C H A P T E R
22
Configuring Switchport Blocking
This chapter describes how to configure switchport blocking on the Cisco NX-OS device.
This chapter includes the following sections:
•
About Switchport Blocking, on page 449
•
Licensing Requirements for Switchport Blocking, on page 449
•
Guidelines and Limitations for Switchport Blocking, on page 449
•
Default Settings for Switchport Blocking, on page 450
•
Configuring Switchport Blocking, on page 450
•
Verifying the Switchport Blocking Configuration, on page 451
•
Configuration Example for Switchport Blocking, on page 451
About Switchport Blocking
Occasionally, unknown multicast or unicast traffic is flooded to a switch port because a MAC address has
timed out or has not been learned by the switch. Security issues could arise if unknown multicast and unicast
traffic is forwarded to a switch port. You can enable switchport blocking to guarantee that no multicast or
unicast traffic is flooded to the port.
Licensing Requirements for Switchport Blocking
The following table shows the licensing requirements for this feature:
License Requirement
Product
Switchport blocking requires no license. Any feature not included in a license package is
bundled with the nx-os image and is provided at no extra charge to you. For an explanation
of the Cisco NX-OS licensing scheme, see the
Cisco NX-OS Licensing Guide
.
Cisco
NX-OS
Guidelines and Limitations for Switchport Blocking
Switchport blocking has the following configuration guidelines and limitations:
• Switchport blocking applies only to egress ports while traffic storm control applies only to ingress ports.
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
449