180
Syntax
port-security
mac-address
aging-type
inactivity
undo port-security mac-address aging-type inactivity
Default
The inactivity aging function is disabled.
Views
Layer 2 Ethernet interface view
Default command level
2: System level
Usage guidelines
If only an aging timer is configured, the aging timer counts up regardless of whether traffic data has
been sent from the sticky MAC address. When you use an aging timer together with the inactivity
aging function, the aging timer restarts once traffic data is detected from the sticky MAC address The
inactivity aging function prevents the unauthorized use of a secure MAC address when the
authorized user is offline, and removes outdated secure MAC addresses so new secure MAC
addresses can be learned.
Examples
# Enable inactivity aging for secure MAC addresses on interface GigabitEthernet 3/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 3/0/1
[Sysname-GigabitEthernet3/0/1] port-security mac-address aging-type inactivity
Related commands
•
port-security timer autolearn aging
•
port-security mac-address dynamic
port-security mac-address dynamic
Use
port-security mac-address dynamic
to enable the dynamic secure MAC function. This
function converts sticky MAC addresses to dynamic, and disables saving them to the configuration
file.
Use
undo port-security mac-address dynamic
to disable the dynamic secure MAC function. Then,
all dynamic secure MAC addresses are converted to sticky MAC addresses, and you can manually
configure sticky MAC address.
Syntax
port-security mac-address dynamic
undo port-security mac-address dynamic
Default
The dynamic secure MAC function is disabled. Sticky MAC addresses can be saved to the
configuration file, and once saved, survive a device reboot.
Views
Layer 2 Ethernet interface view
Default command level
2: System level