violation

Configures the action that must be taken according to the configurable violation modes when a security violation occurs.
Syntax
violation { protect | restrict age | shutdown time }
Command Default

The default action upon PMS violation is protect.

Parameters
protect

Configures the device to drop all packets which are not from secure MAC addresses. In the protect mode, the port never gets shut down.

restrict

Configures the device to drop packets from violated address and allow packets from secure addresses.

age
Configures the time, in minutes, for which the device drops packets after which the violated MAC address is aged out. The valid values are from 0 through 1440 minutes. The default is 5 minutes. Specifying 0 drops packets from the violating address permanently.
shutdown time
Configures the device to disable the port upon detection of first violated MAC address. The valid values are from 0 through 1440 minutes. The default value is 0 which shuts down the port permanently when a security violation occurs. The shutdown time which serves as a recovery interval, brings up the port within a configured time without any manual intervention.
Modes

Port security configuration mode

Port security interface configuration mode

Usage Guidelines

A security violation occurs when a user tries to connect to a port where a MAC address is already locked, or the maximum limit for the number of secure MAC addresses allowed on the interface is exceeded. When a security violation occurs, an SNMP trap and syslog message are generated.

When the restrict option is used, maximum number of MAC addresses that can be restricted is 128. If the number of violated MAC addresses exceeds 128, the port will be shut down. In this mode, manual intervention is required to bring up the port that is forced to shut down after the security violation. Aging for restricted MAC addresses is done in software. There can be a worst case inaccuracy of one minute from the specified time. The restricted MAC addresses are denied in hardware.

The required action must be specified to switch between PMS violation modes.

Examples

The following example configures the violation mode as protect that, upon security violation, drops all packets which are not from secure MAC addresses.

device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# port security
device(config-port-security-e1000-1/1/1)# violation protect

The following example configures the device to drop packets from a violating address and allow packets from secure addresses.

device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# port security
device(config-port-security-e1000-1/1/1)# violation restrict

The following example configures the number of minutes that the device drops packets from a violating address.

device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# port security
device(config-port-security-e1000-1/1/1)# violation restrict 10

The following example shuts downs the port for 5 minutes when a security violation occurs.

device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# port security
device(config-port-security-e1000-1/1/1)# violation shutdown 5
History
Release version Command history
08.0.70 This command was modified to add the protect option.