Re: Catalyst port security problem

From: DAN DORTON (DHSTS68@xxxxxxxxxxxxxxx)
Date: Mon Apr 22 2002 - 10:07:38 GMT-3


   
Were you bridging on this port?

I had a similar issue with doing dynamic port security.

I setup the port for the learned mac of the router plugged into it.

Later I setup a bridge group on it & it was learning an address of another rout
er running DSPU through the bridge group.

Hence: It did what it was supposed to! ;)

>>> "Ahmed Mamoor Amimi" <mamoor@ieee.org> 04/21/02 08:39PM >>>
I guess ur stuck in the age-time of port security .... check out this .... :

http://www.cisco.com/univercd/cc/td/doc/product/lan/cat5000/rel_6_3/config/s
ec_port.htm#xtocid76308

try clearing the security and reenable without the age time..

-Mamoor

----- Original Message -----
From: Lupi, Guy <Guy.Lupi@eurekaggn.com>
To: <ccielab@groupstudy.com>
Sent: Monday, April 22, 2002 5:16 AM
Subject: Catalyst port security problem

> I had a 2611 hooked up to my 5500 the other day with port security turned
> on. It worked fine for about 6 hours, then all of the sudden the switch
> shut the port down due to a security error. I looked, and the switch was
> reporting that a totally different mac address was plugged into that port.
> I looked at the 2611 and it was fine, same mac address that was in the
port
> security filter. Has anyone seen this before? If turning on port
security,
> is it a good idea to lock the mac address down to something other than the
> bia? Thanks.



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 10:58:16 GMT-3