Port Security And Port Types; Port Security And Port-Channel Interfaces - Cisco Nexus 9000 Series Configuration Manual

Nx-os security configuration guide, release 9.x
Hide thumbs Also See for Nexus 9000 Series:
Table of Contents

Advertisement

Configuring Port Security

Port Security and Port Types

You can configure port security only on Layer 2 interfaces. Details about port security and different types of
interfaces or ports are as follows:
Access Ports
Trunk Ports
SPAN Ports
Ethernet Port Channels
Note
You cannot configure port security on VXLAN interfaces.
Note
Port security is supported for FEX interfaces only in non-vPC deployments on Cisco Nexus 9300-EX Series
switches.

Port Security and Port-Channel Interfaces

Port security is supported on Layer 2 port-channel interfaces. Port security operates on port-channel interfaces
in the same manner as on physical interfaces, except as described in this section.
General Guidelines
You can configure port security on interfaces that you have configured as Layer 2 access ports. On an
access port, port security applies only to the access VLAN. VLAN maximums are not useful for access
ports.
You can configure port security on interfaces that you have configured as Layer 2 trunk ports. The device
allows VLAN maximums only for VLANs associated with the trunk port.
You can configure port security on SPAN source ports but not on SPAN destination ports.
You can configure port security on Layer 2 Ethernet port channels in either access mode or trunk mode.
Port security on a port-channel interface operates in either access mode or trunk mode. In trunk mode,
the MAC address restrictions enforced by port security apply to all member ports on a per-VLAN basis.
Enabling port security on a port-channel interface does not affect port-channel load balancing.
Port security does not apply to port-channel control traffic passing through the port-channel interface.
Port security allows port-channel control packets to pass without causing security violations. Port-channel
control traffic includes the following protocols:
• Port Aggregation Protocol (PAgP)
• Link Aggregation Control Protocol (LACP)
• Inter-Switch Link (ISL)
• IEEE 802.1Q
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
Port Security and Port Types
307

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents