Access Layer April 2014
32
switchport port-security aging type inactivity
switchport port-security violation restrict
ip arp inspection limit rate 100
ip dhcp snooping limit rate 100
ip verify source
!
mls qos queue-set output 1 threshold 3 100 100 100 3200
Example: Connected to WAN Router at a small site
VLAN 64
Wired
AN
VLAN 69
Wired
IP: 10.5.64.5/24
VLAN 64
Remote Site
WAN Router
vlan 64
name WiredData
vlan 69
name WiredVoice
!
interface vlan 64
description In-band Management to WAN Router
ip address 10.5.64.5 255.255.255.0
no shutdown
!
ip default-gateway 10.5.64.1
!
ip dhcp snooping vlan 64,69
no ip dhcp snooping information option
ip dhcp snooping
ip arp inspection vlan 64,69
!
spanning-tree portfast bpduguard default
!
interface range GigabitEthernet 1/0/1–24
switchport access vlan 64
switchport voice vlan 69
switchport host
macro apply AccessEdgeQoS
switchport port-security maximum 11
switchport port-security
switchport port-security aging time 2
switchport port-security aging type inactivity
switchport port-security violation restrict
ip arp inspection limit rate 100
ip dhcp snooping limit rate 100
ip verify source
!
mls qos queue-set output 1 threshold 3 100 100 100 3200
Comments to this Manuals