Port Security Activation; Port Security Configuration Guidelines; Configuring Port Security With Auto-Learning And Cfs Distribution - Cisco AP776A - Nexus Converged Network Switch 5020 Configuration Manual

Cisco mds 9000 family cli configuration guide - release 4.x (ol-18084-01, february 2009)
Hide thumbs Also See for AP776A - Nexus Converged Network Switch 5020:
Table of Contents

Advertisement

Chapter 39
Configuring Port Security
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
If you enable auto-learning before activating port security, you cannot activate until auto-learning is
Note
disabled.

Port Security Activation

By default, the port security feature is not activated in any switch in the Cisco MDS 9000 Family.
By activating the port security feature, the following apply:
After the database is activated, subsequent device login is subject to the activated port bound WWN
pairs, excluding the auto-learned entries. You must disable auto-learning before the auto-learned entries
become activated.
When you activate the port security feature, auto-learning is also automatically enabled. You can choose
to activate the port security feature and disable auto-learning.
If a port is shut down because of a denied login attempt, and you subsequently configure the database to
Tip
allow that login, the port does not come up automatically. You must explicitly issue a no shutdown CLI
command to bring that port back online.

Port Security Configuration Guidelines

The steps to configure port security depend on which features you are using. Auto-learning works
differently if you are using CFS distribution.
This section includes the following topics:

Configuring Port Security with Auto-Learning and CFS Distribution

To configure port security, using auto-learning and CFS distribution, follow these steps:
Enable port security. See the
Step 1
Step 2
Enable CFS distribution. See the
OL-18084-01, Cisco MDS NX-OS Release 4.x
Auto-learning is also automatically enabled, which means:
From this point, auto-learning happens only for the devices or interfaces that were not logged
into the switch.
You cannot activate the database until you disable auto-learning.
All the devices that are already logged in are learned and are added to the active database.
All entries in the configured database are copied to the active database.
Configuring Port Security with Auto-Learning and CFS Distribution, page 39-3
Configuring Port Security with Auto-Learning without CFS, page 39-4
Configuring Port Security with Manual Database Configuration, page 39-4
"Enabling Port Security" section on page
"Enabling Distribution" section on page
Cisco MDS 9000 Family CLI Configuration Guide
Port Security Configuration Guidelines
39-5.
39-12.
39-3

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents