25-11
Cisco Catalyst Blade Switch 3130 for Dell Software Configuration Guide
OL-13270-01
Chapter25 Configuring Port-Based Tra ffic Control Configuring Port Security
A secure port cannot be a private-VLAN port.
When you enable port security on an interface that is also configured with a voice VLAN, set the
maximum allowed secure addresses on the port to two. When the port is connected to a Cisco IP
phone, the IP phone requires one MAC address. The Cisco IP phone address is learned on the voice
VLAN, but is not learned on the access VLAN. If you connect a si ngle PC t o t he Ci sco IP pho ne,
no additional MAC addresses are required. If you connect more than one PC to t he Cisco IP phone,
you must configure enough secure addresses to allow one for each PC and on e for the phon e.
When you enter a maximum secure address value for an interf a ce, an d th e new value is greater than
the previous value, the new value overwrites the previous ly configured v alue. If the ne w v alue is less
than the previous value and the number of configured secure addresses o n the in ter f ac e e x ce ed s the
new value, the command is rejected.
The switch does not support port security aging of sticky secure MAC addresses.
Table25-3 summarizes port security compatibility with other port-based features.
Table25-3 Port Security Compatibility with Other Switch Features
Type of Port or Feature on Port Compatible with Port Security
DTP1 port2
1. DTP = Dynamic Trunking Protocol
2. A port configured with the switchport mode dynamic interface configuration command.
No
Trunk port Yes
Dynamic-access port3
3. A VLAN Query Protocol (VQP) port conf igured with the switchport access vlan dynamic interface configuration command.
No
Routed port No
SPAN source port Yes
SPAN destination port No
EtherChannel No
Tunneling port Yes
Protected port Yes
IEEE 802.1x port Yes
Voice VLAN port4
4. You must set the maximum allowed secure addresses on the port to two plus the maximum number of secure addresses
allowed on the access VLAN.
Yes
Private VLAN port No
IP source guard Yes
Dynamic Address Resolution Protocol (ARP) inspection Yes
Flex Links Yes