20-8
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
OL-7753-01
Chapter 20 Configuring Port Security
Database Scenarios
Database activation is rejected in the following cases:
•
Missing or conflicting entries exist in the configuration database but not in the active database.
•
The
auto-learn
option was enabled before the activation.
•
The exact security is not configured for each PortChannel member.
•
If the configured database is empty and the active database is not.
Forcing Port Security Activation
If the database activation is rejected due to one or more conflicts listed in the previous section, you may
decide to proceed with the activation by using the
force
option.
An activation using the
force
option logs out existing devices if they violate the active database.
Reactivating the Database
If the
auto-learn
option is enabled and you activate the database, you will not be allowed to proceed.
Database Scenarios
Table 20-3
lists the differences and interaction between the active and configuration databases.
Table 20-3
Active and Configuration Port Security Databases
Configuration Database
Active Database
Read-write.
Read only.
Saving the configuration saves all the entries in the
configuration database.
Saving the configuration only saves the activated
entries. Learned entries are not saved.
Once activated, the configuration database can be
modified without any effect on the active database.
Once activated, all devices that have already
logged into the VSAN are also learned and added
to the active database.
You can overwrite the configuration database with
the active database.
You can overwrite the active database with the
configured database by activating the port security
database. An activation using the
force
option may
violate the entries already configured in the active
database.