×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

Enabling port security on C4507R shuts down port

Answered Question

I'm trying to enable port security on several 4507R's. When I try to configure a range of ports the switch will randomly put 1 or 2 in err-disable.  It's different every time I apply the config to the same group of ports.  However if I do them one at a time it seems to work.  But I really don't want to configure 6 fully populated switches one port at a time.   We also have a lot of 3750's and they gave me no problem using a port range.


Here is the config I'm trying to configure

 

switchport port-security

switchport port-security maximum 2

switchport port-security aging time 1

switchport port-security aging type inactivity

  

The IOS version is. 12.2(25)EWA8

Correct Answer by Benjamin Kools about 5 years 5 days ago

Try rearranging the order in which you put the commands in. Put "switchport port-security" in last, as immediately when you enter this command, port security is enabled with the default maximum of 1 mac address per interface. If a port has two hosts on it before the next command setting the maximum to 2 is entered, it will get disabled.


Another option is to temporarily enable error disable recovery:


errdisable recovery cause psecure-violation

errdisbale recovery interval 'seconds'


Sent from Cisco Technical Support iPad App

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Benjamin Kools Tue, 08/14/2012 - 17:58
User Badges:

Try rearranging the order in which you put the commands in. Put "switchport port-security" in last, as immediately when you enter this command, port security is enabled with the default maximum of 1 mac address per interface. If a port has two hosts on it before the next command setting the maximum to 2 is entered, it will get disabled.


Another option is to temporarily enable error disable recovery:


errdisable recovery cause psecure-violation

errdisbale recovery interval 'seconds'


Sent from Cisco Technical Support iPad App

johnlloyd_13 Wed, 08/15/2012 - 07:38
User Badges:
  • Blue, 1500 points or more

Hi,


Make sure the ports you're trying to configure are access ports (switchport mode access).


Sent from Cisco Technical Support iPhone App

Actions

This Discussion

Related Content