cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1002
Views
0
Helpful
7
Replies

3750X port goes into err-disabled due to reaching mac-address limit but the show mac address-table is not showing enough mac addresses to reach this limit

CODNetadmin
Beginner
Beginner

Hi Everyone,

Our 3750X port goes into err-disabled due to reaching mac-address limit but the show mac address-table is not showing enough mac addresses to reach this limit. Meaning, for example the port-security limit is set to 10, and the show mac table only lists 3 mac-addresses, the err-disabled due to port-security is still triggered. This is being resolved by shutting/no-shutting the port several times. Any feedback or having the same experience will be much appreciated. Our device is 48-PF-L and version is universalk9 SE5.

Thanks!

7 Replies 7

Georg Pauwen
VIP Master VIP Master
VIP Master

Hello,

that sounds like a bug...but I could not find one that matches your description. Which template are you running (show sdm prefer) ?

You can obviously circumvent the problem by configuring:

switchport port-security violation protect | restrict

which will keep the port from going into err-disable, not sure if that complies with your security policy though...

dperezoquendo
Beginner
Beginner

Hello,

Did you verify that none of the 3 listed mac-addresses are sticky'd on another interface? That would be another cause of tripping port-security.

Hi dperezoquendo,

We are not using sticky.

Thanks!

paul driver
VIP Expert VIP Expert
VIP Expert

Hello
Is this occurring on just one port? -

1) clear port-security configured interface x/x
2) default that interlace and shut it down,Then re-configure it without PS and check the mac table for that interface.
3) re-apply PS and  also enable error recovery.


Please share
sh port-security interface x/x

res
Paul


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

Hi Paul,

This is appearing on multiple random ports.

We have done all those. We don't want a workaround, we want a solution to this problem. I'm looking into upgrading, but i've never seen a bug similar to this.

Thanks!

Hello,

is your 3750X a standalone or stacked switch ? Either way, try and change the aging values, e.g.:

switchport port-security aging time 4

switchport port-security aging type inactivity

Hello

if that's the case and error recovery doesn't work either I would suggest I iOS upgrade to see if that resolves the issue

what kind of hosts are connected?

res

paul


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers