Blocking Unicast Flood Packets On Secure Ports; Port Security Configuration Guidelines; Configuring Port Security On The Switch - Cisco WS-C2948G-GE-TX Configuration Manual

Catalyst 4500 series switch
Table of Contents

Advertisement

Chapter 16
Configuring Port Security

Blocking Unicast Flood Packets on Secure Ports

You can block unicast flood packets on a secure Ethernet port by disabling the unicast flood feature. If
you disable unicast flood on a port, the port will drop unicast flood packets when the port reaches the
allowed maximum number of MAC addresses.
The port automatically restarts unicast flood packet learning when the number of MAC addresses drops
below the maximum number that is allowed. The learned MAC address count decreases when a
configured MAC address is removed or a time to live counter (TTL) is reached.
For more information about unicast flood packets, see
Blocking."

Port Security Configuration Guidelines

This section lists the guidelines for configuring port security:

Configuring Port Security on the Switch

The following sections describe how to configure port security.
Enabling Port Security
Port security is either autoconfigured or enabled manually by specifying a MAC address. If a MAC
address is not specified, the source address from the incoming traffic is autoconfigured and secured, up
to the maximum number of MAC addresses allowed. These autoconfigured MAC addresses remain
secured for a time, depending upon the aging timer set. The autoconfigured MAC addresses are cleared
from the port in case of a link-down event.
When you enable port security on a port, any static or dynamic CAM entries that are associated with the
port are cleared; any currently configured permanent CAM entries are treated as secure.
To enable port security, perform this task in privileged mode:
Task
Step 1
Enable port security on the desired ports. If
desired, specify the secure MAC address.
Step 2
You can add MAC addresses to the list of secure
addresses.
Step 3
Verify the configuration.
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Do not configure port security on a SPAN destination port.
Do not configure SPAN destination on a secure port.
Do not configure dynamic, static, or permanent CAM entries on a secure port.
Port Security Configuration Guidelines
Chapter 17, "Configuring Unicast Flood
Command
set port security mod_num/port_num enable
[mac_addr]
set port security mod_num/port_num mac_addr
show port [mod_num[/port_num]]
16-3

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents