cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
922
Views
2
Helpful
1
Replies

Issue with Port getting shut

jorge.s
Level 1
Level 1

We are having an issue with a port getting shut due to port-security reasons, from a Mac-Address connected in a different switch.

We have the following overall config:

errdisable recovery cause udld

errdisable recovery cause bpduguard

errdisable recovery cause security-violation

errdisable recovery cause channel-misconfig

errdisable recovery cause pagp-flap

errdisable recovery cause dtp-flap

errdisable recovery cause link-flap

errdisable recovery cause gbic-invalid

errdisable recovery cause l2ptguard

errdisable recovery cause psecure-violation

errdisable recovery cause dhcp-rate-limit

errdisable recovery cause unicast-flood

errdisable recovery cause vmps

errdisable recovery cause storm-control

errdisable recovery cause arp-inspection

errdisable recovery cause loopback

errdisable recovery interval 600

and on a port by port, we have:

switchport mode access

switchport port-security

switchport port-security aging time 1

switchport port-security aging type inactivity

but when I check the err-disabled detect, I get the following:

STR0073#sh errdisable detect

ErrDisable Reason Detection Mode

----------------- --------- ----

arp-inspection Enabled port

bpduguard Enabled port

channel-misconfig Enabled port

community-limit Enabled port

dhcp-rate-limit Enabled port

dtp-flap Enabled port

ekey Enabled port

gbic-invalid Enabled port

invalid-policy Enabled port

l2ptguard Enabled port

link-flap Enabled port

link-monitor-fail Enabled port

loopback Enabled port

lsgroup Enabled port

oam-remote-failur Enabled port

pagp-flap Enabled port

psecure-violation Enabled port/vlan

security-violatio Enabled port

sfp-config-mismat Enabled port

storm-control Enabled port

udld Enabled port

unicast-flood Enabled port

vmps Enabled port

if you see on psecure-violation, the mode is port/vlan, what that means?

Thanks

Jorge

1 Reply 1

Edison Ortiz
Hall of Fame
Hall of Fame

A secure port can be an access port or a trunk port therefore the errdisable feature is not only tracking a per port violation but also a per vlan violation.

HTH,

__

Edison.