55-8
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 55 Configuring Port Security
Configuring Port Security on Access Ports
Step 5
Switch(config-if)#
switchport port-security
mac-address forbidden
OR
Switch(config)#
port-security
mac-address
forbidden
(Optional) Sets the MAC address forbidden on the
interface.
OR
Optional) Sets the MAC address forbidden on all
interfaces, globally.
To verify the MAC addresses forbidden on the interface,
use the
show port-security address forbidden
command, in privileged EXEC mode.
Step 6
Switch(config-if)#
switchport port-security
[
aging
{
static
|
time
aging_time
|
type
{
absolute
|
inactivity
}]
Sets the aging time and aging type for all secure addresses
on a port.
Use this feature to remove and add PCs on a secure port
without manually deleting the existing secure MAC
addresses while still limiting the number of secure
addresses on a port.
The
static
keyword enables aging for statically
configured secure addresses on this port.
The
time
aging_time
value
specifies the aging time for this
port. Valid range for
aging_time
is from 0 to 1440 minutes.
If the time is equal to 0, aging is disabled for this port.
The
type
keyword sets the aging type as
absolute
or
inactive
.
•
absolute
—All the secure addresses on this port ago
out exactly after the time (minutes) specified and are
removed from the secure address list.
•
inactive
—The secure addresses on this port age out
only if there is no data traffic from the secure source
address for the specified time period.
To disable port security aging for all secure addresses on
a port, use the
no switchport port-security
aging
time
interface configuration command.
Command
Purpose
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...