Users Guide

Table Of Contents
Supported
Releases
10.5.1.0 or later
mac-move allow
Enables MAC address movement.
Syntax
mac-move allow
Parameters
None
Default MAC address movement is disabled.
Command Mode
CONFIGURATION-PORT-SECURITY
Usage
Information
MAC address movement is not allowed for secure static and sticky MAC addresses. By default, MAC
address movement for dynamically-learned MAC address is disabled on the system.
The no version of this command disables MAC address movement.
Example
OS10(config-if-port-sec)# mac-move allow
Supported
Releases
10.5.1.0 or later
mac-move violation
Configures station move violation actions.
Syntax
mac-move violation {drop | log | shutdown-both | shutdown-offending |
shutdown-original}
Parameters
drop Drops the received packet when an interface detects the same MAC address that the
system has already learned on a different interface.
log Displays a log message when an interface detects the same MAC address that the system has
already learned on a different interface.
shutdown-both Shuts down both interfaces that learned the same MAC address.
shutdown-offending Shuts down the interface which detects the same MAC address that the
system has already learned on a different interface.
shutdown-original Shuts down the interface that originally learned the MAC address.
Default The system displays a log message when a MAC address move violation occurs.
Command Mode
CONFIGURATION-PORT-SECURITY
Usage
Information
The no version of this command disables MAC move violation actions.
Example
OS10(config-if-port-sec)# mac-move-violation log
If you configure the system with the mac-move-violation log command, the system displays a log
message similar to the following:
MAC Move Violation occurred: originalInterface: ethernet
1/13/1, offendingInterface: Ethernet 1/13/2,vlanId: 100, MACAddr:
00:00:07:00:04:15.
Supported
Releases
10.5.1.0 or later
1400 Security