Re: Port-Security MAC address issue

From: Narbik Kocharians <narbikk_at_gmail.com>
Date: Wed, 3 Aug 2011 09:21:27 -0700

Jason is right on the money, you can try absolute or idle time, try them
both and see which one fits your requirements, as far as reducing it to less
than one minute, you need to try it out. Does your switch support EEM? If
so, have a look at it, you will enjoy what you can accomplish through EEM.

On Wed, Aug 3, 2011 at 6:52 AM, Irfan Sid <lifeoverip_at_gmail.com> wrote:

> thanks Guys
>
> Can I reduce it to less then a minute, it seems like one minute is the
> minimum you can configure. Is this right ?
>
> On Wed, Aug 3, 2011 at 4:50 PM, Jason Lunde <willroute4food_at_gmail.com
> >wrote:
>
> > Yes, I think by default it will be set to absolute aging with a 0 time
> > (which essentially disables aging). You will need to set the absolute
> aging
> > time to like a minute if thats what you desire.
> >
> > On Wed, Aug 3, 2011 at 7:17 AM, Irfan Sid <lifeoverip_at_gmail.com> wrote:
> >
> >> I am having ane issue with port-security, in that when a user moves his
> >> laptop from one desk to another, i have to clear off their mac-address
> >> from
> >> the old port before they can plug into the new port.
> >>
> >> With my port-security configuration this shouldnt happen, as I am not
> >> using
> >> MAC-address sticky command. So when the user unplugs his laptop from a
> >> switchport the mac-address should immediately cleared off. This will
> allow
> >> him to use that mac-address (Laptop) on anotehr port. But this is not
> >> happening and each time I have to log on and clear the mac-address off
> the
> >> old port before user can use the new port.
> >>
> >> interface GigabitEthernet0/xx
> >> switchport access vlan 100
> >> switchport mode access
> >> switchport port-security maximum 2
> >> switchport port-security
> >> switchport port-security violation
> >> spanning-tree portfast
> >> spanning-tree bpduguard enable
> >>
> >>
> >> Please advise.
> >>
> >>
> >> Blogs and organic groups at http://www.ccie.net
> >>
> >> _______________________________________________________________________
> >> Subscription information may be found at:
> >> http://www.groupstudy.com/list/CCIELab.html
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html
>
>
>
>
>
>
>
>

-- 
*Narbik Kocharians
*CCSI#30832, CCIE# 12410 (R&S, SP, Security)
www.MicronicsTraining.com <http://www.micronicstraining.com/>
Sr. Technical Instructor
YES! We take Cisco Learning Credits!
Training & Remote Racks available
Blogs and organic groups at http://www.ccie.net
Received on Wed Aug 03 2011 - 09:21:27 ART

This archive was generated by hypermail 2.2.0 : Thu Sep 01 2011 - 06:05:56 ART