Mobile Groups

Page 19-11

How a Port Ages Out of a Mobile Group (move_to_def)

If the port is in “optimized mode,” then the MAC does not age out and the port would stay in

the mobile group even if move_to_def is enabled.

Default
Port assigned to default group.
Mobile Group
If move_to_def is enabled....
Why enable move_to_def?
• Security. Mobile groups only contain
devices and ports that have recently
matched policy criteria.
If move_to_def is disabled....
Why disable move_to_def?
• Switch ports retain group membership
even when idle for some time. May be
appropriate for silent devices, such as
printers.
Default
Port becomes a member of
other mobile groups when it
matches their policies. These
groups may be primary or
secondary groups.
Mobile Group Primary
Group 2
Secondary
Group 3
Default
Port will be removed from
other groups when attached
devices age out of filtering
database.
Mobile Group Primary
Group 2
Secondary
Group 3
Default
Port remains a member of all
mobile groups with which it
has satisfied a policy criteria
even if its devices age out of
the filtering database.
Mobile Group Primary
Group 2
Secondary
Group 3