[c-nsp] Broadcast storm control

Saku Ytti saku+cisco-nsp at ytti.fi
Tue Nov 6 12:10:09 EST 2007


On (2007-11-06 16:56 +0000), Sam Stickland wrote:

> switchport port-security
> switchport port-security maximum x
> switchport port-security aging time 5
> switchport port-security violation restrict
>
> Port security doesn't permamently learn MAC addresses unless "switchport 
> port-security mac-address sticky" is set, and setting the aging time to 5 
> matches the default CAM table timers.

Dynamic MACs you can relearn any time. So consider there is L2
redundancy, with port-security enabled, you have to wait for aging time
before you can switch. I guess I'm only one who finds this really basic
and elementary feature that just should be available.

-- 
  ++ytti


More information about the cisco-nsp mailing list