Port-security MAC address restrictions and flexconnect

Hi - has anyone else seen this issue?
We use port-security on flexconnect ports limiting the maximum mac addresses to 100. The ports are configured so that the native vlan is the AP management vlan and we tag the wireless client vlan.
Recently we had an issue where we were seeing MAC address restriction violations on the ports connected to AP's. Although we could not see the violations happen in realtime they were in the switch logs. In Cisco Prime we checked the client counts on the AP's and they were less than 10 at that time the error occurred.
We then increased the max mac addresses to 200 and still saw the same issue. Removing port-security seemed to fix the problem.
This was the model and version of the switches.
WS-C2960X-24PS-L   15.0(2)EX4            C2960X-UNIVERSALK9-M
Has anyone else had this? 
Any help much appreciated.

Hi - has anyone else seen this issue?
We use port-security on flexconnect ports limiting the maximum mac addresses to 100. The ports are configured so that the native vlan is the AP management vlan and we tag the wireless client vlan.
Recently we had an issue where we were seeing MAC address restriction violations on the ports connected to AP's. Although we could not see the violations happen in realtime they were in the switch logs. In Cisco Prime we checked the client counts on the AP's and they were less than 10 at that time the error occurred.
We then increased the max mac addresses to 200 and still saw the same issue. Removing port-security seemed to fix the problem.
This was the model and version of the switches.
WS-C2960X-24PS-L   15.0(2)EX4            C2960X-UNIVERSALK9-M
Has anyone else had this? 
Any help much appreciated.

Similar Messages

  • Port Security Sticky Addresses

    Does anyone know if there is a way to automatically clear the mac address on a switchport that has port security sticky addressing enabled. I have the following configured on the port(s):
    switchport mode access
    switchport port-security
    switchport port-security aging time 1
    switchport port-security aging type inactivity
    switchport port-security mac-address sticky
    spanning-tree portfast
    I can't get it to release the sticky mac-address after the minute of inactivity. As soon as I try to connect another device to the port after the required inactivity, the port goes into an err-disabled state because it still sees the mac of the old device. Any help is appreciated. This is on a Catalyst 2950G switch.
    Josh

    It is not possible to age out sticky entries.  With sticky entries, they are added to the running config.  So the only way to remove it is through editing the running config....  If you enter the "no switchport port-security mac-address sticky" interface command, then the mac addresses will be learned dynamically, and will be aged out after 1 minute of inactivity, per your config ...

  • [switchport port-security mac ] on [interface VLAN n?]

    Hello,
    did anyone tried to use the command [switchport port-security mac-address n?] on [interface VLAN n?] ? (for example in a 2950).
    I don't have the material to make that test, and I am not sure if it works or not.
    Many thanks!

    Hi,
    Switchport port-security as the name implies is to be configured on switchport. VLAN interface on the switch is a routed interface and hence, you can't apply any switchport configuration on it and that includes, port security.
    HTH
    Sundar

  • Domain authentication with mac address restrictions

    I am in a branch office and I have one WLC 5508 and one ACS 4.2 with three WLANs:
    WLAN1 with SSID1: for company computers and laptops
    WLAN2 with SSID2: for ipads and tablets
    WLAN3 with SSID3:  for guests
    I am asked to configure WLAN2 as “WLAN2: Provides the Wi-Fi connectivity to ipads and tablets, with back end security using domain authentication with mac address restrictions.

    You would need to create a seperate policy and be able to have a seperation between the two policies... It's kind of hard to explain, but you would have for example:
    Policy 1:
    Wireless user on this SSID WLAN1
    AD on this AD Group (Machine)
    Policy 2:
    Wireless user on this SSID WLAN 2
    AD on this AD Group (USer)
    Thanks,
    Scott
    *****Help out other by using the rating system and marking answered questions as "Answered"*****

  • I have several groups on my Mac Address Book and would like to sync only one group to each IOS5 device (each device getting a different group).   Is this possible?

    I have several groups on my Mac Address Book and would like to sync only one group to each IOS5 device (each device getting a different group) via iCloud.   Is this possible?    If so, how is it done?
    Thanks in advance,,,,,

    Can we control syncing at all? I can't seem to make a Local/On My Mac group in Address Book.

  • How can i synchronize mac address book and calendar to icloud

    how can i synchronize mac address book and calendar to iclod?

    What version of OSX do you have.

  • Mac Address restriction

    Hi there,
    I have a express acting as a access point to my network for wireless devices, just wondering if anyone know if it is possible to restrict access via MAC address within the express station? This is a last attempt by me for some security as I can't get encryption to work with all devices. Any help will be good, thanks
    Thanks
    Connor

    You can, however in my opinion it only adds a superficial level of security which can be easily broken.
    Airport Admin Utility -> Configure > Access Control Tab.
    It use to be useful, but MAC address access control is really no longer a real option when it comes to wireless security.
    The problem arises as the MAC addresses are sent unencrypted and therefore can be picked up and read by a determined hacker.
    Not only that with many ethernet devices you can now very easily change the MAC address to a different one, so making it very easy to spoof the Mac address and fool a wireless base station into believing that you are an authenticated client.
    What security are you trying to configure?
    WEP or WPA?
    iFelix

