cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
896
Views
4
Helpful
2
Replies

Performance impact of port security.

t.baranski
Level 4
Level 4

Is there any information available about what the performance impact is of using port security on various switch models? I've never seen anything on Cisco's site about this, but I figure that has to be some type of performance impact (especially on lower-end switches) to comparing the source MAC address of every packet against a known list of authorized MAC addresses, especially when using VMPS as opposed to per-port authorized MAC specifications.

If anyone can offer some insight on this, I'd be appreciative.

Thanks,

Terry

2 Replies 2

s-doyle
Level 3
Level 3

As a learning mechanism, the switch anyway has to look at the source address in each frame and check the CAM table to see whether the address is already available or it needs to be populated. For port security, it has to just additionally check whether the address is allowed on that port which can be done fast. So I am doubtful whether it will create any significant performance impact depending on the hardware/software implementation.

Good point about the source address checking. In the case of VMPS, though, I do wonder if there's a significant performance impact as the VMPS file grows. I imagine the VMPS lookup can be done in parallel with the CAM lookup... If entries in the VMPS file are hashed into a CAM of their own, then perhaps there's no performance hit whatsoever.

Review Cisco Networking for a $25 gift card