All guided builds

Guided buildcore6 steps~18 min5 devices

One jack, one PC: port security

Lock the reception wall jack to one PC with sticky port security, watch a visitor's laptop err-disable it, recover the port, then switch to restrict so the next intruder is dropped without taking reception offline.

What you'll be able to do: A wall jack that admits exactly one machine — learned automatically and kept in the configuration — where a second laptop is dropped and logged while the receptionist keeps working, and you know how to read and recover a port that did shut itself down.

Topics: Port security · Network security · Switching · MAC address table

What you'll build

Step by step

  1. 1. The access switch and the file server

    Drag a switch and a server onto the canvas, cable the server's Eth0 to the switch's Fa0/2, and name both. Give the server 192.168.1.100/24. This office is one flat VLAN and one subnet, so nothing needs a gateway — which also means nothing but the switch port stands between a stranger's laptop and this server.

    • Cable SRV-Files Eth0 ↔ SW-Access Fa0/2

    On SW-Access — Name the access switch

    enable
    configure terminal
    hostname SW-Access
    end

    On SRV-Files — Name the file server and address it

    hostname SRV-Files
    ipconfig Eth0 192.168.1.100 255.255.255.0

    Check: run show interfaces status on SW-Access and look for Fa0/2 connected 1 auto 100 fastethernet.

    Why: On a flat LAN every port reaches every other port, so whoever can plug in can reach the server. Port security moves the first line of defence to the switch port itself: it decides which machines may use a jack at all.

  2. 2. Lock the reception jack before anything is plugged in

    Fa0/1 is the reception wall jack. Make it a static access port, then turn on port security: at most one MAC address, shut the port down on a violation, and learn the address sticky — the first machine that speaks becomes the one allowed. Nothing is plugged in yet, so the port reads Secure-down: armed and waiting.

    On SW-Access — Lock Fa0/1 to a single, sticky-learned MAC address

    enable
    configure terminal
    interface Fa0/1
    description RECEPTION-DESK
    switchport mode access
    switchport port-security
    switchport port-security maximum 1
    switchport port-security violation shutdown
    switchport port-security mac-address sticky
    end

    Check: run show port-security interface Fa0/1 on SW-Access and look for Port Status : Secure-down.

    Why: Port security checks the source MAC of every frame that enters the port against a list of secure addresses. Sticky learning fills that list from the first frames it sees and writes each address into the running-config, so the lock is learned, not typed — and it is set before the first machine arrives, so there is no window in which the wrong one could claim it.

  3. 3. Plug in the reception desk

    Put the small desk switch under reception: its Gi0/1 into the wall jack, Fa0/1, and the reception PC into the desk switch's Fa0/1. Name both, give the PC 192.168.1.10/24, and ping the server. That first exchange carries the PC's MAC address into Fa0/1, and the jack learns it: `show port-security interface Fa0/1` now counts one sticky address.

    • Cable SW-Desk Gi0/1 ↔ SW-Access Fa0/1
    • Cable PC-Reception Eth0 ↔ SW-Desk Fa0/1

    On SW-Desk — Name the desk switch so its console is easy to tell apart

    enable
    configure terminal
    hostname SW-Desk
    end

    On PC-Reception — Name and address the reception PC, then reach the server

    hostname PC-Reception
    ipconfig Eth0 192.168.1.10 255.255.255.0
    ping 192.168.1.100

    Check: run show port-security interface Fa0/1 on SW-Access and look for Sticky MAC Addresses : 1.

    Why: The jack had room for one address and sticky was on, so the first source MAC to arrive became the secure address. From now on Fa0/1 judges every frame by its source MAC against that one address — so what counts is not the desk switch but every machine plugged in behind it.

  4. 4. A visitor plugs a laptop into the desk switch

    Cable a second PC into the desk switch's Fa0/2, name it PC-Visitor, give it 192.168.1.50/24 and ping the server. The laptop's first frame reaches Fa0/1 with a second source MAC, and the jack already holds its one secure address: a violation. The mode you chose, shutdown, err-disables the whole port — and the receptionist goes offline together with the visitor.

    • Cable PC-Visitor Eth0 ↔ SW-Desk Fa0/2

    On PC-Visitor — Name and address the visitor's laptop, then try the server

    hostname PC-Visitor
    ipconfig Eth0 192.168.1.50 255.255.255.0
    ping 192.168.1.100

    Check: run show interfaces status on SW-Access and look for Fa0/1 RECEPTION-DESK err-disabled 1 auto 100 fastethernet.

    Why: Shutdown is the default violation mode because it is the loudest: the port stops forwarding in both directions, the switch logs %PORT_SECURITY-2-PSECURE_VIOLATION, and the violation counter goes up. The price is availability — every machine behind the jack is cut off, not just the intruder.

  5. 5. Bring the port back

    An err-disabled port stays down until someone brings it back by hand: `shutdown`, then `no shutdown`, on Fa0/1. The sticky address survives the bounce, so the reception PC is still the one machine allowed, and it reaches the server again. The visitor is still plugged in, though — in shutdown mode, its next frame would take the port straight back down.

    On SW-Access — Bounce Fa0/1 to clear the err-disabled state

    enable
    configure terminal
    interface Fa0/1
    shutdown
    no shutdown
    end

    On PC-Reception — Confirm reception is back

    ping 192.168.1.100

    Check: run show port-security interface Fa0/1 on SW-Access and look for Port Status : Secure-up.

    Why: Bouncing the port clears the err-disabled state and forgets any dynamically learned addresses, but sticky addresses are configuration, so they stay. Recovery is quick — which is exactly why it is useless until the cause is gone: the rule that tripped the port is unchanged.

  6. 6. Keep reception online: violation restrict

    Change the violation mode on Fa0/1 to restrict, then let the visitor try the server again. This time the laptop's frames are dropped, counted and logged, and the port never goes down — `show interfaces status` still reads connected, and the receptionist keeps working. The visitor can still reach the receptionist, though: that traffic stays inside the desk switch and never crosses Fa0/1. Port security guards the jack, not what hangs off it.

    On SW-Access — Drop and log violators instead of shutting the port

    enable
    configure terminal
    interface Fa0/1
    switchport port-security violation restrict
    end

    On PC-Visitor — The visitor tries the server again

    ping 192.168.1.100

    Check: run show interfaces status on SW-Access and look for Fa0/1 RECEPTION-DESK connected 1 auto 100 fastethernet.

    Why: Restrict drops frames from any address beyond the secure one, counts them and logs a violation, but leaves the port forwarding for the address it trusts. Shutdown is the stricter default; restrict trades a little of its alarm for availability on a jack where a real person works.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
One jack, one PC: port security — step-by-step network lab · NetForge-AI