Linux Storage - MDS port security commands
Linux Storage Solution · Config document · referenced from Port security
ENTERPRISE_PKG licence and said so: the feature runs for a grace period of approximately 119 days and is then shut down. The notes do not record what happened after. Two headings in this section of the notes say "VSAN 21" and "VSAN 22" while the commands say vsan 11 and vsan 12; the commands are right for this switch, see below. The prompt in the notes reads FCwitch1 throughout this section, a typo for FCSwitch1.The command set that enabled the port-security feature on FCSwitch1, wrote one database per VSAN binding each port WWN to the switch interface it may log in on, activated both databases without learning, and checked the result. The port WWNs come from the flogi and fcns databases.
| Item | Value |
|---|---|
| Switch | FCSwitch1, Cisco MDS 9124e, NX-OS 5.2(8) |
| Run as | admin, configuration mode (config)# and the sub-mode (config-port-security)#; the checks ran from configuration mode too |
| Licence | ENTERPRISE_PKG not installed; grace period of approximately 119 days announced |
| VSAN 11 | 4 bindings: bay1, bay2, bay5, ext1 |
| VSAN 12 | 3 bindings: bay3, bay4, ext2 |
| Activation | port-security activate vsan N no-auto-learn for 11 and 12 |
| Result | both databases active, learning disabled, no violations, no fabric distribution |
The commands
Enable the port-security feature. Configuration mode on FCSwitch1; the switch answered with the licence message.
$ feature port-securityoutput 1 line
ENTERPRISE_PKG license not installed. Port Security feature will be shut down after grace period of approximately 119 day(s).
List the WWPN identifiers that may appear on those physical ports. The heading in the notes says "for VSAN 21"; the command says vsan 11, which is the DC VSAN of this switch. port-security database vsan 11 opens the config-port-security sub-mode, each pwwn … interface … line is one binding, exit leaves the sub-mode. Note the space in bay 1 and ext 1, which is how the notes wrote the interface names here.
$ port-security database vsan 11 $ pwwn 50:01:43:80:12:34:56:c0 interface bay 1 $ pwwn 50:01:43:80:12:34:56:d4 interface bay 2 $ pwwn 50:01:43:80:12:34:40:2c interface bay 5 $ pwwn 21:12:00:02:ac:00:ab:cd interface ext 1 $ exit
The same for the DMZ VSAN. The heading in the notes says "for VSAN 22"; the command says vsan 12. Same mode.
$ port-security database vsan 12 $ pwwn 50:01:43:80:12:34:57:90 interface bay 3 $ pwwn 50:01:43:80:12:34:57:92 interface bay 4 $ pwwn 21:11:00:02:ac:00:ab:cd interface ext 2 $ exit
Activate port security for the VSAN 11 (DC). The author's note, marked with three exclamation marks on each side: when we do not want to leave the switch in learning, non-intrusive mode, we must not forget the keyword no-auto-learn. Configuration mode on FCSwitch1.
$ port-security activate vsan 11 no-auto-learn
Activate port security for the VSAN 12 (DMZ). Same mode.
$ port-security activate vsan 12 no-auto-learn
The checks
Check the port-security database for VSAN 11: the configured database. Configuration mode on FCSwitch1.
$ sh port-security database vsan 11
output 8 lines
-------------------------------------------------------------------------------- VSAN Logging-in Entity Logging-in Point (Interface) -------------------------------------------------------------------------------- 11 50:01:43:80:12:34:56:c0(pwwn) 20:0d:54:7f:ee:ab:cd:18(bay1)* 11 50:01:43:80:12:34:56:d4(pwwn) 20:0f:54:7f:ee:ab:cd:18(bay2)* 11 50:01:43:80:12:34:40:2c(pwwn) 20:05:54:7f:ee:ab:cd:18(bay5)* 11 21:12:00:02:ac:00:ab:cd(pwwn) 20:15:54:7f:ee:ab:cd:18(ext1)* [Total 4 entries]
Check the active port-security database for VSAN 11. The same four rows; the Learnt column is empty, because nothing was learnt.
$ sh port-security database active vsan 11
output 8 lines
-------------------------------------------------------------------------------- VSAN Logging-in Entity Logging-in Point (Interface) Learnt -------------------------------------------------------------------------------- 11 50:01:43:80:12:34:56:c0(pwwn) 20:0d:54:7f:ee:ab:cd:18(bay1)* 11 50:01:43:80:12:34:56:d4(pwwn) 20:0f:54:7f:ee:ab:cd:18(bay2)* 11 50:01:43:80:12:34:40:2c(pwwn) 20:05:54:7f:ee:ab:cd:18(bay5)* 11 21:12:00:02:ac:00:ab:cd(pwwn) 20:15:54:7f:ee:ab:cd:18(ext1)* [Total 4 entries]
Check for port-security policy violations. The table came back with a header and no rows.
$ sh port-security violationsoutput 3 lines
------------------------------------------------------------------------------- VSAN Interface Logging-in Entity Last-Time [Repeat count] -------------------------------------------------------------------------------
Check the state of the port-security settings for every VSAN. VSAN 1 is the default VSAN, which has no interfaces in this installation and no database.
$ sh port-security statusoutput 4 lines
Fabric Distribution Disabled VSAN 1 :No Active database, learning is disabled, No Session VSAN 11 :Activated database, learning is disabled, No Session VSAN 12 :Activated database, learning is disabled, No Session
Check the state of the port-security settings for VSAN 11 alone.
$ sh port-security status vsan 11
output 2 lines
Fabric Distribution Disabled VSAN 11 :Activated database, learning is disabled, No Session
The notes hold no sh port-security database vsan 12, database active vsan 12 or status vsan 12; only the all-VSAN status line shows VSAN 12 as activated.
What the lines and columns mean
| Item | Meaning |
|---|---|
feature port-security | enables the feature; without the licence the switch starts a grace period |
port-security database vsan N | the configured database of one VSAN; a VSAN has its own, like its own zoning |
pwwn <wwn> interface <port> | the device with this port WWN may log in on this interface and nowhere else in the VSAN |
port-security activate vsan N no-auto-learn | makes the configured database the active one; no-auto-learn means devices that log in are not added to it, so an unknown device is refused instead of learnt |
Logging-in Entity | the device, here always a port WWN |
Logging-in Point | the interface, printed as a WWN, which I read as the WWN of the switch port (fWWN), with the interface name in brackets; the notes do not say; the listing shows 20:0d:54:7f:ee:ab:cd:18 for bay1, 20:0f:… for bay2, 20:05:… for bay5 and 20:15:… for ext1 |
* | the notes do not explain the asterisk; as I understand the command it marks an entry that is currently logged in |
Learnt | would mark entries added by auto-learning; empty here |
Fabric Distribution Disabled | the database is not distributed to other switches through Cisco Fabric Services, as I understand the line; there is no other switch in this fabric |
No Session | no fabric-wide configuration session open |
VSAN 1 :No Active database | the default VSAN has nothing configured |
The WWNs in that column (20:0d:…, 20:0f:…, 20:05:…, 20:15:…), which I read as the WWNs of the switch ports, share the serial part with the switch WWN 20:00:54:7f:ee:ab:cd:18 that appears in the old zones and differ in the second byte. The notes say nothing about what they are or how they are formed, and I do not derive anything from them.
Checked against Cisco MDS NX-OS 9.4(5a)
| As built | Today |
|---|---|
feature port-security answered with "ENTERPRISE_PKG license not installed … grace period of approximately 119 day(s)" | The 9.x security guide: configuring the port-security policy "requires the advantage or premier tiers license, previously known as ENTERPRISE_PKG license". The licensing guide still lists FC port security in the Enterprise package and still documents the grace period: 120 days to install the licence, after which the switch "automatically disables the feature and removes the configuration" |
Traditional per-switch licence ENTERPRISE_PKG | Traditional MDS licences are themselves end of life: end of sale 4 October 2025, last date of support 31 October 2028, replaced by smart licensing with the Advantage and Premier tiers |
port-security database vsan N, pwwn … interface …, port-security activate vsan N no-auto-learn | Unchanged; the guide's examples are pwwn … interface fc3/1 and port-security activate vsan 1 no-auto-learn, and there is also any-wwn interface fc3/1 to allow any device on one port |
show port-security database, database active, violations, status with "Fabric Distribution Disabled" | Unchanged |
| No fabric binding | feature fabric-binding, the companion feature that binds switches rather than devices, needs the same Advantage or Premier tiers for open-systems VSANs |
NX-OS 5.2(8) on an MDS 9124e | Last release 5.2(8i); last date of support of the MDS 9124 31 January 2019 |
The one line in the licensing guide that matters for this document is what happens at the end of the grace period: the feature is disabled and its configuration removed. On this switch, if no licence followed, the seven bindings above disappeared on their own about four months after they were typed.