Configuring and Monitoring Port Security
Port Security Command Options and Operation
Retention of Static Addresses
Learned Addresses. In the following two cases, a port in Static learn mode
retains a learned MAC address even if you later reboot the switch or disable
port security for that port:
â– The port learns a MAC address after you configure the port for Static learn
mode in both the startup-config file and the running-config file (by exe-
cuting the write memory command).
â– The port learns a MAC address after you configure the port for Static learn
mode in only the running-config file and, after the address is learned, you
execute write memory to configure the startup-config file to match the
running-config file.
To remove an address learned using either of the preceding methods, do one
of the following:
â– Delete the address by using no port-security < port-number > mac-address <
mac-addr >.
â– Download a configuration file that does not include the unwanted MAC
address assignment.
â– Reset the switch to its factory-default configuration.
Assigned/Authorized Addresses. : If you manually assign a MAC address
(using port-security <port-number> address-list <mac-addr>) and then execute
write memory, the assigned MAC address remains in memory until you do one
of the following:
â– Delete it by using no port-security < port-number > mac-address < mac-addr >.
â– Download a configuration file that does not include the unwanted MAC
address assignment.
â– Reset the switch to its factory-default configuration.
9-13