violation
The default action upon PMS violation is protect.
- protect
-
Configures the device to drop all packets which are not from secure MAC addresses. In the protect mode, the port never gets shut down.
- restrict
-
Configures the device to drop packets from violated address and allow packets from secure addresses.
- age
- Configures the time, in minutes, for which the device drops packets after which the violated MAC address is aged out. The valid values are from 0 through 1440 minutes. The default is 5 minutes. Specifying 0 drops packets from the violating address permanently.
- shutdown time
- Configures the device to disable the port upon detection of first violated MAC address. The valid values are from 0 through 1440 minutes. The default value is 0 which shuts down the port permanently when a security violation occurs. The shutdown time which serves as a recovery interval, brings up the port within a configured time without any manual intervention.
Port security configuration mode
Port security interface configuration mode
A security violation occurs when a user tries to connect to a port where a MAC address is already locked, or the maximum limit for the number of secure MAC addresses allowed on the interface is exceeded. When a security violation occurs, an SNMP trap and syslog message are generated.
When the restrict option is used, maximum number of MAC addresses that can be restricted is 128. If the number of violated MAC addresses exceeds 128, the port will be shut down. In this mode, manual intervention is required to bring up the port that is forced to shut down after the security violation. Aging for restricted MAC addresses is done in software. There can be a worst case inaccuracy of one minute from the specified time. The restricted MAC addresses are denied in hardware.
The required action must be specified to switch between PMS violation modes.
The following example configures the violation mode as protect that, upon security violation, drops all packets which are not from secure MAC addresses.
device(config)# interface ethernet 1/1/1 device(config-if-e1000-1/1/1)# port security device(config-port-security-e1000-1/1/1)# violation protect
The following example configures the device to drop packets from a violating address and allow packets from secure addresses.
device(config)# interface ethernet 1/1/1 device(config-if-e1000-1/1/1)# port security device(config-port-security-e1000-1/1/1)# violation restrict
The following example configures the number of minutes that the device drops packets from a violating address.
device(config)# interface ethernet 1/1/1 device(config-if-e1000-1/1/1)# port security device(config-port-security-e1000-1/1/1)# violation restrict 10
| Release version | Command history |
|---|---|
| 08.0.70 | This command was modified to add the protect option. |