09-19-201201:37 PM - last edited on 03-25-201904:21 PM by ciscomoderator
Can I run an EEM script to shut down a switch port when it disconnects? or is there any other way to do that with any other script? I'm trying to save my network from pen testers. I have pretty much locked down everything but last time when they showed they pulled a cable from a printer and connected their laptop and started testing. printer was set to use NAC profile and they spoofed the MAC address. they I'm open to other solution and ideas if mine is not the best one.
Yes you can use EEM script but I will suggest you to use SNMP trap when ever there is any interface down . you can set up email alerts with SNMP trap.
Please see DEMO EEM script and you can change it according to you need.
event manager applet highcpu event snmp oid "184.108.40.206.220.127.116.11.18.104.22.168.1.10.1" get-type exact entry-op ge entry-val 50 exit-op le exit-val 5 poll-interval 5 action 1.0 cli command "enable" action 2.0 cli command "show proc cpu sorted" action 3.0 mail server "172.18.24.31" to firstname.lastname@example.org from "email@example.com" subject "High CPU Alert" body "$_cli_result"