Configuring Port Security
Port Type Changes
When you have configured port security on a Layer 2 interface and you change the port type of the interface,
the device behaves as follows:
Access Port to Trunk Port
Switched Port to Routed Port
Routed Port to Switched Port
Licensing Requirements for Port Security
The following table shows the licensing requirements for this feature:
Product
Cisco
NX-OS
Prerequisites for Port Security
Port security has the following prerequisites:
• You must globally enable port security for the device that you want to protect with port security.
Default Settings for Port Security
This table lists the default settings for port security parameters.
Parameters
Port security enablement globally
Port security enablement per interface
MAC address learning method
Interface maximum number of secure MAC addresses
When you change a Layer 2 interface from an access port to a trunk port, the device drops all secure
addresses learned by the dynamic method. The device moves the addresses learned by the static method
to the native trunk VLAN.
When you change an interface from a Layer 2 interface to a Layer 3 interface, the device disables port
security on the interface and discards all port security configuration for the interface. The device also
discards all secure MAC addresses for the interface, regardless of the method used to learn the address.
When you change an interface from a Layer 3 interface to a Layer 2 interface, the device has no port
security configuration for the interface.
License Requirement
Port security requires no license. Any feature not included in a license package is bundled
with the nx-os image and is provided at no extra charge to you. For an explanation of the Cisco
NX-OS licensing scheme, see the Cisco NX-OS Licensing Guide.
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
Default
Disabled
Disabled
Dynamic
1
Port Type Changes
309