Topic

Port Security practice labs

17 hands-on Port Security scenarios you build in your own Cisco Modeling Labs instance and grade against the answer key. Port Security configuration and troubleshooting practice for CCNA and CCNP.

Management reached over SSH, edge ports hardened — the reference wiring for Device Security & SSH, not a specific lab.

Included with a subscription

BeginnerFree2026-06-30

CCNA Port Security 1: Enable & Verify on Access Ports

Hands-on fundamentals with Cisco port security on host-facing access ports. Build a small two-switch campus with a trunk, place two Linux hosts in the same user VLAN, then enable port security with the explicit defaults (maximum 1, violation shutdown) on both host ports. Verify secure-up state and baseline host connectivity.

CCNA40 min4 objectives

Free with an account

IntermediateLocked

CCNA Port Security: Maximum Secure MACs on Access Ports

Deploy and verify port security maximum settings on host-facing access ports in a pure Layer-2 campus with two access switches uplinked to a distribution switch. You will raise the allowed secure MAC count to 2 on each user port to support a PC and a potential downstream device (e.g., a dock), then verify with show commands. No Layer-3, SVIs, or routing are used; focus purely on access VLANs, trunks, and the port-security maximum behavior.

CCNA45 min4 objectives

AdvancedLocked

CCNA Capstone: Port Security Troubleshooting

Advanced CCNA port-security troubleshooting on a pure Layer-2 design. Two access switches linked by an 802.1Q trunk carry a Users VLAN across closets. Three Alpine Linux hosts are pre-addressed. The lab is intentionally shipped with multiple classic faults: one access port is err-disabled due to a prior port-security shutdown, one user-facing port lacks port-security altogether, another has the wrong violation mode and an overly restrictive maximum, and one port has an incorrect static secure-MAC configured. Your job is to diagnose using show commands, restore connectivity, and implement the intended security posture with sticky MACs, the correct maximum, the proper violation mode, and errdisable auto-recovery—without placing port-security on the trunk.

CCNA55 min6 objectives

IntermediateLocked

CCNA Port Security: Violation Protect vs Restrict

Deploy and compare the two non-disabling port-security violation modes on host-facing access ports. Build a small Layer-2 topology with a trunk between two switches and same-VLAN hosts. Configure violation protect on one access port and restrict on another using deterministic sticky MAC entries. Validate baseline reachability, then observe the different behaviors: protect silently drops with no counter/logs; restrict drops and increments the violation counter.

CCNA45 min4 objectives

IntermediateLocked

Port Security: Err-Disable Auto Recovery

Configure port security in shutdown mode on host-facing access ports and enable automatic errdisable recovery for psecure-violation. The lab uses two Layer-2 switches connected by a trunk and three Linux hosts in the same VLAN to validate baseline L2 connectivity. You will deploy and verify the global errdisable recovery timer and cause while keeping the trunk healthy. Focus is on deterministic configuration and verification via show commands rather than attempting to trigger live violations.

CCNA45 min4 objectives

AdvancedLocked

CCNA Port-Sec 9: Multi-Port Sticky Restrict Policy

Advanced CCNA switchport port-security rollout on multiple access ports across two Layer-2 switches with a trunk. You will standardize a consistent edge policy (sticky MAC learning, maximum 1, violation restrict) on all host-facing access ports while leaving the uplink trunk exempt from port-security. Includes a realistic drift on the trunk allow-list and VLAN database to fix before validating end-to-end user VLAN transport. Pure Layer-2: no SVIs or routing.

CCNA58 min6 objectives

IntermediateLocked

Port Security: Voice + Data on One Access Port

Harden a real desk port that carries both data (PC) and voice (IP phone) using switchport voice vlan and access vlan on a single access port. Apply port security with a maximum that accounts for two MAC addresses (phone + PC) so a third device is restricted. A deliberate trunk allow-list drift on the inter-switch link initially blocks the Voice VLAN; learners must repair the trunk and then verify port-security state on the desk port.

CCNA55 min6 objectives

IntermediateLocked

Port Security: Violation Shutdown & Manual Recovery

Hands-on CCNA L2 switching lab: build a small campus with a distribution switch and two access switches carrying a shared user VLAN over 802.1Q trunks. Harden access ports with sticky port-security in violation shutdown mode. Intentionally seed and diagnose broken trunks/host VLANs, restore end-to-end host reachability, then trigger a port-security violation to observe err-disabled behavior and perform manual recovery.

CCNA65 min5 objectives

IntermediateLocked

Port Security: Static Secure MAC Binding

Troubleshoot a Layer-2 forwarding fault that breaks a user VLAN between access/distribution switches, then implement static secure MAC binding on the client-facing access port. You will restore end-to-end VLAN 20 reachability and enforce a single authorized MAC on the user port using port-security with violation restrict.

CCNA55 min5 objectives

BeginnerLocked

CCNA Port Security 2: Sticky Secure MAC Learning

Two access-layer switches have a VLAN 20 connectivity problem: users in one wiring closet cannot reach users in the other. Diagnose and repair the issue, then deploy sticky secure MAC learning on the host-facing access ports so each port dynamically learns and persists its connected host's MAC. Verify sticky entries in show commands and confirm same-VLAN host connectivity end-to-end.

CCNA45 min4 objectives

AdvancedDailyLocked

Branch Layer 2 Capstone: Build, Verify & Fix VLANs and Trunks

Advanced Layer-2 capstone, run as a fault hunt. A branch was cut over last night: one user VLAN has no gateway, another user sits in the wrong subnet, the management VLAN is unreachable from the distribution switch, and a port that should lock to one MAC no longer does. Nothing was recorded. You get symptoms and the required end state — no fault list. Faults span the router and both switches, and more than one of them presents as 'the trunk is broken'.

CCNA75 min5 objectives

BeginnerDailyLocked

Troubleshoot a Branch ROAS: VLANs, Trunks & Port Security

Deploy and troubleshoot VLANs, 802.1Q trunks, and port security in a realistic small-branch ROAS design. You will stand up VLANs 10/20/99 with a hardened trunk native VLAN 999, configure sticky port security on access ports, correct a misassigned VLAN, and resolve an err-disabled port caused by a port security violation. Finish by verifying end-to-end host connectivity across VLANs.

CCNA55 min5 objectives

IntermediateDailyLocked

Hardened Trunks & ROAS: Allowed VLAN Lists, Native VLAN 999

Implement VLANs, 802.1Q trunking, router-on-a-stick inter-VLAN routing, and access-layer port security on a compact branch network with two access switches and two endpoints. You will configure segmentation (VLANs 10, 20, 99), hardened trunks with a dedicated native VLAN 999, Layer 3 gateways on a core router, and sticky MAC port security on user-facing ports. Verify end-to-end reachability and remediate common misconfigurations like missing allowed VLANs, native VLAN mismatches, and unauthorized endpoint moves.

CCNA68 min6 objectives

BeginnerDailyLocked

Layer 2 Access Hardening: PortFast, BPDU Guard & Sticky MAC

Hands-on CCNA Layer 2 switching lab: build VLANs, access ports, hardened 802.1Q trunks, and basic port-security across two access switches and an L2 core. Verify segmentation end-to-end from real hosts and practice troubleshooting native-VLAN and port/VLAN mismatches.

CCNA55 min5 objectives

BeginnerDailyLocked

VLANs for Two Departments: Trunking & Sticky MAC Security

Hands-on CCNA lab: build VLANs for Sales and Engineering, implement 802.1Q trunks with a hardened native VLAN, assign access ports, and apply sticky MAC port-security on access interfaces. The design uses a compact, realistic branch topology with a router-on-a-stick gateway, a distribution L2 switch, one access L2 switch, and two end hosts. Students deploy, verify, and troubleshoot VLAN reachability, trunk integrity, and port-security violations.

CCNA70 min4 objectives

BeginnerDailyLocked

Compact Branch LAN: Two VLANs, ROAS & Sticky Port Security

Configure a compact branch LAN with router-on-a-stick inter-VLAN routing, two access switches, and two user VLANs. Implement VLANs, 802.1Q trunks with a hardened native VLAN, secure user-facing ports with port-security, and verify end-to-end reachability from the hosts. Includes realistic troubleshooting of VLAN assignment, trunk allow-lists, and port-security violations.

CCNA65 min4 objectives

BeginnerDailyLocked

Campus Layer 2: VLANs, a Management VLAN & Port Security

Build and harden a small branch campus Layer 2 network with a distribution switch and two access switches. Implement VLANs, trunking, and basic port security, then verify from the end hosts and troubleshoot common L2 mistakes.

CCNA75 min6 objectives

Practicing switchport port security on Cisco Modeling Labs

Why it matters, and what these labs cover.

Port security is the access layer simplest control: it limits how many MAC addresses a switch port will accept and decides what happens when an unexpected one shows up. It is a CCNA objective, and it is still what stops someone from hanging an unmanaged switch off a wall jack. The concepts fit on an index card, but the operational details are where people get caught. The command is rejected outright if the port is still negotiating rather than hard-set to access mode. Sticky addresses live in the running config and disappear on a reload unless you save. A limit of one MAC breaks the moment a PC is daisy-chained behind an IP phone. And a port in err-disabled looks identical to a dead cable until you check why it went down. None of that is obvious from reading. It becomes obvious when you plug in a second device and watch the counter move.

These labs run on real Cisco switches in Cisco Modeling Labs with end hosts attached, so violations are something you cause rather than imagine. You will set switchport mode access, enable switchport port-security, size the limit with switchport port-security maximum 2, learn addresses with switchport port-security mac-address sticky, and choose an action with switchport port-security violation protect, restrict, or shutdown. Voice-and-data labs add switchport voice vlan and cap each VLAN independently with the vlan access and vlan voice keywords. Recovery labs bounce an err-disabled port by hand and then automate it with errdisable recovery cause psecure-violation and errdisable recovery interval. Verify with show port-security interface, show port-security address, and show interfaces status err-disabled, and persist sticky entries with copy running-config startup-config. Faults include a maximum set too low for a phone-and-PC port and a port security command rejected because the port was never pinned to access mode. Your uploaded config is graded requirement by requirement against the answer key.

Frequently asked questions

What is the practical difference between protect, restrict, and shutdown?

All three drop frames from unauthorized MAC addresses. Protect drops them silently with no logging, no SNMP trap, and no increment to the violation counter, which makes it the hardest to troubleshoot. Restrict drops them but logs a message, sends a trap, and increments the counter. Shutdown, the default, puts the port into err-disabled so it stops forwarding entirely until it is recovered. Restrict is the usual choice when you need visibility without taking a user offline.

Do sticky MAC addresses survive a reboot?

Only if you save. Sticky learning converts dynamically learned addresses into static secure entries in the running config, but the running config is not written to NVRAM automatically, so a reload wipes them and the port relearns whatever happens to be plugged in at boot. Run copy running-config startup-config once the legitimate devices are connected, which also persists the violation mode and the maximum.

Do these labs need real switches with hosts plugged into them?

No. The Cisco Modeling Labs topologies include the end hosts, so you can present a second MAC address on a secured port and watch the violation counter increment or the interface drop into err-disabled, then recover it. Each lab is a package built on CML free-tier images and imports into your own instance in one click.

Learn Port Security

Study the theory behind these labs — the concept explainer and step-by-step guides.

Looking for something else? Browse the full lab archive, narrow it to self-standing labs, or see today's daily lab.