Users Guide

Table Of Contents
OS10(config-if-port-sec)#no disable
OS10(config-if-port-sec)#mac-learn limit 100
OS10(config-if-port-sec)#sticky
Permit MAC address movement
Use the following command in INTERFACE PORT SECURITY mode:
OS10(config-if-port-sec)#mac-move allow
MAC address movement configuration example
OS10# configure terminal
OS10(config)#interface ethernet 1/1/1
OS10(config-if-eth1/1/1)#switchport port-security
OS10(config-if-port-sec)#no disable
OS10(config-if-port-sec)#mac-learn limit 100
OS10(config-if-port-sec)#mac-move allow
Configure MAC address movement violation actions
Use the following commands in INTERFACE PORT SECURITY mode:
To display which MAC address causes a violation, use the log option. The system also drops the packet.
OS10(config-if-port-sec)#mac-move violation log
To drop the packet when a MAC address movement violation occurs, use the drop option.
OS10(config-if-port-sec)#mac-move violation drop
To shut down the original interface that learned the MAC address on a MAC movement violation, use the shutdown-
original option.
OS10(config-if-port-sec)#mac-move violation shutdown-original
To shut down the interface that detected a MAC address that is already learned by another interface, use the shutdown-
offending option.
OS10(config-if-port-sec)#mac-move violation shutdown-offending
To shut down both original and offending interfaces, use the shutdown-both option.
OS10(config-if-port-sec)#mac-move violation shutdown-both
Recover an error-disabled interface
1. Shut down the interface in INTERFACE mode.
shutdown
2. Bring the interface up in INTERFACE mode.
no shutdown
Clear an error-disabled state of all interfaces
To clear the error-disabled state of all interfaces that was caused by a MAC address learning limit violation, use the following
command in CONFIGURATION mode:
errdisable reset cause mac-learn-limit violation
To clear the error-disabled state of all interfaces that was caused by a MAC address movement violation, use the following
command in CONFIGURATION mode:
errdisable reset cause mac-move-violation
Security
1189