Dynamic Address Aging
The device ages MAC addresses learned by the dynamic method and drops them after the age limit is reached.
You can configure the age limit on each interface. The range is from 0 to 1440 minutes, where 0 disables
aging.
The method that the device uses to determine that the MAC address age is also configurable. The two methods
of determining address age are as follows:
Inactivity
The length of time after the device last received a packet from the address on the applicable interface.
This feature is supported only on Cisco Nexus 9200 and 9300-EX Series switches.
Note
Absolute
The length of time after the device learned the address. This is the default aging method; however, the
default aging time is 0 minutes, which disables aging.
Secure MAC Address Maximums
By default, an interface can have only one secure MAC address. You can configure the maximum number of
MAC addresses permitted per interface or per VLAN on an interface. Maximums apply to secure MAC
addresses learned by any method: static or dynamic.
To ensure that an attached device has the full bandwidth of the port, set the maximum number of addresses
to one and configure the MAC address of the attached device.
Tip
The following three limits can determine how many secure MAC addresses are permitted on an interface:
Device Maximum
The device has a nonconfigurable limit of 8192 secure MAC addresses. If learning a new address would
violate the device maximum, the device does not permit the new address to be learned, even if the interface
or VLAN maximum has not been reached.
Interface Maximum
You can configure a maximum number of 1025 secure MAC addresses for each interface protected by
port security. The default interface maximum is one address. Interface maximums cannot exceed the
device maximum.
VLAN Maximum
You can configure the maximum number of secure MAC addresses per VLAN for each interface protected
by port security. A VLAN maximum cannot exceed the configured interface maximum. VLAN maximums
are useful only for trunk ports. There are no default VLAN maximums.
You can configure VLAN and interface maximums per interface, as needed; however, when the new limit is
less than the applicable number of secure addresses, you must reduce the number of secure MAC addresses
first.
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
305
Configuring Port Security
Dynamic Address Aging