Zone Enforcement
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m .
Activating a Zone Set
Changes to a zone set do not take effect to a full zone set until you activate it.
To activate a zone set, follow these steps:
Command
Step 1
switch# config t
switch(config)#
Step 2
switch(config)# zoneset activate name Zoneset1 vsan 3
switch(config)# no zoneset activate name Zoneset1 vsan 3
You do not have to issue the copy running-config startup-config command to store the active zone set.
Tip
However, you need to issue the copy running-config startup-config command to explicitly store full
zone sets. It is not available across switch resets.
Regular zone set activation and deactivation is per VSAN where IVR zone set activation and deactivation
Caution
is for a set of VSANs. If you deactivate the regular active zone set in a VSAN, the IVZs for the IVZS
are removed, and all IVR traffic to and from that VSAN is stopped. This occurs because the IVZs in the
regular active zone set of that VSAN are also removed and deactivated. IVR traffic between other
VSANs continues to function. To reactivate the IVZS, you must reactivate the regular zone set. See the
"Creating and Activating IVZs and IVZSs" section on page
If the currently active zone set contains IVR zones, activating the zone set from a switch where IVR is
Caution
not enabled disrupts IVR traffic to and from that VSAN. We strongly recommend that you always
activate the zone set from an IVR-enabled switch to avoid disrupting IVR traffic.
Zone Enforcement
Zoning can be enforced in two ways: soft and hard. Each end device (N port or NL port) discovers other
devices in the fabric by querying the name server. When a device logs in to the name server, the name
server returns the list of other devices that can be accessed by the querying device. If an Nx port does
not know about the FC IDs of other devices outside its zone, it cannot access those devices.
In soft zoning, zoning restrictions are applied only during interaction between the name server and the
end device. If an end device somehow knows the FC ID of a device outside its zone, it can access that
device.
Hard zoning is enforced by the hardware on each frame sent by an Nx port. As frames enter the switch,
source-destination IDs are compared with permitted combinations to allow the frame at wirespeed. Hard
zoning is applied to all forms of zoning.
Note
Hard zoning enforces zoning restrictions on every frame, and prevents unauthorized access.
Switches in the Cisco MDS 9000 Family support both hard and soft zoning.
Cisco MDS 9000 Family Configuration Guide
19-10
Chapter 19
Configuring and Managing Zones
Purpose
Enters configuration mode.
Activates the specified zone set.
Deactivates the specified zone set
18-22.
OL-6973-03, Cisco MDS SAN-OS Release 2.x
Need help?
Do you have a question about the DS-X9530-SF1-K9 - Supervisor-1 Module - Control Processor and is the answer not in the manual?
Questions and answers