Port Security Versus Fabric Binding; Fabric Binding Enforcement - Cisco AJ732A - MDS 9134 Fabric Switch Configuration Manual

Cisco nexus 5000 series switch cli software configuration guide, nx-os 4.0(1a)n1 (ol-16597-01, january 2009)
Hide thumbs Also See for AJ732A - Cisco MDS 9134 Fabric Switch:
Table of Contents

Advertisement

Information About Fabric Binding
S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m

Port Security Versus Fabric Binding

Port security and fabric binding are two independent features that can be configured to complement each
other.
Table 46-1
Fabric Binding
Uses a set of sWWNs and a persistent domain
ID.
Binds the fabric at the switch level.
Authorizes only the configured sWWN stored in
the fabric binding database to participate in the
fabric.
Requires activation on a per VSAN basis.
Allows specific user-defined switches that are
allowed to connect to the fabric, regardless of the
physical port to which the peer switch is
connected.
Does not learn about switches that are logging in. Learns about switches or devices that are logging in
Cannot be distributed by CFS and must be
configured manually on each switch in the
fabric.
Port-level checking for xE ports is as follows:
While port security complements fabric binding, they are independent features and can be enabled or
disabled separately.

Fabric Binding Enforcement

To enforce fabric binding, configure the switch world wide name (sWWN) to specify the xE port
connection for each switch. Enforcement of fabric binding policies are done on every activation and
when the port tries to come up. For a Fibre Channel VSAN, the fabric binding feature requires all
sWWNs connected to a switch to be part of the fabric binding active database.
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
46-2
Table 46-1
compares the two features.
Fabric Binding and Port Security Comparison
The switch login uses both port security binding and fabric binding for a given VSAN.
Binding checks are performed on the port VSAN as follows:
E port security binding check on port VSAN
TE port security binding check on each allowed VSAN
Chapter 46
Port Security
Uses pWWNs/nWWNs or fWWNs/sWWNs.
Binds devices at the interface level.
Allows a preconfigured set of Fibre Channel
devices to logically connect to a SAN port. The
switch port, identified by a WWN or interface
number, connects to a Fibre Channel device (a host
or another switch), also identified by a WWN. By
binding these two devices, you lock these two ports
into a group (or list).
Requires activation on a per VSAN basis.
Allows specific user-defined physical ports to
which another device can connect.
if learning mode is enabled.
Can be distributed by CFS.
Configuring Fabric Binding
OL-16597-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents