Quick Question Regarding Port Security

The OCD ICND1 book does not seem to clarify this, but when you are configuring port security and you do not define the MAC addresses of the nodes that are allowed to send frames into a given interface, does the switch default to using the dynamically learned MAC address as the allowed MAC address, which is learned when a frame is received by the switch on that given interface? I assume that it does, but I want to make sure that what I am assuming is correct.

There are three types of secure addresses that port security uses:

  • Static - This are addresses that you specifically configure using switchport port-security mac-address xxxx.xxxx.xxxx.

  • Dynamic - This are addresses that the switch learns though the usual process of MAC address learning. These will eventually age out, allowing different MACs to be learned/permitted.

  • Sticky - These are a compromise between static and dynamic. Sticky addresses are learned dynamically, and then added as (functionally) static addresses in the running-config. This means you can learn the address dynamically but not have it time out with MAC table aging. Sticky learning is configured with the switchport port-security mac-address sticky command.

Perfect explanation. Thanks!

