Home > Port Security Lab Sim

Port Security Lab Sim

September 14th, 2010 in LabSim Go to comments

Question

You are the network security administrator for Big Money Bank Co. You are informed that an attacker has performed a CAM table overflow attack by sending spoofed MAC addresses on one of the switch ports. The attacker has since been identified and escorted out of the campus. You now need to take action to configure the switch port to protect against this kind of attack in the future.

For purposes of this test, the attacker was connected via a hub to the Fa0/12 interface of the switch. The topology is provided for your use. The enable password of the switch is cisco. Your task is to configure the Fa0/12 interface on the switch to limit the maximum number of MAC addresses that are allowed to access the port to two and to shutdown the interface when there is a violation.

PortSecuritySim_Title.jpg

Answer and Explanation

The purpose of this sim is straightforward:

  • Limit the maximum number of MAC addresses that are allowed to access the port to two.
  • Shutdown the interface when there is a violation.

Please remember that we have to access interface Fa0/12 to fulfill the requirements. Before making any configuration, we should use the show running-config to check the status of interface Fa0/12

Switch>enable
Password: cisco

Switch#show running-config

show-running-config.jpg

The interface Fa0/12 hasn’t been configured with anything.

Switch#configure terminal
Switch(config)#interface fa0/12
Switch(config-if)#switchport mode access

First, enable the “port security” feature on this interface:

Switch(config-if)#switchport port-security

Set the maximum number of secure MAC addresses for this interface to 2:

Switch(config-if)#switchport port-security maximum 2

Shutdown if the security is violated:

Switch(config-if)#switchport port-security violation shutdown
Switch(config-if)#no shutdown
Switch(config-if)#end

Now you should check if the configuration is correct or not by typing the command show port-security interface fa0/12

Switch#show port-security interface fa0/12

show_port-security_interface.jpg

Notice that the parameters should be like this:
+ Port Security: Enabled
+ Violation Mode: Shutdown
+ Maximum MAC Address: 2

Save the configuration
Switch#copy running-config startup-config

Just for your information, when the security is violated the port is in the error-disabled state. We can bring it out of this state by entering the “errdisable recovery cause psecure-violation” global configuration command or we can manually re-enable it by entering the “shutdown” and “no shutdown” commands in the interface configuration.

Comments
  1. michael
    August 22nd, 2010

    All I can say is very simple but I really mean it

    THANK YOU

  2. Gerson
    August 23rd, 2010

    wow really easy sim in comparssion to ccna sims…

  3. narayana
    August 25th, 2010

    is this come in ccna security, pls tell me . next month i am going to write this exam

  4. securitytut
    August 26th, 2010

    Yes, this is the sim many candidates have seen in their exams.

  5. bullrem
    August 26th, 2010

    Thank you.
    Say me you has more example lab about CCNA SECURITY

  6. JOJO
    August 28th, 2010

    Hi,
    Is there anymore i can view besides this port Security one?
    I plan on taking this exam next week.

    The other ones i see there is no picture or info when i click.
    Thanks

  7. securitytut
    August 29th, 2010

    In the real exam you will see 3 sims. One of them is “Port Security” as shown above. We will try to update these 2 sims soon.

  8. Romy
    August 29th, 2010

    great job done securitytut..

    looking forward to the other sims also..

    regards
    Romy

  9. Curious
    September 14th, 2010

    Just wondering, you dont need to input “switchport port-security violation shutdown
    ” right? This is the default setting when enabling port-security on an interface.

  10. securitytut
    September 14th, 2010

    Yes, “shutdown” is the default setting so we don’t need to type that command but in the real exam we should type it.

  11. ~!n.o.c.e!~
    September 15th, 2010

    Hi,
    do we need to type

    switchport portsecurity macaddress sticky

    or is the port security sticky enabled by default

  12. andy
    September 18th, 2010

    please anyone update the latest dumps? testinside V6.11 still valid?

    Thanks

  13. Iceman24ccs
    October 14th, 2010

    Si intentas colocar el comando “switchport port-security macaddress sticky”, el programa te informa que el comando no es valido en la simulación, por lo que no es necesario colocarlo; aunque si debería ser colocado en situaciones reales.
    Saludos

  14. Kuru
    October 31st, 2010

    I have doubt in the following question

    Select two protocols from the following to enable cisco sdm to pull ips alerts from a cisco isr router
    tftp syslog
    sdee sdee
    ssh ftp
    https tftp
    ssh
    https
    the first coloumn of option is from the p4s and second tis. The ans they have given is sdee and https. I think sdee and syslog. Any suggestion?

  15. tholemu
    November 25th, 2010

    this is the configuration I used on the exam a few weeks ago, and was given a 75% on layer 2 security portion of exam. one of my colleagues had this exact same outcome, so I am not sure, but there may be an issue with the exam. We both did ‘copy running-config startup-config’ as well as the ‘show’ command.

    any thoughts?

  16. Yagnik
    November 30th, 2010

    Hello,
    Yesterday I gave exam and I cleared it with 977/1000 . I had above simulator in exam
    . I did execute all the same instructed commands still when i did “sh port-security int f0/12″
    it showed
    Port Security: disabled
    Violation Mode: Shutdown
    Maximum MAC Address: 2

    I am pretty sure i had executed all commands and did “sh” and “no sh ” on port 12 couple of times . I did over 2 – 3 times same config still nothing happend.

    I got 75% marks in the exam can anyone explain my mistake so that no 1 repeats them in future. Also i guess that there is some issue in exam

  17. Yagnik
    November 30th, 2010

    switchport port-security mac-address sticky

    I guess we need to add this command .
    I asked my friend who had appeared a month ago he said this command is missing
    any ways . I passed . TY securitytut !!

  18. sashidhar
    December 1st, 2010

    @Yagnik
    brother pls mail the latest dumps u read to my mail id sashidhar06@gmail.com

    r the latest dumps still valid and are all questions coming from dumps pls share u r experience
    thanking u
    sashidhar

  19. Yagnik
    December 1st, 2010

    @sashidhar go through evry question of this website you surely will pass!! I will mail you some important links any ways

  20. joe
    December 4th, 2010

    Hai friends

    pls tell me the best book for ccna sec.anyone have the link pls post

    Thanks in advance

  21. Ahmed tantawy
    December 12th, 2010

    It is very good sim i have passed ccna and i wont to have ccna security exam to.

  22. Keval
    December 19th, 2010

    Hi Shasidhar,

    If you have cleared your exam, will u share the latest dumps.
    my e-mail id is kevalthanki1987@gmail.com

    Thanks in advance
    Keval

  23. Sashidhar
    December 20th, 2010

    http://www.examcollection.com/640-553.html
    For this site you need to download virtual cert exam first. (any old version will do). Just download it after searching this
    software with crack in google.

    http://www.careercert.info/2009/08/ccna-security-study-material.html
    all the books ,dumps , videos from this site

    http://www.securitytut.com
    this site you already know. It has all the rite answers becoz in some dumps pdf answer are marked wrong.

    http://ccna-ccnp-ccsp-ccie-training-gurgaon.blogspot.com/search/label/CCNA%20Security%20640-553

    ALL THE MATERIAL FOR CCNA SECURITY

    IF ANYBODY HAS NEW DUMPS PLEASE GIVE LINK

    Thank u

  24. Chi Chung
    December 23rd, 2010

    I got 1000 in exam yesterday.
    I had above simulator in exam and the answer securitytut provided was right.

    I have entered “switchport port-security mac-address sticky” in exam but the simulator said the command was not support.

  25. jtbouy
    December 30th, 2010

    This site is wonderful!!! I made it even within all odds and pressures. Looking forward to writing my CCSP exams soon. Thanks guys!

  26. nford
    January 21st, 2011

    Yagnik … You do not need mac-address sticky…It says nothing about making the port specific to accepting only certain mac-address but only allowed to two…

  27. ivartyn
    February 23rd, 2011

    @Securitytut: The default settings for port security when enabled are:
    1. Accept a maximum of 1 mac address
    2. Shutdown on violation

    Is it necessary then that we should put the command –
    switchport port-security violation shutdown

  28. securitytut
    March 6th, 2011

    @ivartyn: In fact we don’t need to use that command because it is the default behavior of the router when the security policy is violated.

  29. shiplu
    March 8th, 2011

    I’m need guideline about ccna security lab…..insoanki@gmail.com my mail address….plz help me

  30. kufana
    March 29th, 2011

    i also need a guideline about ccna security labsim, because i just wrote my ccna and i did’nt
    understand the labsim,i was really confused.please help me.(dekuftelecom@yahoo.com)

  31. naveed
    April 8th, 2011

    I just cleared my ccna security yesterday…. got 1000… so yes .. all the answers here are correct and all the sims are absolutely correct….

    i have the latest dumps aswell… if anyone of you need it … mail me at

    naveedquadri@gmail.com

    will be glad to help….

    i am plannin to give my ccsp now… anyone who is also opting for same line… please get in touch …. i need the dumps for ccsp.

    Best of luck everyone!

  32. myself
    April 13th, 2011

    Did test yesterday, got 1000/1000. This is the only true “lab” in the sense of configuring something. Other “labs” are just answering questions after looking at different screens of SDM.

    2 things:
    I did issue the command “switchport port-security violation shutdown” just in case, although I knew it was the default.
    I did “shutdown” followed by “no shutdown”. Twice!

    Those two did not make any difference: in the running config, there was no line under f0/12 saying anything about violation (I guess it’s because this is the default). When issuing command “show port-security interface f0/12″, the port status was secure-down. I’m not sure if this is the right status (why not secure-up?) after shut+no shut, but being a perfect score, I guess it’s correct.

    Do not forget to save your config (copy run start).

    All material on this site is valid, as is http://www.examcollection.com/cisco/Cisco.TestInside.640-553.v2010-08-27.by.noname.137q.vce.file.html from examcollection. Please be advised that in this dump there are two WRONG D&D: 130 and 133. You can find the right answers in questions 56 and 89, respectively.

    Good luck everyone and thanks securitytut.

  33. Netherdrake
    April 19th, 2011

    Yagnik,

    And I’m pretty sure you missed out, typing the command that actually enables port security:

    #switchport port-security

    Once this has been typed in, the port is enabled for PS and any other configuration follows(sticky/violation/static mac). It’s easy to combine and miss the above command since students think starting off with “switchport mode access” OR “switchport port-security maximum 2″ is sufficient enough to get the job done.

    Summary: DO NOT skip #switchport port-security before entering the violation/maximum arguments.

  34. afridi
    May 5th, 2011

    @ Every body…
    Please help me. I got my ccna… please guide me how to get start…

  35. Netherdrake
    May 12th, 2011

    @afridi,

    You need to study. Grab Todd Lammle’s book and study the first few chapters for your basics.

  36. Mike P
    May 12th, 2011

    Does anyone have the Testking 640-553 pf so I can get a copy. If so please send it to email address mylife69_2000@yahoo.com

  37. Robert
    May 23rd, 2011

    Hi all, just pass my ccnas exam. This site still valid. Thanks securitytut.

  38. Waleed
    May 26th, 2011

    @ Robert – Would you please send me the latest dumps by which you passed your exam?
    I have my CCNA Security exam on 3rd June 2011.

    If u have please mail me at: spyofhearts88@yahoo.com

    Thanx :-)

  39. Sourabh
    May 26th, 2011

    @ Robert – please send me a copy of the latest dumps @ skrocks22@gmail.com ,,
    thanksssss

  40. nizar0j
    June 2nd, 2011

    i do it all above steps but my result :
    port security :enable
    port status :secure-up (not down)
    violation mode :shutdown
    this was my problem
    but after change the confige fa0/12
    from no shutdown to shutdown
    he give me same your result
    Is this correct …؟؟؟
    Thank you 9tut

  41. SOFIANE
    June 4th, 2011

    WALEED WOULD YOU PLZ SEND ME DUMPS AND EXAMS YOU GET ABOUT CCNA SECURITY AT

    AERAQUA14@YAHOO.FR THANK U

  42. Rohann
    June 4th, 2011

    Hi All,

    I have given exam and passed with 1000/1000. Studied as follows-
    1. Simlets and lab – used securitytut (100 % valid)
    2. Questions- Testinside Ver 6.12 (Q.137)
    3. CISCO Official certification guide,CCNA Security Authorized Self-Study Guide
    Passing score – 804/1000
    Time- 120 mins (India)

  43. Dabang
    June 5th, 2011

    How much does the exam cost in India?

  44. nizar0j
    June 5th, 2011

    Congratulations! Rohann
    Please try to send me dumps on my email
    eng_nizar0j@hotmail.com
    thanks

  45. yarhim
    June 10th, 2011

    hi today i atten the ccna sec 640-553 i passed score 955 same dumps noname 137 q still dumps valid

  46. MOH
    June 15th, 2011

    Yo guys i just passed my exam today with the total score of 988/1000
    Thanx to u all

  47. TCR
    June 20th, 2011

    Many thanks…passed 2day with 977/1000

  48. delete
    June 23rd, 2011

    inmate is noname still current? and any update on CCNA security dump

  49. Anonymous
    June 24th, 2011

    Yarhim and MOH how many SDM are on the exam? there is only one on this site? what material did your study? thks

  50. WALTER
    June 24th, 2011

    Can some one send a copy of testking pdf WRUSSELL06@YAHOO.COM Thanks

  51. JSK
    June 30th, 2011

    I understand all of the necessary configurations for this particular lab sim. However, why is the “no shutdown” command needed. Isn’t the fa0/12 interface already up and running?

  52. Visitor
    July 15th, 2011

    Whenever you configure the interface it is always in the down (shut) position so you have to bring it up.

  53. Dvd83
    August 12th, 2011
  54. Ratheesh
    August 15th, 2011

    Hi friends,

    Anybody have CCNA Security Latest dumps. I have to attend the exam in another 3 days.

    rathravin@gmail.com

    regards
    Ratheesh

  55. cisco
    August 16th, 2011

    Hi Ratheesh,

    Can you please share your experience after exam as I’ve my exam on 19th August 2011? I want to know whether questions are still valid or not!

    thanks,
    Cisco

  56. Pravin
    August 19th, 2011

    Could someone please send me latest dumps for ccna security.

    praveenkale87@gmail.com

    Thanks…

  57. Obinna
    September 27th, 2011

    Please can anyone tell me where i can find video lectures for CCNP Secirity: 642-617, 642-627, 642-637, 642-647. i would really appreciate it.

    juniorpsalm@yahoo.com

  58. Lagosian
    September 27th, 2011

    Pls assist me with the latest dump for 640-553. My email is mamakola@hotmail.com. Thanks.

  59. Masterbone
    October 13th, 2011

    Taking Security Exam tomorrow…. The onto CCNP IPS Exam.. please send any info for CCNP IPS exam my way please… thank you.. jarvizel1@gmail.com

  60. CCNA SEC
    October 13th, 2011

    HI Masterbone,
    Could you please let us know your experience and is the site still valid ?

    Wish you good luck !!!!!

  61. Tendai1984
    October 26th, 2011

    Guys, anyone with latest CCNA SECURITY dumps

  62. Alinio
    November 1st, 2011

    to “myself”. I want to say that the correct answer at q133 is ” Acces-list will prevent address spoofing from interface E0. For detailed explantion go to page 357 from Kevin Wallce’s books CCNA Security Official Exam Certification Giude, chapter 10 , subtitle Preventing IP Spoofin with ACLs

  63. 6u9t@
    November 4th, 2011

    Passed today..dumps still valid….but I think there is a problem with this lab in the exam…I did all configuration and still scored 75%…Can we look at the config commands again…
    Most of question were drag and drop…with multi choice answers…everything on this site is legit….Thank You securitytut..
    link for the dumps
    http://www.examcollection.com/cisc/Cisco.CertKey.640-553.v2011-08-15.by.Spike.165q.vce.file.html

  64. Attila
    November 18th, 2011

    I’m keep trying to configure the SDM on GNS3 for a week but I have the same result, when the sdm starts loading it shows “Please wait while sdm is loading the current configuration from your router. Discovering router hardware attributes.”
    So now I’m looking for somebody who could help me to set up a virtual lab on mine or for remote login for some paypal donation.
    Please contact me if you have some free time for some money, contact me on kelenyi@gmail.com
    Thanks,
    Attila

  65. isuru bandaranayake
    January 17th, 2012

    please any one can send me a valid ccna security dump. please

    imisuru88@yahoo.com

  66. Johnna
    February 14th, 2012

    PLEASE CAN SOMEONE TELL ME HOW TO OPEN THIS LAB ON PACKET TRACER TO PRACTICE THE COMMAND. THANK YOU VERY MUCH GUYS, WISH EVERYONE THE BEST WITH THEIR STUDIES.

  1. No trackbacks yet.
Add a Comment