Our 3750X port goes into err-disabled due to reaching mac-address limit but the show mac address-table is not showing enough mac addresses to reach this limit. Meaning, for example the port-security limit is set to 10, and the show mac table only lists 3 mac-addresses, the err-disabled due to port-security is still triggered. This is being resolved by shutting/no-shutting the port several times. Any feedback or having the same experience will be much appreciated. Our device is 48-PF-L and version is universalk9 SE5.
that sounds like a bug...but I could not find one that matches your description. Which template are you running (show sdm prefer) ?
You can obviously circumvent the problem by configuring:
switchport port-security violation protect | restrict
which will keep the port from going into err-disable, not sure if that complies with your security policy though...
Is this occurring on just one port? -
1) clear port-security configured interface x/x
2) default that interlace and shut it down,Then re-configure it without PS and check the mac table for that interface.
3) re-apply PS and also enable error recovery.
sh port-security interface x/x
This is appearing on multiple random ports.
We have done all those. We don't want a workaround, we want a solution to this problem. I'm looking into upgrading, but i've never seen a bug similar to this.
is your 3750X a standalone or stacked switch ? Either way, try and change the aging values, e.g.:
switchport port-security aging time 4
switchport port-security aging type inactivity
if that's the case and error recovery doesn't work either I would suggest I iOS upgrade to see if that resolves the issue
what kind of hosts are connected?