I’m trying to simulate a violation and put f0/2 to shutdown state. Everything is set up correctly but I do not know what is happening:

SW4(config-if)#do sh run int f0/2
Building configuration...

Current configuration : 254 bytes
interface FastEthernet0/2
 switchport access vlan 20
 switchport mode access
 switchport port-security
 switchport port-security mac-address sticky
 switchport port-security mac-address sticky 00e0.4c8b.116f
 no ip address
 spanning-tree portfast

When I connect a different device instead of “err-disabled state” i get:

%Error: Cannot add secure address 5442.49f8.7b80
%Error: Total secure addresses on interface reached its max limit of 1

It seems that the switch (3550) that I’m working on can’t update the MAC address, it says configured MAC addresses: 0.

SW4(config-if)#do sh port int f0/2
Port Security : Enabled
Port status : SecureUp
Violation mode : Shutdown
Maximum MAC Addresses : 1
Total MAC Addresses : 1
Configured MAC Addresses : 0
Sticky MAC Addresses : 1
Aging time : 0 mins
Aging type : Absolute
SecureStatic address aging : Disabled
Security Violation count : 0

And I have no errdisable for recovery mode:

SW4#sh errdisable recov
ErrDisable Reason    Timer Status
-----------------    --------------
udld                 Disabled
bpduguard            Disabled
channel-misconfig    Disabled
pagp-flap            Disabled
dtp-flap             Disabled
link-flap            Disabled
l2ptguard            Disabled
psecure-violation    Disabled
gbic-invalid         Disabled

Timer interval: 300 seconds

Interfaces that will be enabled at the next timeout:

Command rejected: Not eligible for secure port

If you have this error message “Command rejected: Not eligible for secure port.” it means that you first must set the port to the access mode.

SW4(config)#int f0/4
SW4(config-if)#switchport port-security
Command rejected: Not eligible for secure port.
SW4(config-if)#switchport mode access
SW4(config-if)#switchport port-security

and that’s it.