07-09-2019 05:31 AM - edited 07-09-2019 05:45 AM
Hi everyone,
I'm kinda new to r&s and just started learning through cbt nuggets and got to port security and I have a question:
I made with Packet Tracer a model of normalSwitch-normalPC and "evil" switch-"evil" PC, as the name suggests- it is evil.
so i configured the normal switch's port security with max:1 ,MAC sticky , violation: shutdown so no one else should connect through that port and when I disconnected the normal PC and replaced it with evilSwitch it worked as expected.
BUT when i change violation to restrict the colors between the normal switch and "evil" switch are turning green (!) and no warning is on my console.
Isn't the sticky MAC should disable the evil switch from connecting ? And why there is no warning on the screen ?
Thanks, Eli !
07-09-2019 05:44 AM
07-09-2019 05:52 AM - edited 07-09-2019 05:55 AM
Thanks for the comment,
The security violation count jumped to astronomous amounts- 700~ ! and later on even to 1000~...
(checked by "show port-security interface fa 0/1")
By your explanation it seems i've done everything right...
Edit: Added a screenshot
07-09-2019 06:11 AM
07-09-2019 07:11 AM - edited 07-09-2019 07:24 AM
Appearently there's a bug in pt that doesnt allow me to trace a packet. I'm starting to think I've done everything right.
By the way the counter is incrementing automatically even with no action to trigger it... seems odd...
EDIT: I tried installing gns3 because solving this issue is important to me but this program is REALLY annoying....
Got tons of questions in the installing process and now it wants to connect to a server and fails. this is so fraustrating....
07-09-2019 06:07 AM
The commands below have been run on a Cisco Catalyst 2960 device and help with port-security troubleshooting. I can not be sure if they all work on the packet tracer.
07-09-2019 07:07 AM
07-09-2019 06:19 AM
Hello
Did you save the running config after you enabled port sec mac sticky otherwise the dynamically learn mac isn’t saved to the cam table and it will then have to be relearnt so it’s possible why it allowed you to add a different device
07-09-2019 07:06 AM
10-25-2023 12:11 PM
I've had a similar issue, but on my end on PT restrict mode drops packets as desired but does not increment the violation counter at all. I'm still at 0 violation count despite being in restrict mode and sending about 12 different pings from an unauthorized MAC address. Definitely looking into GNS3 now.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide