12-10-2017 02:34 AM - edited 03-08-2019 01:03 PM
hi guys
i need to achieve the following objective how can i do that :
1- permit only 3 mac addresses on 3 ports or a vlan
2- they can move between ports but no new device can get connected to any one device
12-10-2017 05:16 AM - edited 12-10-2017 05:18 AM
Hi
interface range <range of ports> example: interface range g1/0/1-48
<it must be an access mode switchport>
switchport
switchport port-security
switchport port-security maximum 3
switchport port-security violation shutdown
switchport port-security mac-address aaaa.aaaa.aaaa
switchport port-security mac-address aaaa.aaaa.aaab
switchport port-security mac-address aaaa.aaaa.aaac
no shutdown
if you set up other mac address (4th) you will see something like:
Total secure mac-addresses on interface FastEthernet0/0 has reached maximum limit.
Hope it is useful
:-)
12-10-2017 05:24 AM
Hello,
the following configuration allows for a maximum of 3 MAC addresses, they will time out after 1 minute, after which a user can move to another port, and nobody else but these 3 MAC addresses are allowed. Is this what you are after ?
switchport port-security maximum 3
switchport port-security aging time 1 type inactivity
switchport port-security mac-address 00:A0:C7:12:C9:25
switchport port-security mac-address 00:A0:C7:12:C9:26
switchport port-security mac-address 00:A0:C7:12:C9:27
12-10-2017 05:52 AM
thanks but when i try to the same config on other ports i get an error message that tells me i have duplicate mac addresses how can i get around this and can i use mac access list in port security?
12-10-2017 06:04 AM - edited 12-10-2017 06:06 AM
Hi
I understand, a solution for this situation could be remove the static entries and set up the mac-address sticky and configuring a MAC address ACL (If you want to connect the same 3 mac addresses):
Also configuring the aging time
:-)
10-03-2019 03:12 AM
There is one problem with mac access-lists. If there are violations there is no logging at all :-(
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: