Explains how port security protects the ACI fabric from unknown MAC address flooding and provides guidance for limiting MAC address learning, configuring protect mode, and verifying deployment.
This chapter contains the following sections:
Port security in Cisco ACI
Describes how port security limits MAC address learning on physical ports, port channels, and virtual port channels to protect the Cisco ACI fabric.
Port security guidelines and limitations
Lists the interface support, MAC address behavior, enforcement scope, and platform limitations that apply when you configure port security in Cisco ACI.
Port-level port security
Describes the Cisco APIC port security settings that control MAC address limits, violation handling, and MAC learning recovery on individual switch ports.
Port security learning behavior
Describes how a port security policy controls endpoint learning, handles endpoints that exceed the MAC address limit, and reports security violations.
Port security protect mode
Describes how port security protect mode responds when a port reaches its MAC address limit by stopping additional learning and dropping violating traffic.
Verify port security installation using Visore
Verifies that the port security policy and its concrete interface object are installed on Cisco APIC and the leaf switch using Visore.
Verify port security installation using Visore
Verifies that the port security policy and its concrete interface object are installed on Cisco APIC and the leaf switch using Visore.