Prerequisites for Port Security
If you try to set the maximum value to a number less than the number of secure addresses already configured
on an interface, the command is rejected.
Note
Restrictions for Port Security
The maximum number of secure MAC addresses that you can configure on a switch or switch stack is set by
the maximum number of available MAC addresses allowed in the system. This number is determined by the
active Switch Database Management (SDM) template. This number is the total of available MAC addresses,
including those used for other Layer 2 functions and any other secure MAC addresses configured on interfaces.
Information About Port Security
Port Security
You can use the port security feature to restrict input to an interface by limiting and identifying MAC addresses
of the stations allowed to access the port. When you assign secure MAC addresses to a secure port, the port
does not forward packets with source addresses outside the group of defined addresses. If you limit the number
of secure MAC addresses to one and assign a single secure MAC address, the workstation attached to that
port is assured the full bandwidth of the port.
If a port is configured as a secure port and the maximum number of secure MAC addresses is reached, when
the MAC address of a station attempting to access the port is different from any of the identified secure MAC
addresses, a security violation occurs. Also, if a station with a secure MAC address configured or learned on
one secure port attempts to access another secure port, a violation is flagged.
Related Topics
Enabling and Configuring Port Security, on page 411
Configuration Examples for Port Security, on page 432
Types of Secure MAC Addresses
The switch supports these types of secure MAC addresses:
•
Static secure MAC addresses
—
These are manually configured by using the
switchport port-security
mac-address mac-address
interface configuration command, stored in the address table, and added to
the switch running configuration.
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
406
OL-29048-01
Configuring Port-Based Traffic Control
Prerequisites for Port Security