cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
843
Views
0
Helpful
4
Replies

Port security

gaelfabrice
Level 1
Level 1

hi

plz i would like to know the purpose of this commands

switchport mode access

switchport port-security

switchport port-security maximum 2

switchport port-security mac-address aaaa.bbbb.cccc

switchport port-security violation shutdown 

if a host with mac-address dddd.eeee.ffff

is directly connected to the switch port what gonna happen

host will be allowed or port will goes down  ?

and if another host with mac-address gggg.hhhh.iiii

connect also what will happen

thx in advance

1 Accepted Solution

Accepted Solutions

Dennis Mink
VIP Alumni
VIP Alumni

the above means that the port will go into error-disable mode when more than 2 mac addresses are learned through that particular port. on mac is aaaa.bbbb.cccc the other is dynamically learned, unless explicitly configured. so your config as it is will allow dddd.eeee.ffff as you set a mximum of 2 mac addresses as per

switchport port-security maximum 2

hope this explains it

Please remember to rate useful posts, by clicking on the stars below.

View solution in original post

4 Replies 4

Dennis Mink
VIP Alumni
VIP Alumni

the above means that the port will go into error-disable mode when more than 2 mac addresses are learned through that particular port. on mac is aaaa.bbbb.cccc the other is dynamically learned, unless explicitly configured. so your config as it is will allow dddd.eeee.ffff as you set a mximum of 2 mac addresses as per

switchport port-security maximum 2

hope this explains it

Please remember to rate useful posts, by clicking on the stars below.

so  

gggg.hhhh.iiii  will be blocked ( port will goes down ) 

and 

dddd.eeee.ffff

allowed right ?

so, as per your initial post, you have  hard set only one mac:

mac-address aaaa.bbbb.cccc

the next mac is still allowed, be it dddd.eeee.ffff  or gggg.hhhh.iiii   because that second mac address in the port is dynamically learned, either mac will be allowed, but not both.

I strongly advise you to test it though

Please remember to rate useful posts, by clicking on the stars below.

thx thxits ok now 

Review Cisco Networking for a $25 gift card