cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
524
Views
0
Helpful
1
Replies

Port security that allows a latop to move around

Tod Larson
Level 3
Level 3

We have a conference room where we only want 1 laptop to connect to the network port in that conference room.  I have configured port security to lock the port down to only that laptop.  That part works great.  However, now that laptop won't work at the user's desk.  The mac address table on the switch shows the mac address as learned from the conference room port... as expected... but that doesn't ever seem to age out.  If I remove port security then she can move between rooms fine.

Is there a way to have port security on one port but then let that mac still be learned on another port?

Thanks for any comments.

1 Reply 1

johnlloyd_13
Level 9
Level 9

hi,

you'll need to add/combine port security aging for your scenario. by deffault, static and sticky MAC addresses don't age out. perform the below on both conference room and user desk ports.

Switch(config-if)#switchport port-security mac-address  

Switch(config-if)#switchport port-security aging time 5

Switch(config-if)#switchport port-security aging type inactivity

Review Cisco Networking products for a $25 gift card