◦
From this point, auto-learning occurs only for the devices or interfaces that were not logged into
the switch.
◦
You cannot activate the database until you disable auto-learning.
•
All the devices that are already logged in are learned and are added to the active database.
•
All entries in the configured database are copied to the active database.
After the database is activated, subsequent device login is subject to the activated port bound WWN pairs,
excluding the auto-learned entries. You must disable auto-learning before the auto-learned entries become
activated.
When you activate the port security feature, auto-learning is also automatically enabled. You can choose to
activate the port security feature and disable auto-learning.
If a port is shut down because of a denied login attempt, and you subsequently configure the database to allow
that login, the port does not come up automatically. You must explicitly enter the
no shutdown
command to
bring that port back online.
Configuring Port Security
Configuring Port Security with Auto-Learning and CFS Distribution
You can configure port security using auto-learning and CFS distribution.
Procedure
Step 1
Enable port security.
Step 2
Enable CFS distribution.
Step 3
Activate port security on each VSAN.
This action turns on auto-learning by default.
Step 4
Issue a CFS commit to copy this configuration to all switches in the fabric.
All switches have port security activated with auto-learning enabled.
Step 5
Wait until all switches and all hosts are automatically learned.
Step 6
Disable auto-learning on each VSAN.
Step 7
Issue a CFS commit to copy this configuration to all switches in the fabric.
The auto-learned entries from every switch are combined into a static active database that is distributed to all
switches.
Step 8
Copy the active database to the configure database on each VSAN.
Step 9
Issue a CFS commit to copy this configuration to all switches in the fabric.
This action ensures that the configured database is the same on all switches in the fabric.
Step 10
Copy the running configuration to the startup configuration, using the fabric option.
Cisco Nexus 5500 Series NX-OS SAN Switching Configuration Guide, Release 7.x
OL-30895-01
247
Configuring Port Security
Configuring Port Security