7/27剛考完300-115, 順便幫忙解惑一下。2 r9 z) o; I1 C0 A9 E
參照cisco文檔:https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/25ew/configuration/guide/conf/port_sec.html#wp1047714
* x% L: h# v' u' q' NDefault Port Security ConfigurationTable 30-1 shows the default port security configuration for an interface. # P& U3 \- o4 L# }. q0 k9 i
[size=1.4]Table 30-1 Default Port Security Configuration Feature Default Setting 0 p" D! S. @- G1 E j. K
[size=1.4]Port security [size=1.4]Disabled on a port ! |3 P S) X2 m w6 Z4 R
[size=1.4]Maximum number of secure MAC addresses [size=1.4]1
) h1 Z+ g/ }; X7 T; j[size=1.4]Violation mode [size=1.4]Shutdown. The port shuts down when the maximum number of secure MAC addresses is exceeded, and an SNMP trap notification is sent.
j7 S9 A5 j/ C2 b[size=1.4]Aging [size=1.4]Disabled ; Z* O8 w6 x, k2 ^
[size=1.4]Aging type [size=1.4]Absolute
' M3 l) m6 C! u- e[size=1.4]Static Aging [size=1.4]Disabled . W- D) _$ r& j3 H, s
[size=1.4]Sticky [size=1.4]Disabled 9 W+ d0 W J, I
Port Security Guidelines and RestrictionsFollow these guidelines when configuring port security: • A secure port cannot be a trunk port. • A secure port cannot be a destination port for Switch Port Analyzer (SPAN). • A secure port cannot belong to an EtherChannel port-channel interface. • A secure port and static MAC address configuration are mutually exclusive. 4 a. {; w/ p, O% p/ U
QUESTION 402 (這題答案A.C沒有問題)! z+ X @$ t+ f& d6 D/ {7 Z# W$ B
Which two restrictions of the port security feature are true? (Choose two.)0 O3 Z2 k; [4 W. g: G8 J- u4 s
A. Static port MAC address assignments are not supported. (正確,secure port與MAC address configuration互斥)
( s7 _6 |" h, R: i. }B. It is not supported on PVLAN ports. (錯誤,支持PVLAN)
( }3 S B& }0 P C7 {, o4 i. u$ DC. It is not supported on EtherChannel port-channel interfaces. (正確)
, O6 g$ d1 X$ `# v8 V: z5 FD. A single device can learn a maximum of three sticky MAC addresses. (錯誤,default值為1)2 J: d6 Y& E# ?- {, M
E. It is supported on destination SPAN ports. (錯誤,不支持)9 @# l9 D/ p7 k$ p2 U: b
# O: f' P- H0 K( hQUESTION 472 (我認為A.B.C皆對,疑似A.B其一敘述中多了not)
! Y5 S9 ?/ S8 v- ~+ q3 u$ cWhich two restrictions of the port security feature are true? (Choose two.), |+ f* F; \1 q: z8 y5 g' y! T
A. It is not supported on destination SPAN ports. (正確)' H0 m$ u* s% z, f4 o3 }& l* ^" p0 g
B. It is not supported on EtherChannel port-channel interfaces. (照答案AC來說疑似B選項多了not)
' S3 R( c s2 V. w4 @" |C. Static port MAC address assignments are not supported. (正確,secure port與MAC address configuration互斥)% \# X) D: s, l) c; Y1 I
D. A single device can learn a maximum of three stick MAC addresses. (錯誤,default值為1)
, b) ?2 R9 s" R( K+ [E. It is not supported on PVLAN ports (錯誤,支持PVLAN)
: A2 f8 Y& E. P0 K5 a7 B% W$ u! r, \: b+ E
2 k# W' y3 K$ o# v
6 g6 b: e i$ c$ B4 S
5 M2 w" | p( Y; }. O |