# How to configure port-security on Cisco Switch

**URL:** https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866
**Category:** Lessons Discussion
**Created:** [December 20, 2016, 10:03pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866 "2016-12-20T22:03:15Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 20, 2016, 10:03pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/1 "2016-12-20T22:03:15Z")

</div>

This topic is to discuss the following lesson:

> **[How to configure port-security on Cisco Switch](https://networklessons.com/switching/how-to-configure-port-security-on-cisco-switch)**
>
> Port-security can be used to filter MAC-addresses on Cisco switches. In this lesson you will learn how it works and how to configure it.

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 15, 2013, 1:09pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/2 "2013-07-15T13:09:58Z")

</div>

Hi, your lessons are very interesting. Thank’s.

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 27, 2013, 3:14pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/3 "2013-07-27T15:14:26Z")

</div>

Hi Rene, thanks for the lessons. Very interesting and informative - keep up the good work 🙂

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [November 25, 2013, 11:36pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/4 "2013-11-25T23:36:14Z")

</div>

Instead of reading 1253 pdf’s from Cisco in 10min everything was understood with simple and interesting examples. Gongratulations René, here it is a very useful lesson.

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [January 14, 2014, 7:31pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/5 "2014-01-14T19:31:20Z")

</div>

Thanks Luís! Glad to hear it was useful to you.

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [January 14, 2014, 11:27pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/6 "2014-01-14T23:27:22Z")

</div>

Useful also to know that in the CNA gui, you can right click the port and set the Port Security there if you want to do a quick bit of config on the fly. Thanks

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [July 14, 2014, 4:37am UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/7 "2014-07-14T04:37:41Z")

</div>

Thanks - nice tutorial and I just applied it to one port on our switch!

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [August 1, 2014, 5:17pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/8 "2014-08-01T17:17:25Z")

</div>

wonderfull tutorial, U’r my angel switch, but can Catalyst 2960 Series work this tutorial?

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [August 2, 2014, 9:03am UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/9 "2014-08-02T09:03:09Z")

</div>

Sure, even the 2950 will work.

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [August 18, 2014, 2:14pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/10 "2014-08-18T14:14:26Z")

</div>

Hi Rene, I have a strange problem related to your post. We have a unmananged switch connected to a managed switch port. That port is configured as follows:

```
 description Conference Room
 switchport access vlan 43
 switchport mode access
 switchport port-security maximum 16
 switchport port-security
 authentication host-mode multi-host
 authentication port-control auto
 dot1x pae authenticator
 dot1x timeout quiet-period 20
 dot1x timeout tx-period 10
 spanning-tree bpduguard enable

```

If a user connects to this switch and then unplugs (not Logoff), goes to their desk and plugs in, their port is Err-disabled. I have to shut the port on the conference room and then shut and no shut their port. After that all is well. What can I do to prevent me having to shut the port the conference room unmanaged switch is in?

Thank you,

Kevin Martin

---

<div class="post-metadata">

### Author: ![varunparihar1983](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/v/f08c70/32.png) [@varunparihar1983](https://forum.networklessons.com/u/varunparihar1983)
#### Post date: [September 4, 2014, 12:27pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/11 "2014-09-04T12:27:37Z")

</div>

rene u r great!!!wat a explanation…

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [October 21, 2014, 7:55pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/12 "2014-10-21T19:55:15Z")

</div>

Try this on the conference room interface.  
switchport port-security aging time 300

In 5 minutes, it should reset.

---

<div class="post-metadata">

### Author: ![system](https://cdn-forum.networklessons.com/uploads/default/original/1X/1d2ef66728c7fbac8377748594345a3f474fce5f.png) [@system](https://forum.networklessons.com/u/system)
#### Post date: [October 21, 2014, 8:01pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/13 "2014-10-21T20:01:47Z")

</div>

Correction.  
Auto-recovery

To avoid having to manually intervene every time a port-security violation forces an interface into the error-disabled state, one can enable auto-recovery for port security violations. A recovery interval is configured in seconds.

```
Switch(config)# errdisable recovery cause psecure-violation
Switch(config)# errdisable recovery interval 600

```

Ten minutes after a port was error-disabled, we can see that the port is automatically transitioned back into operation:

---

<div class="post-metadata">

### Author: ![Openlearner](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/o/ad7895/32.png) [@Openlearner](https://forum.networklessons.com/u/Openlearner)
#### Post date: [January 24, 2015, 7:39pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/14 "2015-01-24T19:39:45Z")

</div>

Hi Rene,

It is normal for companies to have an unmanage linksys switches or other brand connected to a Cisco switch, I had this issue on one company I was working because everytime they connect an unmanage switch a lot of users will loose connectivity then I removed bpduguard and configured port-security allowing only 10 mac addresses and we haven’t had that issue. I noticed that bpdguard will bring the port into err-disable. Please advise if this is correct.

Thanks

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [January 26, 2015, 10:00pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/15 "2015-01-26T22:00:47Z")

</div>

Hi Alfredo,

It depends…in a SMB environment, you can encounter anything. I’ve seen Cisco switches with a combination of any other vendor switch. Sometimes users bring their own stuff and connect it to the network.

In larger (enterprise) networks they typically spend some more time at network design and more money on hardware. You won’t see cheap unmanaged switches there…

BPDUguard will put your interface in err-disable if it receives a BPDU on the interface. Some unmanaged switches might still send these so that could cause the interface to go down. Here’s an example btw:

> **[Spanning Tree BPDU Guard](https://networklessons.com/spanning-tree/spanning-tree-bpduguard)**
>
> BPDUGuard helps to protect your spanning-tree topology. When an interface that has this enabled receives a BPDU, it will go into err-disabled mode.

Typically port-security is only used on access interfaces that connect computers, laptops or IP phones. You can set it to 1 MAC address for computers or two if there’s an IP phone with a computer behind it.

Rene

---

<div class="post-metadata">

### Author: ![peterchidi](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/p/cab0a1/32.png) [@peterchidi](https://forum.networklessons.com/u/peterchidi)
#### Post date: [June 13, 2015, 1:59am UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/16 "2015-06-13T01:59:29Z")

</div>

Hi Rene,

This sound silly but i want know how you can ping from the IOS command line with a packet tracer instead of the command prompt?.  
Thanks,  
Peter

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [June 13, 2015, 3:26pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/17 "2015-06-13T15:26:15Z")

</div>

Hi Peter,

What exactly do you mean? Do you want to use a GUI instead of the command line or something like traceroute?

Rene

---

<div class="post-metadata">

### Author: ![peterchidi](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/p/cab0a1/32.png) [@peterchidi](https://forum.networklessons.com/u/peterchidi)
#### Post date: [June 13, 2015, 4:55pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/18 "2015-06-13T16:55:36Z")

</div>

Hi Rene,

Sorry is a mistake.

Thanks  
peter

---

<div class="post-metadata">

### Author: ![Zaman.rubd](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/z/45deac/32.png) [@Zaman.rubd](https://forum.networklessons.com/u/Zaman.rubd)
#### Post date: [May 11, 2016, 8:52am UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/19 "2016-05-11T08:52:01Z")

</div>

Nice & very informative . Keep it up 🙂

---

<div class="post-metadata">

### Author: ![palanimuthukar](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/p/8c91f0/32.png) [@palanimuthukar](https://forum.networklessons.com/u/palanimuthukar)
#### Post date: [May 14, 2016, 8:44pm UTC](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866/20 "2016-05-14T20:44:00Z")

</div>

Hi Rene

I do not understand what this command (errdisable recovery cause psecure-violation) exactly used for?  
Does the switch port recovers itself from err-disabled mode if we set the aging time to say 10 minutes instead of the default 0 minutes.

Thanks  
Palani

[Next page](https://forum.networklessons.com/t/how-to-configure-port-security-on-cisco-switch/866.md?page=2)
