switchport port-security mac-address {<H.H.H>|sticky}
Pin an allowed MAC by hand, or let the port remember the MACs it learns ('sticky') so they survive in running-config.
Example
SW1(config-if)# switchport port-security mac-address 0200.1a2b.3c4dPin the WRONG address and the attached host is locked out on its very first frame — its ping fails with 'ARP failed' and the port err-disables under the default violation mode.
Don't just read it — type switchport port-security mac-address {<H.H.H>|sticky} in a real network simulator in your browser and watch it take effect. No install, no account needed to start.
Frequently asked
What does the "switchport port-security mac-address {<H.H.H>|sticky}" command do?
Pin an allowed MAC by hand, or let the port remember the MACs it learns ('sticky') so they survive in running-config.
What's the common gotcha with "switchport port-security mac-address {<H.H.H>|sticky}"?
Pin the WRONG address and the attached host is locked out on its very first frame — its ping fails with 'ARP failed' and the port err-disables under the default violation mode.
Example of "switchport port-security mac-address {<H.H.H>|sticky}"
SW1(config-if)# switchport port-security mac-address 0200.1a2b.3c4d