Specifying The Maximum Number Of Secure Mac Addresses; Specifying The Port Security Age Time - Cisco WS-C4003 - Catalyst 4000 Chassis Switch Software Configuration Manual

Software guide
Table of Contents

Advertisement

Chapter 16
Configuring Port Security

Specifying the Maximum Number of Secure MAC Addresses

You can specify the number of MAC addresses to secure on a port. By default, at least one MAC address
per port can be secured. In addition to this default, a global resource of up to 1024 MAC addresses is
available to be shared by the ports. This means that if the entire global resource of 1024 MAC addresses
is used on some ports, you can still enable port security on the rest of the ports with a maximum of one
MAC per port.
If you reduce the maximum number of MAC addresses, the system clears the specified number of MAC
addresses and displays the list of removed addresses.
To set a number of MAC addresses to be secured for a particular port, perform this task in privileged
mode:
Task
Set the number of MAC addresses to be secured
on a port.
This example shows how to set the number of MAC addresses to be secured:
Console> (enable) set port security 4/7 maximum 20
Maximum number of secure addresses
Console> (enable)
This example shows how to reduce the number of MAC addresses and the list that displays the cleared
MAC addresses:
Console> (enable) set port security 4/7 maximum 18
Maximum number of secure addresses set to 18 for port 4/7
00-11-22-33-44-55 cleared from secure address list for port 4/7
00-11-22-33-44-66 cleared from secure address list for port 4/7
Console> (enable)

Specifying the Port Security Age Time

The age time on a port specifies how long all addresses on that port will be secured. This age time is
activated when a MAC address initiates traffic on the port. After the age time expires for a MAC address,
the entry for that MAC address on the port is removed from the secure address list. The valid range is 10
to 1440 minutes. Setting the age time to zero disables aging of secure addresses.
To set the age time on a port, perform this task in privileged mode:
Task
Set the age time for which addresses on a port will
be secured.
Console> (enable) set port security 4/7 age 600
Secure address age time set to 600 minutes for port 4/7.
Console> (enable)
78-12647-02
Software Configuration Guide—Catalyst 4000 Family, Catalyst 2948G, Catalyst 2980G, Releases 6.3 and 6.4
Command
set port security mod_num/port_num maximum
num_of_mac
set to 20 for port 4/7.
Command
set port security mod_num/port_num age time
Configuring Port Security
16-5

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 4000 seriesCatalyst 2948gCatalyst 2980g

Table of Contents