Catalyst 3650 MAC Address Security

Unanswered Question
Dec 18th, 2007

I'm trying to lockdown a Catalyst 3650 by 1 MAC address per port. The problem is that a max of 1 address is allowed by default, but this can be any address as long as only 1 is concurrently connected (e.g. I can switch different machines on the same port). I can get around this by specifying the MAC address, but is there any way to make this dynamic?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Edison Ortiz Tue, 12/18/2007 - 10:31

Sticky secure MAC addresses have these characteristics:

•When you enable sticky learning on an interface by using the switchport port-security mac-address sticky interface configuration command, the interface converts all the dynamic secure MAC addresses, including those that were dynamically learned before sticky learning was enabled, to sticky secure MAC addresses and adds all sticky secure MAC addresses to the running configuration.

•If you disable sticky learning by using the no switchport port-security mac-address sticky interface configuration command or the running configuration is removed, the sticky secure MAC addresses remain part of the running configuration but are removed from the address table. The addresses that were removed can be dynamically reconfigured and added to the address table as dynamic addresses.

•When you configure sticky secure MAC addresses by using the switchport port-security mac-address sticky mac-address interface configuration command, these addresses are added to the address table and the running configuration. If port security is disabled, the sticky secure MAC addresses remain in the running configuration.

•If you save the sticky secure MAC addresses in the configuration file, when the switch restarts or the interface shuts down, the interface does not need to relearn these addresses. If you do not save the sticky secure addresses, they are lost. If sticky learning is disabled, the sticky secure MAC addresses are converted to dynamic secure addresses and are removed from the running configuration.

•If you disable sticky learning and enter the switchport port-security mac-address sticky mac-address interface configuration command, an error message appears, and the sticky secure MAC address is not added to the running configuration.

_____________________

http://www.cisco.com/univercd/cc/td/doc/product/lan/cat3560/12240se/cr/cli3.htm#wp1948361

Actions

This Discussion