Configuring and Enabling Port Security Aging

You can use port security aging to set the aging time for all secure addresses on a port. Two types of aging are supported per port:
♦ Absolute—The secure addresses on that port are deleted after the specified aging time.
♦ Inactivity—The secure addresess on this port are deleted only if the secure addresses are inactive for the specified aging time.
Use this feature to remove and add PCs on a secure port without manually deleting the existing secure MAC addresses while still limiting the number of secure addresses on a port. You can enable or disable aging of statically configured secure addresses on a per port basis.
Displaying Port-Based Traffic Control Settings
Beginning in privileged EXEC mode, follow these steps to configure port security aging:
Step 1 Step 2
Step 3
Step 4 Step 5
Step 6
|
Command |
Purpose |
|
configure terminal |
Enter global configuration mode. |
|
interface interface-id |
Enter interface configuration mode for the port on which you want to enable port security aging. |
|
switchport port-security aging {static | time time | type {absolute | inactivity}} |
Set the aging time, type, and enable or disable static aging for the secure port. Enter static to enable aging for statically configured secure addresses on this port. For time, specify the aging time for this port. Valid range is from 0 to 1440 minutes. If the time is equal to 0, aging is disabled for this port. For type, select one of these keywords: ♦ absolute—Sets the aging type as absolute aging. All the secure addresses on this port age out exactly after the time (minutes) specified lapses and are removed from the secure address list. ♦ inactivity—Sets the aging type as inactivity aging. The secure addresses on this port age out only if there is no data traffic from the secure source addresses for the specified time period. |
|
end |
Return to privileged EXEC mode. |
|
show port security [interface interface-id] [address] |
Verify your entries. |
|
copy running-config startup-config |
(Optional) Save your entries in the configuration file. |
Step 1 Step 2
Step 3
Step 4 Step 5
Step 6
To disable port security aging for all secure addresses on a port, use the no switchport port-security aging time interface configuration command. To disable aging for only statically configured secure addresses, use the no switchport port-security aging static interface configuration command.
This example shows how to set the aging time as 2 hours for the secure addresses on the Fast Ethernet interface 0/1.
Switch(config)# interface fastethernet0/1
Switch(config-if)# switchport port-security aging time 120
This example shows how to set the aging time as 2 minutes for the inactivity aging type for the configured secure addresses on the interface.
Switch(config-if)# switchport port-security aging time 2 Switch(config-if)# switchport port-security aging type inactivity Switch(config-if)# switchport port-security aging static
You can verify the previous commands by entering the show port-security interface interface id privileged EXEC command.
Continue reading here: Disabling and Enabling CDP on an Interface
Was this article helpful?
Readers' Questions
-
Tito1 year ago
- Reply