Guided buildcore6 steps~18 min5 devices
One jack, one PC: port security
Lock the reception wall jack to one PC with sticky port security, watch a visitor's laptop err-disable it, recover the port, then switch to restrict so the next intruder is dropped without taking reception offline.
What you'll be able to do: A wall jack that admits exactly one machine — learned automatically and kept in the configuration — where a second laptop is dropped and logged while the receptionist keeps working, and you know how to read and recover a port that did shut itself down.
Topics: Port security · Network security · Switching · MAC address table
What you'll build
- SW-Access — a switch, the office access switch that owns the wall jacks
- SRV-Files — a server, the file server everyone needs to reach
- SW-Desk — a switch, a small switch under the reception desk
- PC-Reception — a pc, the receptionist's PC, the one machine allowed on the jack
- PC-Visitor — a pc, a visitor's laptop that should not be there
Step by step
1. The access switch and the file server
Drag a switch and a server onto the canvas, cable the server's Eth0 to the switch's Fa0/2, and name both. Give the server 192.168.1.100/24. This office is one flat VLAN and one subnet, so nothing needs a gateway — which also means nothing but the switch port stands between a stranger's laptop and this server.
- Cable SRV-Files Eth0 ↔ SW-Access Fa0/2
On SW-Access — Name the access switch
enable configure terminal hostname SW-Access endOn SRV-Files — Name the file server and address it
hostname SRV-Files ipconfig Eth0 192.168.1.100 255.255.255.0Check: run
show interfaces statuson SW-Access and look forFa0/2 connected 1 auto 100 fastethernet.Why: On a flat LAN every port reaches every other port, so whoever can plug in can reach the server. Port security moves the first line of defence to the switch port itself: it decides which machines may use a jack at all.
2. Lock the reception jack before anything is plugged in
Fa0/1 is the reception wall jack. Make it a static access port, then turn on port security: at most one MAC address, shut the port down on a violation, and learn the address sticky — the first machine that speaks becomes the one allowed. Nothing is plugged in yet, so the port reads Secure-down: armed and waiting.
On SW-Access — Lock Fa0/1 to a single, sticky-learned MAC address
enable configure terminal interface Fa0/1 description RECEPTION-DESK switchport mode access switchport port-security switchport port-security maximum 1 switchport port-security violation shutdown switchport port-security mac-address sticky endCheck: run
show port-security interface Fa0/1on SW-Access and look forPort Status : Secure-down.Why: Port security checks the source MAC of every frame that enters the port against a list of secure addresses. Sticky learning fills that list from the first frames it sees and writes each address into the running-config, so the lock is learned, not typed — and it is set before the first machine arrives, so there is no window in which the wrong one could claim it.
3. Plug in the reception desk
Put the small desk switch under reception: its Gi0/1 into the wall jack, Fa0/1, and the reception PC into the desk switch's Fa0/1. Name both, give the PC 192.168.1.10/24, and ping the server. That first exchange carries the PC's MAC address into Fa0/1, and the jack learns it: `show port-security interface Fa0/1` now counts one sticky address.
- Cable SW-Desk Gi0/1 ↔ SW-Access Fa0/1
- Cable PC-Reception Eth0 ↔ SW-Desk Fa0/1
On SW-Desk — Name the desk switch so its console is easy to tell apart
enable configure terminal hostname SW-Desk endOn PC-Reception — Name and address the reception PC, then reach the server
hostname PC-Reception ipconfig Eth0 192.168.1.10 255.255.255.0 ping 192.168.1.100Check: run
show port-security interface Fa0/1on SW-Access and look forSticky MAC Addresses : 1.Why: The jack had room for one address and sticky was on, so the first source MAC to arrive became the secure address. From now on Fa0/1 judges every frame by its source MAC against that one address — so what counts is not the desk switch but every machine plugged in behind it.
4. A visitor plugs a laptop into the desk switch
Cable a second PC into the desk switch's Fa0/2, name it PC-Visitor, give it 192.168.1.50/24 and ping the server. The laptop's first frame reaches Fa0/1 with a second source MAC, and the jack already holds its one secure address: a violation. The mode you chose, shutdown, err-disables the whole port — and the receptionist goes offline together with the visitor.
- Cable PC-Visitor Eth0 ↔ SW-Desk Fa0/2
On PC-Visitor — Name and address the visitor's laptop, then try the server
hostname PC-Visitor ipconfig Eth0 192.168.1.50 255.255.255.0 ping 192.168.1.100Check: run
show interfaces statuson SW-Access and look forFa0/1 RECEPTION-DESK err-disabled 1 auto 100 fastethernet.Why: Shutdown is the default violation mode because it is the loudest: the port stops forwarding in both directions, the switch logs %PORT_SECURITY-2-PSECURE_VIOLATION, and the violation counter goes up. The price is availability — every machine behind the jack is cut off, not just the intruder.
5. Bring the port back
An err-disabled port stays down until someone brings it back by hand: `shutdown`, then `no shutdown`, on Fa0/1. The sticky address survives the bounce, so the reception PC is still the one machine allowed, and it reaches the server again. The visitor is still plugged in, though — in shutdown mode, its next frame would take the port straight back down.
On SW-Access — Bounce Fa0/1 to clear the err-disabled state
enable configure terminal interface Fa0/1 shutdown no shutdown endOn PC-Reception — Confirm reception is back
ping 192.168.1.100Check: run
show port-security interface Fa0/1on SW-Access and look forPort Status : Secure-up.Why: Bouncing the port clears the err-disabled state and forgets any dynamically learned addresses, but sticky addresses are configuration, so they stay. Recovery is quick — which is exactly why it is useless until the cause is gone: the rule that tripped the port is unchanged.
6. Keep reception online: violation restrict
Change the violation mode on Fa0/1 to restrict, then let the visitor try the server again. This time the laptop's frames are dropped, counted and logged, and the port never goes down — `show interfaces status` still reads connected, and the receptionist keeps working. The visitor can still reach the receptionist, though: that traffic stays inside the desk switch and never crosses Fa0/1. Port security guards the jack, not what hangs off it.
On SW-Access — Drop and log violators instead of shutting the port
enable configure terminal interface Fa0/1 switchport port-security violation restrict endOn PC-Visitor — The visitor tries the server again
ping 192.168.1.100Check: run
show interfaces statuson SW-Access and look forFa0/1 RECEPTION-DESK connected 1 auto 100 fastethernet.Why: Restrict drops frames from any address beyond the secure one, counts them and logs a violation, but leaves the port forwarding for the address it trusts. Shutdown is the stricter default; restrict trades a little of its alarm for availability on a jack where a real person works.
The theory behind it
More in Security & resilience
- Guard the server with an ACL — Let one workstation reach the server, stop the guest laptop, and learn what the implicit deny does to everyone else.
- A DMZ behind a firewall — Stand a firewall between three zones so the public reaches one server and nothing else.
- Two routers, one gateway — Give a LAN a gateway that survives a router failure: two routers share one virtual address with VRRP, and the hosts never notice the handover.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab