Port Security on 2950

Answered Question
Jul 31st, 2009

I have the following setup on a port on my 2950:

interface FastEthernet0/23

switchport mode access

switchport port-security

switchport port-security mac-address 0009.4302.5614

duplex half

speed 10

I have the port-security violation shutdown enabled as well.

DAX_Rack_5#sh port-security

Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action

(Count) (Count) (Count)

-------------------------------------------------------------------------------

Fa0/23 132 2 0 Shutdown

Problem is, it doesnt seem to work. When I change the cable plugged in it still comes up just fine. I thought it was supposed to go ERRDISABLE or something like that?

Thoughts?

James

I have this problem too.
0 votes
Correct Answer by Peter Paluch about 7 years 5 months ago

Hello James,

If I am interpreting your "show port-security" output correctly then the Fa0/23 port seems to have 132 secure MAC addresses allowed. As you have defined one static secure MAC address, there is still space for 131 secure MAC addresses. Until the space is exhausted, the switch will happily learn new MAC addresses withouth causing a security violation.

Try to add this command to your Fa0/23 configuration:

switchport port-security maximum 1

Best regards,

Peter

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Peter Paluch Fri, 07/31/2009 - 11:28

Hello James,

If I am interpreting your "show port-security" output correctly then the Fa0/23 port seems to have 132 secure MAC addresses allowed. As you have defined one static secure MAC address, there is still space for 131 secure MAC addresses. Until the space is exhausted, the switch will happily learn new MAC addresses withouth causing a security violation.

Try to add this command to your Fa0/23 configuration:

switchport port-security maximum 1

Best regards,

Peter

jfraasch Mon, 08/03/2009 - 04:31

Dang, you are right. I had taken it off and forgot to put it back on. The 132 should have been a bit of a clue, eh!

Thanks!

Actions

This Discussion