Kommutatsiya jadvallari to`ldirilishiga yo`naltirilgan hujumlardan, tarmoqni himoya qilish imkonini beruvchi kommutatorning "port-security" funksiyasini sozlash bo`yicha amaliy ko`nikmalarga EGA bo’lish
Xavfsizlik buzilishiga javob berish (реагирование) rejimini sozlash
Download 342 Kb.
|
2 laboratoriya ishi kommutatorda port xavfsizligi (port security
- Bu sahifa navigatsiya:
- Port-security sozlanishlari haqidagi ma’lumotlarni ko`rish
Xavfsizlik buzilishiga javob berish (реагирование) rejimini sozlashXavfsizlik buzilishiga javob berish ning uchta usuli mavjud: switch(config-if)# switchport port-security violation switchport port-security violation restrict – buzilishga javob berish rejimini ko`rsatish. Bunda, agar interfeysda uchinchi notanish MAC-manzil paydo bo`lsa, undan keluvchi barcha paketlar qabul qilinmaydi. Undan tashqari syslog, SNMP trap, violetion counter ka`bi jurnallashtiruvchilarga xabar jo`natiladi. switchport port-security violation shutdown- buzilish aniqlanganda interfeysni error-disabled holatiga o`tkazadi va o`chiradi. Undan tashqari syslog, SNMP trap, violetion counter ka`bi jurnallashtiruvchilarga xabar jo`natiladi. Ushbu holatdan chiqarish uchun shutdown va no shutdown buyruqlaridan foydalaniladi. Agar interfeysga switchport port-security violation protect buyrug`i kiritilgan bo`lsa, unda notanish MAC-manzil paketlari qabul qilinmaydi va xech qanday xabar yaratilmaydi, hamda port shutdown holatiga o`tmaydi. Ushbu usullardan switchport port-security violation restrict ko`pchilik hollarda tavsiya etiladi. MAC-manzillar jadvalini tozalash Boshqa qurilmalar ulanishi uchun MAC-manzillar jadvalini tozalash: switch# clear port-security [all|configured|dynamic|sticky] [address switch #clear port-security all switch #clear port-security configured switch #clear port-security dynamic switch #clear port-security sticky Port-security sozlanishlari haqidagi ma’lumotlarni ko`rishswitch# show port-security switch# show port-security interface fa0/3 switch# show port-security address Topshiriq 2.4-rasmda keltirilgan tarmoq topologiyasini Cisco Packet Tracer dasturida tuzish talab qilinadi; Har bir kompyuter uchun IP manzilni sozlang va MAC manzillarni 2.2-rasmda ko`rsatilgandek aniqlang; Kommutatorning har bir portlariga xavfsizlik ko`rsatkichlarini sozlang; 2.1-jadvalga yuqorida keltirilgan topshiriqlarni kiriting. 2.4-rasm. Tarmoq topologiyasi. 2.1-jadval
Ishni bajarish tartibi Switch>enable Switch#configure terminal Switch(config)#hostname Sw1 Sw1(config)#interface fa0/1 1. Portni access rejimiga o`zgartirish Sw1(config-if)#switchport mode access 2. Portda port-securityni ishga tushurish Sw1 (config-if)#switchport port-security 3. Secure-MAC ni dinamik aniqlashni ko`rsatish Sw1 (config-if)#switchport port-security mac-address sticky Sw1 (config-if)#exit 4. Secure-MAC ni statik aniqlashni ko`rsatish Sw1(config)#interface fastEthernet 0/2 Sw1(config-if)#switchport mode access Sw1(config-if)#switchport port-security Sw1(config-if)#switchport port-security mac-address 000B.BE9B.EE4A Sw1(config-if)#end 5. Xavfsizlik buzilishigi javob berish rejimini sozlash Sw1(config)#interface fastEthernet 0/3 Sw1(config-if)#switchport mode access Sw1(config-if)#switchport port-security Sw1(config-if)#switchport port-security mac-address sticky Sw1(config-if)#switchport port-security violation protect Sw1(config-if)#end 6. Ishlatilmayotgan portlarni o`chirish Sw1(config)#interface range fastEthernet 0/5-24 Sw1(config-if-range)#shutdown 7. Portda secure-MAC maksimal soni N ni ko`rsatish (Bu buyruq Sw2 kommutatorga tavsiya etiladi) Switch>enable Switch#configure terminal Switch(config)#hostname Sw2 Sw2(config)#interface fa0/4 Sw2(config-if)#switchport mode trunk Sw2(config-if)#switchport port-security maximum 4 Sw1(config-if)#switchport port-security violation restrict 8. Natijani tekshirish Switch#show port-security interface fa 0/1 Port Security : Enabled Port Status : Secure-up Violation Mode : Shutdown Aging Time : 0 mins Aging Type : Absolute SecureStatic Address Aging : Disabled Maximum MAC Addresses : 1 Total MAC Addresses : 0 Configured MAC Addresses : 0 Sticky MAC Addresses : 0 Last Source Address:Vlan : 0001.63B4.E4A6:1 Security Violation Count : 0 9. Sozlamalarni saqlash Switch#copy running-config startup-config Download 342 Kb. Do'stlaringiz bilan baham: |
Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©fayllar.org 2024
ma'muriyatiga murojaat qiling
ma'muriyatiga murojaat qiling