Configuring and Monitoring Port Security

Port Security Command Options and Operation

Assigned/Authorized Addresses. : If you manually assign a MAC address (using port-security<port-number>address-list<mac-addr>) and then execute write memory, the assigned MAC address remains in memory until you do one of the following:

Delete it by using no port-security < port-number> mac-address < mac­ addr >.

Download a configuration file that does not include the unwanted MAC address assignment.

Reset the switch to its factory-default configuration.

Displaying Current Port Security Settings

The CLI uses the same command to provide two types of port security listings:

All ports on the switch with their Learn Mode and (alarm) Action

Only the specified ports with their Learn Mode, Address Limit, (alarm) Action, and Authorized Addresses

Using the CLI To Display Port Security Settings.

Syntax: show port-security

show port-security [e] <port number>

show port-security [ e ] [<port number>-<port number]. . .[,<port number>]

Without port parameters, show port-securitydisplays Operating Control settings for all ports on a switch. For example:

Figure 7-2. Example Port Security Listing (Ports A7 and A8 Show the Default Setting)

7-9