cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
873
Views
0
Helpful
2
Replies

Sticky Port Security 3560

paultjohnson
Level 1
Level 1

Is there a better solution to resetting sticky port security on a single port on a Catalyst 3560 SW when a PC is swapped out than:-

sw(config-if)#no switchport port-security mac-address sticky

sw(config-if)#switchport port-security mac-address sticky

sw(config-if)#shutdown

sw(config-if)#no shutdown

sw#wr

I know that you can clear the whole mac address table at the enable prompt, but that is a security risk until all the ports have re-learned the mac addresses.

Any help would be appreciated.

Thanks

1 Accepted Solution

Accepted Solutions

Mark Yeates
Level 7
Level 7

I think you are looking for the "clear port security sticky interface fa0/X" command. Instead of turning off port security and the interface and enabling them this command will do the same thing. I don't see a security issue by doing this.

http://www.ciscosystems.com/en/US/docs/switches/lan/catalyst3560/software/release/12.2_40_se/command/reference/cli1.html#wpmkr4260639

HTH,

Mark

View solution in original post

2 Replies 2

Mark Yeates
Level 7
Level 7

I think you are looking for the "clear port security sticky interface fa0/X" command. Instead of turning off port security and the interface and enabling them this command will do the same thing. I don't see a security issue by doing this.

http://www.ciscosystems.com/en/US/docs/switches/lan/catalyst3560/software/release/12.2_40_se/command/reference/cli1.html#wpmkr4260639

HTH,

Mark

Many thanks Mark, hadn't followed the sub-commands far enough!

Review Cisco Networking products for a $25 gift card