Re: PORT-SECURITY with HSRP

From: Joe Astorino <jastorino_at_ipexpert.com>
Date: Fri, 24 Jul 2009 15:02:04 -0400

use the "use-bia" command inside your HSRP config. It will force the HSRP
process to use your actual mac-address instead of a virtual MAC

On Fri, Jul 24, 2009 at 2:29 PM, kaushalccie patel <kaushalccie_at_gmail.com>wrote:

> Not sure if this will help...................
>
> Sometime back Gaurav Madan has suggested following solution....
>
> There are 2 solutions when u are working with HSRP and Port-Security.
> Here probably 1st sol is not of interest as u are configuring port-security
> with 1 secure addreess
>
>
> Sol 1
> *******
> int f1/0/4
> switchport port-security
> *switchport port-security maximum 3*
>
>
>
> if you have given " switchport port-security mac-address sticky" CLI ..
> you
> will see
>
> *switchport port-security mac-address sticky 0001.0002.0003* <== router mac
> *switchport port-security mac-address sticky 0000.0c07.ac01* <== HSRP MAC.
>
>
> Solution 2
> *****************
> R4
> int f0/0
> ip address <> <>
> mac-address 0001.0002.0003
> *standby use-bia*
>
> SW
> int f1/0/4
> switchport port-security
> switchport-security mac-address 0001.0002.0003.
>
> HTH
> Gaurav Madan
> CCIE
> ==========================================
>
> Kaushal
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html
>
>
>
>
>
>
>
>

-- 
Regards,
Joe Astorino - CCIE #24347 R&S
Technical Instructor - IPexpert, Inc.
Cell: +1.586.212.6107
Fax: +1.810.454.0130
Mailto:  jastorino_at_ipexpert.com
Blogs and organic groups at http://www.ccie.net
Received on Fri Jul 24 2009 - 15:02:04 ART

This archive was generated by hypermail 2.2.0 : Sat Aug 01 2009 - 13:10:23 ART