← All labs Lab 14 · Packet Tracer

Port security

MAC limit, sticky learning and violation modes

Level: Intermediate Time: 20 min Domain 5.0 Security Fundamentals

Scenario

Someone plugged a home switch under a desk and several devices come in through Fa0/1. Who can connect must be limited.

On Fa0/1, set the port to access mode and enable port security with a maximum of 2 MACs, sticky learning and restrict violation mode (drops and counts disallowed traffic without shutting the port). On Fa0/2, access mode and port security with default values.

Check which MAC it learned with show port-security interface fa0/1.

Topology

SW1PC1PC2Fa0Fa0/1Fa0Fa0/2

Devices and cabling

FromToCable
PC1 Fa0SW1 Fa0/1Straight-through
PC2 Fa0SW1 Fa0/2Straight-through

If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.

Addressing

DeviceInterfaceAddressMaskDefault gateway
PC1SW1 Fa0/1192.168.1.10255.255.255.0—
PC2SW1 Fa0/2192.168.1.11255.255.255.0—

Starting configuration

In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.

SW1hostname SW1 no ip domain-lookup

PCs and servers (Desktop › IP Configuration)

Tasks

What must end up working. In the app, each one ticks itself off as soon as you get it.

  1. Fa0/1 in access mode
  2. Port security enabled on Fa0/1
  3. Maximum of 2 MAC addresses
  4. Sticky learning
  5. Restrict violation mode
  6. PC1's MAC is stored as sticky
  7. Fa0/2: access and default port security
  8. Checked with show port-security interface fa0/1
In Packet Tracer
  • In Packet Tracer, the switch learns the MAC when the PC sends traffic: ping from PC1 to PC2 after configuring the port.
Hints
  • Fa0/1 in access mode: interface fa0/1 → switchport mode access. Port security can't be enabled on a dynamic port.
  • Port security enabled on Fa0/1: switchport port-security
  • Maximum of 2 MAC addresses: switchport port-security maximum 2
  • Sticky learning: switchport port-security mac-address sticky: learned MACs go into the running-config
  • Restrict violation mode: switchport port-security violation restrict
  • PC1's MAC is stored as sticky: With sticky enabled, PC1's MAC shows up in show running-config
  • Fa0/2: access and default port security: interface fa0/2 → switchport mode access → switchport port-security (maximum 1 and shutdown)
  • Checked with show port-security interface fa0/1: show port-security interface fa0/1

Step-by-step solution

Try it on your own first: you learn much more by typing the commands yourself.

Show the solution

1Pin Fa0/1 as access and enable port security SW1

Port security can't be enabled on a dynamic port: IOS replies "Command rejected: … is a dynamic port".

SW1enable configure terminal interface fa0/1 switchport mode access switchport port-security

2Maximum, sticky and violation mode SW1

sticky stores the learned MACs in the running-config. restrict drops and counts what's not allowed without shutting the port.

SW1switchport port-security maximum 2 switchport port-security mac-address sticky switchport port-security violation restrict

3Fa0/2 with default values SW1

By default: one MAC and, on a violation, the port goes err-disabled.

SW1interface fa0/2 switchport mode access switchport port-security end

Verification

Maximum 2, Restrict mode and PC1's MAC as sticky.

SW1SW1#show port-security interface fa0/1 Port Security : Enabled Port Status : Secure-up Violation Mode : Restrict Aging Time : 0 mins Aging Type : Absolute SecureStatic Address Aging : Disabled Maximum MAC Addresses : 2 Total MAC Addresses : 1 Configured MAC Addresses : 0 Sticky MAC Addresses : 1 Last Source Address:Vlan : 00d0.af38.7a1a:1 Security Violation Count : 0

The learned MAC shows up in the port's configuration: save with copy run start to keep it.

SW1SW1#show running-config interface fa0/1 Building configuration... Current configuration : 268 bytes ! interface FastEthernet0/1 switchport mode access switchport port-security maximum 2 switchport port-security switchport port-security violation restrict switchport port-security mac-address sticky switchport port-security mac-address sticky 00d0.af38.7a1a end

Common mistakes

Practice this lab on your phone

RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.

Get RoutingLab