Skip to main content
PacketMentor logo
Open menu
← All topics
Security Fundamentals Foundational

Port Security

Lock a switch port to a specific MAC address (or addresses). Covers static, dynamic, and sticky learning, violation modes (protect / restrict / shutdown), and the err-disable recovery dance.

Quick summary
  • Port security restricts which MAC addresses can use a switch port. Unauthorized device = port shuts down (or drops frames silently).
  • Three learning modes: static (manually configured), dynamic (learned from first traffic, lost on reload), sticky (learned and saved to running-config).
  • Three violation modes: shutdown (default: err-disable), restrict (drop + log), protect (drop silently).
Port Security · lock a port to specific MAC addressesSW1Gi0/1 · port-securityPC-A ✓aaaa.bbbb.ccccRogue ✗deee.eeee.ffffSHUTport-security · max 1 MAC · violation = err-disableAllowed (sticky): aaaa.bbbb.ccccUnknown MAC arrives → port shuts down
Port security pins an access port to one (or N) specific MAC addresses. An unauthorized device triggers an immediate shutdown.

Mental model

A switch port, by default, accepts traffic from any device that plugs in. That’s flexible, but it means anyone who can physically reach a network port (visitor jack in a meeting room, a janitor’s closet, a coffee shop) can plug in a laptop and join your LAN.

Port security says: “this port is locked to one specific MAC address (or N specific MAC addresses); anything else: react.”

That’s the whole concept. The rest is detail: how the MAC gets registered, and what “react” means when an unauthorized device shows up.

Three ways the switch learns the allowed MAC

ModeHow it learnsSurvives reload?
StaticHardcoded with switchport port-security mac-address XYes
DynamicLearned from the first frame on the portNo: lost on reload
StickyLearned dynamically, then saved to running-configYes (once write memory runs)

Sticky is the typical production choice. Set it up, let the legitimate device connect once (its MAC gets learned and saved), and you’re protected forever.

Three ways the switch reacts to a violation

Violation modeWhat happensCounter increments?Log message?
shutdown (default)Port goes to err-disable (down)YesYes
restrictFrames from bad MACs dropped, port stays upYesYes
protectFrames dropped silentlyNoNo

Most production deployments use restrict. It logs the event without killing the port (which would also kick off the legitimate user if someone else briefly plugs in).

Commands

Basic sticky port security (the production default)

SW1(config)# interface GigabitEthernet0/1
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 10
SW1(config-if)# switchport port-security
SW1(config-if)# switchport port-security maximum 1
SW1(config-if)# switchport port-security mac-address sticky
SW1(config-if)# switchport port-security violation restrict

Read it as: “this access port allows up to 1 MAC address; learn it dynamically and save it; on violation, drop frames but stay up.”

Allow a phone + a PC behind the phone

A common scenario: a Cisco IP phone plugs into the wall, and a PC plugs into the phone. Two MACs on one port.

SW1(config-if)# switchport port-security maximum 2

Statically allow a specific MAC

SW1(config-if)# switchport port-security mac-address aaaa.bbbb.cccc

Verification

SW1# show port-security
SW1# show port-security interface GigabitEthernet0/1
SW1# show port-security address
SW1# show interfaces status err-disabled

show port-security is the do-everything command. It shows: which ports have port-security enabled, max MACs allowed, current MACs learned, violation count, action mode.

Recovering from err-disable

When a port hits a violation in shutdown mode, it goes err-disabled: down, and it won’t come up by itself.

Manual recovery

SW1(config)# interface GigabitEthernet0/1
SW1(config-if)# shutdown
SW1(config-if)# no shutdown

Auto-recovery after a timeout

SW1(config)# errdisable recovery cause psecure-violation
SW1(config)# errdisable recovery interval 300

Tells the switch: auto-recover from port-security err-disables after 300 seconds. Use cautiously: if the violation persists, the port will flap every 5 minutes.

Common mistakes

  1. Enabling port-security on a dynamic (DTP) port. The switch rejects switchport port-security on a port left in dynamic auto or dynamic desirable (“is a dynamic port”). Set switchport mode access first. Port security is also supported on static trunks, but it is rarely a good fit there.

  2. Leaving maximum at default 1 when a phone is in line. A Cisco IP phone has its own MAC, and the PC behind it has another. With max 1, the phone learns first, the PC violates. Set max to 2 (or use voice VLAN handling that exempts the voice VLAN).

  3. Using dynamic learning in production. Learned MACs are lost on reload. Power cycles → no one can use the port → tickets. Always use sticky in production.

  4. Setting violation mode to shutdown without err-disable recovery. Someone briefly plugs in the wrong device → port is dead until an admin SSHes in. For low-stakes deployments, use restrict + log.

  5. Forgetting to save running-config after sticky learning. The MAC appears in show running-config, but if you don’t write memory, a reload wipes it. Always save after enabling sticky.

  6. Locking a port to a MAC, then swapping the connected device. New device → new MAC → violation. To swap devices legitimately, either: clear port-security sticky interface Gi0/1 (removes the learned sticky MAC); or update the static MAC.

Lab to try tonight

  1. One switch. Plug a laptop into Gi0/1.
  2. Configure Gi0/1 for sticky port security with max 1, violation restrict.
  3. Verify with show port-security: should show one MAC learned (your laptop’s).
  4. Unplug your laptop, plug in a different device. Verify with show port-security: violation counter increments, port stays up but frames are dropped.
  5. Plug your laptop back in. Should work immediately.
  6. Switch violation to shutdown. Repeat the swap: port should now err-disable.
  7. Add errdisable recovery cause psecure-violation + errdisable recovery interval 60. Watch the port recover automatically after 60s.

Cheat strip

ConceptPlain English
Static / Dynamic / StickyHow the allowed MAC is configured. Use sticky in production.
Maximum NHow many MACs are allowed on the port
Violation: shutdownDefault. Port err-disables on violation.
Violation: restrictDrop frames + log, port stays up
Violation: protectDrop frames silently, no log
StickyDynamic + save-to-running-config. Most common production setting.
err-disableThe state a port enters after a shutdown-mode violation
RecoveryManual shut/no shut or auto via errdisable recovery

Frequently asked questions

Q: What’s the difference between shutdown, restrict, and protect violation modes? A: Shutdown (default): port goes to err-disabled state, drops all traffic, must be manually recovered or errdisable recovery timer. Restrict: drops offending traffic, generates SNMP trap and syslog, keeps forwarding valid traffic, counter increments. Protect: silently drops offending traffic, no logging, no counter. Common choice: restrict for user ports when you want logging without downtime; shutdown where strict enforcement matters.

Q: What is sticky MAC learning? A: switchport port-security mac-address sticky tells the switch to learn MACs dynamically but save them into running-config as if they were manually configured. First device to connect on a port gets pinned to that port. Great for asset-tracking scenarios (only this laptop can use this port). Common gotcha: sticky-learned MACs need to be saved to startup-config or they’re lost at reboot.

Q: How do I recover a port from err-disabled state? A: Manual: shutdown then no shutdown on the interface. Automatic: enable errdisable recovery cause psecure-violation globally and set errdisable recovery interval <seconds> (default 300). Automatic recovery is convenient but hides recurring problems. Every 5 minutes the port comes back, gets slammed again, err-disables. Fix the root cause instead of just enabling auto-recovery.

Q: Should I use port-security on trunk ports? A: Usually not. It is supported on static trunks, but trunks carry traffic for many VLANs from many devices (potentially thousands of MACs). Port-security assumes a small number of expected MACs per port. On trunks, use DAI + DHCP snooping + BPDU Guard on the far-end access ports, not port-security. Port-security is for access ports facing single devices.

Q: What’s the max MAC address count I should set? A: 1 for a bare workstation. 2 for a PC-behind-phone (phone’s own MAC + PC’s MAC via the phone). 3-4 for a shared workstation or lab bench. If you’re setting it higher than 5-10, you probably want a different tool (802.1X). The whole point of port-security is “small number of expected MACs”: high limits defeat the purpose.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on Port Security. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where Port Security fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.