<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port Security violation, please help in IP Telephony and Phones</title>
    <link>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580922#M139983</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to disable port security and check how many mac-address are learned after 5 minutes, 10 minutes and 30 minutes.&lt;BR /&gt;In this way you can verify if the problem is the maximum number of mac.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;from cisco doc:&lt;BR /&gt;When an IP phone is connected to a switch through the switchport configured for voice VLAN, the phone sends untagged CDP packets and tagged voice CDP packets. So the MAC address of the IP phone is learned on both the PVID and the VVID. If the appropriate number of secure addresses are not configured, you can get an error message.&lt;BR /&gt;You must set the maximum allowed secure addresses on the port to two (for IP phone) plus the maximum number of secure addresses allowed on the access VLAN in order to resolve this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Dec 2010 13:17:58 GMT</pubDate>
    <dc:creator>Daniele Giordano</dc:creator>
    <dc:date>2010-12-28T13:17:58Z</dc:date>
    <item>
      <title>Port Security violation, please help</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580921#M139982</link>
      <description>&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've&amp;nbsp; got problem with port security on port Fast4/4. There is currently&amp;nbsp; Cisco IP phone 7961 connected and nothing else. I still get&amp;nbsp; PSECURE_VIOLATION. What can cause the problem? Please help. Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are my logs and configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show logging&lt;BR /&gt;Dec 27 10:21:05.631 CET: %PM-4-ERR_DISABLE: psecure-violation error detected on Fa4/4, putting Fa4/4 in err-disable state&lt;BR /&gt;Dec&amp;nbsp; 27 10:21:05.639 CET: %PORT_SECURITY-2-PSECURE_VIOLATION: Security&amp;nbsp; violation occurred, caused by MAC address 0023.339c.e1cf on port&amp;nbsp; FastEthernet4/4.&lt;BR /&gt;Dec 27 10:24:05.646 CET: %PM-4-ERR_RECOVER: Attempting to recover from psecure-violation err-disable state on Fa4/4&lt;BR /&gt;Dec 27 13:14:51.073 CET: %PM-4-ERR_DISABLE: psecure-violation error detected on Fa4/4, putting Fa4/4 in err-disable state&lt;BR /&gt;Dec&amp;nbsp; 27 13:14:51.077 CET: %PORT_SECURITY-2-PSECURE_VIOLATION: Security&amp;nbsp; violation occurred, caused by MAC address 0023.339c.e1cf on port&amp;nbsp; FastEthernet4/4.&lt;BR /&gt;Dec 27 13:17:51.072 CET: %PM-4-ERR_RECOVER: Attempting to recover from psecure-violation err-disable state on Fa4/4&lt;BR /&gt;Dec 27 14:32:39.083 CET: %PM-4-ERR_DISABLE: psecure-violation error detected on Fa4/4, putting Fa4/4 in err-disable state&lt;BR /&gt;Dec&amp;nbsp; 27 14:32:39.087 CET: %PORT_SECURITY-2-PSECURE_VIOLATION: Security&amp;nbsp; violation occurred, caused by MAC address 0023.339c.e1cf on port&amp;nbsp; FastEthernet4/4.&lt;BR /&gt;Dec 27 14:35:39.081 CET: %PM-4-ERR_RECOVER: Attempting to recover from psecure-violation err-disable state on Fa4/4&lt;BR /&gt;Dec 27 15:16:59.369 CET: %PM-4-ERR_DISABLE: psecure-violation error detected on Fa4/4, putting Fa4/4 in err-disable state&lt;BR /&gt;Dec&amp;nbsp; 27 15:16:59.373 CET: %PORT_SECURITY-2-PSECURE_VIOLATION: Security&amp;nbsp; violation occurred, caused by MAC address 0023.339c.e1cf on port&amp;nbsp; FastEthernet4/4.&lt;BR /&gt;Dec 27 15:19:59.356 CET: %PM-4-ERR_RECOVER: Attempting to recover from psecure-violation err-disable state on Fa4/4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show mac address-table interface fasTEthernet 4/4&lt;BR /&gt;Unicast Entries&lt;BR /&gt; vlan&amp;nbsp;&amp;nbsp; mac address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocols&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port&lt;BR /&gt;-------+---------------+--------+---------------------+--------------------&lt;BR /&gt; 412&amp;nbsp;&amp;nbsp;&amp;nbsp; 0023.339c.e1cf&amp;nbsp;&amp;nbsp;&amp;nbsp; static ip,ipx,assigned,other FastEthernet4/4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Multicast Entries&lt;BR /&gt; vlan&amp;nbsp;&amp;nbsp;&amp;nbsp; mac address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type&amp;nbsp;&amp;nbsp;&amp;nbsp; ports&lt;BR /&gt;-------+---------------+-------+--------------------------------------------&lt;BR /&gt; 112&amp;nbsp;&amp;nbsp;&amp;nbsp; ffff.ffff.ffff&amp;nbsp;&amp;nbsp; system Fa4/1,Fa4/2,Fa4/3,Fa4/4,Fa4/6,Fa4/9,Fa4/10&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fa4/11,Fa4/12,Fa4/14,Fa4/15,Fa4/17,Fa4/18&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fa4/33,Fa4/35,Fa4/40,Fa4/41,Fa4/43,Fa4/44&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fa4/45,Fa4/46,Fa4/47,Fa4/48,Fa5/48,Gi1/1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi1/2,Switch&lt;BR /&gt; 412&amp;nbsp;&amp;nbsp;&amp;nbsp; ffff.ffff.ffff&amp;nbsp;&amp;nbsp; system Fa4/1,Fa4/2,Fa4/3,Fa4/4,Fa4/6,Fa4/9,Fa4/10&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fa4/11,Fa4/12,Fa4/14,Fa4/15,Fa4/17,Fa4/18&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fa4/33,Fa4/35,Fa4/40,Fa4/41,Fa4/43,Fa4/44&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fa4/45,Fa4/46,Fa4/47,Fa4/48,Fa5/48,Gi1/1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi1/2,Switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#show port-security interface fastEthernet 4/4&lt;BR /&gt;Port Security&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&lt;BR /&gt;Port Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Secure-up&lt;BR /&gt;Violation Mode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Shutdown&lt;BR /&gt;Aging Time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1 mins&lt;BR /&gt;Aging Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Inactivity&lt;BR /&gt;SecureStatic Address Aging : Disabled&lt;BR /&gt;Maximum MAC Addresses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3&lt;BR /&gt;Total MAC Addresses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1&lt;BR /&gt;Configured MAC Addresses&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;Sticky MAC Addresses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;Last Source Address:Vlan&amp;nbsp;&amp;nbsp; : 0023.339c.e1cf:412&lt;BR /&gt;Security Violation Count&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#interface FastEthernet4/4&lt;BR /&gt; switchport access vlan 112&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 412&lt;BR /&gt; switchport port-security maximum 3&lt;BR /&gt; switchport port-security&lt;BR /&gt; switchport port-security aging time 1&lt;BR /&gt; switchport port-security aging type inactivity&lt;BR /&gt; no logging event link-status&lt;BR /&gt; load-interval 60&lt;BR /&gt; qos vlan-based&lt;BR /&gt; no snmp trap link-status&lt;BR /&gt; tx-queue 3&lt;BR /&gt;&amp;nbsp;&amp;nbsp; priority high&lt;BR /&gt; ip dhcp snooping limit rate 10&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show cdp neighbors fastEthernet 4/4&lt;BR /&gt;Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone, &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - Remote, C - CVTA, M - Two-port Mac Relay&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Local Intrfce&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Holdtme&amp;nbsp;&amp;nbsp;&amp;nbsp; Capability&amp;nbsp; Platform&amp;nbsp; Port ID&lt;BR /&gt;SEP0023339CE1CF&amp;nbsp; Fas 4/4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 168&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; H P M&amp;nbsp; IP Phone&amp;nbsp; Port 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#show power inline fastEthernet 4/4&lt;BR /&gt;Available:3700(w)&amp;nbsp; Used:685(w)&amp;nbsp; Remaining:3015(w)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface Admin&amp;nbsp; Oper&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Power(Watts)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; From PS&amp;nbsp;&amp;nbsp;&amp;nbsp; To Device&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;--------- ------ ---------- ---------- ---------- ------------------- -----&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fa4/4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; auto&amp;nbsp;&amp;nbsp; on&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Phone 7961&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp; AdminPowerMax&amp;nbsp;&amp;nbsp; AdminConsumption&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Watts)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Watts)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;---------- --------------- --------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fa4/4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15.4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#show ver&lt;BR /&gt;Cisco IOS Software, Catalyst 4500 L3 Switch Software (cat4500-IPBASEK9-M), Version 12.2(50)SG6, RELEASE SOFTWARE (fc2)&lt;BR /&gt;&lt;SPAN&gt;Technical Support: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/techsupport" target="_blank"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;BR /&gt;Copyright (c) 1986-2009 by Cisco Systems, Inc.&lt;BR /&gt;Compiled Wed 02-Dec-09 23:12 by prod_rel_team&lt;BR /&gt;Image text-base: 0x10000000, data-base: 0x11C3225C&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ROM: 12.2(31r)SGA1&lt;BR /&gt;Dagobah Revision 226, Swamp Revision 34&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cza-ua-12300a uptime is 34 weeks, 16 hours, 53 minutes&lt;BR /&gt;System returned to ROM by reload&lt;BR /&gt;System restarted at 21:28:42 CEST Mon May 3 2010&lt;BR /&gt;System image file is "bootflash:cat4500-ipbasek9-mz.122-50.SG6.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This product contains cryptographic features and is subject to United&lt;BR /&gt;States and local country laws governing import, export, transfer and&lt;BR /&gt;use. Delivery of Cisco cryptographic products does not imply&lt;BR /&gt;third-party authority to import, export, distribute or use encryption.&lt;BR /&gt;Importers, exporters, distributors and users are responsible for&lt;BR /&gt;compliance with U.S. and local country laws. By using this product you&lt;BR /&gt;agree to comply with applicable laws and regulations. If you are unable&lt;BR /&gt;to comply with U.S. and local laws, return this product immediately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A summary of U.S. laws governing Cisco cryptographic products may be found at:&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/wwl/export/crypto/tool/stqrg.html" target="_blank"&gt;http://www.cisco.com/wwl/export/crypto/tool/stqrg.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you require further assistance please contact us by sending email to&lt;BR /&gt;&lt;A class="jive-link-email-small" href="mailto:export@cisco.com" target="_blank"&gt;export@cisco.com&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cisco WS-C4506 (MPC8245) processor (revision 10) with 262144K bytes of memory.&lt;BR /&gt;Processor board ID FOX1222GVRS&lt;BR /&gt;MPC8245 CPU at 266Mhz, Supervisor II+&lt;BR /&gt;Last reset from Reload&lt;BR /&gt;6 Virtual Ethernet interfaces&lt;BR /&gt;192 FastEthernet interfaces&lt;BR /&gt;2 Gigabit Ethernet interfaces&lt;BR /&gt;511K bytes of non-volatile configuration memory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration register is 0x2101&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 16 Mar 2019 09:36:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580921#M139982</guid>
      <dc:creator>radoslav-drabik</dc:creator>
      <dc:date>2019-03-16T09:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: Port Security violation, please help</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580922#M139983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to disable port security and check how many mac-address are learned after 5 minutes, 10 minutes and 30 minutes.&lt;BR /&gt;In this way you can verify if the problem is the maximum number of mac.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;from cisco doc:&lt;BR /&gt;When an IP phone is connected to a switch through the switchport configured for voice VLAN, the phone sends untagged CDP packets and tagged voice CDP packets. So the MAC address of the IP phone is learned on both the PVID and the VVID. If the appropriate number of secure addresses are not configured, you can get an error message.&lt;BR /&gt;You must set the maximum allowed secure addresses on the port to two (for IP phone) plus the maximum number of secure addresses allowed on the access VLAN in order to resolve this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 13:17:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580922#M139983</guid>
      <dc:creator>Daniele Giordano</dc:creator>
      <dc:date>2010-12-28T13:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Port Security violation, please help</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580923#M139984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have seen both versions in the Cisco Literature &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;When you enable port security on an interface that&amp;nbsp; is also configured with a voice VLAN, set the maximum allowed secure&amp;nbsp; addresses on the port to two. When the port is connected to a Cisco IP&amp;nbsp; phone, &lt;STRONG&gt;the IP phone requires one MAC address. &lt;/STRONG&gt;The Cisco IP phone address&amp;nbsp; is learned on the voice VLAN, but is not learned on the access VLAN. If&amp;nbsp; you connect a single PC to the Cisco IP phone, no additional MAC&amp;nbsp; addresses are required. If you connect more than one PC to the Cisco IP&amp;nbsp; phone, you must configure enough secure addresses to allow one for each&amp;nbsp; PC and one for the phone. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/switches/lan/catalyst3560/software/release/12.2_52_se/configuration/guide/swtrafc.html#wp1038501"&gt;http://www.cisco.com/en/US/partner/docs/switches/lan/catalyst3560/software/release/12.2_52_se/configuration/guide/swtrafc.html#wp1038501&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Dec 2010 01:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580923#M139984</guid>
      <dc:creator>dijohn</dc:creator>
      <dc:date>2010-12-29T01:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: Port Security violation, please help</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580924#M139985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey I think I figured what the poroblem is...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H3 class="p_H_Head3"&gt;Example 1: Configuring Maximum MAC Addresses for Voice and Data VLANs&lt;/H3&gt;&lt;A name="wp1134855"&gt;&lt;/A&gt;&lt;P class="pB1_Body1"&gt;This example shows how to designate a maximum of one MAC address for a&amp;nbsp; voice VLAN (for a Cisco IP Phone, let's say) and one MAC address for the&amp;nbsp; data VLAN (for a PC, let's say) on Fast Ethernet interface 5/1 and to&amp;nbsp; verify the configuration:&lt;/P&gt;&lt;A name="wp1167930"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;Switch# &lt;STRONG class="cBold"&gt;configure terminal
&lt;/STRONG&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1167931"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;Enter configuration commands, one per line. End with CNTL/Z.
&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1167932"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;Switch(config)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;interface fa5/1
&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1167933"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;Switch(config-if)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;switchport mode access
&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1167934"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;Switch(config-if)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;switchport port-security
&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1167935"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;Switch(config-if)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;switchport port-security maximum 2
&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1167936"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;Switch(config-if)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;switchport port-security mac-address sticky
&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1167937"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;Switch(config-if)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;switchport port-security maximum 1 vlan voice
&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1167938"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;Switch(config-if)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;switchport port-security maximum 1 vlan access
&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;A name="wp1167939"&gt;&lt;/A&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;Switch(config-if)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;end
&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Make sure you give the "voice" and "access" in the end.&lt;BR /&gt;&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/50sg/configuration/guide/port_sec.html"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/50sg/configuration/guide/port_sec.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Here's a random fact &lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="content"&gt;Prior to Cisco IOS Release 12.2(31)SG, you 
required three MAC addresses as the maximum parameter to support an IP 
Phone and a PC. With Cisco IOS Release 12.2(31)SG and later releases, 
the maximum parameter must be configured to two, one for the phone and 
one for the PC.
&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;Let me know how that works out for you.&lt;BR /&gt;&lt;BR /&gt;Pls Rate the post if its helpful.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Here's another post on the CSC&lt;BR /&gt;&lt;BR /&gt;&lt;A class="jive-link-external-small" href="https://learningnetwork.cisco.com/message/75452"&gt;https://learningnetwork.cisco.com/message/75452&lt;/A&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Dec 2010 02:00:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580924#M139985</guid>
      <dc:creator>dijohn</dc:creator>
      <dc:date>2010-12-29T02:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: Port Security violation, please help</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580925#M139986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried to change Violation mode to "Restrict" and today I have got this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show port-security interface fastEthernet 4/4&lt;BR /&gt;Port Security&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&lt;BR /&gt;Port Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Secure-up&lt;BR /&gt;Violation Mode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Restrict&lt;BR /&gt;Aging Time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1 mins&lt;BR /&gt;Aging Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Inactivity&lt;BR /&gt;SecureStatic Address Aging : Disabled&lt;BR /&gt;Maximum MAC Addresses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3&lt;BR /&gt;Total MAC Addresses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1&lt;BR /&gt;Configured MAC Addresses&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;Sticky MAC Addresses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;Last Source Address:Vlan&amp;nbsp;&amp;nbsp; : 0023.339c.e1cf:412&lt;BR /&gt;Security Violation Count&amp;nbsp;&amp;nbsp; : 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show logging&lt;/P&gt;&lt;P&gt;Dec&amp;nbsp; 27 14:32:39.087 CET: %PORT_SECURITY-2-PSECURE_VIOLATION: Security&amp;nbsp; violation occurred, caused by MAC address 0023.339c.e1cf on port&amp;nbsp; FastEthernet4/4.