Port security on Catalyst 3560 switch.

Posted on 2010-08-26
Medium Priority
Last Modified: 2012-05-10
I have a Catalyst 3560 switch. I want to block a port to only allow traffic from 1 MAC address. How do I do this?
Question by:Neptune IT
LVL 18

Expert Comment

by:Jimmy Larsson, CISSP, CEH
ID: 33533739
interface FastEthernet0/4
 switchport mode access
 switchport port-security
 switchport port-security maximum 1



Accepted Solution

ffleisma earned 2000 total points
ID: 33540589
Switch(config)#interface FastEthernet X/X
Switch(config-if)#switchport mode access
Switch(config-if)#switchport port-security
Switch(config-if)#switchport port-security maximum 1
Switch(config-if)#switchport port-security mac-address 0006.5b02.a841
Switch(config-if)# switchport port-security violation {shutdown | restrict | protect}

shutdown - port goes to err-disable
restrict - port stays up but packets are droped and can send SNMP trap and syslog
protect - port stays up but packets are droped, no record is kept or syslog message sent

you can also try
Switch(config-if)#switchport port-security mac-address sticky
instead of
Switch(config-if)#switchport port-security mac-address

with sticky option, the switch gets and stores the mac-address of the first device you plug-in

hope this helps :-)

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
Watch the video to know how one can repair corrupt Exchange OST file effortlessly and convert OST emails to MS Outlook PST file format by using Kernel for OST to PST converter tool. It can convert OST to MSG, MBOX, EML to access them. It can migrate…
When you have multiple client accounts to manage, it often feels like there aren’t enough hours in the day. With too many applications to juggle, you can’t focus on your clients, much less your growing to-do list. But that doesn’t have to be the cas…

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question