HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 136

Frame redirection zoning, Creating an initiator - target zone, M-EOSn 9.8. Only the M6140, M4700F

Page 136 highlights

3 Zoning considerations Frame redirection zoning Name Server-based frame redirection enables the Brocade encryption switch or blade to be deployed transparently to hosts and targets in the fabric. NS-based frame redirection is enabled as follows: • You first create a zone that includes host (H) and target (T). This may cause temporary traffic disruption to the host. • You then create a CryptoTarget container for the target and configure the container to allow access to the initiator. • When you commit the transaction, a special zone called a "redirection zone" is generated automatically. The redirection zone includes the host (H), the virtual target (VT), the virtual initiator (VI), and the target (T). • When configuring multi-path LUNs do not commit the CryptoTarget container configuration before you have performed the following steps in sequence to prevent data corruption. Refer to the section "Configuring a multi-path Crypto LUN" on page 141 for more information. - Complete all zoning for ALL hosts that should gain access to the targets. - Complete the CryptoTarget container configuration for ALL target ports in sequence, including adding the hosts that should gain access to these targets. Host-target zoning must precede any CryptoTarget configuration. NOTE To enable frame redirection, the host and target edge switches must run Fabric OS v6.1.1 and Fabric OS v5.3.1.b or later firmware to ensure host and target connectivity with legacy platforms. In McDATA fabrics, the hosts and the switches hosting the targets require firmware versions M-EOSc 9.8 and M-EOSn 9.8. Only the M6140, M4700F, McDATA 4400, and the Brocade Intrepid 10000 support frame redirection. Creating an initiator - target zone 1. Log into the group leader as Admin or FabricAdmin. 2. Determine the initiator PWWN. Enter the nsshow command to view the devices connected to this switch. In the following example, the port name 10:00:00:00:c9:2b:c9:3a is the initiator PWWN. FabricAdmin:switch>nsshow { Type Pid COS PortName NodeName TTL(sec) N 010600; 2,3;10:00:00:00:c9:2b:c9:3a;20:00:00:00:c9:2b:c9:3a; na NodeSymb: [35] "Emulex LP9002 FV3.82A1 DV5-4.81A4 " Fabric Port Name: 20:06:00:05:1e:41:9a:7e Permanent Port Name: 10:00:00:00:c9:2b:c9:3a Port Index: 6 Share Area: No Device Shared in Other AD: No Redirect: No The Local Name Server has 1 entry } 118 Fabric OS Encryption Administrator's Guide 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

118
Fabric OS Encryption Administrator’s Guide
53-1001864-01
Zoning considerations
3
Frame redirection zoning
Name Server-based frame redirection enables the Brocade encryption switch or blade to be
deployed transparently to hosts and targets in the fabric.
NS-based frame redirection is enabled as follows:
You first create a zone that includes host (H) and target (T). This may cause temporary traffic
disruption to the host.
You then create a CryptoTarget container for the target and configure the container to allow
access to the initiator.
When you commit the transaction, a special zone called a “redirection zone” is generated
automatically. The redirection zone includes the host (H), the virtual target (VT), the virtual
initiator (VI), and the target (T).
When configuring multi-path LUNs do not commit the CryptoTarget container configuration
before you have performed the following steps in sequence to prevent data corruption. Refer to
the section
“Configuring a multi-path Crypto LUN”
on page 141 for more information.
-
Complete all zoning for ALL hosts that should gain access to the targets.
-
Complete the CryptoTarget container configuration for ALL target ports in sequence,
including adding the hosts that should gain access to these targets.
Host-target zoning must precede any CryptoTarget configuration.
NOTE
To enable frame redirection, the host and target edge switches must run Fabric OS v6.1.1 and Fabric
OS v5.3.1.b or later firmware to ensure host and target connectivity with legacy platforms. In McDATA
fabrics, the hosts and the switches hosting the targets require firmware versions M-EOSc 9.8 and
M-EOSn 9.8. Only the M6140, M4700F, McDATA 4400, and the Brocade Intrepid 10000 support
frame redirection.
Creating an initiator - target zone
1.
Log into the group leader as Admin or FabricAdmin.
2.
Determine the initiator PWWN. Enter the
nsshow
command to view the devices connected to
this switch. In the following example, the port name 10:00:00:00:c9:2b:c9:3a is the initiator
PWWN.
FabricAdmin:switch>
nsshow
{
Type Pid
COS PortName
NodeName
TTL(sec)
N 010600; 2,3;
10:00:00:00:c9:2b:c9:3a
;20:00:00:00:c9:2b:c9:3a; na
NodeSymb: [35] "Emulex LP9002 FV3.82A1 DV5-4.81A4 "
Fabric Port Name: 20:06:00:05:1e:41:9a:7e
Permanent Port Name: 10:00:00:00:c9:2b:c9:3a
Port Index: 6
Share Area: No
Device Shared in Other AD: No
Redirect: No
The Local Name Server has 1 entry }