&lt;BR /&gt;Dec 27 14:35:39.081 CET: %PM-4-ERR_RECOVER: Attempting to recover from psecure-violation err-disable state on Fa4/4&lt;BR /&gt;Dec 27 15:16:59.369 CET: %PM-4-ERR_DISABLE: psecure-violation error detected on Fa4/4, putting Fa4/4 in err-disable state&lt;BR /&gt;Dec&amp;nbsp; 27 15:16:59.373 CET: %PORT_SECURITY-2-PSECURE_VIOLATION: Security&amp;nbsp; violation occurred, caused by MAC address 0023.339c.e1cf on port&amp;nbsp; FastEthernet4/4.&lt;BR /&gt;Dec 27 15:19:59.356 CET: %PM-4-ERR_RECOVER: Attempting to recover from psecure-violation err-disable state on Fa4/4&lt;BR /&gt;Dec&amp;nbsp; 29 04:01:19.048 CET: %PORT_SECURITY-2-PSECURE_VIOLATION: Security&amp;nbsp; violation occurred, caused by MAC address 0023.339c.e1cf on port&amp;nbsp; FastEthernet4/4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;On&amp;nbsp; Thursday, I am going to plug this phone to another port and will see.&amp;nbsp; If the problem persist I will replace that phone. I will let you know&amp;nbsp; the result. In meantime I will try to use sticky mac-address to see what MACs do that (dijohn's advice).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you all for you responses.&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Dec 2010 09:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580925#M139986</guid>
      <dc:creator>radoslav-drabik</dc:creator>
      <dc:date>2010-12-29T09:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Port Security violation, please help</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580926#M139987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just some update. I've tried to configure sticky MAC address and I still get the same error and violation count is incrementing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dec 29 12:32:03.147 CET: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address 0023.339c.e1cf on port FastEthernet4/4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show port-security int fast 4/4&lt;BR /&gt;Port Security&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&lt;BR /&gt;Port Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Secure-up&lt;BR /&gt;Violation Mode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Restrict&lt;BR /&gt;Aging Time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1 mins&lt;BR /&gt;Aging Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Inactivity&lt;BR /&gt;SecureStatic Address Aging : Disabled&lt;BR /&gt;Maximum MAC Addresses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3&lt;BR /&gt;Total MAC Addresses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1&lt;BR /&gt;Configured MAC Addresses&amp;nbsp;&amp;nbsp; : 0&lt;BR /&gt;Sticky MAC Addresses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1&lt;BR /&gt;Last Source Address:Vlan&amp;nbsp;&amp;nbsp; : 0023.339c.e1cf:412&lt;BR /&gt;Security Violation Count&amp;nbsp;&amp;nbsp; : 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#interface FastEthernet4/4&lt;BR /&gt; switchport access vlan 112&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 412&lt;BR /&gt; switchport port-security maximum 3&lt;BR /&gt; switchport port-security maximum 1 vlan access&lt;BR /&gt; switchport port-security maximum 1 vlan voice&lt;BR /&gt; switchport port-security&lt;BR /&gt; switchport port-security aging time 1&lt;BR /&gt; switchport port-security violation restrict&lt;BR /&gt; switchport port-security aging type inactivity&lt;BR /&gt; switchport port-security mac-address sticky&lt;BR /&gt; switchport port-security mac-address sticky 0023.339c.e1cf vlan voice&lt;BR /&gt; no logging event link-status&lt;BR /&gt; load-interval 60&lt;BR /&gt; qos vlan-based&lt;BR /&gt; no snmp trap link-status&lt;BR /&gt; tx-queue 3&lt;BR /&gt;&amp;nbsp;&amp;nbsp; priority high&lt;BR /&gt; ip dhcp snooping limit rate 10&lt;BR /&gt;end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Dec 2010 13:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580926#M139987</guid>
      <dc:creator>radoslav-drabik</dc:creator>
