09-21-2017 12:37 AM - edited 03-08-2019 12:06 PM
Having a issue with port secuirty, happens more than once and on diffrent ports with the same port config
See below outputs am i missing something? or not understading
***Show logg***
%PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address f8ca.z835.b777 on port GigabitEthernet2/0/41
***show port-security***
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count) (Count) (Count)
---------------------------------------------------------------------------
Gi2/0/41 20 1 1397 Restrict
***show port-security interface gigabitEthernet 2/0/41***
Port Security : Enabled
Port Status : Secure-up
Violation Mode : Restrict
Aging Time : 10 mins
Aging Type : Absolute
SecureStatic Address Aging : Disabled
Maximum MAC Addresses : 20
Total MAC Addresses : 1
Configured MAC Addresses : 0
Sticky MAC Addresses : 0
Last Source Address:Vlan : 0019.z1e5.b999:20
Security Violation Count : 1397
***Port Config***
interface GigabitEthernet2/0/41
switchport access vlan 10
switchport mode access
switchport nonegotiate
switchport voice vlan 20
switchport port-security maximum 20
switchport port-security
switchport port-security aging time 10
switchport port-security violation restrict
load-interval 30
storm-control broadcast level 5.00
spanning-tree portfast
spanning-tree guard root
ip dhcp snooping limit rate 30
09-21-2017 01:42 AM
Dear Aran,
Your "show port-security" command shows that there is 1397 times that you sent frames that were not in your 20 cached MAC Addresses for port security.
Regards,
Mahdi
09-21-2017 01:58 AM
Hi,
Is this mac address f8ca.z835.b777 on the same VLAN as the port Gi2/0/41 (VLAN 10)? Could you trace it? My guess is that a device with the mac (f8ca.z835.b777) was originally connected on a port other than Gi2/0/41 on same VLAN and someone plugged it on port Gi2/0/41 that caused this error.
If traffic with a secure MAC address that is configured or learned on one secure port attempts to access another secure port in the same VLAN, applies the configured violation mode.
Cheers
09-21-2017 02:07 AM
I think you right cause when i search for the mac address f8ca.z835.b777 i find it connected to Gi2/0/33
Im guessing the user would leave his desk and then go to a confrence room for example and plug in there.
Would changing the aging timer fix this issue?
09-21-2017 02:29 AM
09-21-2017 09:40 AM
Hello
it looks like PS has kicked in due to inactivity on the port
res
paul
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide