HP 8/40 Access Gateway Administrator's Guide (53-1001760-01, June 2010) - Page 49

Enabling and disabling the Advanced Device Security policy

Page 49 highlights

Advanced Device Security policy 3 Enabling and disabling the Advanced Device Security policy By default, the ADS policy is disabled. When you manually disable the ADS policy, all of the allow lists (global and per-port) are cleared. Before disabling the ADS policy, you should save the configuration using the configupload command in case you need this configuration again. 1. Connect to the switch and log in using an account assigned to the admin role. 2. Enter the ag --policyenable ads command to enable the ADS policy. switch:admin> ag --policyenable ads The policy ADS is enabled 3. Enter the ag --policydisable ads command to disable the ADS policy. switch:admin> ag --policydisable ads The policy ADS is disabled NOTE Use the ag --policyshow command to determine the current status of the ADS policy. Setting the list of devices allowed to log in You can determine which devices are allowed to log in on a per F_Port basis by specifying the device's port WWN (PWWN). Lists must be enclosed in double quotation marks. List members must be separated by semicolons. The maximum number of entries in the allowed device list is twice the per port maximum log in count. Replace the WWN list with an asterisk (*) to indicate all access on the specified F_Port list. Replace the F_Port list with an asterisk (*) to add the specified WWNs to all the F_Ports' allow lists. A blank WWN list ("") indicates no access. The ADS policy must be enabled for this command to succeed. NOTE Use an asterisk enclosed in quotation marks,"*", to set the Allow list to "All Access" to all F_Ports; use a pair of double quotation marks ("") to set the Allow list to "No Access". Note the following characteristics of the Allow List: • The maximum device entries allowed in the Allow List is twice the per port max login count. • Each port can be configured to "not allow any device" or "to allow all the devices" to log in. • If the ADS policy is enabled, by default, every port is configured to allow all devices to log in. • The same Allow List can be specified for more than one F_Port. 1. Connect to the switch and log in using an account assigned to the admin role. 2. Enter the ag --adsset command with the appropriate operands to set the list of devices allowed to log into specific ports. In the following example, ports 1, 10, and, 13 are set to "all access." switch:admin> ag --adsset "1;10;13" "*" WWN list set successfully as the Allow Lists of the F_Port[s] Access Gateway Administrator's Guide 29 53-1001760-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96

Access Gateway Administrator’s Guide
29
53-1001760-01
Advanced Device Security policy
3
Enabling and disabling the Advanced Device Security policy
By default, the ADS policy is disabled. When you manually disable the ADS policy, all of the allow
lists (global and per-port) are cleared. Before disabling the ADS policy, you should save the
configuration using the
configupload
command in case you need this configuration again.
1.
Connect to the switch and log in using an account assigned to the admin role.
2.
Enter the
ag
--
policyenable ads
command to enable the ADS policy.
switch:admin>
ag --policyenable ads
The policy ADS is enabled
3.
Enter the
ag
--
policydisable ads
command to disable the ADS policy.
switch:admin>
ag --policydisable ads
The policy ADS is disabled
NOTE
Use the
ag --policyshow
command to determine the current status of the ADS policy.
Setting the list of devices allowed to log in
You can determine which devices are allowed to log in on a per F_Port basis by specifying the
device’s port WWN (PWWN). Lists must be enclosed in double quotation marks. List members must
be separated by semicolons. The maximum number of entries in the allowed device list is twice the
per port maximum log in count. Replace the WWN list with an asterisk (*) to indicate all access on
the specified F_Port list. Replace the F_Port list with an asterisk (*) to add the specified WWNs to
all the F_Ports' allow lists. A blank WWN list (““) indicates no access. The ADS policy must be
enabled for this command to succeed.
NOTE
Use an asterisk enclosed in quotation marks,“*”, to set the Allow list to “All Access” to all F_Ports;
use a pair of double quotation marks (“”) to set the Allow list to “No Access”.
Note the following characteristics of the Allow List:
The maximum device entries allowed in the Allow List is twice the per port max login count.
Each port can be configured to “not allow any device” or “to allow all the devices” to log in.
If the ADS policy is enabled, by default, every port is configured to allow all devices to log
in.
The same Allow List can be specified for more than one F_Port.
1.
Connect to the switch and log in using an account assigned to the admin role.
2.
Enter the
ag
--
adsset
command with the appropriate operands to set the list of devices
allowed to log into specific ports. In the following example, ports 1, 10, and, 13 are set to “all
access.”
switch:admin> ag --adsset "1;10;13" "*"
WWN list set successfully as the Allow Lists of the F_Port[s]