9.2 Port Security and MAC Address Limiting
Key Takeaways
CAM table flooding attacks exploit switch MAC learning mechanisms to exhaust memory, forcing switches into fail-open hub mode where unicast traffic is flooded across all ports.
MAC address limiting restricts the maximum number of simultaneous Layer 2 MAC addresses permitted on an access interface, preventing unauthorized switches, hubs, or rogue APs.
AOS-CX port security learns MACs dynamically by default up to the client limit (default 1), accepts static MACs with
mac-address, and makes learned MACs sticky withsticky-learn enable; sticky clients survive reboots and link flaps.port-access security violation action {notify | shutdown}sets the violation response: notify (default) blocks the intruder and logs an event and SNMP trap, while shutdown disables the port and can auto-recover after a recovery timer.Port security provides basic Layer 2 device containment at the physical port level, serving as a first line of defense before advanced identity-based authentication mechanisms like 802.1X.
Port Security and MAC Address Limiting
Quick Summary: Ethernet switches make forwarding decisions using a Content Addressable Memory (CAM) table that dynamically learns source MAC addresses arriving on physical interfaces. Malicious actors exploit this mechanism through CAM table flooding attacks, overwhelming switch memory with randomized MAC addresses to force the switch into a broadcast "fail-open" mode. Port Security and MAC Address Limiting mitigates this threat by capping the number of permitted MAC addresses on an interface; unauthorized clients are always blocked, and the violation action (notify or shutdown) decides whether the switch only reports the violation or also disables the port.
The MAC Address Table and CAM Flooding Attacks
To forward unicast frames efficiently, an Ethernet switch maintains a hardware-accelerated forwarding database known as the MAC Address Table or Content Addressable Memory (CAM) table. When a frame enters a physical port, the switch ASIC reads the Source MAC address and records it alongside the ingress port and VLAN ID. Future frames destined for that MAC address are switched directly out that specific port rather than flooded across the VLAN.
The Mechanics of CAM Table Flooding
Hardware CAM tables possess finite memory capacity (typically 8,000 to 64,000 MAC addresses depending on switch platform specifications, such as the Aruba CX 6100 vs. CX 6300). Attackers take advantage of this physical limitation using automated flooding tools (such as macof):
+---------------------------------------------------------------------------------------------------------+
| CAM TABLE FLOODING ATTACK MECHANICS |
| |
| [ Attacker Workstation ] |
| | (Transmits 50,000 frames/sec with randomized Source MACs: 00:01:aa..., 00:02:bb...) |
| v |
| [ Access Switch CAM Table ] ---> [ Full: 32,768 / 32,768 MACs Exhausted! ] |
| | |
| v |
| [ Switch Enters Fail-Open State: Acts Like a Legacy Shared Hub ] |
| | |
| +-----> Floods ALL Unicast Frames to All Ports in VLAN! |
| +-----> Attacker passively sniffs confidential user sessions, credentials, and traffic! |
+---------------------------------------------------------------------------------------------------------+
- High-Velocity Frame Transmission: The attacker floods the physical switch port with tens of thousands of Ethernet frames per second, each featuring a randomized, bogus source MAC address.
- Table Saturation: The switch rapidly updates its CAM table, learning the bogus MACs until memory capacity is entirely exhausted. Legitimate dynamic host entries are aged out or overwritten.
- The "Fail-Open" Condition: Once the CAM table is full, the switch cannot learn new addresses. When a legitimate frame arrives destined for an address missing from the CAM table, the switch must treat it as an unknown unicast frame. Standard Layer 2 behavior requires flooding unknown unicast frames out every port within the broadcast domain.
- Passive Eavesdropping: By forcing the switch into this hub-like broadcasting state, the attacker connects a packet analyzer (such as Wireshark) and passively captures confidential traffic passing between other legitimate workstations, completely undermining Layer 2 privacy.
Port Security and MAC Address Limiting Principles
Port Security provides edge protection by restricting the number and identity of MAC addresses permitted to transmit traffic through a physical switch interface. It achieves three primary operational objectives:
- CAM Table Protection: Caps the maximum number of MAC addresses learned on any single port, ensuring that a single compromised endpoint cannot exhaust the entire switch forwarding table.
