To restrict single port by connecting multiport switch.

  • This is possible when one 1 mac address switch port, anyone who tries to attach multiple port switch or hub to connect to particular port and create another extended star network.

  • To restrict it do as shown here.


Switch(config)# show ip interface brief

Switch(config)# terminal monitor

Switch(config)# show mac address-table

Switch(config)# interface fastEthernet 0/5 or interface f3 0/5

Switch(config-if )# switchport mode access

Switch(config)# switchport port-security maximum 1


Switchport port security

  • What happens if someone connect multiport switch/hub It gives 3 option (Protect / Restrict / Shutdown )


Switch(config)# switchport port-security violation ?


Switchport port security protect

  • Protect : mode will only ignore it, only first mac address will work and rest will be Ignored when someone attach multiple port switch.


Switch(config)# switchport port-security violation Protect


Switchport port security restrict

  • Restrict will display message when someone tries to connect switch with multiple port. It will ignore remaining mac address and log message.

Switch(config)# switchport port-security violation Restrict


Switchport port security shutdown

  • Shutdown : when somebody try to attach multiple port hub on this port, then This port will shutdown. To again activate it you need to apply No shutdown on this interface.

Switch(config)# switchport port-security violation shutdown


Restrict port to use only specific mac address

  • This command will register mac address given to port no 0/5.

  • Anyone Other than this mac address will not be able to use switch.

  • However this will take very good time if you try to restrict each Interface by manually entering mac address of each desktop/laptop To check effect of above command


Switch(config)# switchport port-security mac-address 0015.cba1.eefa

Automatically assigning MAC address to switch

  • In above case you need to put lots of manual effort in entering Mac addresses of each desktop, laptop, switches. While sticky command can be applied when everything in organization is connected.

  • It will Automatically hardcode the mac address in running configuration.


Switch(config)# switchport port-security mac-address sticky

Switch(config)# ^z

Switch# show running-config

Switch# show port-security interface fastEthernet 0/5

Switch# show port-security


Automatically assigning MAC address to all Ports of Switch

  • It is time consuming and very difficult to set mac address for each ports.

  • So you can set range of ports for which you want to stick MAC address to switch.

  • Do as follows.


Switch# config terminal

Switch(config)# interface range fastEthernet 0/2 - 24

Switch(config)# switchport mode access

Switch(config)# switchport port-security mac-address sticky

Switch(config)# ^z

