How to configure port-security on Cisco Switch

Hello Hussein.

In order to clearly answer this question, we have to define two different functionalities of the switch: port security and the MAC address table.

Port security has been explained well in this lesson, so I’ll just mention that port security allows only devices with specific MAC addresses to connect and function on a specific interface.

The MAC address table is a table that records MAC addresses and the corresponding interface on which they can be found. This table exists to give a switch it’s most basic function which also distinguishes it from a hub: to eliminate collision domains.

So these are two very different functionalities that both use MAC addresses.

Now to your question:

Concerning switchport port-security aging time: When aging is configured on an interface that’s using port security, all the dynamically learned secure addresses age out when the aging time expires. This can be configured as an absolute value, where the aging time exires regardless of activity on the port, or it can be configured where it defines the period of inactivity after which all the dynamically learned secure addresses age out.

Concerning mac-address-table aging-time: This command configures the amount of time before a dynamically learned MAC address in the CAM table (or MAC address table) is removed. It defines the period of inactivity after which all the dynamically learned MAC addresses age out.

So, these are two very different functionalities that function in a similar manner.

I hope this has been helpful for you!

Laz

1 Like