Chapter 32
Configuring Port Security
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m .
When you activate the port security feature, the auto-learning is also automatically enabled. You can
choose to activate the port security feature and disable autolearing.
To activate the port security feature, follow these steps:
Command
Step 1
switch# config t
switch(config)#
Step 2
switch(config)# port-security activate vsan 1
switch(config)# port-security activate vsan 1
no-auto-learn
switch(config)# no port-security activate vsan 1
Note
If required, you can disable autolearning (see the
Database Activation Rejection
Database activation is rejected in the following cases:
•
•
•
•
If the database activation is rejected due to one or more conflicts listed in the previous section, you may
decide to proceed by forcing the port security activation.
Forcing Port Security Activation
If the port security activation request is rejected, you can force the activation
An activation using the force option can log out existing devices if they violate the active database.
Note
You can view missing or conflicting entries using the port-security database diff active vsan command
in EXEC mode.
To forcefully activate the port security database, follow these steps:
Command
Step 1
switch# config t
switch(config)#
Step 2
switch(config)# port-security activate vsan 1 force
OL-6973-03, Cisco MDS SAN-OS Release 2.x
Missing or conflicting entries exist in the configuration database but not in the active database.
If the auto-learn feature was enabled before the activation. To reactivate a database in this state.
The exact security is not configured for each PortChannel member.
The configured database is empty but the active database is not.
Purpose
Enters configuration mode.
Activates the port security database for the
specified VSAN, and automatically enables
auto-learning.
Activates the port security database for the
specified VSAN, and disables auto-learning.
Deactivates the port security database for the
specified VSAN, and automatically disables
auto-learning.
"Disabling Autolearning" section on page
Purpose
Enters configuration mode.
Forces the VSAN 1 port security
database to activate despite conflicts.
Cisco MDS 9000 Family Configuration Guide
Port Security Activation
32-7).
32-5
Need help?
Do you have a question about the DS-X9530-SF1-K9 - Supervisor-1 Module - Control Processor and is the answer not in the manual?
Questions and answers