BOOTP,CDP,FTP,TFTP,NETP,PAD,TCP/UDP
Service tcp-small-servers
Service udp-small-servers
TCP 的 ping 其实就是 telnet ,哈哈 Telnet 12.1.1.1 daytime 可以回显时间,后面可以跟很多功能 Service timestamps log datetime localtime
No ip redirects 关闭 ICMP 重定向 Switchport port-security mac-add 0030.80f1.d6c2
Switchport port-security violation
Restrict 限制,可以接续工作,但是会发送报警消息 Shutdown 违反了直接就 shutdown 了 Errdisable recovery interval 全局定义恢复时间单位为秒 Err-disable 要想恢复要先 shutdown 然后再 no shutdown Sw port-security mac-address sticky 粘性 动态学到的东西,会将学到的 Mac 地址进行保存 Aaa authentication dot1x
default group tacacs+
Dot1x system-auth-control
Tacacs-server host 192.168.1.10
Switchport mode dynamic desirable
Ac 1 permit
192.168.1.0 0.0.0.255
Vlan filterxixi vlan-list
Private-vlan association 200,300 关联 Vlan Switchport mode private-vlan host
Switchport mode private-vlan host-association 100 200
Switchport mode private-vlan host
Switchport mode private-vlan host-association 100 300
DHCP 欺骗攻击 DHCP Spoof Attacks Ip dhcp snooping Vlan 500
Ip verify source port-security
Ip source binding 00c0.83hf.1234 vlan 100 192.168.100.1 interface f0/4
Ip arp insection limit rate 20 限制每秒接收的 arp 包 Ip arp inspection vlan 500
本文转自 Jhuster 51CTO博客,原文链接:http://blog.51cto.com/xwnet/171811,如需转载请自行联系原作者