  • MAC Address Filtering and SPI set up

    Hi,
    I just purchased a WRT54GS V 6 wireless router.  I updated the firmware to the latest (May 30) and the set up seems to be OK.  Using the security recommendations in the manual as a guide, I implemented them - the turn off SSID, and the others. 
    IF I try to filter the MAC addresses (accept only those on the list) for my wife's Sony VAIO VGN - S260 laptop, it can see the network but will not connect. When I turn off the MAC filtering, it is fine.  I used the WPA2 personal encryption, and input the passphrase into both router and computer. 
    My other issue is the firewall Statefull Packet Inspection (SPI).  On the Security set up screen, firewall tab - I have the four radio button settings that I am supposed to (Block WAN request, filter Multicast, Filter NAT, & Filter IDENT), however, I do NOT have the option to turn on the firewall (SPI) above the 4 radio buttons - that setting is totally missing from the set up screen.  Reference Page 28 of the manual.
    I would appreciate any help or suggestions, as I could not find any ideas searching the forum.  Thanks for your help

    you can try and change a few wireless settings ....in the routers wireless section....go to the advanced wireless settings.....here you can reduce the beacon interval to 50...also reduce the RTS and Fragmentation by 40 each.....

  • Linksys WAP300N Change MAC address, console and etc

    Linksys WAP300N is very very suxx.
    Not simultaneous work of 2,4 and 5 Ghz, very buggy firmware and not reasonable price.
    I have 3 psc of this...
    About topic:
    Linksys WAP300N #1 updated to v1.0.03 - 5 Ghz stops working normally. Clients disconnect on heavy load.
    I want roll back to v1.0.00 but on official site no 1.0.00 firmware.
    OK. I am dump flash ic from normal, working WAP300N #2 with v1.0.00 and
    flash this dump to broken WAP300N #1 - 1.0.03. All is ok - AP is working, but MAC address from #2.
    I want access to bootloader for change MAC. I connect RS232toTTL cable to AP board serial port, but seems no normal
    serial it has. FFFFF.
    What can I do? If who has v1.0.00 firmware - please upload somewhere.
    p.s. Advise - if you buy this - do not update to v1.0.03. If not buy - DONT BUY!

    I don't have v1.0.00 firmware but I'd rather you properly isolate this by checking if you have experienced this to your other wireless devices. Because if the same scenario happened to all of your wireless devices connected to 5GHz, then it's best to change the 5 GHz network wireless channel. Preferred channels are 36, 40, 44 and 48 which are recommended to less likely suffer interference.  Also, make sure to take note each of the device's MAC address if you're trying to setup wireless MAC filter and do it manually. I normally use this link when I'm setting up wireless MAC filtering.

  • Iphone Sync deleted all contacts on google, Mac Address Book and Itunes

    I have my phone synced to my google contacts. I did a sync trying to sync itunes, google and my address book and now everything has been deleted. I created a back up a month ago but when I do a restore from back up, it still does not give me my contacts, some how it is still syncing to google which is now blank. It's weird because the restore even gives me texts and photos I had on the back up date but it won't give me the contacts. I have tried changing the settings on the phone so it won't sync to google, I even changed my password on google hoping this would stop teh sync & allow the backup to show my contacts. I have tried using an iphoen extractor as well but since my phone is not jailbroken I am unable to use the file. I would appreciate any help you can give me.

    Sorry, should have given more info-I have an iphone 3G, MacBook Pro, operating system is MAC OS X.
    Iphone syncs to google contacts but last sync deleted all of them (google & address book). I do have a back up which I know has all the contacts but when I do the restore, it still is syncing to google so I still don't have any contacts. How do I get my contacts from the backup & prevent the iphone from over riding the back up & syncing to google?

  • How to get MAC address list and HDD serial number from Windows and MAC machine?

    Hi,
    I'm developing a AIR application. I'm implementing the product key mechanishm. I need to identify the users' machines uniquely. I chose MAC address would be a better way. But a computer has list of MAC addresses including LAN card and Wi-Fi card addresses. So, I need to get the list of available MAC addresses from the computer and the Hard Disk Drive's serial number. HDD serial number would be helpful to cross verify the identity.
    I'm able to get the MAC address using NetworkInfo class. But I need to get a list of available MAC addresses and HDD serial number.
    Is there any classess to accomplish this task?
    Thanks in advance.

    See if this link can be of a little use to you.
    http://www.adobe.com/devnet/air/flex/articles/retrieving_network_interfaces.html#ionComHea ding

  • Sync Treo 755p with Mac address book and ical

    I just bought a Treo 755p Verizon.  I loaded in the Palm software, but it does not sync with the mac address book.  I don't want to have to re-enter 600 contacts.  How can I get Palm and Mac address book to talk to each other?
    Post relates to: Treo 755p (Verizon)

    Well, I got some good news for you.  I just synced my Treo 755p with my Macbook Pro using both the palm sync and isync.  It synced both my iCal & Address book. It has to do with the conduit setting in the palm sync manager.  Here's what I did...try it and let me know.
    I downloaded the latest version of the Palm Desktop (although I do not use it)
    Then, at the top of the page of the Palm Desktop go to "HotSync" then to "Conduit Settings"
    Then highlight "iSync Conduit" by clicking on it and press the big square button at the top called "Conduit Settings"
    Then check the box :enable isync for this device"  Then click OK.
    This did it for me....It's syncing with my ical, addressbook, etc.
    Let me know if this helps!!!
    Thanks for yours!!
    Billy Bob 
    Post relates to: Treo 755p (Sprint)

  • Sync to Entourage and Not Mac Address book and ical HELP

    I just got a brand new MacBook Pro (no more PC)!!!! My I Sync my phone and it put all the data in ical and address book. I use Entourage and thats where i would like all my info to go. how do i set up itunes to go to entourage and not the apple sofware.
    And Can i sync via bluetooth?
    thanks you
    Brad "new Mac guy" Glaberson
    Message was edited by: bradley Glaberson

    The isync database, as I called it, is really just the master database from which ical, address book, bookmarks, etc., are stored, and it's used for syncing with the .mac service. Entourage can sync with it too, just go to the Entourage menu, choose Preferences, and look under General Preferences for Sync Services. Then check the boxes you want -- I just wanted the contacts to be the same in Entourage and Address Book so I only checked that one. The calendar is kind of funky because iCal uses separate calendars to group events, and I think if you check that box, iCal will then get a new calendar called Entourage, or something like that, in which all the Entourage events will go to and from. That is, I think Entourage will sync only with that iCal calendar, but I could be wrong about that since I don't use it.
    Once you check the contacts box, Entourage will populate with all the contacts in your Address Book, and I think if you don't already have contacts there (that is if you've only been using Entourage for your contacts) then it will ask you if you want to put all your Entourage contacts into Address Book. I just don't remember.
    Surely someone else out there is more familiar with this, but it should get you started.

  • Synchronising Entourage to Mac Address Book and iCal

    I've done my initial sync between Entourage 2008 (Version 12.3.5), iCal and Mac Address Books but now if I update anything in the Entourage Calendar or Address Book, it fails to then send the info to iCal and Mac Address Book. Therefore, the info isn't making it to my iPhone which is updated to the Phone iOS 6.0.1.
    Has anyone had the same problems and if so how did you fix it?
    I've done a lot of reading to try and find out what is wrong but I'm just getting more and more frustrated. I did read something about having the Daylight Saving Modes switched on or off but can't remember if it was on or off.
    I don't see why I should have to export/import ALL the info every single time. It used to work quite ok but just ins't anymore?? I think it somehow worked through iSync?
    Oh, and on top of that, if I put anything on my iPhone Address Book or Calendar, it's not synchronising to my Mac! Actually, I've just checked and addresses are synchronising to my Address Book but not then Synchronising to the Entourage Address Book.
    And I seem to be getting double ups of entries on my iPhone from my Calendar if I make a change, instead of updating the info in the actual event already created AND I get balnk "new events"! Rather annoying!!
    I don't use iCloud either. Apparently that would just make things even worse.
    HELP!!
    PS. It seems the only way to sync things is by remembering what I've added to either Address Boook or Calendars on either one of the devices/programs and update it manually on all the others via exporting a single vcf file ...

    The isync database, as I called it, is really just the master database from which ical, address book, bookmarks, etc., are stored, and it's used for syncing with the .mac service. Entourage can sync with it too, just go to the Entourage menu, choose Preferences, and look under General Preferences for Sync Services. Then check the boxes you want -- I just wanted the contacts to be the same in Entourage and Address Book so I only checked that one. The calendar is kind of funky because iCal uses separate calendars to group events, and I think if you check that box, iCal will then get a new calendar called Entourage, or something like that, in which all the Entourage events will go to and from. That is, I think Entourage will sync only with that iCal calendar, but I could be wrong about that since I don't use it.
    Once you check the contacts box, Entourage will populate with all the contacts in your Address Book, and I think if you don't already have contacts there (that is if you've only been using Entourage for your contacts) then it will ask you if you want to put all your Entourage contacts into Address Book. I just don't remember.
    Surely someone else out there is more familiar with this, but it should get you started.

  • HT5500 Facebook photos not integrating into Mac Address Book and iMessage

    Anyone have any idea why ALL my Facebook contacts photos aren't flowing into my address book on my Mac & iMessage (on Mac)? Most of them are, but not all of them. I have tried "updating contacts" under Facebook settings on my iPhone several times.

    Ill take a look at that website.  I have heard you can sync with Gmail or Yahoo.  The problem is Ive never stored contacts there.  There's a lot more spam in those histories than contacts Id want to keep.
    I wasnt asking about a particular phone but in general.  Im not really a techie and I currently have an older non-smartphone.
    Im assuming if I had an iphone, there would be an easy way to transfer or sync the address book.  If t here isnt, then Id be very surprised.
    I might have to go with an Android or other phone only because the monthly plans on the iphone are much more expensive.
    I was also wondering in general how it works with Verizon or Sprint since they dont have SIM cards.
    Ill look at that site you recommended; thanks

Maybe you are looking for