cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2120
Views
0
Helpful
12
Replies

Cisco 2960 Switches randomly activating port security on random computers.

nilay.joshi
Level 1
Level 1

Hello,

I have weird problem on our 2960 Access Switches where the switch automatically activates port-security randomly on the random computers on the network.  I don't move the computer once its in place like just today it happened in the CEO's computer.  It's just strange that it decides to activate the port security for no reason?  I don't know if any one had this kind of issue before but here is the config that you can look and let me know if I am missing anything?

 description User
 switchport access vlan 302
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS | AccessEdgeQoS  | AccessEdgeQoS | AccessEdgeQoS
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source

12 Replies 12

Paul
Level 1
Level 1

Can you post a sh log output, and a sh mac-address table?

With the sh mac-address table int <affected interface> how many MAC addresses are associated with the interface?

Is there a hub in his office? Does she switch off his phone?

Unrelated curiosity - why even have port security enabled if 11 MAC addresses are allowed?

Please see attached .txt file for the log and mac address that is associated with the port. I have only 1 Mac address associated with the port.  He does not have any Hub in the office.  The port that the computer is connected to is stand alone port. It doesn't have anything else is connected except a computer. 

We have port security just incase if someone comes in with rouge device and it blocks it.  I do think we should only allow 2 to 3 MAC addresses but I am not the one who is making decision.. it is all decided by my IT director.

VIOLATION: Security violation occurred, caused by MAC address c8cb.b80c.ce2e on                                                                                                                                                              port GigabitEthernet1/0/28.
Oct  5 09:05:46.407: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:05:51.940: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:05:57.128: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:06:06.688: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:06:13.130: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:06:21.092: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:06:38.678: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:06:44.106: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:06:51.489: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:06:57.494: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:07:13.223: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:07:42.277: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:07:49.160: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:08:01.044: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occu                                                                                                                                                             rred, caused by MAC address c8cb.b80c.ce2e on port GigabitEthernet1/0/28.
Oct  5 09:09:29.080: %LINK-5-CHANGED: Interface GigabitEthernet1/0/28, changed s                                                                                                                                                             tate to administratively down
Oct  5 09:09:30.080: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthe                                                                                                                                                             rnet1/0/28, changed state to down
Oct  5 09:09:41.059: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/28, changed st                                                                                                                                                             ate to down
Oct  5 09:09:45.540: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/28, changed st                                                                                                                                                             ate to up
Oct  5 09:09:45.845: %SYS-5-CONFIG_I: Configured from console by admin on vty0 (                                                                                                                                                             10.1.20.4)
Oct  5 09:09:46.558: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthe                                                                                                                                                             rnet1/0/28, changed state to up
Oct  5 09:10:17.649: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthe                                                                                                                                                             rnet1/0/28, changed state to down
Oct  5 09:10:18.649: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/28, changed st                                                                                                                                                             ate to down
Oct  5 09:10:25.815: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/28, changed st                                                                                                                                                             ate to up
Oct  5 09:10:26.818: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthe                                                                                                                                                             rnet1/0/28, changed state to up
Oct  5 09:12:23.908: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthe                                                                                                                                                             rnet1/0/28, changed state to down
Oct  5 09:12:24.908: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/28, changed st                                                                                                                                                             ate to down
Oct  5 09:12:32.867: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/28, changed st                                                                                                                                                             ate to up
Oct  5 09:12:33.870: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthe                                                                                                                                                             rnet1/0/28, changed state to up
Oct  5 09:12:43.077: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthe                                                                                                                                                             rnet1/0/28, changed state to down
Oct  5 09:12:44.077: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/28, changed st                                                                                                                                                             ate to down
Oct  5 09:12:46.999: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/28, changed st                                                                                                                                                             ate to up
Oct  5 09:12:48.002: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthe                                                                                                                                                             rnet1/0/28, changed state to up

Nilay,

Also attach a sh port-sec

Secure Port  MaxSecureAddr  CurrentAddr  SecurityViolation  Security Action
                (Count)       (Count)          (Count)
---------------------------------------------------------------------------
    Gi1/0/2             11            1                  0         Restrict
    Gi1/0/4             11            1                  0         Restrict
    Gi1/0/6             11            1                  0         Restrict
    Gi1/0/8             11            1                  0         Restrict
    Gi1/0/9             11            1                  0         Restrict
   Gi1/0/10             11            1                  0         Restrict
   Gi1/0/11             11            1                  0         Restrict
   Gi1/0/12             11            1                  0         Restrict
   Gi1/0/13             11            1                  0         Restrict
   Gi1/0/14             11            1                  0         Restrict
   Gi1/0/15             11            0                  0         Restrict
   Gi1/0/17             11            1                  0         Restrict
   Gi1/0/19             11            0                  0         Restrict
   Gi1/0/20             11            0                  0         Restrict
   Gi1/0/21             11            1                  0         Restrict
   Gi1/0/22             11            1                  0         Restrict
   Gi1/0/24             11            1                  0         Restrict
   Gi1/0/25             11            1                  0         Restrict
   Gi1/0/26             11            1                  0         Restrict
   Gi1/0/28             11            1                  0         Restrict
   Gi1/0/31             11            1                  0         Restrict
   Gi1/0/33             11            1                  0         Restrict
   Gi1/0/36             11            0                  0         Restrict
   Gi1/0/37             11            1                  0         Restrict
   Gi1/0/38             11            1                  0         Restrict
   Gi1/0/40             11            0                  0         Restrict
   Gi1/0/45             11            1                  0         Restrict
---------------------------------------------------------------------------
Total Addresses in System (excluding one mac per port)     : 0
Max Addresses limit in System (excluding one mac per port) : 8192

Interesting. All looks good from those outputs.

Care to share the entire switch config?


Current configuration : 26649 bytes
!
! Last configuration change at 10:38:48 CDT Thu Sep 29 2016 by admin
! NVRAM config last updated at 10:38:49 CDT Thu Sep 29 2016 by admin
!
version 15.0
no service pad
service timestamps debug datetime msec localtime
service timestamps log datetime msec localtime
service password-encryption
!
hostname (name of the host)
!
boot-start-marker
boot-end-marker
!
logging buffered 8192
enable secret 5 Seceret key
!
username admin privilege 15 secret 5 Secret key.
aaa new-model
!
!
!
!
!
!
!
!
aaa session-id common
clock timezone CST -6 0
clock summer-time CDT recurring
switch 1 provision ws-c2960s-48fps-l
!
!
ip domain-name demarlogisticsinc.com
ip name-server ip address
ip name-server ip address
ipv6 nd raguard policy HOST_POLICY
!
vtp domain CS
vtp mode transparent
udld enable

!
mls qos map policed-dscp  0 10 18 24 46 to 8
mls qos map cos-dscp 0 8 16 24 32 46 48 56
mls qos srr-queue output cos-map queue 1 threshold 3 4 5
mls qos srr-queue output cos-map queue 2 threshold 1 2
mls qos srr-queue output cos-map queue 2 threshold 2 3
mls qos srr-queue output cos-map queue 2 threshold 3 6 7
mls qos srr-queue output cos-map queue 3 threshold 3 0
mls qos srr-queue output cos-map queue 4 threshold 3 1
mls qos srr-queue output dscp-map queue 1 threshold 3 32 33 40 41 42 43 44 45
mls qos srr-queue output dscp-map queue 1 threshold 3 46 47
mls qos srr-queue output dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23
mls qos srr-queue output dscp-map queue 2 threshold 1 26 27 28 29 30 31 34 35
mls qos srr-queue output dscp-map queue 2 threshold 1 36 37 38 39
mls qos srr-queue output dscp-map queue 2 threshold 2 24
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63
mls qos srr-queue output dscp-map queue 3 threshold 3 0 1 2 3 4 5 6 7
mls qos srr-queue output dscp-map queue 4 threshold 1 8 9 11 13 15
mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14
mls qos queue-set output 1 threshold 1 100 100 50 200
mls qos queue-set output 1 threshold 2 125 125 100 400
mls qos queue-set output 1 threshold 3 100 100 100 400
mls qos queue-set output 1 threshold 4 60 150 50 200
mls qos queue-set output 1 buffers 15 25 40 20
mls qos
!
crypto pki trustpoint TP-self-signed-436274944
 enrollment selfsigned
 subject-name cn=IOS-Self-Signed-Certificate-436274944
 revocation-check none
 rsakeypair TP-self-signed-436274944
!
!
crypto pki certificate chain TP-self-signed-436274944
 certificate self-signed 01
  30820242 308201AB A0030201 02020101 300D0609 2A864886 F70D0101 04050030
  30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
  69666963 6174652D 34333632 37343934 34301E17 0D393330 36323830 30313235
  365A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
  532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3433 36323734
  39343430 819F300D 06092A86 4886F70D 01010105 0003818D 00308189 02818100
  B6DAC7DE 83E447BE AB4F0B75 CD319FE8 7D365D65 97120D5D 32CB20C7 4045E4A6
  940FAC59 32A24ABF 95822238 788BDEA3 5B13F2A6 A1CC5F18 2BA1C5D9 6D989CF2
  9ADF062C 102F98C4 371B011C 23FDB94F 3498DDD8 8ADD6400 8D0D2100 264BBB70
  D8DB0AAD 60DEF6D4 CECC2D2F 51B595A1 140107A3 D56D955D 3A76B1D3 48D2FB33
  02030100 01A36C30 6A300F06 03551D13 0101FF04 05300301 01FF3017 0603551D
  11041030 0E820C63 73316573 77616363 30322E30 1F060355 1D230418 30168014
  E7AE0569 20B3A85B D6328229 A8013143 DCDE83D8 301D0603 551D0E04 160414E7
  AE056920 B3A85BD6 328229A8 013143DC DE83D830 0D06092A 864886F7 0D010104
  05000381 81002057 161B9F3B 2D783612 18D8D621 DCDDA411 33BEFFFA 5744635E
  B4128E3D F1D38A86 E534CC94 FD530AA9 809656F6 8ECC9A2D 466B9EC2 E6887267
  24A48C8B 3B90E331 D3339F31 4437C07C 46EAA618 079D4B18 C2F85778 5F9E2E82
  6ABC8F8A D0A7F046 2080F83B 775594A9 525CAC60 6B7676C4 04B27305 FC0AC680
  153B9BDF 96BC
        quit
!
spanning-tree mode rapid-pvst
spanning-tree portfast bpduguard default
spanning-tree extend system-id
!
!
!
!
!
errdisable recovery cause udld
errdisable recovery cause bpduguard
errdisable recovery cause security-violation
errdisable recovery cause channel-misconfig (STP)
errdisable recovery cause pagp-flap
errdisable recovery cause dtp-flap
errdisable recovery cause link-flap
errdisable recovery cause sfp-config-mismatch
errdisable recovery cause gbic-invalid
errdisable recovery cause psecure-violation
errdisable recovery cause port-mode-failure
errdisable recovery cause dhcp-rate-limit
errdisable recovery cause pppoe-ia-rate-limit
errdisable recovery cause mac-limit
errdisable recovery cause vmps
errdisable recovery cause storm-control
errdisable recovery cause inline-power
errdisable recovery cause arp-inspection
errdisable recovery cause loopback
errdisable recovery cause small-frame
port-channel load-balance src-dst-ip
!
!
!
!
vlan internal allocation policy ascending
!
vlan 302
 name User
!
vlan 304
 name name of vlan
!
vlan 310
 name name of vlan
!
vlan 311
 name name of vlan
!
vlan 320
 name  name of vlan
!
vlan 999
 name AnitVlanHopping
!
ip tftp source-interface Vlan310
ip ssh version 2
ip scp server enable
!
class-map match-all AUTOQOS_VOIP_DATA_CLASS
  match ip dscp ef
class-map match-all AUTOQOS_DEFAULT_CLASS
  match access-group name AUTOQOS-ACL-DEFAULT
class-map match-all AUTOQOS_VOIP_SIGNAL_CLASS
  match ip dscp cs3
!
policy-map AUTOQOS-SRND4-CISCOPHONE-POLICY
 class AUTOQOS_VOIP_DATA_CLASS
   set dscp ef
  police 128000 8000 exceed-action policed-dscp-transmit
 class AUTOQOS_VOIP_SIGNAL_CLASS
   set dscp cs3
  police 32000 8000 exceed-action policed-dscp-transmit
 class AUTOQOS_DEFAULT_CLASS
   set dscp default
  police 10000000 8000 exceed-action policed-dscp-transmit
!
!
!
!
!
!
!
!
!
macro name AccessEdgeQoS
auto qos voip cisco-phone
@
macro name EgressQoS
mls qos trust dscp
queue-set 1
srr-queue bandwidth share 1 30 35 5
priority-queue out
@
!
!
interface Port-channel2
 description EtherChannel to cs1eswcor01
 switchport trunk native vlan 999
 switchport trunk allowed vlan 302,304,310,311,320
 switchport mode trunk
 logging event trunk-status
 load-interval 30
!
interface FastEthernet0
 no ip address
 shutdown
!
interface GigabitEthernet1/0/1
 description Sears Industrial SW
 switchport access vlan 302
 switchport mode access
!
interface GigabitEthernet1/0/2
 description CS-AIR-1
 switchport access vlan 310
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/3
 description User
 switchport access vlan 302
 switchport mode access
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/4
 description User
 switchport access vlan 302
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS | AccessEdgeQoS  | AccessEdgeQoS | AccessEdgeQoS
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/5
 description User
 switchport access vlan 302
 switchport mode access
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS | AccessEdgeQoS
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
!
interface GigabitEthernet1/0/6
 switchport access vlan 304
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS | AccessEdgeQoS
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/7
 shutdown
!
interface GigabitEthernet1/0/8
 description voip
 switchport access vlan 304
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS | AccessEdgeQoS
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/9
 description User
 switchport access vlan 302
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/10
 description voip
 switchport access vlan 304
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/11
 description Users
 switchport access vlan 320
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 spanning-tree bpduguard enable
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/12
 description voip
 switchport access vlan 304
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/13
 description Users
 switchport access vlan 320
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 spanning-tree bpduguard enable
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/14
 description voip
 switchport access vlan 304
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/15
 description B:A7 (IT Label Printer)
 switchport access vlan 320
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/16
 shutdown
!
interface GigabitEthernet1/0/17
 description User
 switchport access vlan 302
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/18
 shutdown
!
interface GigabitEthernet1/0/19
 description Martins Temp Cubical
 switchport access vlan 320
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS | AccessEdgeQoS | AccessEdgeQoS | AccessEdgeQoS | AccessEdgeQoS | AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 spanning-tree bpduguard enable
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/20
 description voip
 switchport access vlan 304
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/21
 description Users
 switchport access vlan 320
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 spanning-tree bpduguard enable
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/22
 description voip
 switchport access vlan 304
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/23
 description User (R1/P4-11)
 switchport access vlan 302
 switchport mode access
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS | AccessEdgeQoS
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
!
interface GigabitEthernet1/0/24
 description User (R1/P5-11)
 switchport access vlan 302
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS | AccessEdgeQoS
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/25
 description voip (R1/P5-12)
 switchport access vlan 304
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS | AccessEdgeQoS
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/26
 description IT Station Cubicle P4_Jack12
 switchport access vlan 320
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
!
interface GigabitEthernet1/0/27
 shutdown
!
interface GigabitEthernet1/0/28
 description Lynn's Printer
 switchport access vlan 302
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/29
 shutdown
!
interface GigabitEthernet1/0/30
 shutdown
!
interface GigabitEthernet1/0/31
 description Camera Vlan 311
 switchport access vlan 311
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/32
 shutdown
!
interface GigabitEthernet1/0/33
 description Camera Vlan 311
 switchport access vlan 311
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/34
 shutdown
!
interface GigabitEthernet1/0/35
 shutdown
!
interface GigabitEthernet1/0/36
 description APC UPS
 switchport access vlan 310
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/37
 description APC UPS
 switchport access vlan 310
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/38
 description APC UPS
 switchport access vlan 310
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/39
 shutdown
!
interface GigabitEthernet1/0/40
 description APC UPS Rack 2 TOP 1500
 switchport access vlan 310
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS | AccessEdgeQoS
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/41
 shutdown
!
interface GigabitEthernet1/0/42
 shutdown
!
interface GigabitEthernet1/0/43
 shutdown
!
interface GigabitEthernet1/0/44
 shutdown
!
interface GigabitEthernet1/0/45
 description CS1 Time Clock
 switchport access vlan 310
 switchport mode access
 switchport port-security maximum 11
 switchport port-security violation restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 ipv6 nd raguard attach-policy HOST_POLICY
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description AccessEdgeQoS
 auto qos voip cisco-phone
 spanning-tree portfast
 service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
 ip verify source
!
interface GigabitEthernet1/0/46
 shutdown
!
interface GigabitEthernet1/0/47
 shutdown
!
interface GigabitEthernet1/0/48
 shutdown
!
interface GigabitEthernet1/0/49
 shutdown
!
interface GigabitEthernet1/0/50
 shutdown
!
interface GigabitEthernet1/0/51
 description Link to name of  core switch
 switchport trunk native vlan 999
 switchport trunk allowed vlan 302,304,310,311,320
 switchport mode trunk
 logging event trunk-status
 logging event bundle-status
 load-interval 30
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 mls qos trust dscp
 macro description EgressQoS
 channel-protocol lacp
 channel-group 2 mode active
!
interface GigabitEthernet1/0/52
 description Link to name of core switch
 switchport trunk native vlan 999
 switchport trunk allowed vlan 302,304,310,311,320
 switchport mode trunk
 logging event trunk-status
 logging event bundle-status
 load-interval 30
 srr-queue bandwidth share 1 30 35 5
 priority-queue out
 mls qos trust dscp
 macro description EgressQoS
 channel-protocol lacp
 channel-group 2 mode active
!
interface Vlan1
 no ip address
 shutdown
!
interface Vlan310
 ip address ip address 255.255.255.0
!
ip default-gateway ip address
no ip http server
ip http secure-server
!
!
ip access-list extended AUTOQOS-ACL-DEFAULT
 permit ip any any
logging facility local5
logging host ip address
access-list 1 permit ip address 0.0.0.255
access-list 1 permit ip address 0.0.0.255
access-list 1 permit ip address 0.0.0.255
!
snmp-server community demarswitchro RO
snmp-server location CS1 Server Room
!
!
!
!
line con 0
line vty 0 4
 access-class 1 in vrf-also
 length 0
 transport preferred none
 transport input ssh
line vty 5 15
 access-class 1 in vrf-also
 length 0
 transport preferred none
 transport input ssh
!
ntp server ip address
end

I have put in words where there needs to be IP Addresses, vlan descriptions, and core switch name for security reasons but here is the config.

Thanks for posting. I see on the port config it is access in vlan 302, is this your voice VLAN? Port desc says it is a printer, but you identified it as the CEO's machine (MAC ID says HP device).

Is a computer switching off the phone?

IP source guard may also be suspect.

Yes 302 is our Voice Vlan and it's HP machine.  The phone is not being switched off. Phone and Computer are on totally separate jacks. The Computer is built in all in one computer that has NIC and WIFI Card. How ever the wifi card isn't connected to network could that be causing the issue? but even than we allow 11 MAC's that shouldn't active the port- security.

Ah, okay.

Is the phone an HP phone? Or is an HP computer trying to join the voice vlan?

The phone is Cisco IP phone 7965.  No the HP isn't trying to join the voice vlan.  Both are on separate vlans.  Also, Computer and Phone both are hooked up into separate ports on the switch.

pearl2468
Level 1
Level 1

Hi ,

Can you provide the below command results.

show port-security interface GigabitEthernet1/0/28

Regards,

p

Review Cisco Networking for a $25 gift card