Configuring Port Security
Port Security Activation
By default, the port security feature is not activated in any switch in the Cisco MDS 9000 Family.
By activating the port security feature, the following apply:
• Auto-learning is also automatically enabled, which means:
• All the devices that are already logged in are learned and are added to the active database.
• All entries in the configured database are copied to the active database.
After the database is activated, subsequent device login is subject to the activated port bound WWN pairs,
excluding the auto-learned entries. You must disable auto-learning before the auto-learned entries become
activated.
When you activate the port security feature, auto-learning is also automatically enabled. You can choose to
activate the port security feature and disable auto-learning.
Tip
If a port is shut down because of a denied login attempt, and you subsequently configure the database to allow
that login, the port does not come up automatically. You must explicitly issue a no shutdown CLI command
to bring that port back online.
Port Security Configuration
The steps to configure port security depend on which features you are using. Auto-learning works differently
if you are using CFS distribution.
This section includes the following topics:
Configuring Port Security with Auto-Learning and CFS Distribution
To configure port security, using auto-learning and CFS distribution, follow these steps:
Procedure
Step 1
Enable port security. See the
Step 2
Enable CFS distribution. See the
Step 3
Activate port security on each VSAN. This turns on auto-learning by default. See the
on page
Step 4
Issue a CFS commit to copy this configuration to all switches in the fabric. See the
on page
Step 5
Wait until all switches and all hosts are automatically learned.
Step 6
Disable auto-learn on each VSAN. See the
• From this point, auto-learning happens for the devices or interfaces that were already logged into
the switch and also for the new devices will login in future.
• You cannot activate the database until you disable auto-learning.
Enabling Port Security, on page
Enabling Distribution, on page
229.
238. At this point, all switches are activated, and auto-learning.
229.
236.
Disabling Auto-learning, on page
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
Port Security Activation
Activating Port Security,
Committing the Changes,
232.
227