20-7
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
OL-7753-01
Chapter 20 Configuring Port Security
Manually Configuring Port Security
Manually Configuring Port Security
To configure port security in any switch in the Cisco MDS 9000 Family, follow these steps:
Step 1
Identify the WWN of the ports that need to be secured.
Step 2
Secure the fWWN to an authorized nWWN or pWWN.
Step 3
Activate the port security database.
Step 4
Verify your configuration.
Identifying WWNs to Configure Port Security
If you decide to manually configure port security, be sure to adhere to the following guidelines:
•
Identify switch ports by the interface or the fWWN.
•
Identify devices by the pWWN or nWWN.
•
If an Nx port:
–
is allowed to login to SAN switch port Fx, then that Nx port can only log in through the specified
Fx port.
–
nWWN is bound to a Fx port WWN, then all pWWNs in the Nx port are implicitly paired with
the Fx port.
•
TE port checking is done on each VSAN in the allowed VSAN list of the trunk port.
•
All PortChannel xE ports must be configured with the same set of WWNs in the same PortChannel.
•
E port security is implemented in the port VSAN of the E port. In this case the sWWN is used to
secure authorization checks.
•
Once activated, the config database can be modified without any effect on the active database.
•
Saving the running configuration saves the configuration database and activated entries in the active
database. Learned entries in the active database are not saved.
Securing Authorized Ports
After identifying the WWN pairs that need to be bound, add those pairs to the port security database.
Activating the Port Security Database
When you activate the port security database, all entries in the configured database are copied to the
active database. After the database is activated, subsequent device login is subject to the activated port
bound WWN pairs. Additionally, all devices that have already logged into the VSAN at the time of
activation are also learned and added to the active database. If the
auto-learn
option is already enabled
in a VSAN, you will not be allowed to activate the database.
Содержание DS-C9216I-K9
Страница 26: ...Contents xxvi Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 ...
Страница 42: ...xlii Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 New and Changed Information ...
Страница 128: ...10 8 Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 Chapter 10 Managing System Hardware ...