Routelearn.net
Course menu

Course 13: Security FundamentalsLesson 1.1 (1 of 8 in this course)79 of 91 in the CCNA series

Port security

Limiting which and how many MAC addresses may use a switch port, violation modes and recovery.

Intermediate · 10 min read

Port security is a Cisco switch feature that limits which and how many source MAC addresses may send frames into an access port. When a frame breaks the rule, the switch takes the configured violation action: shutdown (err-disable the port), restrict or protect.

In simple terms: Port security lets a switch port accept only the devices you expect. If an unknown device is plugged in, the switch blocks it or shuts the port down.

A real-life situation

A meeting room has one network socket, patched to port Gi1/0/1 on SW1. It is meant for the room's PC. One day a visitor unplugs the PC and connects their own laptop. Another day someone adds a small home switch so four people can share the socket. Neither was allowed, and nobody noticed. Port security lets the switch notice and act on its own.

Gi1/0/1✕ link downGi1/0/1Gi1/0/24Gi0/1R1Gi0/1 192.168.10.1SW1VLAN 10PC AGi1/0/1 · 0011.2233.4455unknown MACVisitor laptopGi1/0/1 · 00aa.bbcc.ddee
  1. 1. The allowed MAC. PC A's MAC is the secure address on Gi1/0/1, so its frames are forwarded as usual.
  2. 2. A new MAC appears. The laptop is plugged into the same socket. The port already has its maximum of one secure MAC, so this is a violation.
  3. 3. The switch reacts. In the default shutdown mode, Gi1/0/1 is put in the err-disabled state and a log message is sent. Nothing passes until an admin recovers it.

What port security is

Port security is a Cisco switch feature that limits which source MAC addresses may send frames into an access port, and how many. A MAC address the port accepts is called a secure MAC address. If a frame arrives from a MAC address that would break the rule, that is a violation, and the switch reacts in the way you choose.

If you need a refresher on how a switch reads source MACs, see How a switch learns MAC addresses. Port security hooks into exactly that learning step.

There are three ways a port gets its secure MAC addresses:

TypeHow it is addedSurvives a reload?
StaticYou type it: switchport port-security mac-address 0011.2233.4455Yes, it is in the configuration
DynamicLearned from traffic, like normal MAC learningNo, it is only in memory
StickyLearned from traffic, then written into the running configurationYes, if you save the configuration

Why it works that way

  • The switch already sees every source MAC. Learning MAC addresses is its normal job, so checking them against a limit costs almost nothing and needs no extra server.
  • A limit stops MAC flooding. An attacker can send thousands of frames with random source MACs to fill the MAC address table. When the table is full, the switch floods unknown frames out of every port, and the attacker sees traffic meant for others. With a maximum of one or two MACs per port, that attack fails at the first port.
  • Sticky learning saves typing. You don't have to collect the MAC of every desk PC. The port learns the first device, writes it down, and from then on only accepts that device.
  • It is not proof of identity. MAC addresses can be changed in software. Port security keeps honest people honest and blocks simple attacks; stronger checks use 802.1X, covered in AAA: RADIUS and TACACS+.

How it works step by step

Frame arrives on Gi1/0/1
the switch reads the source MAC
Is the MAC already secure on this port?
yes: forward the frame normally
Not yet: is there room under the maximum?
yes: learn it as a dynamic or sticky secure MAC
No room: violation
the frame is dropped and the violation mode decides the rest
What SW1 does with each frame that arrives on a port with port security enabled.

A violation also happens if a MAC that is secure on one port shows up on another port in the same VLAN. The violation mode decides what happens next:

ModeDrops bad framesLog / SNMP trapViolation counterPort state
shutdown (default)Yes (all traffic)YesIncreaseserr-disabled
restrictYesYesIncreasesStays up
protectYesNoNo changeStays up

In restrict and protect mode, frames from the allowed MACs keep flowing; only the extra MACs are dropped. In shutdown mode the whole port stops, so the allowed PC loses its connection too.

Err-disabled (error-disabled) is a state where the switch has turned a port off by itself because of an error. The port's LED goes off and it passes no traffic until it is recovered, either by hand or by an automatic recovery timer.

How to configure it on Cisco IOS

⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device.

Port security only works on a port whose mode is set by hand. A port left in the default dynamic mode refuses the command, so set switchport mode access first.

interface GigabitEthernet1/0/1 switchport mode access switchport access vlan 10 switchport port-security

The minimum. With nothing else set: maximum 1 MAC, violation mode shutdown, dynamic learning, no aging.

interface GigabitEthernet1/0/1 switchport port-security maximum 2 switchport port-security mac-address sticky switchport port-security violation restrict

Allow two MACs (for example an IP phone with a PC behind it), learn them as sticky, and drop and log extra MACs instead of shutting the port.

interface GigabitEthernet1/0/1 switchport port-security aging time 60 switchport port-security aging type inactivity

Optional. Remove a dynamic secure MAC after 60 minutes without traffic (absolute aging removes it after 60 minutes no matter what).

A full example for SW1

interface range GigabitEthernet1/0/1 - 5 description User ports switchport mode access switchport access vlan 10 switchport port-security switchport port-security maximum 1 switchport port-security mac-address sticky switchport port-security violation shutdown spanning-tree portfast spanning-tree bpduguard enable ! errdisable recovery cause psecure-violation errdisable recovery interval 600 ! end copy running-config startup-config

Every user port allows one device, learned as sticky. A violating port shuts down and the switch retries it after 10 minutes. Saving keeps the sticky MACs across a reload.

After PC A sends its first frame, the running configuration gains a line like this under Gi1/0/1:

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show running-config interface GigabitEthernet1/0/1
Building configuration...
!
interface GigabitEthernet1/0/1
 description User ports
 switchport access vlan 10
 switchport mode access
 switchport port-security mac-address sticky
 switchport port-security mac-address sticky 0011.2233.4455
 switchport port-security
 spanning-tree portfast
 spanning-tree bpduguard enable
end
The second sticky line was added by the switch. Lines for defaults (maximum 1, violation shutdown) are not shown.

How to verify it

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show port-security interface GigabitEthernet1/0/1
Port Security              : Enabled
Port Status                : Secure-up
Violation Mode             : Shutdown
Aging Time                 : 0 mins
Aging Type                 : Absolute
SecureStatic Address Aging : Disabled
Maximum MAC Addresses      : 1
Total MAC Addresses        : 1
Configured MAC Addresses   : 0
Sticky MAC Addresses       : 1
Last Source Address:Vlan   : 0011.2233.4455:10
Security Violation Count   : 0
Secure-up means the feature is on and the port is forwarding. After a shutdown violation it reads Secure-shutdown. Last Source Address is the most recent MAC seen, which after a violation is usually the offending device.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show port-security
Secure Port  MaxSecureAddr  CurrentAddr  SecurityViolation  Security Action
                (Count)       (Count)          (Count)
---------------------------------------------------------------------------
     Gi1/0/1              1            1                  0         Shutdown
     Gi1/0/2              1            1                  0         Shutdown
     Gi1/0/3              1            0                  0         Shutdown
---------------------------------------------------------------------------
One line per secured port: a quick way to spot a port with a rising violation count.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show port-security address
               Secure Mac Address Table
-----------------------------------------------------------------------------
Vlan    Mac Address       Type                          Ports   Remaining Age
                                                                   (mins)
----    -----------       ----                          -----   -------------
  10    0011.2233.4455    SecureSticky                  Gi1/0/1        -
  10    0011.2233.6677    SecureSticky                  Gi1/0/2        -
The type shows how each address was learned: SecureConfigured, SecureDynamic or SecureSticky.

What goes wrong and how to troubleshoot it

When a shutdown violation happens, SW1 logs it and the port goes err-disabled:

Example output · based on Cisco documentation; exact format varies by platform and software version
%PM-4-ERR_DISABLE: psecure-violation error detected on Gi1/0/1, putting Gi1/0/1 in err-disable state
%PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address 00aa.bbcc.ddee on port GigabitEthernet1/0/1.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show interfaces status err-disabled
Port         Name               Status       Reason               Err-disabled Vlans
Gi1/0/1      User ports         err-disabled psecure-violation

To recover by hand:

  1. Find the device with the MAC in the log and remove it (or decide it is allowed).
  2. If the device is a legitimate replacement, clear the old sticky MAC: clear port-security sticky interface GigabitEthernet1/0/1, or remove the sticky line from the interface.
  3. Bounce the port: shutdown then no shutdown on the interface.
interface GigabitEthernet1/0/1 shutdown no shutdown

An err-disabled port stays down until it is shut and re-enabled (or auto-recovered). Doing this without removing the cause only triggers the violation again.

SymptomLikely cause
Command rejected: ... is a dynamic portThe port is still in dynamic auto/desirable mode. Set switchport mode access first.
A user's new PC gets no network on its first dayThe old PC's sticky MAC is still saved on the port.
Port shuts down when an IP phone is connectedMaximum is 1, but the phone and the PC behind it are two MACs.
Users complain, but the port is up and no logsViolation mode protect is silently dropping a second device.
After a reload, ports learn new devices againSticky MACs were never saved to the startup configuration.

Common mistakes

  • Typing the options but forgetting the bare switchport port-security command, which is what actually turns the feature on.
  • Expecting port security on a trunk to an access point or another switch with the same small limits: every device behind it counts.
  • Thinking protect logs violations. It is the only mode that doesn't.
  • Believing port security stops MAC spoofing. A device that copies an allowed MAC still gets in.
  • Shutting and re-enabling the port without removing the cause, so it goes err-disabled again within seconds.

💡 Exam tip: memorise the defaults (maximum 1, violation shutdown, port must be a static access or trunk port) and the three violation modes. A favourite question gives you the output of show port-security interface and asks what happened, or asks which mode drops frames and sends a log but keeps the port up (restrict). Also know that sticky MACs land in the running configuration and need saving.

Key takeaways

  • Port security limits which and how many source MACs may use a port.
  • Secure MACs are static, dynamic or sticky; sticky ones are written into the running configuration.
  • Defaults: maximum 1, violation mode shutdown, no aging.
  • shutdown err-disables the port; restrict drops and logs; protect drops silently.
  • Recover with shutdown / no shutdown or errdisable recovery cause psecure-violation.

Check yourself

Predict · scenario 1

You enter switchport port-security on an access port and nothing else. A second device sends a frame on that port. What happens?

Predict · scenario 2

Which violation mode drops frames from unknown MACs, sends a syslog message and increases the violation counter, but keeps the port up?

Predict · scenario 3

Sticky learning is on. The switch reloads before anyone saves the configuration. What happens to the learned MACs?

Predict · scenario 4

show port-security interface Gi1/0/1 shows Port Status: Secure-shutdown. What is the right order to recover?

Predict · scenario 5

Why does port security help against a MAC flooding attack?

FAQ

Does port security stop someone from spoofing an allowed MAC address?
No. Port security only checks the source MAC address in the frame, and a MAC address is easy to change in software. It stops casual misuse such as plugging in an unknown device or a small switch. Strong identity checks need 802.1X, which asks the device or user to prove who they are.
What is the difference between restrict and protect?
Both drop frames from MAC addresses that break the rule and keep the port up. Restrict also sends a log message (and an SNMP trap if configured) and increases the violation counter. Protect drops silently, so you get no warning that anything happened.
Why must I save the configuration after sticky learning?
Sticky MAC addresses are written into the running configuration. If you don't copy the running configuration to the startup configuration, they are lost at the next reload and the port learns again from scratch.
How do I bring an err-disabled port back?
Remove the cause first, then enter shutdown and no shutdown on the interface. Alternatively, errdisable recovery cause psecure-violation makes the switch try again on its own after the recovery interval (300 seconds by default).