Skip to main content
AD Academy
CCNA — Cisco Networking Fundamentals
Beginner13 minLast updated: Topic 6 of 12

Network Security in CCNA: Port Security, ACL, and 802.1X

Basic protections on the switch and router, and why they are also important for Active Directory.

Not read

What you will learn here

  • How Port Security limits switch connections
  • What an ACL does on a router
  • How 802.1X ties into AD

Worth reading first:Network Services: DHCP, DNS, NAT, and NTP

Most attacks on start on the network: someone connects to an available port, sets up a Rogue DHCP, or runs poisoning. Layer 2 and 3 protections stop this early.

  • — Limits how many MAC addresses are allowed on a port.
  • — Only defined (Trusted) ports are allowed to respond as DHCP.
  • Dynamic ARP Inspection — Prevents ARP poisoning (MitM).
  • — Authenticates the device/user against (NPS) before granting network access.
  • ACL — Filters traffic by address and port.
! Port Security
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 2
Switch(config-if)# switchport port-security violation restrict
Switch(config-if)# switchport port-security mac-address sticky

! DHCP Snooping
Switch(config)# ip dhcp snooping
Switch(config)# ip dhcp snooping vlan 10,20
Switch(config-if)# ip dhcp snooping trust

! Extended ACL — Block SMB from Guest Network to Server Farm
Router(config)# ip access-list extended GUEST-IN
Router(config-ext-nacl)# deny tcp 192.168.99.0 0.0.0.255 192.168.50.0 0.0.0.255 eq 445
Router(config-ext-nacl)# permit ip any any
Router(config-if)# ip access-group GUEST-IN in
bash
Architecture and Theory — Under the Hood

L2 security is the first line of defense: if the attacker is already inside the switch, an ACL on the router won't help. , , and Dynamic ARP Inspection stop most local network attacks.

  • Difference between violation modes: protect silently drops, restrict drops + counts + SNMP trap, shutdown moves the port to err-disabled until manual intervention or errdisable recovery.
  • : Marks ports as Trusted (towards a legitimate DHCP server) and Untrusted (users) — blocks Rogue DHCP.
  • : Checks ARP against the Snooping table — stops ARP Spoofing.
  • : Authenticates the user/computer against /NPS before the port is even opened.
Practical Configuration (CLI)
! Port Security
SW(config-if)# switchport mode access
SW(config-if)# switchport port-security
SW(config-if)# switchport port-security maximum 2
SW(config-if)# switchport port-security mac-address sticky
SW(config-if)# switchport port-security violation restrict

! DHCP Snooping + DAI
SW(config)# ip dhcp snooping
SW(config)# ip dhcp snooping vlan 10,20
SW(config)# interface gi0/24
SW(config-if)# ip dhcp snooping trust
SW(config)# ip arp inspection vlan 10,20

! 802.1X
SW(config)# aaa new-model
SW(config)# aaa authentication dot1x default group radius
SW(config)# radius server NPS
SW(config-radius-server)# address ipv4 192.168.10.10 auth-port 1812
SW(config-radius-server)# key S3cret!
SW(config)# dot1x system-auth-control
SW(config-if)# authentication port-control auto
SW(config-if)# dot1x pae authenticator
bash
Real-world Scenarios in an Organization
  • Meeting rooms and lobby: + Guest VLAN so a guest cannot connect to the internal network.
  • in an organization with : NPS authenticates the computer account, and assigns a dynamic VLAN based on the group.
  • prevents damage from a home Router that someone brings and connects to the network.
Troubleshooting
SW# show port-security interface gi0/5
SW# show port-security address
SW# show ip dhcp snooping binding
SW# show ip arp inspection statistics
SW# show authentication sessions interface gi0/5
SW# show interfaces status err-disabled
SW(config-if)# shutdown
SW(config-if)# no shutdown          ! Release err-disabled port
bash
  • Port enters err-disabled after replacing a computer → Delete the old sticky MAC.
  • IP phone + computer on the same port need a maximum of 2 at least.
  • fails → Check certificate/password, connectivity to , and policy in NPS.
Glossary and Quick Command Line
  • violation: protect (drops), restrict (drops+logs), shutdown (default, err-disabled)
  • errdisable recovery cause psecure-violation — automatic recovery
  • Snooping trust = only towards a legitimate DHCP server
  • = Supplicant + Authenticator (Switch) + Authentication Server (/NPS)

Check yourself

Which protection stops a fake DHCP server on the network?

What does 802.1X provide?

Was this page helpful?