LINUXOR.SK ... open source notes ...

Linux Storage - MDS port security commands

category: solutionz · date: 2013-12-31 · updated: 2026-10-03 · author: LALA

Linux Storage Solution · Config document · referenced from Port security

noteThe switch had no ENTERPRISE_PKG licence and said so: the feature runs for a grace period of approximately 119 days and is then shut down. The notes do not record what happened after. Two headings in this section of the notes say "VSAN 21" and "VSAN 22" while the commands say vsan 11 and vsan 12; the commands are right for this switch, see below. The prompt in the notes reads FCwitch1 throughout this section, a typo for FCSwitch1.

The command set that enabled the port-security feature on FCSwitch1, wrote one database per VSAN binding each port WWN to the switch interface it may log in on, activated both databases without learning, and checked the result. The port WWNs come from the flogi and fcns databases.

ItemValue
SwitchFCSwitch1, Cisco MDS 9124e, NX-OS 5.2(8)
Run asadmin, configuration mode (config)# and the sub-mode (config-port-security)#; the checks ran from configuration mode too
LicenceENTERPRISE_PKG not installed; grace period of approximately 119 days announced
VSAN 114 bindings: bay1, bay2, bay5, ext1
VSAN 123 bindings: bay3, bay4, ext2
Activationport-security activate vsan N no-auto-learn for 11 and 12
Resultboth databases active, learning disabled, no violations, no fabric distribution

The commands

Enable the port-security feature. Configuration mode on FCSwitch1; the switch answered with the licence message.

bash
$ feature port-security
output 1 line
ENTERPRISE_PKG license not installed. Port Security feature will be shut down after grace period of approximately 119 day(s).

List the WWPN identifiers that may appear on those physical ports. The heading in the notes says "for VSAN 21"; the command says vsan 11, which is the DC VSAN of this switch. port-security database vsan 11 opens the config-port-security sub-mode, each pwwn … interface … line is one binding, exit leaves the sub-mode. Note the space in bay 1 and ext 1, which is how the notes wrote the interface names here.

bash
$ port-security database vsan 11
$ pwwn 50:01:43:80:12:34:56:c0 interface bay 1
$ pwwn 50:01:43:80:12:34:56:d4 interface bay 2
$ pwwn 50:01:43:80:12:34:40:2c interface bay 5
$ pwwn 21:12:00:02:ac:00:ab:cd interface ext 1
$ exit

The same for the DMZ VSAN. The heading in the notes says "for VSAN 22"; the command says vsan 12. Same mode.

bash
$ port-security database vsan 12
$ pwwn 50:01:43:80:12:34:57:90 interface bay 3
$ pwwn 50:01:43:80:12:34:57:92 interface bay 4
$ pwwn 21:11:00:02:ac:00:ab:cd interface ext 2
$ exit

Activate port security for the VSAN 11 (DC). The author's note, marked with three exclamation marks on each side: when we do not want to leave the switch in learning, non-intrusive mode, we must not forget the keyword no-auto-learn. Configuration mode on FCSwitch1.

bash
$ port-security activate vsan 11 no-auto-learn

Activate port security for the VSAN 12 (DMZ). Same mode.

bash
$ port-security activate vsan 12 no-auto-learn

The checks

Check the port-security database for VSAN 11: the configured database. Configuration mode on FCSwitch1.

bash
$ sh port-security database vsan 11
output 8 lines
--------------------------------------------------------------------------------
VSAN Logging-in Entity             Logging-in Point       (Interface)
--------------------------------------------------------------------------------
11   50:01:43:80:12:34:56:c0(pwwn) 20:0d:54:7f:ee:ab:cd:18(bay1)*
11   50:01:43:80:12:34:56:d4(pwwn) 20:0f:54:7f:ee:ab:cd:18(bay2)*
11   50:01:43:80:12:34:40:2c(pwwn) 20:05:54:7f:ee:ab:cd:18(bay5)*
11   21:12:00:02:ac:00:ab:cd(pwwn) 20:15:54:7f:ee:ab:cd:18(ext1)*
[Total 4 entries]

Check the active port-security database for VSAN 11. The same four rows; the Learnt column is empty, because nothing was learnt.

bash
$ sh port-security database active vsan 11
output 8 lines
--------------------------------------------------------------------------------
VSAN Logging-in Entity             Logging-in Point       (Interface)     Learnt
--------------------------------------------------------------------------------
11   50:01:43:80:12:34:56:c0(pwwn) 20:0d:54:7f:ee:ab:cd:18(bay1)*
11   50:01:43:80:12:34:56:d4(pwwn) 20:0f:54:7f:ee:ab:cd:18(bay2)*
11   50:01:43:80:12:34:40:2c(pwwn) 20:05:54:7f:ee:ab:cd:18(bay5)*
11   21:12:00:02:ac:00:ab:cd(pwwn) 20:15:54:7f:ee:ab:cd:18(ext1)*
[Total 4 entries]

Check for port-security policy violations. The table came back with a header and no rows.

bash
$ sh port-security violations
output 3 lines
-------------------------------------------------------------------------------
VSAN Interface        Logging-in Entity             Last-Time    [Repeat count]
-------------------------------------------------------------------------------

Check the state of the port-security settings for every VSAN. VSAN 1 is the default VSAN, which has no interfaces in this installation and no database.

bash
$ sh port-security status
output 4 lines
Fabric Distribution Disabled
VSAN 1 :No Active database, learning is disabled, No Session
VSAN 11 :Activated database, learning is disabled, No Session
VSAN 12 :Activated database, learning is disabled, No Session

Check the state of the port-security settings for VSAN 11 alone.

bash
$ sh port-security status vsan 11
output 2 lines
Fabric Distribution Disabled
VSAN 11 :Activated database, learning is disabled, No Session

The notes hold no sh port-security database vsan 12, database active vsan 12 or status vsan 12; only the all-VSAN status line shows VSAN 12 as activated.

What the lines and columns mean

ItemMeaning
feature port-securityenables the feature; without the licence the switch starts a grace period
port-security database vsan Nthe configured database of one VSAN; a VSAN has its own, like its own zoning
pwwn <wwn> interface <port>the device with this port WWN may log in on this interface and nowhere else in the VSAN
port-security activate vsan N no-auto-learnmakes the configured database the active one; no-auto-learn means devices that log in are not added to it, so an unknown device is refused instead of learnt
Logging-in Entitythe device, here always a port WWN
Logging-in Pointthe interface, printed as a WWN, which I read as the WWN of the switch port (fWWN), with the interface name in brackets; the notes do not say; the listing shows 20:0d:54:7f:ee:ab:cd:18 for bay1, 20:0f:… for bay2, 20:05:… for bay5 and 20:15:… for ext1
*the notes do not explain the asterisk; as I understand the command it marks an entry that is currently logged in
Learntwould mark entries added by auto-learning; empty here
Fabric Distribution Disabledthe database is not distributed to other switches through Cisco Fabric Services, as I understand the line; there is no other switch in this fabric
No Sessionno fabric-wide configuration session open
VSAN 1 :No Active databasethe default VSAN has nothing configured

The WWNs in that column (20:0d:…, 20:0f:…, 20:05:…, 20:15:…), which I read as the WWNs of the switch ports, share the serial part with the switch WWN 20:00:54:7f:ee:ab:cd:18 that appears in the old zones and differ in the second byte. The notes say nothing about what they are or how they are formed, and I do not derive anything from them.

Checked against Cisco MDS NX-OS 9.4(5a)

As builtToday
feature port-security answered with "ENTERPRISE_PKG license not installed … grace period of approximately 119 day(s)"The 9.x security guide: configuring the port-security policy "requires the advantage or premier tiers license, previously known as ENTERPRISE_PKG license". The licensing guide still lists FC port security in the Enterprise package and still documents the grace period: 120 days to install the licence, after which the switch "automatically disables the feature and removes the configuration"
Traditional per-switch licence ENTERPRISE_PKGTraditional MDS licences are themselves end of life: end of sale 4 October 2025, last date of support 31 October 2028, replaced by smart licensing with the Advantage and Premier tiers
port-security database vsan N, pwwn … interface …, port-security activate vsan N no-auto-learnUnchanged; the guide's examples are pwwn … interface fc3/1 and port-security activate vsan 1 no-auto-learn, and there is also any-wwn interface fc3/1 to allow any device on one port
show port-security database, database active, violations, status with "Fabric Distribution Disabled"Unchanged
No fabric bindingfeature fabric-binding, the companion feature that binds switches rather than devices, needs the same Advantage or Premier tiers for open-systems VSANs
NX-OS 5.2(8) on an MDS 9124eLast release 5.2(8i); last date of support of the MDS 9124 31 January 2019

The one line in the licensing guide that matters for this document is what happens at the end of the grace period: the feature is disabled and its configuration removed. On this switch, if no licence followed, the seven bindings above disappeared on their own about four months after they were typed.

← solutionz