Port Security, Storm Control, RA Guard & PoE
CCNA 200-301 v2.0 · Live Feb 3, 2027 (v1.1 valid through Feb 2, 2027) Cisco Packet Tracer
مقصدObjectiveObjective
اس لیب میں آپ سوئچ کے سیکیورٹی فیچرز سیکھیں گے: port security، storm control، RA guard اور PoE۔ یہ سب v2.0 کے D2 میں نئے/واضح ٹاپکس ہیں۔Is lab mein aap switch ke security features seekhenge: port security, storm control, RA guard aur PoE. Ye sab v2.0 ke D2 mein naye/wazeh topics hain.In this lab, you'll learn switch security features: port security, storm control, RA guard, and PoE. These are all new/explicit topics in v2.0's Domain 2.
آسان مثالSimple AnalogySimple Analogy
سوچو کہ آپ کے آفس کے دروازے پر گارڈ ہے جو صرف پہچانے ہوئے لوگوں کو اندر آنے دیتا ہے (port security)۔ باہر اگر اچانک بھیڑ آ جائے تو گارڈ کہتا ہے 'ایک وقت میں اتنے ہی' (storm control)۔ IPv6 میں کوئی جھوٹا اعلان کرے کہ 'میں راؤٹر ہوں' تو گارڈ اسے پکڑ لیتا ہے (RA guard)۔ اور PoE کا مطلب سوئچ خود ہی فون/کیمرہ کو بجلی دے دیتا ہے — الگ اڈاپٹر کی ضرورت نہیں۔Socho ke aapke office ke darwaze par guard hai jo sirf pehchane hue logon ko andar aane deta hai (port security). Bahar agar achanak bheed aa jaye to guard kehta hai 'ek waqt mein itne hi' (storm control). IPv6 mein koi jhoota elaan kare ke 'main router hun' to guard usay pakar leta hai (RA guard). Aur PoE ka matlab switch khud hi phone/camera ko bijli de deta hai — alag adapter ki zaroorat nahi.Imagine a guard at your office door who only lets recognized people in (port security). If a crowd suddenly gathers outside, the guard says 'only this many at a time' (storm control). In IPv6, if someone falsely announces 'I am the router', the guard catches them (RA guard). And PoE means the switch itself powers the phone/camera — no separate adapter needed.
سیٹ اپLab SetupLab Setup
SW1 کا Fa0/2 PC1 سے کنیکٹڈ۔ IP فون ہو تو اسے بھی Fa0/3 پر لگا کر PoE ٹیسٹ کرو۔ ڈیوائسز: 1x سوئچ 2960 (SW1)، 2x پی سی، 1x IP فون (optional)۔ PC1: 192.168.10.10/24، VLAN 10 میں۔SW1 ka Fa0/2 PC1 se connected. IP phone ho to usay bhi Fa0/3 par laga kar PoE test karo. Devices: 1x Switch 2960 (SW1), 2x PC, 1x IP Phone (optional) PC1: 192.168.10.10/24, VLAN 10 mein.SW1's Fa0/2 connects to PC1. If you have an IP phone, also connect it to Fa0/3 to test PoE. Devices: 1x Switch 2960 (SW1), 2x PCs, 1x IP Phone (optional). PC1: 192.168.10.10/24, in VLAN 10.
اقداماتStepsSteps
Step 1
SW1 پر Port Security۔ Port security پورٹ پر صرف allowed MAC ایڈریسز کو آنے دیتی ہے۔SW1 par Port Security. Port security port par sirf allowed MAC addresses ko aane deti hai.Port Security on SW1. Port security only allows permitted MAC addresses on the port.
enable configure terminal interface fa0/2 switchport mode access switchport port-security
Step 2
Maximum 2 MACs، violation پر restrict (drop + log)، اور sticky سے پہلے دو MACs خود یاد ہو جاتے ہیں۔Maximum 2 MACs, violation par restrict (drop + log), aur sticky se pehle do MACs khud yaad ho jate hain.Maximum 2 MACs, restrict on violation (drop + log), and sticky remembers the first two MACs automatically.
switchport port-security maximum 2 switchport port-security violation restrict switchport port-security mac-address sticky exit
Step 3
Storm Control، RA Guard، PoE۔ Storm control broadcast ٹریفک کو 20% سے زیادہ نہیں بڑھنے دیتا۔Storm Control, RA Guard, PoE. Storm control broadcast traffic ko 20% se zyada nahi barhne deta.Storm Control, RA Guard, PoE. Storm control doesn't let broadcast traffic grow beyond 20%.
interface fa0/2 storm-control broadcast level 20.00 storm-control action trap exit
Step 4
RA guard IPv6 کے جھوٹے router advertisements روکتا ہے۔RA guard IPv6 ke jhoote router advertisements rokta hai.RA guard blocks fake IPv6 router advertisements.
interface fa0/2 ipv6 nd raguard exit
Step 5
PoE auto سے سوئچ IP فون کو بجلی دے گا۔PoE auto se switch IP phone ko bijli dega.With PoE auto, the switch will power the IP phone.
interface fa0/2 power inline auto exit
Step 6
ٹیسٹنگ: ایک تیسرا PC Fa0/2 پر لگاؤ (hub سے یا پورٹ بدل کر) — restrict کی وجہ سے اس کا ٹریفک drop ہونا چاہیے۔Testing: Ek teesra PC Fa0/2 par lagao (hub se ya port badal kar) — restrict ki wajah se uska traffic drop hona chahiye.Testing: connect a third PC to Fa0/2 (via a hub or by swapping ports) — its traffic should be dropped because of restrict.
Step 7
show port-security interface fa0/2 سے SecurityViolation کاؤنٹر بڑھتا دیکھو۔show port-security interface fa0/2 se SecurityViolation counter barhta dekho.Watch the SecurityViolation counter increase with show port-security interface fa0/2.
تصدیقVerifyVerify
show port-security interface fa0/2 سے violations دیکھو۔ show power inline سے PoE اسٹیٹس دیکھو۔show port-security interface fa0/2 se violations dekho. show power inline se PoE status dekho.Check violations with show port-security interface fa0/2. Check PoE status with show power inline.
show port-security interface fa0/2 show power inline
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ پرانا PC ہٹانے کے بعد نیا PC کام نہیں کر رہا۔Purana PC hatane ke baad naya PC kaam nahi kar raha.After removing the old PC, the new PC doesn't work.
✅ Sticky MACs کلیئر کرنے کے لیے: no switchport port-security mac-address sticky، یا clear port-security sticky interface fa0/2۔Sticky MACs clear karne ke liye: no switchport port-security mac-address sticky, ya clear port-security sticky interface fa0/2.To clear sticky MACs: no switchport port-security mac-address sticky, or clear port-security sticky interface fa0/2.
⚠️ جائز ڈیوائس بھی بلاک ہو رہی ہے۔Jaiz device bhi block ho raha hai.Even a legitimate device is being blocked.
✅ یا تو maximum بڑھاؤ، یا صحیح MAC کو manually allow کرو: switchport port-security mac-address xxxx.xxxx.xxxx۔Ya to maximum barhao, ya sahi MAC ko manually allow karo: switchport port-security mac-address xxxx.xxxx.xxxx.Either raise the maximum, or manually allow the correct MAC: switchport port-security mac-address xxxx.xxxx.xxxx.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ Port security کے تین violation modes؟Port security ke teen violation modes?What are the three port security violation modes?
Shutdown = پورٹ بند (ڈیفالٹ، سب سے سخت)۔ Restrict = پیکٹ drop + log، پورٹ چلتا ہے۔ Protect = صرف پیکٹ drop، کوئی log نہیں۔Shutdown = port band (default, sab se sakht). Restrict = packet drop + log, port chalta hai. Protect = sirf packet drop, koi log nahi.Shutdown = port shuts down (default, strictest). Restrict = packet dropped + logged, port keeps running. Protect = packet dropped only, no log.