Q7Security
Refer to the exhibit. An engineer configures port security on a Cisco Nexus 9000 Series Switch. The requirement is to prevent any newly learned MAC addresses from forwarding traffic on the interface. Also, the already learned MAC addresses must remain unaffected by the changes. Which configuration meets these requirements?
← → navigate · a answer
Community votes
Discussion · 13
A 3
Selected Answer: A
restrict should be the one
2
I think A or B, both could be right.
A 2
Selected Answer: A
Protect—This mode allows traffic from known MAC addresses to keep being forwarded while dropping traffic from unknown MAC addresses when the allowed MAC address limit is exceeded. When configured with this mode, no notification action is taken when traffic is dropped.
Restrict—This mode allows traffic from known MAC addresses to keep being forwarded while dropping traffic from unknown MAC addresses when the allowed MAC address limit is exceeded. When configured with this mode, a syslog message is logged, a Simple Network Management Protocol (SNMP) trap is sent, and a violation counter is incremented when traffic is dropped.
2
I will vote for A - restrict, from Cisco 9000 guide:
Protect mode is not supported on 7.0(3)I5(2) release
B 1
Selected Answer: B
B is correct
A 1
Selected Answer: A
A is correct
Example: Configuring Port Security on an Orphan Port
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/7-x/security/configuration/guide/b_Cisco_Nexus_9000_Series_NX-OS_Security_Configuration_Guide_7x/b_Cisco_Nexus_9000_Series_NX-OS_Security_Configuration_Guide_7x_chapter_010101.html
B 1
Selected Answer: B
I will vote for B, as normally admins should be informed about that incident
1
I had A in mind, with Restrict
B 1
Selected Answer: B
protect and NTFY is set to false in the exhibit
B 1
Selected Answer: B
Protect, because NTFY is F
1
Restrict mode does notify
B 1
Selected Answer: B
For now I think B is right because NTFY = F, but I'm not 100% sure if it is the correct solution
B 1
Selected Answer: B
Since it shows NTFY = F, we know it has to be protect rather than restrict.
Violation modes:
protect: Drops frames from unknown MAC addresses without raising alerts or changing port status. The port stays operational.
restrict: Drops frames from unknown MAC addresses, increments the violation counter, logs a syslog message, and sends an SNMP trap. The port stays up.