Errdisable Recovery for L2 Security
Bundle lab
Layer 2 Security Hardening, Lab 9/10. You will enable automatic errdisable recovery on a campus access switch so ports shut down by Layer-2 security (Dynamic ARP Inspection, DHCP rate-limit, or storm control) can return to service automatically after a safe interval. The switch already enforces DHCP snooping with a correct trust boundary, DAI validation, and broadcast/multicast/unicast storm-control with shutdown actions. Your job: turn on errdisable auto-recovery for arp-inspection, dhcp-rate-limit, and storm-control, and set the interval to 60 seconds. Verify with show errdisable recovery.
Learning objectives
- Explain why ports enter errdisabled state for Layer-2 security violations (DAI, DHCP rate-limit, storm-control).
- Configure errdisable auto-recovery for specific security causes on a Cisco access switch.
- Set and verify the global recovery interval so transient faults self-heal without manual intervention.
- Confirm trust-boundary placement for DHCP snooping and DAI (uplink trusted, access untrusted).
- Use show errdisable recovery to validate timers and enabled causes.
Troubleshooting focus
- If show errdisable recovery does not list your causes, ensure each cause is explicitly enabled globally.
- If ports remain down indefinitely, confirm the recovery interval is nonzero and that the cause is enabled for recovery.
- If DHCP or ARP stops working, verify the uplink is trusted for DHCP snooping and DAI; access ports must remain untrusted.
- If errdisable events keep recurring, inspect rate limits and storm-control thresholds — overly aggressive limits can cause flaps.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.