Configuring a Dynamic Port Profile
Note: Port profiles
are supported only on physical Ethernet ports.
Note: Do
not include ports that are members of a Link Aggregation Group (LAG) when specifying
ports for a dynamic port profile.
- Enter global configuration mode.
- Create a port profile and assign a profile name.
- Assign one or more tagged VLANs for the ports configured using this profile.
- Assign an untagged VLAN.
- Set the access-list name for incoming packets.
- (Optional) Enable the ports associated with this profile to be protected.
- Create a Link Layer Discovery Protocol (LLDP) device entry using either the system name, system description, or both.
- (Optional) Specify a pattern to match the beginning of the system name, the system description, or both.
- (Optional) Specify a pattern to match anywhere within the system name, the system description, or both.
- (Optional) Use the
exclude-portscommand to add a port or a range of ports to the exclude-ports list. During dynamic port profile binding with Media Access Control Organizationally Unique Identifier (MAC OUI) or LLDP, the system checks this list. Ports on the exclude list will not be included in the dynamic port profile.Note: Theexclude-portscommand only prevents the current profile from being applied to the specified ports. To prevent an interface from participating in any dynamic port-profile assignments across the entire system, use theexclude port-profilecommand in interface configuration mode. Refer to Excluding an Interface from Dynamic Port-Profile Assignments for more information. - Disable and then enable the
interface to apply the dynamic port profile.
device(config-port-profile-profile2)# exit device(config)# interface ethernet 1/1/12 device(config-if-e1000-1/1/12)# disable device(config-if-e1000-1/1/12)# enable device(config-if-e1000-1/1/12)# exit
Note: If you are connecting the powered device (PD) after the port profile creation, you do not need to disable and enable the interface. If the PD is connected to the switch before creating the port profile, disable and enable the interface as shown in the examples.
The following example configures a
MAC OUI entry. After applying the MAC OUI, disable and enable the PD-connected
interface.
device(config)# port-profile profile2 device(config-port-profile-profile2)# mac-oui F8:E7:1E device(config-port-profile-profile2)# exit device(config)# interface ethernet 1/1/42 device(config-if-e1000-1/1/42)# disable device(config-if-e1000-1/1/42)# enable device(config-if-e1000-1/1/42)# exit