Manually Configuring Port Security; Identifying Wwns To Configure Port Security; Securing Authorized Ports; Activating The Port Security Database - Cisco DS-C9216I-K9 Configuration Manual

Switch guide
Table of Contents

Advertisement

Chapter 20
Configuring Port Security

Manually Configuring Port Security

To configure port security in any switch in the Cisco MDS 9000 Family, follow these steps:
Identify the WWN of the ports that need to be secured.
Step 1
Secure the fWWN to an authorized nWWN or pWWN.
Step 2
Activate the port security database.
Step 3
Verify your configuration.
Step 4

Identifying WWNs to Configure Port Security

If you decide to manually configure port security, be sure to adhere to the following guidelines:

Securing Authorized Ports

After identifying the WWN pairs that need to be bound, add those pairs to the port security database.

Activating the Port Security Database

When you activate the port security database, all entries in the configured database are copied to the
active database. After the database is activated, subsequent device login is subject to the activated port
bound WWN pairs. Additionally, all devices that have already logged into the VSAN at the time of
activation are also learned and added to the active database. If the auto-learn option is already enabled
in a VSAN, you will not be allowed to activate the database.
OL-7753-01
Identify switch ports by the interface or the fWWN.
Identify devices by the pWWN or nWWN.
If an Nx port:
is allowed to login to SAN switch port Fx, then that Nx port can only log in through the specified
Fx port.
nWWN is bound to a Fx port WWN, then all pWWNs in the Nx port are implicitly paired with
the Fx port.
TE port checking is done on each VSAN in the allowed VSAN list of the trunk port.
All PortChannel xE ports must be configured with the same set of WWNs in the same PortChannel.
E port security is implemented in the port VSAN of the E port. In this case the sWWN is used to
secure authorization checks.
Once activated, the config database can be modified without any effect on the active database.
Saving the running configuration saves the configuration database and activated entries in the active
database. Learned entries in the active database are not saved.
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
Manually Configuring Port Security
20-7

Advertisement

Table of Contents
loading

Table of Contents