP snooping enabled globaly on switch. The problem is that when we configure the IPSG with mac check the port security is not working and not sending alarm messages to syslog server. So when we use on port:

ip verify source port-security

port- security is not working. But when we use:

ip verify source

on port all is working properlly (IPSG checks only IP but not mac).

Is it a bug or some our misconfiguration?

2 Replies 2

nspasov
Cisco Employee
Cisco Employee

Can you also post your logging and snmp configuration settings?

Also, the output of show logging

Thank you for rating helpful posts!

Our current config

Our current snmp-server is disabled and maybe in case of comand "ip verify source port-security" switch sends alerts to snmp server but it cannot be reach. But actually it would be strange...

Logging:

logging trap debugging
logging host 192.168.XXX.XXX

SNMP:

snmp-server community XXXXX RO XXXXXXX
snmp-server trap link ietf
snmp-server trap-source VlanXXX
snmp-server source-interface informs VlanXXX
snmp-server enable traps mac-notification change move threshold
snmp-server host XXXXXX XXXXXXXX

show logging:

No Active Message Discriminator.
No Inactive Message Discriminator.

    Console logging: disabled
    Monitor logging: disabled
    Buffer logging:  level debugging, 14963547 messages logged, xml disabled,
                    filtering disabled
    Exception Logging: size (4096 bytes)
    Count and timestamp logging messages: disabled
    File logging: disabled
    Persistent logging: disabled

No active filter modules.

    Trap logging: level debugging, 14517775 message lines logged
        Logging to XXXXXXXXX  (udp port 514, audit disabled,
              link up),
              14517733 message lines logged,
              0 message lines rate-limited,
              0 message lines dropped-by-MD,
              xml disabled, sequence number disabled
              filtering disabled
        Logging Source-Interface:       VRF Name:
Review Cisco Networking for a $25 gift card