HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 179

Deployment as part of an edge fabric

Page 179 highlights

Deployment as part of an edge fabric 4 Deployment as part of an edge fabric In this deployment, the encryption switch is connected to either the host or target edge fabric. The backbone fabric may contain a 7500 extension switch or FR4-18i blade in a 48000 director, DCX, or DCX-4S, or an FCR-capable switch or blade. The encryption resources of the encryption switch can be shared with the other edge fabrics using FCR in the backbone fabric (Figure 66). . Host Target Virtual Initiator Virtual Target Redirection zone: (Automatically created) Encryption Switch E_Port Backbone Fabric Host Extension Switch Ex_Port Host Edge Fabric E_Port Ex_Port E_Port Target Edge Fabric Create zone: Host, Target, Virtual Initiator, Virtual Target Target FIGURE 66 Encryption switch as part of an edge fabric The following is a summary of steps for creating and enabling the frame redirection features in the FCR configuration (edge to edge): • The encryption device creates the frame redirection zone automatically, consisting of host, target, virtual target, and virtual initiator. when the target and host are configured on the encryption device. In Figure 66, the encryption device is connected to the host edge fabric. • Create the frame redirection one consisting of host, target, virtual target, and virtual initiator in the target edge fabric. The CLI command is zone --rdcreate [host wwn] [target wwn] [VI wwn] [VT wwn][nonrestartable] [noFCR]. Always specify nonrestartable as policy for creating redirection zones in case of the encryption device. The VI and VT port WWNs can be obtained by running the cryptocfg --show -container -cfg command on the encryption switch or blade. After the redirection zones are created, commit the configuration with the cfgsave command. • Create the LSAN zone consisting of host, target, virtual target, and virtual initiator in both the backbone fabric and the target edge fabrics. Refer to the Fabric OS Administrator's Guide for information about LSANs, LSAN zoning, and Fibre Channel routing (FCR) configurations. Fabric OS Encryption Administrator's Guide 161 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS Encryption Administrator’s Guide
161
53-1001864-01
Deployment as part of an edge fabric
4
Deployment as part of an edge fabric
In this deployment, the encryption switch is connected to either the host or target edge fabric. The
backbone fabric may contain a 7500 extension switch or FR4-18i blade in a 48000 director, DCX,
or DCX-4S, or an FCR-capable switch or blade. The encryption resources of the encryption switch
can be shared with the other edge fabrics using FCR in the backbone fabric (
Figure 66
).
.
FIGURE 66
Encryption switch as part of an edge fabric
The following is a summary of steps for creating and enabling the frame redirection features in the
FCR configuration (edge to edge):
The encryption device creates the frame redirection zone automatically, consisting of host,
target, virtual target, and virtual initiator. when the target and host are configured on the
encryption device. In
Figure 66
, the encryption device is connected to the host edge fabric.
Create the frame redirection one consisting of host, target, virtual target, and virtual initiator in
the target edge fabric. The CLI command is
zone
--
rdcreate [host wwn] [target wwn] [VI wwn]
[VT wwn][nonrestartable] [noFCR]
. Always specify
nonrestartable
as policy for creating
redirection zones in case of the encryption device. The VI and VT port WWNs can be obtained
by running the
cryptocfg --show -container <crypto container name> -cfg
command on the
encryption switch or blade. After the redirection zones are created, commit the configuration
with the
cfgsave
command.
Create the LSAN zone consisting of host, target, virtual target, and virtual initiator in both the
backbone fabric and the target edge fabrics. Refer to the
Fabric OS Administrator’s Guide
for
information about LSANs, LSAN zoning, and Fibre Channel routing (FCR) configurations.
Host
Target
Encryption
Switch
Backbone Fabric
Host
Target
Virtual
Initiator
Virtual
Target
Ex_Port
E_Port
E_Port
E_Port
Ex_Port
Host Edge Fabric
Target Edge Fabric
Create zone: Host, Target,
Virtual Initiator, Virtual Target
Redirection zone:
(Automatically created)
Extension
Switch