Cisco CCNA Certification Exam Tutorial: Port-Based Authentication

Aug 31, 2012 by CaveDeena869

To pass your CCNA exam and earn this coveted certification, you have to realize the details of port-based authentication. This knowledge has a fantastic deal of worth in production networks as nicely, because this authentication scheme is frequently implemented. Let’s take an appear at this certain CCNA ability.

Think about a scenario exactly where you have a server that will be connected to your switch, and you want the port to shut down if a device with a diverse MAC address that that of the switch attempts to connect to that port. You could also have a scenario where you have a person who has a connection to a switch port in his workplace, and he wants to make positive that only his laptop can use that port.

Each of these examples are genuine-planet situations, and there are two solutions for each. First, we could develop a static MAC entry for that distinct switch port. I do not suggest this, mostly since both you and I have better things to do than handle static MAC entries. The much better resolution is to configure port-based authentication on the switch.

The Cisco switch utilizes MAC addresses to enforce port security. With port security, only devices with certain MAC addresses can connect to the port effectively. This is another cause supply MACs are looked at before the destination MAC is examined. If the source MAC is non-secure and port-based authentication is in impact, the destination does not matter, as the frame will not be forwarded. In essence, the supply MAC address serves as the password.

MAC addresses that are allowed to successfully communicate with the switch port are secure MAC addresses. The default quantity of secure MAC addresses is 1, but a maximum of 132 secure MACs can be configured.

When a non-secure MAC address attempts to communicate with the switch port, a single of three actions will happen, depending on the port security mode. In Safeguard mode, frames with non-secure MAC addresses are dropped. There is no notification that a violation has occurred. The port will continue to switch frames for the secure MAC address.

In Restrict mode, the same action is taken, but a syslog message is logged by means of SNMP, which is a messaging protocol used by Cisco routers.

In Shutdown mode, the interface goes into error-disabled state, the port LED will go out, and a syslog message is logged. The port has to be manually reopened. Shutdown mode is the default port-security mode.

Port-based authentication is just one particular of the a lot of switching abilities you are going to have to demonstrate to earn your CCNA certification. Make sure you know the basics shown here, such as the action of every single particular mode, and you are on your way to CCNA exam good results!

To know more about it, please go to: company security officer