07-19-2023 02:17 AM
Hello community, i'm just a new CCNA R&S certified
When configuring port-security on an interface of a Cisco c2960 Series, i face a small issue because i wanted to insert 250 secure static mac addresses on port fa0/15 without rewrite the same command line "switchport port-security mac-address aaa.bbb.ccc". Therefore, does a command or feature like "mac-address range" or "mac-address list..." exist on c2960 switches ?
How can i do to simplify this task ?
Solved! Go to Solution.
07-19-2023 05:20 AM
sorry, the only way then is add manually one by one.
07-19-2023 02:34 AM
you can use sticky port-security with max 250
this make port learn 250 mac address add it as static secure automatic.
07-19-2023 05:11 AM
It is true, but if an unidentify machine (coming outside from the enterprise) plug onto that port, it will automatically accepted and secured in running configurations because the maximum (250 mac addresses) won't be reached yet. Where the necessity to insert statically all internal host mac addresses to avoid this kind of incident (except if i'm wrong). So how to acheive it easily.
07-19-2023 05:20 AM
sorry, the only way then is add manually one by one.
07-19-2023 06:27 AM
In other hand, i think that Cisco can (if they want) add this feature to access switches, the possibility to add (statically) a list or range of secured mac address the command "switchport port-security mac-address list/range mac-address list/range" why not something like that when implementing port security. Or something like that exist on advanced category of switches...
07-19-2023 06:31 AM
There is something in my mind' I will check it tonight in my lab and update you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide