By default, learned MAC addresses stay secure indefinitely.
Parameters
global-mac
Configures hardware-based aging of all secure MAC addresses.
time
Configures the age timer. Valid values range is from 0 through 1440 minutes. If 0
is specified, the MAC addresses stay secure indefintely.
absolute
Configures all secure MAC addresses to age out immediately once the specified time
expires.
Modes
Port security configuration mode
Port security interface configuration mode
Usage Guidelines
If the
absolute keyword is not specified, secure MAC addresses are aged out only when the configured
hardware MAC address age time expires.
Note: Even though you can set the age time to specific ports independent of the device-level
setting, the age timer will take the greater of the two values. If you set the age
timer to 3 minutes for the port, and 10 minutes for the device, the port MAC address
aging occurs in 10 minutes (the device-level setting), which is greater than the port
setting that you have configured.
On the ICX 7750, the port security age can only be set to the global hardware age.
The absolute age and no aging of secure MACs are configured as static in hardware.
The
no form of the command configures to never age out secure MAC addresses.
Examples
The following example sets the port security age timer to 10 minutes on all interfaces.
device(config)# port security
device(config-port-security)# age 10
The following example ages out secure MAC addresses immediately after one minute.
device(config)# port security
device(config-port-security)# age 1 absolute
The following example sets the port security age timer to 10 minutes on a specific
interface.
device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)#port security
device(config-port-security-e1000-1/1/1)# age 10