[c-nsp] quick port-security question

Kyle York kyork at cisco.com
Wed Jun 20 12:29:06 EDT 2007


Greetings,

Justin M. Streiner wrote:
> In reading over the documentation for configuring port-security, I didn't 
> see a clear answer for the following condition.  Assume the maximum 
> number of allowed MAC addresses is set to 1 and the response action is set 
> to restrict.
> 
> If a switchport sees frames for a second MAC address on a secured port 
> and the switch sends the appropriate alert, will it continue sending 
> alerts for every frame it sees that violates the configured policy, or 
> will it only send one alert per unique MAC address in violation of the 
> policy?

Sends alerts for every frame, throttled to one message every 5s.

> 
> If you have a link to a document on the CCO that lays this out in detail, 
> please let me know.  Everything I've run across so far has been basic 
> setup instructions and not much more.

Sorry, no idea.

-- 
Kyle A. York
Sr. Subordinate Grunt


More information about the cisco-nsp mailing list