Fabric Binding Enforcement; Fabric Binding Initiation - Cisco DS-X9530-SF1-K9 - Supervisor-1 Module - Control Processor Configuration Manual

Mds 9000 family
Table of Contents

Advertisement

Fabric Binding Configuration
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m .
Port-level checking for xE-ports
While port security complements fabric binding, they are independent features and can be enabled or
disabled separately.

Fabric Binding Enforcement

To enforce fabric binding, configure the switch world wide name (sWWN) to specify the xE port
connection for each switch. Enforcement of fabric binding policies are done on every activation and
when the port tries to come up. However, enforcement of fabric binding at the time of activation happens
only if the VSAN is a FICON VSAN. The fabric binding feature requires all sWWNs connected to a
switch and their persistent domain IDs to be part of the fabric binding active database.
To configure fabric binding in each switch in the fabric, follow these steps.
Enable the fabric configuration feature.
Step 1
Configure a list of sWWNs and their corresponding domain IDs for devices that are allowed to access
Step 2
the fabric.
Activate the fabric binding database.
Step 3
Copy the fabric binding active database to the fabric binding config database.
Step 4
Save the fabric binding configuration.
Step 5
Verify the fabric binding configuration.
Step 6

Fabric Binding Initiation

The fabric binding feature must be enabled in each switch in the fabric that participates in the fabric
binding. By default, this feature is disabled in all switches in the Cisco MDS 9000 Family. The
configuration and verification commands for the fabric binding feature are only available when fabric
binding is enabled on a switch. When you disable this configuration, all related configurations are
automatically discarded.
To enable fabric binding on any participating switch, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# fabric-binding enable
switch(config)# no fabric-binding enable
Cisco MDS 9000 Family Configuration Guide
24-38
switch login uses both port binding as well as the fabric binding feature for a given VSAN.
Binding checks are done on the port VSAN:
E-port security binding check is done on port VSAN.
TE-port security binding check is done in each allowed VSAN.
Purpose
Enters configuration mode.
Enables fabric binding on that switch.
Disables (default) fabric binding on that switch.
OL-6973-03, Cisco MDS SAN-OS Release 2.x
Chapter 24
Configuring FICON

Advertisement

Table of Contents
loading

Table of Contents