- Rogue Switch and AP Prevention: Prevents users from attaching unmanaged desktop switches, consumer Wi-Fi routers, or wireless extenders to cubicle wall jacks to connect unauthorized multiple devices.
- Physical Access Lockdown: Binds authorized device MAC addresses to specific physical ports, preventing unauthorized hardware from communicating if plugged into an enterprise network jack.
MAC Address Learning Modes: Dynamic, Static, and Sticky
Aruba AOS-CX port security supports three methods for defining and retaining authorized MAC addresses:
| Learning Mode | Operational Behavior | Retention Across Reboots | Administrative Overhead |
|---|---|---|---|
| Dynamic Learning | The default. MAC addresses are learned dynamically from incoming frames up to the configured client-limit. | Relearned after a reboot or link flap. | Minimal; fully automated. |
| Static Binding | The administrator configures exact authorized MAC addresses (mac-address <mac> in the port-security context). You can also configure some MACs and let the port learn the rest. | Stored in the configuration file; survives reboots. | High; requires manual tracking of every network card replacement. |
| Sticky Learning | sticky-learn enable makes all existing and newly learned non-static MACs sticky (sticky-dynamic); sticky MACs can also be configured (sticky-static). | Sticky clients are not affected by a reboot or link flap once learned (AOS-CX 10.14 Security Guide). | Low; captures authorized devices on initial connection without manual typing. |
Sticky MAC Learning Mechanics
Sticky MAC learning delivers the convenience of dynamic learning combined with the security of static bindings. When an administrator enables sticky learning on an access port, the MACs learned on that port become sticky. If the switch reboots or the cable is disconnected, the port continues to permit only those MAC addresses, preventing an unauthorized user from disconnecting the corporate PC and attaching a rogue laptop. Moving a sticky client to a different port is itself a violation (show port-access security violation sticky-mac-client-move interface).
Violation Modes and Administrative Actions
A port security violation occurs when a frame arrives on a secured interface from a source MAC address that is not authorized and the port has already reached its client limit. On AOS-CX, port security always blocks the intruding device from sending traffic through the port; the configured action decides what else happens (AOS-CX 10.14 CLI and Security Guides):
+---------------------------------------------------------------------------------------------------------+
| PORT SECURITY VIOLATION ACTIONS |
| |
| [ Action: NOTIFY (default) ] ---> Intruder blocked; authorized clients keep working. |
| Event log entry + SNMP trap ("Client limit exceeded on port ..."). |
| |
| [ Action: SHUTDOWN ] -----------> Port is shut down; all clients on it lose service. |
| Optional auto-recovery after a recovery timer. |
+---------------------------------------------------------------------------------------------------------+
Detailed Analysis of Violation Actions
-
notify(default):- Action: The unauthorized client is blocked, and the switch writes an event-log entry (for example, "Client limit exceeded on port 1/1/8, caused by an unauthenticated client ...") and sends an SNMP trap.
- Impact: Authorized MAC addresses on the port continue to forward normally.
- Use Case: Standard enterprise offices where the security team wants visibility without disrupting legitimate users.
-
shutdown:- Action: The switch shuts down the port where the client limit was exceeded.
- Impact: All traffic stops on the port, including traffic from previously authorized endpoints and IP phones.
- Recovery: Manual
shutdown/no shutdown, or automatic recovery withport-access security violation action shutdown auto-recovery enableandport-access security violation action shutdown recovery-timer <seconds>(auto-recovery is disabled by default). - Use Case: High-security environments where any unauthorized connection indicates tampering.
Note: Other platforms offer a silent "protect" or "drop" mode. On AOS-CX the choice is only notify or shutdown; blocking the intruder happens in both.
AOS-CX Configuration Commands and Verification
The following configuration session enables port security globally and on a port, sets a client limit of 2 (an IP phone and a PC), enables sticky learning, and chooses the shutdown action with auto-recovery:
switch# configure terminal
! Step 1: Globally enable port security
switch(config)# port-access port-security enable
! Step 2: Configure Port Security on an Access Interface
switch(config)# interface 1/1/10
switch(config-if)# description Desk-10-PC-and-Phone
switch(config-if)# no routing
switch(config-if)# vlan access 10
switch(config-if)# port-access port-security enable
switch(config-if)# port-access port-security
switch(config-if-port-security)# client-limit 2
switch(config-if-port-security)# sticky-learn enable
switch(config-if-port-security)# exit
switch(config-if)# port-access security violation action shutdown
switch(config-if)# port-access security violation action shutdown auto-recovery enable
switch(config-if)# exit
! Step 3: Manual Recovery for a Shut-Down Port
switch(config)# interface 1/1/10
switch(config-if)# shutdown
switch(config-if)# no shutdown
switch(config-if)# exit
Essential Verification Commands
| Command | Output and Diagnostic Purpose |
|---|---|
show port-access port-security interface 1/1/10 client-status | Shows the authorized clients on the port and whether each is static, dynamic, sticky-static, or sticky-dynamic. |
show port-access port-security interface 1/1/10 port-statistics | Shows client counts and limits for the port. |
show port-access port-security violation client-limit-exceeded interface 1/1/10 | Displays client-limit violations and the offending MAC addresses. |
show mac-address-table interface 1/1/10 | Displays active hardware forwarding entries associated with interface 1/1/10. |
Port Security vs. Enterprise Network Access Control (802.1X)
It is vital for enterprise network engineers to understand the architectural boundary between basic port security and enterprise Network Access Control (NAC):
- Port Security Limitations: Port security operates strictly on unauthenticated Layer 2 MAC addresses. Because MAC addresses can be easily sniffed and spoofed by an attacker using free software utilities, port security does not provide cryptographic identity verification.
- Enterprise NAC (802.1X / ClearPass): Enterprise environments deploy IEEE 802.1X port-based authentication backed by Aruba ClearPass Policy Manager. 802.1X enforces cryptographic user credentials or digital certificates, role-based access control, dynamic VLAN assignment, and posture assessment, providing comprehensive Zero Trust access control.
Common Exam Traps
- Global Enablement Prerequisite: Port security must be enabled globally (
port-access port-security enablein config context) as well as on the port. Omitting the global command is a frequent troubleshooting trap. - Sticky Means Persistent: On AOS-CX, sticky-learned clients are not affected by a switch reboot or link flap. Disabling sticky learning turns them back into dynamic clients.
- Shutdown vs. Notify: The exam frequently tests which violation action keeps authorized devices working.
shutdowndisables the entire port (cutting off all users), whereasnotify(the default) blocks only the intruder and reports the violation.
What primary security objective does an attacker achieve when successfully executing a CAM table flooding attack against an unprotected campus access switch?
The switch Layer 3 routing engine is hijacked to advertise fraudulent BGP autonomous systems to the Internet
The switch automatically shuts down all PoE power supplies due to excessive ASIC thermal dissipation
The switch MAC address table is exhausted, forcing the switch to flood unknown unicast frames out all ports like a hub
The switch firmware is permanently erased, forcing the hardware to reboot into recovery ROM monitor mode
An administrator wants edge ports on an Aruba CX 6200 switch to authorize the first connected device automatically and keep that MAC address authorized across reboots and link flaps, without typing MAC addresses. Which feature achieves this?
A MAC address-table age-time of 60 seconds on the access VLANs
MAC authentication with a reject role for unknown devices
Dynamic ARP Inspection with an ARP inspection trust setting on the port
Sticky learning (sticky-learn enable in the port-security context)
Interface 1/1/8 on an AOS-CX switch has port security enabled with sticky learning, a client limit of 1, and the default violation action. The authorized PC's MAC address was learned as a sticky entry. A user unplugs the PC and connects an unmanaged switch with two unauthorized laptops. What happens?
The laptops' traffic is blocked, the port stays up, and the switch logs the violation
The port is shut down, blocking all three devices until an administrator re-enables it
The switch redirects both laptops to a captive portal page so they can register their MACs
Both laptops are allowed because the port automatically raises its client limit to match
Sections you finish are checked off in the contents.