S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
37-17
Cisco MDS 9000 Family CLI Configuration Guide
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Chapter 37 Configuring Port Security
Database Interaction
Use the
port-security database copy vsan
command to copy from the active to the configured database.
If the active database is empty, this command is not accepted.
switch#
port-security database copy vsan 1
Use the
port-security database diff active vsan
command to view the differences between the active
database and the configuration database. This command can be used when resolving conflicts.
switch#
port-security database diff active vsan 1
Use the
port-security database diff config vsan
command to obtain information on the differences
between the configuration database and the active database.
switch#
port-security database diff config vsan 1
Port Security Database Deletion
Tip
If the distribution is enabled, the deletion creates a copy of the database. An explicit
port-security
commit
command is required to actually delete the database.
Use the
no port-security database vsan
command in configuration mode to delete the configured
database for a specified VSAN
switch(config)#
no port-security database vsan 1
Port Security Database Cleanup
Use the
clear port-security statistics vsan
command to clear all existing statistics from the port security
database for a specified VSAN.
switch#
clear port-security statistics vsan 1
Use the
clear port-security database auto-learn interface
command to clear any learned entries in the
active database for a specified interface within a VSAN.
switch#
clear port-security database auto-learn interface fc1/1 vsan 1
Use the
clear port-security database auto-learn vsan
command to clear any learned entries in the
active database for the entire VSAN.
switch#
clear port-security database auto-learn vsan 1
Note
The
clear port-security database auto-learn
and
clear port-security statistics
commands are only
relevant to the local switch and do not acquire locks. Also, learned entries are only local to the switch
and do not participate in distribution.
Use the
port-security clear vsan
command to clear the pending session in the VSAN from any switch
in the VSAN.
switch#
clear
port-security session vsan 5