CCNA Capstone: Port Security Troubleshooting
Bundle lab
Advanced CCNA port-security troubleshooting on a pure Layer-2 design. Two access switches linked by an 802.1Q trunk carry a Users VLAN across closets. Three Alpine Linux hosts are pre-addressed. The lab is intentionally shipped with multiple classic faults: one access port is err-disabled due to a prior port-security shutdown, one user-facing port lacks port-security altogether, another has the wrong violation mode and an overly restrictive maximum, and one port has an incorrect static secure-MAC configured. Your job is to diagnose using show commands, restore connectivity, and implement the intended security posture with sticky MACs, the correct maximum, the proper violation mode, and errdisable auto-recovery—without placing port-security on the trunk.
Learning objectives
- Diagnose port-security states and violations with show port-security and show port-security interface
- Recover an err-disabled port caused by a psecure violation and enable errdisable auto-recovery
- Correct violation mode drift (protect vs restrict vs shutdown) to the stated policy
- Adjust a too-low maximum secure MAC count to meet port intent
- Enable sticky MAC learning on host-facing access ports and avoid applying port-security to trunks
- Remove an incorrect static secure-MAC binding and convert to a supported policy
Troubleshooting focus
- Identify which interface is err-disabled and why
- Differentiate between violation protect, restrict, and shutdown behavior
- Spot ports that lack port-security entirely
- Locate a too-low maximum secure MAC policy
- Find and remove a wrong static secure-MAC binding
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.