Our intent with port-security is mostly to prevent users from uplinking hubs or switches of their own. We'll limit each switchport to a single mac address (dynamicaly learned).

Indeed, we also do have some private vlans in use already. Quite usefull in DMZ segments for example...


Ammo