S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
19-12
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
OL-9285-05
Chapter 19 Troubleshooting FC-SP, Port Security, and Fabric Binding
Port Security Issues
Cannot Activate Port Security
Symptom
Cannot activate port security.
Unauthorized Device Gains Access to Fabric
Symptom
Unauthorized device gains access to fabric.
Table 19-5
Cannot Activate Port Security
Symptom
Possible Cause
Solution
Cannot activate port
security.
Autolearn is enabled.
See the
“Disabling Autolearn Using Fabric Manager”
section on page 19-13
or the
“Disabling Autolearn Using
the CLI” section on page 19-13
.
Conflicting entries in the configure
database.
Remove the conflicting entries. Conflicting entries are
those that when activated will cause existing logged in
devices to logout. See the
“Verifying the Active Port
Security Database Using Fabric Manager” section on
page 19-9
or the
“Verifying the Active Port Security
Database Using the CLI” section on page 19-9
.
Configure database is empty.
Choose
Fabric
xx
> VSAN
xx
> Port Security
, select the
Actions
tab, heck the
CopyActive to Config
check box,
and click
Apply Changes
in Fabric Manager to copy the
active database to the configure database.
Or use the
port-security database copy
CLI command.
Not all members of a PortChannel are
configured for port security.
Add the missing members. Make sure that the sWWNs are
the same for all the members.
See the
“Verifying the Active Port Security Database Using
Fabric Manager” section on page 19-9
or the
“Verifying the
Active Port Security Database Using the CLI” section on
page 19-9
.
Table 19-6
Unauthorized Device Gains Access to Fabric
Symptom
Possible Cause
Solution
Unauthorized device
gains access to fabric.
Port security disabled.
See the
“Configuring Port Security with Autolearn Using
Fabric Manager” section on page 19-14
or the
“Configuring Port Security with Autolearn Using the CLI”
section on page 19-15
.
Port security not activated in the
VSAN.
Autolearn is enabled.
Disable autolearn. See the
“Disabling Autolearn Using
Fabric Manager” section on page 19-13
or the
“Disabling
Autolearn Using the CLI” section on page 19-13
.