On 23/11/2010 19:21, Peter Rathlev wrote:
The best thing would be if one could just limit the number of allowed
MAC addresses on a port, forcing the port err-disabled if the limit is
crossed. Whenever I look at port-security it seems to address a lot of
other "problems", and that tends to complicate implementation. :-|

Limiting MAC addresses was what I was referring to, when I mentioned port-security:

 switchport port-security maximum 1
 switchport port-security aging time 5
 switchport port-security violation shutdown

Nick
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to