Activating Port Security; Database Activation Rejection; Forcing Port Security Activation - Cisco AJ732A - MDS 9134 Fabric Switch Configuration Manual

Cisco nexus 5000 series switch cli software configuration guide, nx-os 4.0(1a)n1 (ol-16597-01, january 2009)
Hide thumbs Also See for AJ732A - Cisco MDS 9134 Fabric Switch:
Table of Contents

Advertisement

Port Security Activation
S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m

Activating Port Security

To activate port security, perform this task:
Command
Step 1
switch# configuration terminal
switch(config)#
Step 2
switch(config)# port-security activate vsan
vsan-id
switch(config)# port-security activate vsan
vsan-id no-auto-learn
switch(config)# no port-security activate vsan
vsan-id

Database Activation Rejection

Database activation is rejected in the following cases:
If the database activation is rejected due to one or more conflicts listed in the previous section, you may
decide to proceed by forcing the port security activation.

Forcing Port Security Activation

If the port security activation request is rejected, you can force the activation.
Note
If you force the activation, existing devices are logged out if they violate the active database.
You can view missing or conflicting entries using the port-security database diff active vsan command
in EXEC mode.
To forcefully activate the port security database, perform this task:
Command
Step 1
switch# configuration terminal
switch(config)#
Step 2
switch(config)# port-security activate vsan vsan-id
force
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
45-6
Missing or conflicting entries exist in the configuration database but not in the active database.
The auto-learning feature was enabled before the activation. To reactivate a database in this state,
disable auto-learning.
The exact security is not configured for each port channel member.
The configured database is empty but the active database is not.
Chapter 45
Configuring Port Security
Purpose
Enters configuration mode.
Activates the port security database for the
specified VSAN, and automatically enables
auto-learning.
Activates the port security database for the
specified VSAN, and disables auto-learning.
Deactivates the port security database for the
specified VSAN, and automatically disables
auto-learning.
Purpose
Enters configuration mode.
Forces the port security database to
activate for the specified VSAN even
if conflicts occur.
OL-16597-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents