Port-security with a two-MAC limit is on the lobby socket — how does a visitor still get on, and what does the violation mode cost?
answer
- it counts addresses, it does not check them
- a MAC is asserted by the sender
- first device to speak gets pinned
- shutdown mode is someone else's outage
- silent drop means no record at all
basics
~20 sA MAC address is a claim the endpoint makes, not an identity: the visitor clones the room phone's address and stays inside the limit. Shutdown mode then lets anyone take the port offline; silent-drop modes leave no record.
solid answer
~50 sPort-security counts learned source addresses on a port; it never verifies them. A visitor unplugs the room's phone or reads the address off the label on the video box, sets their own interface to it, and the port stays inside its limit. Sticky learning does not help if the port flaps or the switch reloads before the entries are saved — whichever device speaks first becomes the trusted one, and in a public room that could be the laptop. Then the violation mode is a choice about who absorbs the failure. Shutdown disables the port until an operator or a recovery timer restores it, so a nuisance device takes the room's phone down with it. Protect drops offending frames silently and leaves no trace, so you never learn it happened. Restrict drops and records, which is the useful posture but generates noise wherever people daisy-chain their own kit.
go deeper
Know what a per-port MAC limit does at face value: it caps how many devices a port will learn, and it reacts when the cap is exceeded. Know that the address itself comes from the device.
Explain the three violation behaviours — silent drop, drop with a record, and disabling the port — and be able to say why cloning a discoverable address defeats the limit entirely.
Demonstrate the operational judgment: who re-enables a disabled port, what an auto-recovery timer really buys, and why the desk-side switch quietly widens every limit you set.
Be ready to say where this control belongs in a defence at all — a record and a speed bump on stable ports — and to refuse it as the answer for public sockets without pretending the stronger option is free.
## What port-security actually is Port-security is a local switchport feature. It caps how many source MAC addresses a port may learn, optionally pins them ("sticky" learning writes the learned addresses into the running configuration), and defines what the port does when the cap is exceeded. Everything it knows about a device is the source address in the frames it sends. That is the whole corrective, and it is the wrong answer a competent engineer gives: they treat a MAC limit as admission control for the lobby socket. It is not. It is a **counter with a consequence**. A MAC address is a value the endpoint's own software sets and can change in seconds; it is a claim, never an identity, and nothing in the frame proves the sender is the device that was originally there. ## How the visitor passes it The attack does not need tooling: 1. The room contains a device whose address is discoverable — an IP phone with the address printed on a label under it, a video codec that shows it on screen, a printer that prints its own configuration page. 2. The visitor unplugs that device (or plugs into the second socket, or into the phone's pass-through port) and sets their interface to the same address. 3. The switch sees a familiar address within the limit and forwards. Sticky learning narrows the window but does not close it. Sticky entries live in the running configuration; if they were never written to the saved configuration, a switch reload or a long port-down leaves the port ready to learn again — and the first device to send a frame becomes the pinned one. In a public room, first-to-speak is not a safe way to choose whom to trust. ## The violation modes are a choice about who pays | Mode | Behaviour | Who absorbs it | | --- | --- | --- | | protect | Offending frames dropped, no counter, no notification | You do — silently. The event is invisible, so it is never investigated | | restrict | Offending frames dropped, counters incremented, notification raised | The team that reads the notifications — real signal, plus noise from daisy-chained kit | | shutdown | Port disabled until an operator or an auto-recovery timer restores it | The room does. The phone, the video system and the desk on that port go down | Shutdown is the mode people pick because it sounds strongest, and it is the one that converts a nuisance into an outage anyone standing in the room can trigger. Worse, it needs an owner: someone has to re-enable the port, at whatever hour it happened, or an automatic recovery timer has to do it, which quietly turns the control back into a speed bump. Protect is the mode people pick to avoid outages, and it is the one that guarantees you never find out. Restrict is usually the right default because it preserves the record, but only if someone actually receives what it raises. ## The desk-side switch problem A MAC limit assumes one socket equals one device. Users defeat that with a five-port unmanaged switch under a desk, or an IP phone with a PC pass-through, or a docking station chained to a second dock. Each of these puts several addresses behind one switchport, so the limit has to be raised to two, three or five — and at that point the control is no longer distinguishing a legitimate fan-out from a visitor plugged in alongside it. The physical estate quietly outgrew the model the control depends on. ## Where it still earns its place None of this makes port-security worthless. On a stable single-device port it raises the effort required, it produces a record when something changes, and it constrains the crude case of an extra device appearing. What it must not be sold as is admission control for a public room: it authenticates nothing, and its strongest mode gives the person in the room a switch to turn the room's own services off. If you need a socket in a public place to admit only devices you trust, the decision has to be made by something that checks a credential, not by something that counts addresses. ## What an interviewer is listening for The direction of the claim — a MAC address is asserted, not verified — and an honest account of the violation-mode trade-off framed as who absorbs the cost. Naming the sticky-learning reload case and the desk-switch fan-out separates a candidate who has configured this from one who has read about it.
- A user puts a five-port unmanaged switch under their desk. What does that do to your MAC limit?It forces the limit up to cover the fan-out, and once the limit covers several devices the control can no longer tell a legitimate dock chain from an extra laptop plugged in alongside it. It also breaks the assumption the port record depends on: one switchport is no longer one wall socket, so the physical map and the port count disagree by however many of these exist.
- If shutdown mode is too disruptive, is an auto-recovery timer a good compromise?It is a compromise that should be chosen deliberately, not by default. A recovery timer bounds the outage but also means the port restores itself without anyone investigating, so the control degrades to a delay. If you use one, the violation still has to raise something a person receives, otherwise you have kept the disruption and thrown away the signal.
- Does sticky learning make port-security safe to enable on an unattended public socket?No. Sticky pins whatever the port learns, and it learns whenever it has room — after a reload with unsaved entries, or after the pinned device is removed and the entries age. On a socket in a room strangers sit in, the device that speaks first is not reliably yours. Sticky is a hardening step on a stable desk port, not an admission decision for a public one.
saying these in an interview costs you the question
- Treats a MAC address as an identity the switch verifies
- Says sticky MAC means the switch confirmed the device
- Picks shutdown mode without asking who re-enables the port
- Calls protect mode the safe choice while it leaves no record
- Assumes one switchport always means one connected device