Port Security and Port Types
You can configure port security only on Layer 2 interfaces. Details about port security and different types of
interfaces or ports are as follows:
Access Ports
You can configure port security on interfaces that you have configured as Layer 2 access ports. On an
access port, port security applies only to the access VLAN. VLAN maximums are not useful for access
ports.
Trunk Ports
You can configure port security on interfaces that you have configured as Layer 2 trunk ports. The device
allows VLAN maximums only for VLANs associated with the trunk port.
SPAN Ports
You can configure port security on SPAN source ports but not on SPAN destination ports.
Ethernet Port Channels
You can configure port security on Layer 2 Ethernet port channels in either access mode or trunk mode.
You cannot configure port security on VXLAN interfaces.
Note
Port security is supported for FEX interfaces only in non-vPC deployments on Cisco Nexus 9300-EX Series
switches.
Note
Port Security and Port-Channel Interfaces
Port security is supported on Layer 2 port-channel interfaces. Port security operates on port-channel interfaces
in the same manner as on physical interfaces, except as described in this section.
General Guidelines
Port security on a port-channel interface operates in either access mode or trunk mode. In trunk mode,
the MAC address restrictions enforced by port security apply to all member ports on a per-VLAN basis.
Enabling port security on a port-channel interface does not affect port-channel load balancing.
Port security does not apply to port-channel control traffic passing through the port-channel interface.
Port security allows port-channel control packets to pass without causing security violations. Port-channel
control traffic includes the following protocols:
• Port Aggregation Protocol (PAgP)
• Link Aggregation Control Protocol (LACP)
• Inter-Switch Link (ISL)
• IEEE 802.1Q
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
307
Configuring Port Security
Port Security and Port Types