Cisco MDS 9000 Series Configuration Manual page 253

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring Port Security
About WWN Identification
If you decide to manually configure port security, be sure to adhere to the following guidelines:
• Identify switch ports by the interface or by the fWWN.
• Identify devices by the pWWN or by the nWWN.
• If an Nx port is allowed to log in to SAN switch port Fx, then that Nx port can only log in through the
• If an Nx port's nWWN is bound to an Fx port WWN, then all pWWNs in the Nx port are implicitly
• TE port checking is done on each VSAN in the allowed VSAN list of the trunk port.
• All PortChannel xE ports must be configured with the same set of WWNs in the same PortChannel.
• E port security is implemented in the port VSAN of the E port. In this case the sWWN is used to secure
• Once activated, the config database can be modified without any effect on the active database.
• By saving the running configuration, you save the configuration database and activated entries in the
Adding Authorized Port Pairs
To add authorized port pairs for port security, follow these steps:
Procedure
Step 1
switch# configure terminal
switch(config)#
Enters configuration mode.
Step 2
switch(config)# port-security database vsan 1
switch(config-port-security)#
Enters the port security database mode for the specified VSAN.
Step 3
switch(config)# no port-security database vsan 1
switch(config)#
(Optional) Deletes the port security configuration database from the specified VSAN.
Step 4
switch(config-port-security)# swwn 20:01:33:11:00:2a:4a:66 interface port-channel 5
Configures the specified sWWN to only log in through PortChannel 5.
Step 5
switch(config-port-security)# any-wwn interface fc1/1 - fc1/8
Configures any WWN to log in through the specified interfaces.
Step 6
switch(config-port-security)# pwwn 20:11:00:33:11:00:2a:4a fwwn 20:81:00:44:22:00:4a:9e
Configures the specified pWWN to only log in through the specified fWWN.
Step 7
switch(config-port-security)# no pwwn 20:11:00:33:11:00:2a:4a fwwn 20:81:00:44:22:00:4a:9e
specified Fx port.
paired with the Fx port.
authorization checks.
active database. Learned entries in the active database are not saved.
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
About WWN Identification
235

Advertisement

Table of Contents
loading

Table of Contents