
Switch#show isolate-port
Gi 0/1 : Gi 0/2
Gi 0/2 : Gi 0/1
Gi 0/3 :
Gi 0/4 :
Gi 0/5 :
Gi 0/6 :
Gi 0/7 :
Gi 0/8 :
Gi 0/9 :
link-aggregation 1 :
12.3.
Port Security
12.3.1. Overview
Port security function through the source MAC address message to define whether packet can enter
the switch port,You can set a specific static MAC addresses or learn to limit the number of dynamic
MAC address to control the message whether can enter the port.Enable port security port called port
security.Only the source MAC address is the port security address table configuration or has to learn
the MAC address message,before they can enter the exchange communication,other packets will be
dropped.You can also set the port security address bind IP+MAC+PORT to port security address used
to limit must be consistent with the binding for the source MAC address of the packet to switch the
communication;In accordance with ARP message IP+MAC+PORT can enter the switch,Does not
conform to the IP+MAC+PORT message binding will be dropped.
Port security also supports the function of the Sticky MAC address,by enable the function,Can be
dynamically learned to address the safety of the conversion for static configurationIn show
running-config, can be seen in the configuration,Save the configuration after the restart, without
having to learn these dynamic security address,And if this feature is not enabled, then the dynamic
learning into the safety of the MAC address on the switch after the restart to learn again.You can
secure address for each security port configured maximum security address number,maximum
security address number refers to the total number of static configuration and dynamic learning
security address,when the security port security address does not reach the maximum number of
safety,security port can dynamically learn new dynamic security address,when security address
number reaches maximum number,Safe port will no longer study dynamic security address,If there
are new user access security port, will produce a security violation.You can handle security violation
according to the following three ways:
protect
:
When the number of address is full, safe port will discard all new user data access
flow.The processing mode as the default for violation processing mode.
12.3.2. The default configuration of port security
The following table shows the default configuration of port security:
Features
Default value
Port safety switch
All ports are closed port security function
Security address
None