Database Activation Rejection; Forcing Port Security Activation - Cisco AP775A - Nexus Converged Network Switch 5010 Configuration Manual

Fabric manager configuration guide, release 4.x
Hide thumbs Also See for AP775A - Nexus Converged Network Switch 5010:
Table of Contents

Advertisement

Activating Port Security
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Click in the Action column under Activation, next to the switch or VSAN on which you want to activate
Step 3
port security. You see a drop-down menu with the following options:
Set the Action field you want for that switch.
Step 4
Uncheck the AutoLearn check box for each switch in the VSAN to disable auto-learning.
Step 5
Click the CFS tab and set the command column to commit on all participating switches in the VSAN.
Step 6
Click Apply Changes in Fabric Manager or Apply in Device Manager to save these changes.
Step 7
If required, you can disable auto-learning (see the
Note

Database Activation Rejection

Database activation is rejected in the following cases:
If the database activation is rejected due to one or more conflicts listed in the previous section, you may
decide to proceed by forcing the port security activation.

Forcing Port Security Activation

If the port security activation request is rejected, you can force the activation.
Note
An activation using the force option can log out existing devices if they violate the active database.
To forcefully activate the port security database using Fabric Manager, follow these steps:
Expand a VSAN and select Port Security in the Logical Domains pane.
Step 1
You see the port security configuration for that VSAN in the Information pane.
Click the Actions tab.
Step 2
Cisco MDS 9000 Family Fabric Manager Configuration Guide
46-10
activate—Valid port security settings are activated.
activate (TurnLearningOff)—Valid port security settings are activated and auto-learn turned off.
forceActivate—Activation is forced.
forceActivate(TurnLearningOff)—Activation is forced and auto-learn is turned off.
deactivate—All currently active port security settings are deactivated.
NoSelection— No action is taken.
Missing or conflicting entries exist in the configuration database but not in the active database.
The auto-learning feature was enabled before the activation. To reactivate a database in this state,
disable auto-learning.
The exact security is not configured for each PortChannel member.
The configured database is empty but the active database is not.
Chapter 46
"Disabling Auto-learning" section on page
OL-17256-03, Cisco MDS NX-OS Release 4.x
Configuring Port Security
46-13).

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents