HP 8/8 Access Gateway Administrator's Guide (53-1001760-01, June 2010) - Page 50

Setting the list of devices not allowed to log in, Removing devices from the list of allowed devices

Page 50 highlights

3 Advanced Device Security policy Setting the list of devices not allowed to log in 1. Connect to the switch and log in using an account assigned to the admin role. 2. Enter the ag --adsset command with the appropriate operands to set the list of devices not allowed to log into specific ports. In the following example, ports 11 and 12 are set to "no access." switch:admin > ag --adsset "11;12" "" WWN list set successfully as the Allow Lists of the F_Port[s] Removing devices from the list of allowed devices Use the ag --adsdel command to delete the specified WWNs from the list of devices allowed to log in to the specified F_Ports. Lists must be enclosed in double quotation marks. List members must be separated by semicolons. Replace the F_Port list with an asterisk (*) to remove the specified WWNs from all the F_Ports' allow lists. The ADS policy must be enabled for this command to succeed. 1. Connect to the switch and log in using an account assigned to the admin role. 2. Enter the ag --adsdel command to remove one or more devices from the list of allowed devices. Use the following syntax: ag--adsdel "F_Port [;F_Port2;...]" "WWN [;WWN2;...]" In the following example, two devices are removed from the list of allowed devices (for ports 3 and 9). switch:admin> ag --adsdel "3;9" "22:03:08:00:88:35:a0:12;22:00:00:e0:8b:88:01:8b" WWNs removed successfully from Allow Lists of the F_Port[s]Viewing F_Ports allowed to login Adding new devices to the list of allowed devices You can add the specified WWNs to the list of devices allowed to log in to the specified F_Ports. Lists must be enclosed in double quotation marks. List members must be separated by semicolons. Replace the F_Port list with an asterisk (*) to add the specified WWNs to all the F_Ports' allow lists. The ADS policy must be enabled for this command to succeed. 1. Connect to the switch and log in using an account assigned to the admin role. 2. Enter the ag --adsadd command with appropriate operands to add one or more new devices to the list of allowed devices. Use the following syntax: ag--adsadd "F_Port [;F_Port2;...]" "WWN [;WWN2;...]" In the following example, two devices are added to the list of allowed devices (for ports 3 and 9). switch:admin> ag --adsadd "3;9" "20:03:08:00:88:35:a0:12;21:00:00:e0:8b:88:01:8b" WWNs added successfully to Allow Lists of the F_Port[s] 30 Access Gateway Administrator's Guide 53-1001760-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96

30
Access Gateway Administrator’s Guide
53-1001760-01
Advanced Device Security policy
3
Setting the list of devices not allowed to log in
1.
Connect to the switch and log in using an account assigned to the admin role.
2.
Enter the
ag
--
adsset
command with the appropriate operands to set the list of devices not
allowed to log into specific ports. In the following example, ports 11 and 12 are set to “no
access.”
switch:admin >
ag –-adsset “11;12” “”
WWN list set successfully as the Allow Lists of the F_Port[s]
Removing devices from the list of allowed devices
Use the
ag
--
adsdel
command to delete the specified WWNs from the list of devices allowed to log
in to the specified F_Ports. Lists must be enclosed in double quotation marks. List members must
be separated by semicolons. Replace the F_Port list with an asterisk (*) to remove the specified
WWNs from all the F_Ports' allow lists. The ADS policy must be enabled for this command to
succeed.
1.
Connect to the switch and log in using an account assigned to the admin role.
2.
Enter the
ag
--
adsdel
command to remove one or more devices from the list of allowed
devices.
Use the following syntax:
ag--adsdel "F_Port [;F_Port2;...]" "WWN [;WWN2;...]"
In the following example, two devices are removed from the list of allowed devices (for ports 3
and 9).
switch:admin>
ag --adsdel "3;9"
"22:03:08:00:88:35:a0:12;22:00:00:e0:8b:88:01:8b"
WWNs removed successfully from Allow Lists of the F_Port[s]Viewing F_Ports
allowed to login
Adding new devices to the list of allowed devices
You can add the specified WWNs to the list of devices allowed to log in to the specified F_Ports.
Lists must be enclosed in double quotation marks. List members must be separated by
semicolons. Replace the F_Port list with an asterisk (*) to add the specified WWNs to all the
F_Ports' allow lists. The ADS policy must be enabled for this command to succeed.
1.
Connect to the switch and log in using an account assigned to the admin role.
2.
Enter the
ag --adsadd
command with appropriate operands to add one or more new devices to
the list of allowed devices.
Use the following syntax:
ag--adsadd "F_Port [;F_Port2;...]" "WWN [;WWN2;...]"
In the following example, two devices are added to the list of allowed devices (for ports 3 and
9).
switch:admin>
ag --adsadd "3;9"
"20:03:08:00:88:35:a0:12;21:00:00:e0:8b:88:01:8b"
WWNs added successfully to Allow Lists of the F_Port[s]