35-3
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
78-13315-02
Chapter 35 Configuring Port Security
Port Security Configuration Guidelines
Port Security Configuration Guidelines
Follow these guidelines when configuring port security:
•
You cannot configure port security on a trunk port.
•
You cannot enable port security on a SPAN destination port and vice versa.
•
You cannot configure dynamic, static, or permanent CAM entries on a secure port.
•
When you enable port security on a port, any static or dynamic CAM entries associated with the port
are cleared; any currently configured permanent CAM entries are treated as secure.
Configuring Port Security
These sections describe how to configure port security:
•
Enabling Port Security, page 35-3
•
Setting the Maximum Number of Secure MAC Addresses, page 35-4
•
Setting the Port Security Age Time, page 35-5
•
Clearing MAC Addresses, page 35-5
•
Specifying the Security Violation Action, page 35-6
•
Setting the Shutdown Timeout, page 35-6
•
Disabling Port Security, page 35-7
•
Restricting Traffic Based on a Host MAC Address, page 35-7
•
Displaying Port Security, page 35-8
Enabling Port Security
To enable port security, perform this task in privileged mode:
This example shows how to enable port security using the learned MAC address on a port and verify the
configuration:
Console> (enable)
set port security 2/1 enable
Port 2/1 port security enabled with the learned mac address.
Trunking disabled for Port 2/1 due to Security Mode
Console> (enable)
show port 2/1
Port Name Status Vlan Level Duplex Speed Type
----- ------------------ ---------- ---------- ------ ------ ----- ------------
2/1 connected 522 normal half 100 100BaseTX
Task
Command
Step 1
Enable port security on the desired ports. If
desired, specify the secure MAC address.
set port security
mod/port
enable
[
mac_addr
]
Step 2
You can add MAC addresses to the list of secure
addresses.
set port security
mod/port
mac_addr
Step 3
Verify the configuration.
show port
[
mod
[
/
port
]]