Why does a Cisco switch port enter err-disabled status? Learn how port security violations trigger err-disabled state and how to resolve it—essential knowledge for the Cisco Certified Field Technician (CCT) exam.
Table of Contents
Question
A switch port is showing err-disabled status. What is the most likely cause?
A. Spanning-tree loop detected
B. Excessive broadcast traffic
C. Port security violation
D. Duplex mismatch
E. The switch has failed
Answer
C. Port security violation
Explanation
A port enters an error-disabled state when a security violation (such as an unauthorized MAC address) occurs.
A Cisco switch port typically enters err-disabled status due to a port security violation.
- Port security is a feature that restricts the number or specific MAC addresses allowed on a switch port. If an unauthorized device connects or the number of learned MAC addresses exceeds the configured limit, a violation occurs.
- When a violation is detected, the default action is to shut down the port and place it in an err-disabled state, effectively disabling all traffic on that port.
- The switch logs a security violation message and the port status changes to err-disabled, indicated by an orange LED and confirmed by commands like show interfaces status err-disabled.
- Other causes for err-disabled state include BPDU guard, link flapping, broadcast storms, and duplex mismatches, but port security violations are among the most common and are specifically designed to prevent unauthorized access.
- To recover, the port must be manually shut down and brought back up, or errdisable autorecovery can be configured.
A port security violation, such as an unauthorized MAC address on the port, is the most likely cause for a port entering err-disabled status on a Cisco switch.
Cisco Certified Field Technician (CCT) certification exam practice question and answer (Q&A) dump with detail explanation and reference available free, helpful to pass the Cisco Certified Field Technician (CCT) exam and earn Cisco Certified Field Technician (CCT) certification.