About Auto-Learning; Enabling Auto-Learning; Disabling Autolearning - Cisco DS-X9530-SF1-K9 - Supervisor-1 Module - Control Processor Configuration Manual

Mds 9000 family
Table of Contents

Advertisement

Chapter 32
Configuring Port Security
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m .

About Auto-Learning

You can instruct the switch to automatically learn (auto-learn) the port security configurations over a
specified period. This feature allows any switch in the Cisco MDS 9000 Family to automatically learn
about devices and switches that connect to it. Use this feature to activate the port security feature for the
first time as it saves tedious manual configuration for each port. You must configure auto-learning on a
per-VSAN basis. If enabled, devices and switches that are allowed to connect to the switch are
automatically learned, even if you have not configured any port access. Learned entries on a port are
cleaned up after you shut down that port. Learning does not override the enforced port security policies.
When you activate the port security feature autolearning is also automatically enabled. When
auto-learning is enabled, the following apply:

Enabling Auto-Learning

The state of the auto-learning configuration depends on the state of the port security feature:
If auto-learning is enabled on a VSAN, you can only activate the database for that VSAN by using the
Tip
force option.
To enable auto-learning, follow these steps:
Command
Step 1
switch# config t
switch(config)#
Step 2
switch(config)# port-security
auto-learn vsan 1

Disabling Autolearning

To disable autolearning, follow these steps:
Command
Step 1
switch# config t
switch(config)#
Step 2
switch(config)# no port-security auto-learn vsan 1
OL-6973-03, Cisco MDS SAN-OS Release 2.x
Learning happens only for the devices or interfaces that were not activated.
You will not be allowed to activate the database.
If the port security feature is not activated, auto-learning is disabled by default.
If the port security feature is activated, auto-learning is enabled by default (unless you explicitly
disabled this option).
Purpose
Enters configuration mode.
Enables auto-learn so the switch can learn about any device
that is allowed to access VSAN 1. These devices are logged in
the port security active database.
Purpose
Enters configuration mode.
Disables auto-learn and stops the switch
from learning about new devices accessing
the switch. Enforces the database contents
based on the devices learned up to this
point.
Cisco MDS 9000 Family Configuration Guide
About Auto-Learning
32-7

Advertisement

Table of Contents
loading

Table of Contents