=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2005.08.23 08:13:27 =~=~=~=~=~=~=~=~=~=~=~= RACK98AS>1 [Resuming connection 1 to r1 ... ] R1#sh cdp nei Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge S - Switch, H - Host, I - IGMP, r - Repeater Device ID Local Intrfce Holdtme Capability Platform Port ID S6 Eth 0/1 151 S I WS-C3550-2Fas 0/1 S5 Eth 0/0 147 S I WS-C3550-2Fas 0/1 R1# R1# R1# R1# R1# RACK98AS>5 [Resuming connection 5 to r5 ... ] 22 S5#config t Enter configuration commands, one per line. End with CNTL/Z. S5(config)#do sh ip route Default gateway is not set Host Gateway Last Use Total Uses Interface ICMP redirect cache is empty S5(config)#ip routing S5(config)#ip routingdo sh ip route Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area * - candidate default, U - per-user static route, o - ODR P - periodic downloaded static route Gateway of last resort is not set 208.28.1.0/24 is variably subnetted, 2 subnets, 2 masks C 208.28.1.128/27 is directly connected, Vlan20 C 208.28.1.64/28 is directly connected, Vlan10 S5(config)#^Z S5# RACK98AS>1 [Resuming connection 1 to r1 ... ] R1#sh ip    cdp nei Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge S - Switch, H - Host, I - IGMP, r - Repeater Device ID Local Intrfce Holdtme Capability Platform Port ID S6 Eth 0/1 133 S I WS-C3550-2Fas 0/1 S5 Eth 0/0 129 S I WS-C3550-2Fas 0/1 R1#sh cdp nei Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge S - Switch, H - Host, I - IGMP, r - Repeater Device ID Local Intrfce Holdtme Capability Platform Port ID S6 Eth 0/1 129 S I WS-C3550-2Fas 0/1 S5 Eth 0/0 125 S I WS-C3550-2Fas 0/1 R1#sh cdp nei Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge S - Switch, H - Host, I - IGMP, r - Repeater Device ID Local Intrfce Holdtme Capability Platform Port ID S6 Eth 0/1 128 S I WS-C3550-2Fas 0/1 S5 Eth 0/0 123 S I WS-C3550-2Fas 0/1 R1#sh cdp nei Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge S - Switch, H - Host, I - IGMP, r - Repeater Device ID Local Intrfce Holdtme Capability Platform Port ID S6 Eth 0/1 179 S I WS-C3550-2Fas 0/1 S5 Eth 0/0 174 R S I WS-C3550-2Fas 0/1 R1# RACK98AS>5 [Resuming connection 5 to r5 ... ] 22 S5#sh run | in ip routing ip routing S5# S5# S5# S5# S5# S5#config t Enter configuration commands, one per line. End with CNTL/Z. S5(config)#int fa 0/21 S5(config-if)#? Interface configuration commands: arp Set arp type (arpa, probe, snap) or timeout auto Configure Automation bandwidth Set bandwidth informational parameter carrier-delay Specify delay for interface transitions cdp CDP interface subcommands channel-group Etherchannel/port bundling configuration channel-protocol Select the channel protocol (LACP, PAgP) default Set a command to its defaults delay Specify interface throughput delay description Interface specific description dot1x Interface Config Commands for 802.1x duplex Configure duplex operation. exit Exit from interface configuration mode fair-queue Enable Fair Queuing on an Interface flowcontrol Configure flow operation. help Description of the interactive help system hold-queue Set hold queue depth ip Interface Internet Protocol config commands keepalive Enable keepalive l2protocol-tunnel Tunnel Layer2 protocols lacp LACP interface subcommands --More--   load-interval Specify interval for load calculation for an interface logging Configure logging for interface mac MAC interface commands macro Command macro max-reserved-bandwidth Maximum Reservable Bandwidth on an Interface mls Configure MultiLayer Switching characteristics mvr MVR per port configuration no Negate a command or set its defaults pagp PAgP interface subcommands priority-queue Configure priority scheduling random-detect Enable Weighted Random Early Detection (WRED) on an Interface rmon Configure Remote Monitoring on an interface service-policy Configure QoS Service Policy shutdown Shutdown the selected interface snmp Modify SNMP interface parameters spanning-tree Spanning Tree Subsystem speed Configure speed operation. storm-control storm configuration switchport Set switching mode characteristics tcam tcam keyword timeout Define timeout values for this interface --More--   S5(config-if)#swi S5(config-if)#switchport ? access Set access mode characteristics of the interface block Disable forwarding of unknown uni/multi cast addresses broadcast Set broadcast suppression level on this interface host Set port host mode Set trunking mode of the interface multicast Set multicast suppression level on this interface nonegotiate Device will not engage in negotiation protocol on this interface port-security Security related command priority Set appliance 802.1p priority protected Configure an interface to be a protected port trunk Set trunking characteristics of the interface unicast Set unicast suppression level on this interface voice Voice appliance attributes S5(config-if)#switchport bro S5(config-if)#switchport broadcast ? <0-100> Broadcast suppression level as a % of total bandwidth S5(config-if)#switchport broadcast 50 % This command is deprecated. Use the interface config command storm-control S5(config-if)# S5(config-if)# S5(config-if)# S5(config-if)#sto S5(config-if)#storm-control ? broadcast Broadcast address storm control multicast Multicast address storm control unicast Unicast address storm control S5(config-if)#storm-control bro S5(config-if)#storm-control broadcast 50  ? level Set storm suppression level on this interface S5(config-if)#storm-control broadcast 50 ? % Unrecognized command S5(config-if)#storm-control broadcast 50   ^ % Invalid input detected at '^' marker. S5(config-if)#storm-control broadcast 50    level ? pps Enter suppression level in packets per second <0 - 100> Enter Integer part of level as percentage of bandwidth S5(config-if)#storm-control broadcast level 5-0  0 S5(config-if)#stor S5(config-if)#storm-control mult S5(config-if)#storm-control multicast level 62 S5(config-if)#^Z S5#sh run 22:56:30: %SYS-5-CONFIG_I: Configured from console by console S5#sh run int s   fa 0/21 Building configuration... Current configuration : 167 bytes ! interface FastEthernet0/21 switchport mode dynamic desirable storm-control broadcast level 50.00 storm-control multicast level 62.00 spanning-tree portfast end S5# S5#config t Enter configuration commands, one per line. End with CNTL/Z. S5(config)#access-list 100 ? deny Specify packets to reject dynamic Specify a DYNAMIC list of PERMITs or DENYs permit Specify packets to forward remark Access list entry comment S5(config)#access-list 100 deny ? <0-255> An IP protocol number ahp Authentication Header Protocol eigrp Cisco's EIGRP routing protocol esp Encapsulation Security Payload gre Cisco's GRE tunneling icmp Internet Control Message Protocol igmp Internet Gateway Message Protocol igrp Cisco's IGRP routing protocol ip Any Internet Protocol ipinip IP in IP tunneling nos KA9Q NOS compatible IP over IP tunneling ospf OSPF routing protocol pcp Payload Compression Protocol pim Protocol Independent Multicast tcp Transmission Control Protocol udp User Datagram Protocol S5(config)#access-list 100 deny tcp ? A.B.C.D Source address any Any source host host A single source host S5(config)#access-list 100 deny tcp any any eq 113   ? <0-65535> Port number bgp Border Gateway Protocol (179) chargen Character generator (19) cmd Remote commands (rcmd, 514) daytime Daytime (13) discard Discard (9) domain Domain Name Service (53) echo Echo (7) exec Exec (rsh, 512) finger Finger (79) ftp File Transfer Protocol (21) ftp-data FTP data connections (used infrequently, 20) gopher Gopher (70) hostname NIC hostname server (101) ident Ident Protocol (113) irc Internet Relay Chat (194) klogin Kerberos login (543) kshell Kerberos shell (544) login Login (rlogin, 513) lpd Printer service (515) nntp Network News Transport Protocol (119) pim-auto-rp PIM Auto-RP (496) --More--   S5(config)#access-list 100 deny tcp any any eq ident S5(config)#access-list 1- 00 per ip any any S5(config)#int range fa 0/1 - 24 S5(config-if-range)#ip access-gr 100 out ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ip access-gr 100 out ^ % Invalid input detected at '^' marker. ^ % Invalid input detected at '^' marker. S5(config-if-range)#ip access-gr 100 out   ? in inbound packets S5(config-if-range)#ip access-gr 100 in S5(config-if-range)#ip access-gr 100 innip access-gr 100 inoip access-gr 100 in ip access-gr 100 in S5(config-if-range)#do shrun    run Building configuration... Current configuration : 2991 bytes ! version 12.1 no service pad service timestamps debug uptime service timestamps log uptime no service password-encryption ! hostname S5 ! ! ip subnet-zero ip routing ! no ip domain-lookup ! spanning-tree mode pvst spanning-tree extend system-id ! ! ! ! --More--  ! interface FastEthernet0/1 switchport access vlan 10 switchport mode access spanning-tree portfast ! interface FastEthernet0/2 switchport mode dynamic desirable shutdown spanning-tree portfast ! interface FastEthernet0/3 switchport access vlan 34 switchport mode access spanning-tree portfast ! interface FastEthernet0/4 switchport mode dynamic desirable shutdown spanning-tree portfast ! interface FastEthernet0/5 switchport mode dynamic desirable --More--   spanning-tree portfast ! interface FastEthernet0/6 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/7 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/8 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/9 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/10 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/11 --More--   switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/12 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/13 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/14 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/15 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/16 switchport mode dynamic desirable spanning-tree portfast ! --More--  interface FastEthernet0/17 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/18 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/19 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/20 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/21 switchport mode dynamic desirable storm-control broadcast level 50.00 storm-control multicast level 62.00 spanning-tree portfast ! interface FastEthernet0/22 --More--   switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/23 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/24 switchport trunk encapsulation dot1q switchport mode trunk ! interface GigabitEthernet0/1 switchport mode dynamic desirable ! interface GigabitEthernet0/2 switchport mode dynamic desirable ! interface Vlan1 no ip address shutdown ! interface Vlan10 ip address 208.28.1.65 255.255.255.240 --More--  ! interface Vlan20 ip address 208.28.1.130 255.255.255.224 ! ip classless ip http server ! access-list 100 deny tcp any any eq ident access-list 100 permit ip any any ! line con 0 exec-timeout 0 0 logging synchronous line vty 0 4 login line vty 5 15 login ! ! end S5(config-if-range)#exit S5(config)#no access-list 100 S5(config)#as ce cess-list 100 per tcp any any eq ident S5(config)#vla S5(config)#vlan ? WORD ISL VLAN IDs 1-4094 access-map Create vlan access-map or enter vlan access-map command mode dot1q dot1q parameters filter Apply a VLAN Map internal internal VLAN S5(config)#vlan acc S5(config)#vlan access-map ? WORD Vlan access map tag S5(config)#vlan access-map Pron b17 ? <0-65535> Sequence to insert to/delete from existing vlan access-map entry S5(config)#vlan access-map Prob17 10 ? S5(config)#vlan access-map Prob17 10 S5(config-access-map)#? Vlan access-map configuration commands: action Take the action default Set a command to its defaults exit Exit from vlan access-map configuration mode match Match values. no Negate a command or set its defaults S5(config-access-map)#match ? ip IP based match mac MAC based match S5(config-access-map)#match ip >? % Unrecognized command S5(config-access-map)#match ip > ? address Match IP address to access control. S5(config-access-map)#match ip add ? <1-199> IP access list (standard or extended) <1300-2699> IP expanded access list (standard or extended) WORD Access-list name S5(config-access-map)#match ip add 100 ? <1-199> IP access list (standard or extended) <1300-2699> IP expanded access list (standard or extended) WORD Access-list name S5(config-access-map)#match ip add 100 S5(config-access-map)#? Vlan access-map configuration commands: action Take the action default Set a command to its defaults exit Exit from vlan access-map configuration mode match Match values. no Negate a command or set its defaults S5(config-access-map)#act S5(config-access-map)#action ? drop Drop packets forward Forward packets S5(config-access-map)#action drop ? S5(config-access-map)#action drop S5(config-access-map)#action drop match ip add 100 vlan access-map Prob17 10 access-list 100 per tcp any any eq identvlan access-map Prob17 10    20 S5(config-access-map)#actio for S5(config-access-map)#actio forward S5(config-access-map)#exit S5(config)#vlan ? WORD ISL VLAN IDs 1-4094 access-map Create vlan access-map or enter vlan access-map command mode dot1q dot1q parameters filter Apply a VLAN Map internal internal VLAN S5(config)#vlan fil S5(config)#vlan filter ? WORD VLAN map name S5(config)#vlan filter Prob17 ? vlan-list VLANs to apply filter to S5(config)#vlan filter Prob17 vl S5(config)#vlan filter Prob17 vlan-list ? <1-4094> VLAN id all Remove this filter from all VLANs S5(config)#vlan filter Prob17 vlan-list all S5(config)# S5(config)# S5(config)# S5(config)# S5(config)#do sh run Building configuration... Current configuration : 3098 bytes ! version 12.1 no service pad service timestamps debug uptime service timestamps log uptime no service password-encryption ! hostname S5 ! ! ip subnet-zero ip routing ! no ip domain-lookup ! spanning-tree mode pvst spanning-tree extend system-id ! ! ! ! --More--  vlan access-map Prob17 10 action drop match ip address 100 vlan access-map Prob17 20 action forward vlan filter Prob17 vlan-list 1-4094 ! ! interface FastEthernet0/1 switchport access vlan 10 switchport mode access spanning-tree portfast ! interface FastEthernet0/2 switchport mode dynamic desirable shutdown spanning-tree portfast ! interface FastEthernet0/3 switchport access vlan 34 switchport mode access spanning-tree portfast ! --More--  interface FastEthernet0/4 switchport mode dynamic desirable shutdown spanning-tree portfast ! interface FastEthernet0/5 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/6 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/7 