Configuring Port Security
After the database is activated, subsequent device login is subject to the activated port bound WWN pairs,
excluding the auto-learned entries. You must disable auto-learning before the auto-learned entries become
activated.
When you activate the port security feature, auto-learning is also automatically enabled. You can choose to
activate the port security feature and disable auto-learning.
If a port is shut down because of a denied login attempt, and you subsequently configure the database to allow
that login, the port does not come up automatically. You must explicitly enter a no shutdown CLI command
to bring that port back online.
Configuring Port Security
Configuring Port Security with Auto-Learning and CFS Distribution
To configure port security, using auto-learning and CFS distribution, perform this task:
Procedure
Step 1
Enable port security.
Step 2
Enable CFS distribution.
Step 3
Activate port security on each VSAN.
This action turns on auto-learning by default.
Step 4
Issue a CFS commit to copy this configuration to all switches in the fabric.
All switches have port security activated with auto-learning enabled.
Step 5
Wait until all switches and all hosts are automatically learned.
Step 6
Disable auto-learn on each VSAN.
Step 7
Issue a CFS commit to copy this configuration to all switches in the fabric.
The auto-learned entries from every switch are combined into a static active database that is distributed to all
switches.
Step 8
Copy the active database to the configure database on each VSAN.
Step 9
Issue a CFS commit to copy this configuration to all switches in the fabric.
This ensures that the configure database is the same on all switches in the fabric.
Step 10 Copy the running configuration to the startup configuration, using the fabric option.
Related Topics
•
•
•
•
•
•
OL-16597-01
Activating Port Security, page 639
Committing the Changes, page 646
Copying the Port Security Database, page 651
Disabling Auto-Learning, page 641
Enabling Port Security, page 638
Enabling Port Security Distribution, page 645
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
Configuring Port Security
637