Cisco MDS 9000 Series Configuration Manual page 257

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring Port Security
pending database, the learned entries become static entries in the active database and are distributed to all
switches in the fabric. After the commit, the active database on all switches is identical.
If the pending database contains more than one activation and auto-learning configuration when you commit
the changes, then the activation and auto-learning changes are consolidated and the behavior may change (see
the following table).
Table 21: Scenarios for Activation and Auto- learning Configurations in Distributed Mode
Scenario
Actions
A and B exist
1. You activate the port
in the
security database and
configuration
enable auto-learning.
database,
activation is
not done and
1. A new entry E is added to
devices C,D
the configuration
are logged in.
database.
1. You issue a commit.
A and B exist
1. You activate the port
in the
security database and
configuration
enable auto-learning.
database,
activation is
not done and
1. You disable learning.
devices C,D
are logged in.
1. You issue a commit.
5
The * (asterisk):autolearned entries * (asterisk) indicates learned entries.
Tip
In this case, we recommend that you perform a commit at the end of each operation: after you activate port
security and after you enable auto-learning.
Distribution = OFF
configuration database = {A,B}
5
active database = {A,B, C
, D*}
configuration database = {A,B,
E}
active database = {A,B, C*, D*}
Not applicable
configuration database = {A,B}
active database = {A,B, C*, D*}
configuration database = {A,B}
active database = {A,B, C, D}
Not applicable
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
Activation and Auto-learning Configuration Distribution
Distribution = ON
configuration database = {A,B}
active database = {null}
pending database = {A,B + activation to be
enabled}
configuration database = {A,B}
active database = {null}
pending database = {A,B, E + activation to be
enabled}
configuration database = {A,B, E}
active database = {A,B, E, C*, D*}
pending database = empty
configuration database = {A,B}
active database = {null}
pending database = {A,B + activation to be
enabled}
configuration database = {A,B}
active database = {null}
pending database = {A,B + activation to be enabled
+learning to be disabled}
configuration database = {A,B}
active database = {A,B} and devices C and D are
logged out. This is equal to an activation with
auto-learning disabled.
pending database = empty
239

Advertisement

Table of Contents
loading

Table of Contents