MAC Learning Limit
This section has the following sub-sections:
•
mac learning-limit dynamic on page 563
•
mac learning-limit station-move on page 563
•
mac learning-limit no-station-move on page 564
•
mac learning-limit sticky on page 564
•
Displaying MAC Learning-Limited Interfaces on page 566
•
Learning Limit Violation Actions on page 566
•
Station Move Violation Actions on page 566
•
Recovering from Learning Limit and Station Move Violations on page 567
•
Per-VLAN MAC Learning Limit on page 567
MAC Address Learning Limit is a method of port security on Layer 2 physical, port-channel, and VLAN
interfaces. It enables you to set an upper limit on the number of MAC addresses learned on an interface/
VLAN. After the limit is reached, the system drops all traffic from a device with an unlearned MAC
address.
FTOS Behavior: When configuring MAC Learning Limit on a port or VLAN the configuration is
accepted (becomes part of running-config and
verifies that sufficient CAM space exists. If the CAM check fails, the a message is displayed:
%E90MH:5 %ACL_AGENT-2-ACL_AGENT_LIST_ERROR: Unable to apply
Mac-Limit
In this case, the configuration is still present in the running-config and
before re-applying a MAC learning limit with lower value. Also, ensure that Syslog messages can be viewed on
your session.
Note: The CAM-check failure message beginning in FTOS version 8.3.1.0 is different from versions
8.2.1.1 and earlier, which read:
% Error: ACL returned error
% Error: Remove existing limit configuration if it was configured before
To set a MAC learning limit on an interface:
Task
Specify the number of MAC addresses that the system
can learn off a Layer 2 interface.
Three options are available with the
station-move,
Note: An SNMP trap is available for
for MAC Learning Limit, including limit violations.
562
|
Layer 2
on GigabitEthernet 5/84
mac learning-limit
mac learning-limit station-move
show mac learning-limit interface
show
Command Syntax
mac learning-limit address_limit
command:
dynamic
. No other SNMP traps are available
) before the system
access-list
output. Remove the configuration
Command Mode
INTERFACE
,
, and
no-station-move