age

Configures the device to age out secure MAC addresses after a specified amount of time.
Syntax
age { global-mac | time [ absolute ] }
no age{ global-mac | time [ absolute ] }
Command Default

By default, learned MAC addresses stay secure indefinitely.

Parameters
global-mac
Configures hardware-based aging of all secure MAC addresses.
time
Configures the age timer. Valid values range is from 0 through 1440 minutes. If 0 is specified, the MAC addresses stay secure indefintely.
absolute
Configures all secure MAC addresses to age out immediately once the specified time expires.
Modes

Port security configuration mode

Port security interface configuration mode

Usage Guidelines

If the absolute keyword is not specified, secure MAC addresses are aged out only when the configured hardware MAC address age time expires.

Note: Even though you can set the age time to specific ports independent of the device-level setting, the age timer will take the greater of the two values. If you set the age timer to 3 minutes for the port, and 10 minutes for the device, the port MAC address aging occurs in 10 minutes (the device-level setting), which is greater than the port setting that you have configured.

The no form of the command configures to never age out secure MAC addresses.

Examples

The following example sets the port security age timer to 10 minutes on all interfaces.

device(config)# port security
device(config-port-security)# age 10

The following example ages out secure MAC addresses immediately after one minute.

device(config)# port security
device(config-port-security)# age 1 absolute

The following example sets the port security age timer to 10 minutes on a specific interface.

device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)#port security
device(config-port-security-e1000-1/1/1)# age 10