Chapter 26 Configuring Port-Based Traffic Control

Configuring Port Security

A secure port cannot be a private-VLAN port.

When you enable port security on an interface that is also configured with a voice VLAN, set the maximum allowed secure addresses on the port to two. When the port is connected to a Cisco IP phone, the IP phone requires one MAC address. The Cisco IP phone address is learned on the voice VLAN, but is not learned on the access VLAN. If you connect a single PC to the Cisco IP phone, no additional MAC addresses are required. If you connect more than one PC to the Cisco IP phone, you must configure enough secure addresses to allow one for each PC and one for the phone.

When you enter a maximum secure address value for an interface, and the new value is greater than the previous value, the new value overwrites the previously configured value. If the new value is less than the previous value and the number of configured secure addresses on the interface exceeds the new value, the command is rejected.

The switch does not support port security aging of sticky secure MAC addresses.

Table 26-3summarizes port security compatibility with other port-based features.

Table 26-3

Port Security Compatibility with Other Switch Features

 

 

Type of Port or Feature on Port

Compatible with Port Security

 

 

 

DTP1 port2

 

No

Trunk port

 

Yes

 

 

Dynamic-access port3

No

Routed port

 

No

 

 

SPAN source port

Yes

 

 

SPAN destination port

No

 

 

 

EtherChannel

 

No

 

 

 

Tunneling port

 

Yes

 

 

 

Protected port

 

Yes

 

 

IEEE 802.1x port

Yes

 

 

Voice VLAN port4

Yes

Private VLAN port

No

 

 

 

IP source guard

 

Yes

 

 

Dynamic Address Resolution Protocol (ARP) inspection

Yes

 

 

 

Flex Links

 

Yes

 

 

 

1.DTP = Dynamic Trunking Protocol

2.A port configured with the switchport mode dynamic interface configuration command.

3.A VLAN Query Protocol (VQP) port configured with the switchport access vlan dynamic interface configuration command.

4.You must set the maximum allowed secure addresses on the port to two plus the maximum number of secure addresses allowed on the access VLAN.

 

 

Catalyst 3750-E and 3560-E Switch Software Configuration Guide

 

 

 

 

 

 

OL-9775-02

 

 

26-11

 

 

 

 

 

Page 607
Image 607
Cisco Systems 3750E manual 26-11