When you enable port security on an interface that is also configured with a voice VLAN, what is
the maximum number of secure MAC addresses that should be set on the port?
A.
No more than one secure MAC address should be set.
B.
The default is set.
C.
The IP phone should use a dedicated port, therefore only one MAC address is needed per port.
D.
No value is needed if the switchport priority extend command is configured.
E.
No more than two secure MAC addresses should be set.
Explanation:
Usually, an IP Phone needs two MAC addresses, one for the voice vlan and one for the accessvlan. If you don’t want other devices to access this port then you should not set more than two
secure MAC addresses.
Below is an example for this configuration:
Switch(config)# interface fa0/1Switch(config-if)# switchport mode accessSwitch(config-if)#
switchport port-securitySwitch(config-if)# switchport port-security mac-address
stickySwitch(config-if)# switchport port-security maximum 1 vlan voiceSwitch(config-if)# switchport
port-security maximum 1 vlan access//Configure static MAC addresses for these
VLANsSwitch(config-if)#switchport port-security mac-address sticky
0000.0000.0001Switch(config-if)#switchport port-security mac-address sticky 0000.0000.0002
vlan voice
(For more information about this, please
readhttp://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/31sg/configuration/guide/por
t_sec.html)