The objective is to limit one mac address per port. The mac address should not be fixed to a particular port and full 802.1x migration for all users is not possible. PCs are connected to Cisco IP Phone.Have explored Dynamic Port security:- works well...