port security limitations on 3500s



We turned on port security on all of our switches and limited the
number of MAC addresses per port. Recently we noticed a problem that
occurs with our 3548s where if one port picks up a MAC address (and
subsequently stores in its table), that same MAC can't be moved
anywhere else. Our 3550s are not affected by this. This can be a pain
with users who have laptops and they move from cubicle to cubicle. I
tried turning on auto-aging on those switches but it doesn't appear to
work. The address is still retained on that port. I had to manually
shut down the port where the mac address was last attached to in order
for it to connect to another. I don't know if there is a limitation
with 3548s or if there is a workaround where we can keep port security
on yet the mac address tables should be dynamic (getting rid of
addresses it no longer detects OR allows it to traverse from port to
port).

.



Relevant Pages

  • Re: Static IP outside of router DHCP range
    ... Unfortunately my 8 clients are little $50 boxes with an Ethernet port and yellow, red, and white outputs for composite NTSC video and stereo audio, but no provisions whatsoever to flash their NVRAM. ... So I have no way to either reserve IP addresses based on Mac addresses, nor do I have a way to set them up as static. ... I still am wondering if my Netgear switches truly have any "memory" of the ports associated with specific IP addresses of the connected clients, as they have no reset or reboot function as far as I know. ...
    (alt.comp.hardware.pc-homebuilt)
  • Re: ROGUE APs at Work - How to locate them?!
    ... If you have the MAC address and you have ethernet switches that are smart ... MAC address, then you lookup that MAc address on the switches until you find ... the hardware port. ... network card in the PC could unplug the computer, ...
    (alt.internet.wireless)
  • Re: How to block a client from DHCP?
    ... server, and compliant operating systems. ... Another option is to use switches that can protect the network based on mac ... My HP2512 switch also can do port isolation ...
    (microsoft.public.windows.server.networking)
  • Re: Network scanning
    ... HP managed switches have this feature too, as a bonus you can also specify ... simultanious MACs on a port, or specify which addresses are allowed. ... Subject: Network scanning ... Most newer switches can lock down how many mac addresses are allowed to ...
    (Security-Basics)
  • Re: Seeing unexpected skinny heartbeats when sniffing IP phones network traffic
    ... :supposedly a normal occurance when the switches MAC table gets filled ... :its table, it sends it out all its ports; not as a broadcast packet, ... :but essentially a broadcast because it is sent out every port. ...
    (comp.dcom.sys.cisco)