43-34
Software Configuration Guide—Release 15.0(2)SG
OL-23818-01
Chapter 43 Configuring Port Security
Port Security Configuration Guidelines and Restrictions
When you enter a maximum secure address value for an interface, and the new value is greater than
the previous value, the new value overwrites the previously confi gured v alue. If the ne w valu e is less
than the previous value and the number of configured secure addresses on the interface exceeds the
new value, the command is rejected.
While configuring trunk port security on a trunk port, you do not need to account for the protocol
packets such as CDP and BPDU) because they are not learned and secured.
You cannot enable port security aging on sticky secure MAC addresses.
To restrict MAC spoofing using port security, you must enable 802.1X authentication.
You cannot configure port security on dynamic ports. You must change the mode to access before
you enable port security.
When port security is enabled on an EtherChannel, 802.1X cannot be enabled.
A secure EtherChannel does not work in PVLAN mode.