|
Posted by Jason on February 27, 2008, 6:10 pm
If you were Registered and logged in, you could reply and use other advanced thread options
> I have noticed something strange when I configure port-security on my
> "SWITCH1". When I configure a sticky mac address everything seems to
> work as it should, i.e. when I plug another device into the port I
> cannot get a connection, but when I do a show port-security for the
> interface it says "Port status : SecureUp" and no violation count
> increment. Also when I unplug a cable I still see "Port status :
> SecureUp" which is contrary to what I see on my other switch & I would
> expect. One thing I have noticed is that it seems I deleted the entire
> contents of the MAC address table at some point as I am seeing no CPU
> entries, whereas on my other identical switch (2950) I see the below
> listed in the MAC table (See both SWITCH1 & SWITCH2), could this be
> causing the problem & if so how do I get them back? Also out of
> curiosity what are they used for?
>
> I have tried to enter the values manually but IOS doesn't allow it, I
> have also wiped the switch & copied over a backed up startup-config &
> vlan.dat but the MAC entries are still missing. Maybe this is not the
> cause of the port-security problem so any suggestions on both problems
> would be appreciated.
>
> TIA, Jason
>
For anyone who is interested I have solved the mystery of the missing MAC
address table entries & strange switch behavior. It seems that the switches
were running different versions of IOS.
SWITCH1 was running version:
c2950-i6q4l2-mz.121-11.EA1.bin
with SWITCH2 running version
c2950-i6q4l2-mz.121-13.EA1.bin
Once I copied the IOS from SWITCH2 to SWITCH1 everything started working
correctly & the MAC address tables matched. I think the MAC address table
in SWITCH1 was always missing the CPU entries but I only noticed when
compared to SWITCH2, and I wrongly assumed that I had somehow deleted them
- it's all part of the learning curve I suppose.
Jason.
|