A real-life situation
A meeting room has one network socket, patched to port Gi1/0/1 on SW1. It is meant for the room's PC. One day a visitor unplugs the PC and connects their own laptop. Another day someone adds a small home switch so four people can share the socket. Neither was allowed, and nobody noticed. Port security lets the switch notice and act on its own.
- 1. The allowed MAC. PC A's MAC is the secure address on Gi1/0/1, so its frames are forwarded as usual.
- 2. A new MAC appears. The laptop is plugged into the same socket. The port already has its maximum of one secure MAC, so this is a violation.
- 3. The switch reacts. In the default shutdown mode, Gi1/0/1 is put in the err-disabled state and a log message is sent. Nothing passes until an admin recovers it.
What port security is
Port security is a Cisco switch feature that limits which source MAC addresses may send frames into an access port, and how many. A MAC address the port accepts is called a secure MAC address. If a frame arrives from a MAC address that would break the rule, that is a violation, and the switch reacts in the way you choose.
If you need a refresher on how a switch reads source MACs, see How a switch learns MAC addresses. Port security hooks into exactly that learning step.
There are three ways a port gets its secure MAC addresses:
| Type | How it is added | Survives a reload? |
|---|---|---|
| Static | You type it: switchport port-security mac-address 0011.2233.4455 | Yes, it is in the configuration |
| Dynamic | Learned from traffic, like normal MAC learning | No, it is only in memory |
| Sticky | Learned from traffic, then written into the running configuration | Yes, if you save the configuration |
Why it works that way
- The switch already sees every source MAC. Learning MAC addresses is its normal job, so checking them against a limit costs almost nothing and needs no extra server.
- A limit stops MAC flooding. An attacker can send thousands of frames with random source MACs to fill the MAC address table. When the table is full, the switch floods unknown frames out of every port, and the attacker sees traffic meant for others. With a maximum of one or two MACs per port, that attack fails at the first port.
- Sticky learning saves typing. You don't have to collect the MAC of every desk PC. The port learns the first device, writes it down, and from then on only accepts that device.
- It is not proof of identity. MAC addresses can be changed in software. Port security keeps honest people honest and blocks simple attacks; stronger checks use 802.1X, covered in AAA: RADIUS and TACACS+.
How it works step by step
A violation also happens if a MAC that is secure on one port shows up on another port in the same VLAN. The violation mode decides what happens next:
| Mode | Drops bad frames | Log / SNMP trap | Violation counter | Port state |
|---|---|---|---|---|
| shutdown (default) | Yes (all traffic) | Yes | Increases | err-disabled |
| restrict | Yes | Yes | Increases | Stays up |
| protect | Yes | No | No change | Stays up |
In restrict and protect mode, frames from the allowed MACs keep flowing; only the extra MACs are dropped. In shutdown mode the whole port stops, so the allowed PC loses its connection too.
Err-disabled (error-disabled) is a state where the switch has turned a port off by itself because of an error. The port's LED goes off and it passes no traffic until it is recovered, either by hand or by an automatic recovery timer.
How to configure it on Cisco IOS
⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device.
Port security only works on a port whose mode is set by hand. A port left in the default dynamic mode refuses the command, so set switchport mode access first.
interface GigabitEthernet1/0/1
switchport mode access
switchport access vlan 10
switchport port-securityThe minimum. With nothing else set: maximum 1 MAC, violation mode shutdown, dynamic learning, no aging.
interface GigabitEthernet1/0/1
switchport port-security maximum 2
switchport port-security mac-address sticky
switchport port-security violation restrictAllow two MACs (for example an IP phone with a PC behind it), learn them as sticky, and drop and log extra MACs instead of shutting the port.
interface GigabitEthernet1/0/1
switchport port-security aging time 60
switchport port-security aging type inactivityOptional. Remove a dynamic secure MAC after 60 minutes without traffic (absolute aging removes it after 60 minutes no matter what).
A full example for SW1
interface range GigabitEthernet1/0/1 - 5
description User ports
switchport mode access
switchport access vlan 10
switchport port-security
switchport port-security maximum 1
switchport port-security mac-address sticky
switchport port-security violation shutdown
spanning-tree portfast
spanning-tree bpduguard enable
!
errdisable recovery cause psecure-violation
errdisable recovery interval 600
!
end
copy running-config startup-configEvery user port allows one device, learned as sticky. A violating port shuts down and the switch retries it after 10 minutes. Saving keeps the sticky MACs across a reload.
After PC A sends its first frame, the running configuration gains a line like this under Gi1/0/1:
SW1#show running-config interface GigabitEthernet1/0/1 Building configuration... ! interface GigabitEthernet1/0/1 description User ports switchport access vlan 10 switchport mode access switchport port-security mac-address sticky switchport port-security mac-address sticky 0011.2233.4455 switchport port-security spanning-tree portfast spanning-tree bpduguard enable end
How to verify it
SW1#show port-security interface GigabitEthernet1/0/1 Port Security : Enabled Port Status : Secure-up Violation Mode : Shutdown Aging Time : 0 mins Aging Type : Absolute SecureStatic Address Aging : Disabled Maximum MAC Addresses : 1 Total MAC Addresses : 1 Configured MAC Addresses : 0 Sticky MAC Addresses : 1 Last Source Address:Vlan : 0011.2233.4455:10 Security Violation Count : 0
SW1#show port-security Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action (Count) (Count) (Count) --------------------------------------------------------------------------- Gi1/0/1 1 1 0 Shutdown Gi1/0/2 1 1 0 Shutdown Gi1/0/3 1 0 0 Shutdown ---------------------------------------------------------------------------
SW1#show port-security address Secure Mac Address Table ----------------------------------------------------------------------------- Vlan Mac Address Type Ports Remaining Age (mins) ---- ----------- ---- ----- ------------- 10 0011.2233.4455 SecureSticky Gi1/0/1 - 10 0011.2233.6677 SecureSticky Gi1/0/2 -
What goes wrong and how to troubleshoot it
When a shutdown violation happens, SW1 logs it and the port goes err-disabled:
%PM-4-ERR_DISABLE: psecure-violation error detected on Gi1/0/1, putting Gi1/0/1 in err-disable state %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address 00aa.bbcc.ddee on port GigabitEthernet1/0/1.
SW1#show interfaces status err-disabled Port Name Status Reason Err-disabled Vlans Gi1/0/1 User ports err-disabled psecure-violation
To recover by hand:
- Find the device with the MAC in the log and remove it (or decide it is allowed).
- If the device is a legitimate replacement, clear the old sticky MAC:
clear port-security sticky interface GigabitEthernet1/0/1, or remove the sticky line from the interface. - Bounce the port:
shutdownthenno shutdownon the interface.
interface GigabitEthernet1/0/1
shutdown
no shutdownAn err-disabled port stays down until it is shut and re-enabled (or auto-recovered). Doing this without removing the cause only triggers the violation again.
| Symptom | Likely cause |
|---|---|
| Command rejected: ... is a dynamic port | The port is still in dynamic auto/desirable mode. Set switchport mode access first. |
| A user's new PC gets no network on its first day | The old PC's sticky MAC is still saved on the port. |
| Port shuts down when an IP phone is connected | Maximum is 1, but the phone and the PC behind it are two MACs. |
| Users complain, but the port is up and no logs | Violation mode protect is silently dropping a second device. |
| After a reload, ports learn new devices again | Sticky MACs were never saved to the startup configuration. |
Common mistakes
- Typing the options but forgetting the bare
switchport port-securitycommand, which is what actually turns the feature on. - Expecting port security on a trunk to an access point or another switch with the same small limits: every device behind it counts.
- Thinking
protectlogs violations. It is the only mode that doesn't. - Believing port security stops MAC spoofing. A device that copies an allowed MAC still gets in.
- Shutting and re-enabling the port without removing the cause, so it goes err-disabled again within seconds.
💡 Exam tip: memorise the defaults (maximum 1, violation shutdown, port must be a static access or trunk port) and the three violation modes. A favourite question gives you the output of show port-security interface and asks what happened, or asks which mode drops frames and sends a log but keeps the port up (restrict). Also know that sticky MACs land in the running configuration and need saving.
Key takeaways
- Port security limits which and how many source MACs may use a port.
- Secure MACs are static, dynamic or sticky; sticky ones are written into the running configuration.
- Defaults: maximum 1, violation mode shutdown, no aging.
- shutdown err-disables the port; restrict drops and logs; protect drops silently.
- Recover with
shutdown/no shutdownorerrdisable recovery cause psecure-violation.
Check yourself
You enter switchport port-security on an access port and nothing else. A second device sends a frame on that port. What happens?
Which violation mode drops frames from unknown MACs, sends a syslog message and increases the violation counter, but keeps the port up?
Sticky learning is on. The switch reloads before anyone saves the configuration. What happens to the learned MACs?
show port-security interface Gi1/0/1 shows Port Status: Secure-shutdown. What is the right order to recover?
Why does port security help against a MAC flooding attack?