nerdexam
Juniper

JN0-351 · Question #28

You implemented the MAC address limit feature with the shutdown action on all interfaces on your switch. In this scenario, which statement is correct when a violation occurs?

The correct answer is A. By default, you must manually clear the violation for the interface to send and receive traffic. When the MAC address limit feature with the shutdown action is implemented on a switch, if a violation occurs, the interface is disabled and a system log entry is generated. If the switch has been configured with the port-error-disable statement, the disabled interface recovers…

Layer 2 Security

Question

You implemented the MAC address limit feature with the shutdown action on all interfaces on your switch. In this scenario, which statement is correct when a violation occurs?

Options

  • ABy default, you must manually clear the violation for the interface to send and receive traffic
  • BBy default, the violation will automatically be cleared after 300 seconds and the interface will
  • CBy default, devices that are learned before the violation occurs are still allowed to send and
  • DBy default, the interface will continue to send and receive traffic for all connected devices after a

How the community answered

(28 responses)
  • A
    71% (20)
  • B
    14% (4)
  • C
    11% (3)
  • D
    4% (1)

Explanation

When the MAC address limit feature with the shutdown action is implemented on a switch, if a violation occurs, the interface is disabled and a system log entry is generated. If the switch has been configured with the port-error-disable statement, the disabled interface recovers automatically upon expiration of the specified disable timeout. However, if the switch has not been configured for auto-recovery from port error disabled conditions, you must manually clear the violation by running the clear ethernet-switching port-error command for the interface to send and receive traffic again. This explanation is based on the Enterprise Routing and Switching Specialist (JNCIS-ENT) documents and learning resources available at Juniper Networks.

Topics

#MAC limiting#port security#violation action#shutdown

Community Discussion

No community discussion yet for this question.

Full JN0-351 Practice