Cisco 4500M Command Reference Manual page 497

Command reference
Hide thumbs Also See for 4500M:
Table of Contents

Advertisement

Chapter2
Cisco IOS Commands for the Catalyst 4500 Series Switches
Command Modes
Interface configuration
Command History
Release
12.1(13)EW
12.1(19)EW
12.2(18)EW
Usage Guidelines
After you have set the maximum number of secure MAC addresses allowed on a port, you can add secure
addresses to the address table by manually configuring them, by allowing the port to dynamically
configure them, or by configuring some MAC addresses and allowing the rest to be dynamically
configured.
Packets are dropped into hardware when the maximum number of secure MAC addresses are in the
address table and a station that does not have a MAC address in the address table attempts to access the
interface.
If you enable port security on a voice VLAN port and if there is a PC connected to the IP phone, you set
the maximum allowed secure addresses on the port to more than 1.
You cannot configure static secure MAC addresses in the voice VLAN.
A secure port has the following limitations:
When a secure port is in the error-disabled state, you can remove it from this state by entering the
errdisable recovery cause psecure-violation global configuration command, or you can manually
reenable it by entering the shutdown and no shut down interface configuration commands.
To enable secure address aging for a particular port, set the aging time to a value other than 0 for that
port.
78-16201-01
When port security is enabled and no keywords are entered, the default maximum number of secure
MAC addresses is 1.
Aging is disabled.
Aging time is 0 minutes
All secure addresses on this port age out immediately after they are removed from the secure address
list.
Modification
Support for this command was introduced on the Catalyst 4500 series switch.
Extended to include DHCP snooping security enhancement.
Add support for sticky interfaces.
A secure port cannot be a dynamic access port or a trunk port.
A secure port cannot be a routed port.
A secure port cannot be a protected port.
A secure port cannot be a destination port for Switched Port Analyzer (SPAN).
A secure port cannot belong to a Fast EtherChannel or Gigabit EtherChannel port group.
A secure port cannot be an 802.1X port.
If you try to enable 802.1X on a secure port, an error message appears, and 802.1X is not enabled.
If you try to change an 802.1X-enabled port to a secure port, an error message appears, and the
security settings are not changed.
Catalyst4500 Series SwitchCiscoIOS Command Reference—Release 12.2(18)EW
switchport port-security
2-465

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ws-c4507r4500 series

Table of Contents