22-16
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
OL-9639-07
Chapter 22 Configuring Port-Based Traffic Control
Configuring Port Security
Enabling and Configuring Port Security Aging
You can use port security aging to set the aging time for all secure addresses on a port. Two types of
aging are supported per port:
•
Absolute—The secure addresses on the port are deleted after the specified aging time.
•
Inactivity—The secure addresses on the port are deleted only if the secure addresses are inactive for
the specified aging time.
Use this feature to remove and add devices on a secure port without manually deleting the existing secure
MAC addresses and to still limit the number of secure addresses on a port. You can enable or disable the
aging of secure addresses on a per-port basis.
Beginning in privileged EXEC mode, follow these steps to configure port security aging:
To disable port security aging for all secure addresses on a port, use the
no switchport port-security
aging
time
interface configuration command. To disable aging for only statically configured secure
addresses, use the
no switchport port-security
aging
static
interface configuration command.
Command
Purpose
Step 1
configure terminal
Enter global configuration mode.
Step 2
interface
interface-id
Specify the interface to be configured, and enter interface
configuration mode.
Step 3
no shutdown
Enable the port, if necessary. By default, UNIs and ENIs are
disabled, and NNIs are enabled.
Step 4
switchport port-security
aging
{
static | time
time
|
type
{
absolute | inactivity}
}
Enable or disable static aging for the secure port, or set the
aging time or type.
Note
The switch does not support port security aging of
sticky secure addresses.
Enter
static
to enable aging for statically configured secure
addresses on this port.
For
time
, specify the aging time for this port. The valid range is
from 0 to 1440 minutes.
For
type
, select one of these keywords:
•
absolute
—Sets the aging type as absolute aging. All the
secure addresses on this port age out exactly after the
time
(
minutes) specified lapses and are removed from the secure
address list.
•
inactivity
—Sets the aging type as inactivity aging. The
secure addresses on this port age out only if there is no data
traffic from the secure source addresses for the specified
time period.
Step 5
end
Return to privileged EXEC mode.
Step 6
show port-security
[
interface
interface-id
]
[
address
]
Verify your entries.
Step 7
copy running-config startup-config
(Optional) Save your entries in the configuration file.
Содержание ME 3400 Series
Страница 40: ...Contents xl Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 ...
Страница 44: ...xliv Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 Preface ...
Страница 1138: ...Index IN 52 Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 ...