Cisco MDS 9000 Series Configuration Manual page 246

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring Port Security with Auto-Learning without CFS
Step 7
Issue a CFS commit to copy this configuration to all switches in the fabric. See the
on page
that is distributed to all switches.
Step 8
Copy the active database to the configure database on each VSAN. See the
on page
Step 9
Issue a CFS commit to copy this configuration to all switches in the fabric. See the
on page
Step 10
Copy the running configuration to the startup configuration, using the fabric option. This saves the port security
configure database to the startup configuration on all switches in the fabric.
Configuring Port Security with Auto-Learning without CFS
To configure port security using auto-learning without CFS, follow these steps:
Procedure
Step 1
Enable port security. See the
Step 2
Activate port security on each VSAN. This turns on auto-learning by default. See the
on page
Step 3
Wait until all switches and all hosts are automatically learned.
Step 4
Disable auto-learn on each VSAN. See the
Step 5
Copy the active database to the configure database on each VSAN. See the
on page
Step 6
Copy the running configuration to the startup configuration This saves the port security configure database
to the startup configuration.
Step 7
Repeat Step 1 through Step 6 for all switches in the fabric.
Configuring Port Security with Manual Database Configuration
To configure port security and manually configure the port security database, follow these steps:
Procedure
Step 1
Enable port security. See the
Step 2
Manually configure all port security entries into the configure database on each VSAN. See the
Manual Configuration, on page
Step 3
Activate port security on each VSAN. This turns on auto-learning by default. See the
on page
Step 4
Disable auto-learn on each VSAN. See the
Step 5
Copy the running configuration to the startup configuration This saves the port security configure database
to the startup configuration.
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
228
238. At this point, the auto-learned entries from every switch are combined into a static active database
241.
238. This ensures that the configure database is the same on all switches in the fabric.
Enabling Port Security, on page
229.
241.
Enabling Port Security, on page
234.
229.
229.
Disabling Auto-learning, on page
229.
Disabling Auto-learning, on page
Configuring Port Security
Committing the Changes,
Copying the Port Security Database,
Committing the Changes,
Activating Port Security,
232.
Copying the Port Security Database,
Port Security
Activating Port Security,
232.

Advertisement

Table of Contents
loading

Table of Contents