protected-port

Configures a port as protected, restricting communication among such ports at the system level, providing isolation to end hosts.
Syntax
protected-port
no protected-port
Command Default

Protected port is not enabled.

Modes

Interface configuration mode

Usage Guidelines

Use the no form of this command to disable the protected port feature.

The following configurations are supported with the protected port feature:

  • Port MAC security
  • 802.1x security
  • DHCP snooping
  • Control protocols
  • Aggregated ports (LAGs)

The following should not be configured as protected ports:

  • Uplink ports
  • DHCP server ports
  • ARP inspection trusted ports
  • DHCP snooping trusted ports
  • Ports on an active xSTP path in a device
  • IGMP/MLD snooping router ports
  • IGMP/MLD source ports

In addition, it is recommended that multiple ports (MIF) mode be configured.

The following features are not supported on protected ports:

  • Layer 3 interfaces (IP addresses are not supported)
  • Mirror or monitor ports
  • Private VLAN (PVLAN)
  • PVLAN extension to protected-port switches
  • Virtual Ethernet (VE) and group VE interfaces
  • Loopback interfaces
  • Management interfaces
  • OpenFlow ports
  • Multi-Chassis Trunk (MCT)
Examples

The following example enables protected port on a single interface.

device# configure terminal
device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# protected-port 

The following example enables protected port on multiple ports in MIF mode.

device# configure terminal
device(config)# interface ethernet 2/1/1 ethernet 3/1/1
device(config-if-e1000-2/1/1,3/1/1)# protected-port 

The following example disables protected port for the previous example.

device# configure terminal
device(config)# interface ethernet 2/1/1 ethernet 3/1/1
device(config-if-e1000-2/1/1,3/1/1)# no protected-port 

History
Release version Command history
08.0.61 This command was introduced.