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/8 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/9 switchport mode dynamic desirable --More--   spanning-tree portfast ! interface FastEthernet0/10 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/11 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/12 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/13 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/14 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/15 --More--   switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/16 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/17 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/18 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/19 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/20 switchport mode dynamic desirable spanning-tree portfast ! --More--  interface FastEthernet0/21 switchport mode dynamic desirable storm-control broadcast level 50.00 storm-control multicast level 62.00 spanning-tree portfast ! interface FastEthernet0/22 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/23 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/24 switchport trunk encapsulation dot1q switchport mode trunk ! interface GigabitEthernet0/1 switchport mode dynamic desirable ! interface GigabitEthernet0/2 switchport mode dynamic desirable --More--  ! interface Vlan1 no ip address shutdown ! interface Vlan10 ip address 208.28.1.65 255.255.255.240 ! interface Vlan20 ip address 208.28.1.130 255.255.255.224 ! ip classless ip http server ! access-list 100 permit tcp any any eq ident ! line con 0 exec-timeout 0 0 logging synchronous line vty 0 4 login line vty 5 15 login --More--  ! ! end S5(config)#   ^Z S5# 23:09:16: %SYS-5-CONFIG_I: Configured from console by console S5#vlan data % Warning: It is recommended to configure VLAN from config mode, as VLAN database mode is being deprecated. Please consult user documentation for configuring VTP/VLAN in config mode. S5(vlan)#sh cur VLAN ISL Id: 1 Name: default Media Type: Ethernet VLAN 802.10 Id: 100001 State: Operational MTU: 1500 Backup CRF Mode: Disabled Remote SPAN VLAN: No VLAN ISL Id: 10 Name: VLAN0010 Media Type: Ethernet VLAN 802.10 Id: 100010 State: Operational MTU: 1500 Backup CRF Mode: Disabled Remote SPAN VLAN: No VLAN ISL Id: 20 Name: VLAN0020 Media Type: Ethernet VLAN 802.10 Id: 100020 State: Operational --More--   S5(vlan)# S5# 23:09:34: %SYS-5-CONFIG_I: Configured from console by console S5#sh run Building configuration... Current configuration : 3098 bytes ! version 12.1 no service pad service timestamps debug uptime service timestamps log uptime no service password-encryption ! hostname S5 ! ! ip subnet-zero ip routing ! no ip domain-lookup ! spanning-tree mode pvst spanning-tree extend system-id ! ! ! ! --More--  vlan access-map Prob17 10 action drop match ip address 100 vlan access-map Prob17 20 action forward vlan filter Prob17 vlan-list 1-4094 ! ! interface FastEthernet0/1 switchport access vlan 10 switchport mode access spanning-tree portfast ! interface FastEthernet0/2 switchport mode dynamic desirable shutdown spanning-tree portfast ! interface FastEthernet0/3 switchport access vlan 34 switchport mode access spanning-tree portfast ! --More--   S5#sh run | inm  access-list access-list 100 permit tcp any any eq ident S5# S5#config t Enter configuration commands, one per line. End with CNTL/Z. S5(config)#int range fa 1 0/  16 - 21 S5(config-if-range)#sw S5(config-if-range)#switchport ? access Set access mode characteristics of the interface block Disable forwarding of unknown uni/multi cast addresses broadcast Set broadcast suppression level on this interface host Set port host mode Set trunking mode of the interface multicast Set multicast suppression level on this interface nonegotiate Device will not engage in negotiation protocol on this interface port-security Security related command priority Set appliance 802.1p priority protected Configure an interface to be a protected port trunk Set trunking characteristics of the interface unicast Set unicast suppression level on this interface voice Voice appliance attributes S5(config-if-range)#switchport protected ? S5(config-if-range)#switchport protected   S5(config-if-range)# S5# 23:15:02: %SYS-5-CONFIG_I: Configured from console by console S5#SH RUN | B            sh reun   un Building configuration... Current configuration : 3230 bytes ! version 12.1 no service pad service timestamps debug uptime service timestamps log uptime no service password-encryption ! hostname S5 ! ! ip subnet-zero ip routing ! no ip domain-lookup ! spanning-tree mode pvst spanning-tree extend system-id ! ! ! ! --More--  vlan access-map Prob17 10 action drop match ip address 100 vlan access-map Prob17 20 action forward vlan filter Prob17 vlan-list 1-4094 ! ! interface FastEthernet0/1 switchport access vlan 10 switchport mode access spanning-tree portfast ! interface FastEthernet0/2 switchport mode dynamic desirable shutdown spanning-tree portfast ! interface FastEthernet0/3 switchport access vlan 34 switchport mode access spanning-tree portfast ! --More--  interface FastEthernet0/4 switchport mode dynamic desirable shutdown spanning-tree portfast ! interface FastEthernet0/5 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/6 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/7 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/8 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/9 switchport mode dynamic desirable --More--   spanning-tree portfast ! interface FastEthernet0/10 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/11 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/12 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/13 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/14 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/15 --More--   switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/16 switchport mode dynamic desirable switchport protected spanning-tree portfast ! interface FastEthernet0/17 switchport mode dynamic desirable switchport protected spanning-tree portfast ! interface FastEthernet0/18 switchport mode dynamic desirable switchport protected spanning-tree portfast ! interface FastEthernet0/19 switchport mode dynamic desirable switchport protected spanning-tree portfast ! --More--  interface FastEthernet0/20 switchport mode dynamic desirable switchport protected spanning-tree portfast ! interface FastEthernet0/21 switchport mode dynamic desirable switchport protected storm-control broadcast level 50.00 storm-control multicast level 62.00 spanning-tree portfast ! interface FastEthernet0/22 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/23 switchport mode dynamic desirable spanning-tree portfast ! interface FastEthernet0/24 switchport trunk encapsulation dot1q switchport mode trunk --More--   S5#config t Enter configuration commands, one per line. End with CNTL/Z. S5(config)#int fa 0/21 S5(config-if)#swi S5(config-if)#switchport bo S5(config-if)#switchport bo  S5(config-if)#switchport bl S5(config-if)#switchport block mo=u S5(config-if)#switchport block mo=u   u S5(config-if)#switchport block multicast ? S5(config-if)#switchport block multicast S5# 23:18:26: %SYS-5-CONFIG_I: Configured from console by console S5#config t Enter configuration commands, one per line. End with CNTL/Z. S5(config)#int fa 0/20 S5(config-if)#sto S5(config-if)#storm-control ? broadcast Broadcast address storm control multicast Multicast address storm control unicast Unicast address storm control S5(config-if)#storm-control mu S5(config-if)#storm-control multicast l S5(config-if)#storm-control multicast level mu S5(config-if)#storm-control multicast level mu  ? pps Enter suppression level in packets per second <0 - 100> Enter Integer part of level as percentage of bandwidth S5(config-if)#storm-control multicast level 0 S5(config-if)#^Z S5# 23:22:12: %SYS-5-CONFIG_I: Configured from console by console S5#sh run omt fa 0/20 ^ % Invalid input detected at '^' marker. S5#sh run omt fa 0/20t fa 0/20 t fa 0/20 it fa 0/20nt fa 0/20 Building configuration... Current configuration : 151 bytes ! interface FastEthernet0/20 switchport mode dynamic desirable switchport protected storm-control multicast level 0.00 spanning-tree portfast end S5# S5#config t Enter configuration commands, one per line. End with CNTL/Z. S5(config)#int fa 0/21 S5(config-if)#sw S5(config-if)#switchport po S5(config-if)#switchport port-security ? aging Port-security aging commands mac-address Secure mac address maximum Max secure addresses violation Security violation mode S5(config-if)#switchport port-security mac S5(config-if)#switchport port-security mac-address ? H.H.H 48 bit mac address sticky Configure dynamic secure addresses as sticky S5(config-if)#switchport port-security mac-address 0023: .1123.4443 ? S5(config-if)#switchport port-security mac-address 0023.1123.4443 FastEthernet0/21 is dynamic port. port-security parameters cannot be set. S5(config-if)#switch mode access S5(config-if)#switch mode accessport port-security mac-address 0023.1123.4443 S5(config-if)#do shr    t run int fa 0/21 Building configuration... Current configuration : 231 bytes ! interface FastEthernet0/21 switchport mode access switchport protected switchport port-security mac-address 0023.1123.4443 storm-control broadcast level 50.00 storm-control multicast level 62.00 spanning-tree portfast end S5(config-if)#switchport port-security S5(config-if)#^Z S5#sh 23:26:14: %SYS-5-CONFIG_I: Configured from console by console S5#sh port S5#sh port-security ? address Show secure address interface Show secure interface | Output modifiers S5#sh port-security in fa 0/21 Port Security : Enabled Port Status : Secure-down Violation Mode