      <dc:date>2010-12-29T13:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Port Security violation, please help</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580927#M139988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problem solved. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There were no errors&amp;nbsp; on the switch port. But when I looked at the phone statistics I fount these:&lt;/P&gt;&lt;P&gt;Rx crcErr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00135361&amp;nbsp; (incrementing rapidly)&lt;/P&gt;&lt;P&gt;Rx alignErr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00001891&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't see anything on the switch (show int fast 4/4) but Rx crcErr were incrementing on the phone rapidly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wiring issues....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2012 07:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580927#M139988</guid>
      <dc:creator>radoslav-drabik</dc:creator>
      <dc:date>2012-03-30T07:59:09Z</dc:date>
    </item>
    <item>
      <title>this is an old post but</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580928#M139989</link>
      <description>&lt;P&gt;this is an old post but related to my question:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are cisco IP phones with 1 PC hanging off of it.&lt;/P&gt;
&lt;P&gt;we are using port security with sticky mac:&amp;nbsp; basically everything works ok, but sometimes I can clear the port, but it just errors back out.&lt;/P&gt;
&lt;P&gt;The port config is :&lt;/P&gt;
&lt;DIV&gt;
&lt;PRE&gt;
Switch(config-if)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;switchport port-security maximum 2
&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;PRE&gt;
Switch(config-if)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;switchport port-security mac-address sticky
&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;PRE&gt;
Switch(config-if)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;switchport port-security maximum 1 vlan voice
&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;PRE&gt;
Switch(config-if)# &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;switchport port-security maximum 1 vlan access
&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt;which is the same in the above post:&lt;/P&gt;
&lt;P&gt;I will issue the clear arp, clear mac add d, clear port all, clear port stick interface (INT) then I go into conf t, then the interface, and do&amp;nbsp; shut, no shut.&lt;/P&gt;
&lt;P&gt;it works 97% of the time.&lt;/P&gt;
&lt;P&gt;what I mean is that it always clears the port, but the port will re-error out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so I have to change the max from 2 to 4 and the access vlan and voice vlan from 1 to 2 and then it works fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any idea why?&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2015 09:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580928#M139989</guid>
      <dc:creator>slotking22</dc:creator>
      <dc:date>2015-05-31T09:59:52Z</dc:date>
    </item>
    <item>
      <title>Hi slotking22, first of all,</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580929#M139990</link>
      <description>&lt;P&gt;Hi slotking22,&lt;/P&gt;&lt;P&gt;&amp;nbsp;first of all, remember that &lt;STRONG&gt;port-security&lt;/STRONG&gt; is defined by &lt;STRONG&gt;MAC &amp;amp; VLAN&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;Sometimes, when the &lt;STRONG&gt;Phone &lt;/STRONG&gt;boots the &lt;STRONG&gt;Phone MAC &lt;/STRONG&gt;is associated to the &lt;STRONG&gt;Data VLAN &lt;/STRONG&gt;first and after that to the &lt;STRONG&gt;Voice VLAN&lt;/STRONG&gt; ... if you use the '&lt;EM&gt;maximum 2&lt;/EM&gt;' you will reach a violation because you will have &lt;STRONG&gt;3x MAC &amp;amp; VLAN &lt;/STRONG&gt;info:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Phone MAC &lt;/STRONG&gt;in &lt;STRONG&gt;Data VLAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Phone MAC &lt;/STRONG&gt;in &lt;STRONG&gt;Voice VLAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PC &lt;/STRONG&gt;in &lt;STRONG&gt;Data VLAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Because of that, it's recommended to use at least '&lt;EM&gt;maximum 3&lt;/EM&gt;' ... I personally use '&lt;EM&gt;maximum 5&lt;/EM&gt;'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 08:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/1580929#M139990</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2015-06-04T08:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: Port Security violation, please help</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/4433472#M398097</link>
      <description>&lt;P&gt;thanks for your good information Radolav.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem same as your case now, can you please advise me what thing you did then the issue solved?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 02:01:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/port-security-violation-please-help/m-p/4433472#M398097</guid>
      <dc:creator>LaVangkeelao1323</dc:creator>
      <dc:date>2021-07-15T02:01:41Z</dc:date>
    </item>
  </channel>
</rss>

