HP Cisco MDS 9020 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 44

Installing Fabric Manager, Fabric Manager Client, and Enabling HTTPS

Page 44 highlights

Before You Begin Chapter 2 Getting Started Send documentation comments to [email protected] Step 4 Step 5 From the role drop-down menu, select either sme-admin, sme-kmc-admin, sme-stg-admin, or sme-recovery. Click Add. Creating and Assigning Cisco SME Roles Using the CLI For detailed information on creating and assigning roles, refer to the Cisco MDS 9000 Family CLI Configuration Guide. To create a Cisco SME role or to modify the profile for an existing Cisco SME role, follow these steps: Step 1 Step 2 Step 3 Step 4 Step 5 Step 6 Step 7 Step 8 Command switch# config t switch(config)# role name sme-admin switch(config-role)# switch(config)# no role name sme-admin switch(config-role)# rule 1 permit read-write feature sme-stg-admin switch(config-role)# rule 2 permit read feature sme-stg-admin switch(config-role)# rule 3 permit debug feature sme switch(config-role)# description SME Admins switch(config)# username usam role sme-admin Purpose Enters configuration mode. Places you in the mode for the specified role (sme-admin). Note: The role submode prompt indicates that you are now in the role submode. This submode is now specific to Cisco SME. Deletes the role called sme-admin. Allows you to add Cisco SME configuration commands. Allows you to add Cisco SME show commands. Allows you to add Cisco SME debug commands to the sme-admin role. Assigns a description to the new role. The description is limited to one line and can contain spaces. Adds the specified user (usam) to the sme-admin role. Note Only users belonging to the network-admin role can create roles. Note The four security roles required by Cisco SME can be implicitly created by using the setup sme command. For VSAN-based access control, you must create the custom roles. Installing Fabric Manager, Fabric Manager Client, and Enabling HTTPS To be able to manage Cisco SME, you need to install Fabric Manager Server Enterprise edition. For information on installing Cisco Fabric Manager, refer to the installation chapters of the Cisco MDS 9000 Family Fabric Manager Configuration Guide. Note To configure Cisco SME, the Fabric Manager user credentials must be the same as the switch user. 2-12 Cisco MDS 9000 Family Storage Media Encryption Configuration Guide OL-18091-01, Cisco MDS NX-OS Release 4.x

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
2-12
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Chapter 2
Getting Started
Before You Begin
Step 4
From the role drop-down menu, select either
sme-admin, sme-kmc-admin, sme-stg-admin,
or
sme-recovery
.
Step 5
Click
Add
.
Creating and Assigning Cisco SME Roles Using the CLI
For detailed information on creating and assigning roles, refer to the
Cisco MDS 9000 Family CLI
Configuration Guide
.
To create a Cisco SME role or to modify the profile for an existing Cisco SME role, follow these steps:
Note
Only users belonging to the network-admin role can create roles.
Note
The four security roles required by Cisco SME can be implicitly created by using the
setup sme
command. For VSAN-based access control, you must create the custom roles.
Installing Fabric Manager, Fabric Manager Client, and Enabling HTTPS
To be able to manage Cisco SME, you need to install Fabric Manager Server Enterprise edition. For
information on installing Cisco Fabric Manager, refer to the installation chapters of the
Cisco MDS 9000
Family Fabric Manager Configuration Guide
.
Note
To configure Cisco SME, the Fabric Manager user credentials must be the same as the switch user.
Command
Purpose
Step 1
switch#
config t
Enters configuration mode.
Step 2
switch(config)#
role name sme-admin
switch(config-role)#
Places you in the mode for the specified role (sme-admin).
Note:
The role submode prompt indicates that you are
now in the role submode. This submode is now specific to
Cisco SME.
Step 3
switch(config)#
no role name
sme-admin
Deletes the role called sme-admin.
Step 4
switch(config-role)#
rule 1 permit
read-write feature sme-stg-admin
Allows you to add Cisco SME configuration commands.
Step 5
switch(config-role)#
rule 2
permit
read feature sme-stg-admin
Allows you to add Cisco SME show commands.
Step 6
switch(config-role)#
rule 3 permit
debug feature sme
Allows you to add Cisco SME debug commands to the
sme-admin role.
Step 7
switch(config-role)#
description SME
Admins
Assigns a description to the new role. The description is
limited to one line and can contain spaces.
Step 8
switch(config)#
username usam role
sme-admin
Adds the specified user (usam) to the sme-admin role.