Configuring a Dynamic Port Profile

Complete the following steps to configure and apply a dynamic port profile on a specific interface.
Note: Port profiles are supported only on physical Ethernet ports.
Note: Do not include ports that are members of a Link Aggregation Group (LAG) when specifying ports for a dynamic port profile.
  1. Enter global configuration mode.
    device# configure terminal
  2. Create a port profile and assign a profile name.
    device(config)# port-profile profile2
  3. Assign one or more tagged VLANs for the ports configured using this profile.
    device(config-port-profile-profile2)# tagged-vlans 111 113
  4. Assign an untagged VLAN.
    device(config-port-profile-profile2)# untagged-vlan 112
  5. Set the access-list name for incoming packets.
    device(config-port-profile-profile2)# ingress-acl ing_filt
  6. (Optional) Enable the ports associated with this profile to be protected.
    device(config-port-profile-profile2)# protected-port 
  7. Create a Link Layer Discovery Protocol (LLDP) device entry using either the system name, system description, or both.
    device(config-port-profile-profile2)# lldp-device system-name "RUCKUS"  
     
    device(config-port-profile-profile2)# lldp-device system-desc "RUCKUS"
    device(config-port-profile-profile2)# lldp-device system-name "RUCKUS" system-desc "RUCKUS"
  8. (Optional) Specify a pattern to match the beginning of the system name, the system description, or both.
    device(config-port-profile-profile2)# lldp-device system-name-begin "RUCKUS" system-desc-begin "RUCKUS"
  9. (Optional) Specify a pattern to match anywhere within the system name, the system description, or both.
    device(config-port-profile-profile2)# lldp-device system-name-include "RUCKUS" system-desc-include "RUCKUS"
  10. (Optional) Use the exclude-ports command to add a port or a range of ports to the exclude-ports list. During dynamic port profile binding with Media Access Control Organizationally Unique Identifier (MAC OUI) or LLDP, the system checks this list. Ports on the exclude list will not be included in the dynamic port profile.
    device(config-port-profile-profile2)# exclude-ports ethernet 1/2/2
    Note: The exclude-ports command only prevents the current profile from being applied to the specified ports. To prevent an interface from participating in any dynamic port-profile assignments across the entire system, use the exclude port-profile command in interface configuration mode. Refer to Excluding an Interface from Dynamic Port-Profile Assignments for more information.
  11. Disable and then enable the interface to apply the dynamic port profile.
    device(config-port-profile-profile2)# exit
    device(config)# interface ethernet 1/1/12
    device(config-if-e1000-1/1/12)# disable
    device(config-if-e1000-1/1/12)# enable
    device(config-if-e1000-1/1/12)# exit
    
    Note: If you are connecting the powered device (PD) after the port profile creation, you do not need to disable and enable the interface. If the PD is connected to the switch before creating the port profile, disable and enable the interface as shown in the examples.
The following example configures a MAC OUI entry. After applying the MAC OUI, disable and enable the PD-connected interface.
device(config)# port-profile profile2
device(config-port-profile-profile2)# mac-oui F8:E7:1E 
device(config-port-profile-profile2)# exit
device(config)# interface ethernet 1/1/42
device(config-if-e1000-1/1/42)# disable
device(config-if-e1000-1/1/42)# enable
device(config-if-e1000-1/1/42)# exit