IntermediatePublished 2026-06-30
Port Security: Err-Disable Auto Recovery
Bundle lab
Configure port security in shutdown mode on host-facing access ports and enable automatic errdisable recovery for psecure-violation. The lab uses two Layer-2 switches connected by a trunk and three Linux hosts in the same VLAN to validate baseline L2 connectivity. You will deploy and verify the global errdisable recovery timer and cause while keeping the trunk healthy. Focus is on deterministic configuration and verification via show commands rather than attempting to trigger live violations.
Learning objectives
- Enforce port security on host-facing access ports, using the strictest response so a violation shuts the port down
- Enable automatic errdisable recovery for psecure-violation and set the recovery interval
- Verify port-security state per-interface and global errdisable recovery status
- Validate same-VLAN host reachability across an 802.1Q trunk
Troubleshooting focus
- Access ports accidentally configured as trunks or missing access VLAN
- Port-security commands applied to the trunk (should never be applied to uplinks)
- Errdisable recovery not activated for psecure-violation or interval set too high/low
- Forgetting to cap the number of allowed MAC addresses on the port, resulting in unexpected default behavior
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.