AdvancedPublished 2026-06-30
CCNA Port-Sec 9: Multi-Port Sticky Restrict Policy
Bundle lab
Advanced CCNA switchport port-security rollout on multiple access ports across two Layer-2 switches with a trunk. You will standardize a consistent edge policy (sticky MAC learning, maximum 1, violation restrict) on all host-facing access ports while leaving the uplink trunk exempt from port-security. Includes a realistic drift on the trunk allow-list and VLAN database to fix before validating end-to-end user VLAN transport. Pure Layer-2: no SVIs or routing.
Learning objectives
- Deploy a consistent port-security policy (maximum 1, sticky MAC, violation restrict) on multiple host-facing access ports
- Deliberately exclude the trunk/uplink from port-security and explain why
- Verify secure MAC learning and per-interface state with show port-security and show port-security interface
- Align VLAN databases and trunk allow-lists to ensure same-VLAN hosts can communicate across switches
- Differentiate violation restrict behavior from protect/shutdown using counters without errdisabling the port
- Apply edge-hardening extras (portfast, bpduguard) safely on access ports only
Troubleshooting focus
- Identify and fix a missing VLAN from a trunk allow-list that breaks same-VLAN reachability across switches
- Resolve host ports assigned to the wrong VLAN causing silent isolation
- Validate native VLAN alignment to avoid control-plane warnings and L2 anomalies
- Use show port-security, address tables, and violation counters to confirm policy operation
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.