Our intent with port-security is mostly to prevent users from uplinking hubs or switches of their own. We'll limit each switchport to a single mac address (dynamicaly learned).
Indeed, we also do have some private vlans in use already. Quite usefull in DMZ segments for example...
Ammo




Reply With Quote