Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

Port security on 2950,3560.

Hi all,

I have very interesting question

related to port security on above mentioned switches.

We have IP telephony implemented and connection goes from PC to IP phone and IP phone(non Cisco) to Cisco switch.

On switches we have port security and

aging configured like this below:

switchport access vlan 20

switchport mode access

switchport voice vlan 60

switchport port-security

switchport port-security maximum 2

switchport port-security aging time 1

switchport port-security violation restrict

switchport port-security mac-address sticky

switchport port-security aging static

switchport port-security mac-address sticky 0007.1bdf.d5ea

switchport port-security mac-address sticky 0006.9013.26cf vlan voice

spanning-tree portfast

But when I want to connect my PC to another port this PC doesnt work because

port where is IP phone connected is still up. So my question is why these addresses doesnt time out when over there is aging configured (default absolute)?

How we can configure our switches to time out sticky addresses?

Any suggestions?

BR

jl

4 REPLIES

Re: Port security on 2950,3560.

Hi,

You have configured mac-address sticky option and the swithces doesnot support the againg of stickey learned mac-addresses. The only way it will work if you take out the stiacky configuration out of the port.

USE no switchport port-security mac-address sticky interface configuration command.

Please go through the link for more info:

http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2950/12122ea2/2950scg/swtrafc.htm#wp1038546

HTH, Please rate if it does.

-amit singh

Silver

Re: Port security on 2950,3560.

The whole idea about Port Security is to stop people from pulling connections and placing a rogue PC or foreign device on the network. The Port security locks down the port to just one MAC address. It cannot time out nor would you want it timed out(if you were the person responsible for security in your corporation). The only way to wipe it away is to stop the security and clear the mac address from the port manually...Good Luck..Please rate..

Re: Port security on 2950,3560.

Hi pciaccio,

I dont agree with your post above. Its only the Sticky mac-addresses that dont getwiped out even after the aging time and switch reboot because they are dynamically learned sticky addresses. If your adress is not stickey and its learned dynamically, it will be wiped out after the aging time.

Please go through the link posted in my first reply, it will give you more idea.

HTH,

-amit singh

Community Member

Re: Port security on 2950,3560.

Hi all,

thanks for your answers. Amit I agree with you.

Iv tested all possible alternatives. It is pity

that I cannot do this:

configure sticky command on port....switch adds MAC

I remove PC from port and plug it to another port without port security. Switch removes from table and

from port sticky learned MAC after defined aging time. And my PC in this moment can work.

When I disconnect PC from port and I connect this PC

to the same port with sticky ..switch adds MAC again.

It is crucial for example for notebooks. When someone move on from place to place..it is hard

for admins still refresh MAC from port to port (with sticky configured).

What is best solution to have port security?

I dont want to do 802.1x.

Any suggestions?

BR

jl

201
Views
0
Helpful
4
Replies
CreatePlease to create content