switchport port-security
protect
restrict
shutdown
Defaults
Port security is disabled.
When port security is enabled and no keywords are entered, the default maximum number of secure
MAC addresses is 1.
Sticky learning is disabled.
The default violation mode is shutdown.
Command Modes
Interface configuration
Command History
Release
12.1(8)EA1
12.1(11)EA1
12.1(14)EA1
Usage Guidelines
The maximum number of available MAC addresses on a secure port or VLAN is determined by the active
Switch Database Management (SDM) template. Refer to the software configuration guide for more
information about configuring an SDM template.
Catalyst 3550 Multilayer Switch Command Reference
2-468
(Optional) Set the security violation protect mode. When the number of
secure MAC addresses reach the limit allowed on the port, packets with
unknown source addresses are dropped until you remove a sufficient
number of secure MAC addresses or increase the number of maximum
allowable addresses. You are not notified that a security violation has
occurred.
Note
We do not recommend enabling the protect mode on a trunk
port. The protect mode disables learning when any VLAN
reaches its maximum limit, even if the port has not reached its
maximum limit.
(Optional) Set the security violation restrict mode. When the number of
secure MAC addresses reach the limit allowed on the port, packets with
unknown source addresses are dropped until you remove a sufficient
number of secure MAC addresses or increase the number of maximum
allowable addresses. In this mode, you are notified that a security
violation has occurred. Specifically, an SNMP trap is sent, a syslog
message is logged, and the violation counter increments.
(Optional) Set the security violation shutdown mode. In this mode, a
port security violation causes the interface to immediately become
error-disabled and turns off the port LED. It also sends an SNMP trap,
logs a syslog message, and increments the violation counter. When a
secure port is in the error-disabled state, you can bring it out of this state
by entering the errdisable recovery cause psecure-violation global
configuration command, or you can manually re-enable it by entering
the shutdown and no shut down interface configuration commands.
Modification
This command was first introduced.
The mac-address sticky [mac-address] option was added.
The vlan vlan-id and vlan vlan-list keywords were added.
Chapter 2 Cisco IOS Commands
78-11195-09