Someone plugged a home switch under a desk and several devices come in through Fa0/1. Who can connect must be limited.
On Fa0/1, set the port to access mode and enable port security with a maximum of 2 MACs, sticky learning and restrict violation mode (drops and counts disallowed traffic without shutting the port). On Fa0/2, access mode and port security with default values.
Check which MAC it learned with show port-security interface fa0/1.
Topology
Devices and cabling
SW1·2960-24TT
PC1, PC2·PC-PT
From
To
Cable
PC1Fa0
SW1Fa0/1
Straight-through
PC2Fa0
SW1Fa0/2
Straight-through
If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.
Addressing
Device
Interface
Address
Mask
Default gateway
PC1
SW1 Fa0/1
192.168.1.10
255.255.255.0
—
PC2
SW1 Fa0/2
192.168.1.11
255.255.255.0
—
Starting configuration
In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.
SW1hostname SW1
no ip domain-lookup
PCs and servers (Desktop › IP Configuration)
PC1: IP 192.168.1.10, mask 255.255.255.0
PC2: IP 192.168.1.11, mask 255.255.255.0
Tasks
What must end up working. In the app, each one ticks itself off as soon as you get it.
Fa0/1 in access mode
Port security enabled on Fa0/1
Maximum of 2 MAC addresses
Sticky learning
Restrict violation mode
PC1's MAC is stored as sticky
Fa0/2: access and default port security
Checked with show port-security interface fa0/1
In Packet Tracer
In Packet Tracer, the switch learns the MAC when the PC sends traffic: ping from PC1 to PC2 after configuring the port.
Hints
Fa0/1 in access mode: interface fa0/1 → switchport mode access. Port security can't be enabled on a dynamic port.
Port security enabled on Fa0/1: switchport port-security
Maximum of 2 MAC addresses: switchport port-security maximum 2
Sticky learning: switchport port-security mac-address sticky: learned MACs go into the running-config
By default: one MAC and, on a violation, the port goes err-disabled.
SW1interface fa0/2
switchport mode access
switchport port-security
end
Verification
Maximum 2, Restrict mode and PC1's MAC as sticky.
SW1SW1#show port-security interface fa0/1
Port Security : Enabled
Port Status : Secure-up
Violation Mode : Restrict
Aging Time : 0 mins
Aging Type : Absolute
SecureStatic Address Aging : Disabled
Maximum MAC Addresses : 2
Total MAC Addresses : 1
Configured MAC Addresses : 0
Sticky MAC Addresses : 1
Last Source Address:Vlan : 00d0.af38.7a1a:1
Security Violation Count : 0
The learned MAC shows up in the port's configuration: save with copy run start to keep it.
SW1SW1#show running-config interface fa0/1
Building configuration...
Current configuration : 268 bytes
!
interface FastEthernet0/1
switchport mode access
switchport port-security maximum 2
switchport port-security
switchport port-security violation restrict
switchport port-security mac-address sticky
switchport port-security mac-address sticky 00d0.af38.7a1a
end
Common mistakes
Enabling port security without switchport mode access.
Waiting for the MAC to show up without generating traffic from the PC.
Practice this lab on your phone
RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.