HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.3.0b Release Notes (AA-RWEYF - Page 13

Tunnel mode in Encapsulating Security Payload ESP, HP StorageWorks Fabric OS 5.3.0b release notes

Page 13 highlights

HA IPSec for B-Series MP Router Blade (FR4-18i) Fabric Merge Scalability FRU insertion System boot Performance Monitoring Management - Proxy switches If there is an already segmented port and backbone devices are exported to an edge fabric, a build fabric/fabric reconfiguration can occur after running haFailover. Ensure that there no segmented port exist before upgrading firmware. • IPSec implementation details: • Pre-shared key • Main mode (IKE negotiation protocol) • Tunnel mode in Encapsulating Security Payload (ESP) • IPSec specific statistics not provided. • No NAT or IPV6 support • FastWrite and Tape Pipelining will not be supported in conjunction with secure tunnels. • Jumbo frames will not be supported on secure tunnels. • ICMP redirect is not supported for IPSec-enabled tunnels. • Only a single secure tunnel will be allowed on a port. Non-secure tunnels will not be allowed on the same port as secure tunnels. • Modify operations are not allowed on secure tunnels. To change the configuration of a secure tunnel, you must first delete the tunnel and then re-create it with the desired options. • Only a single route is supported on an interface with a secure tunnel. • An IPSec tunnel cannot be created using the same local IP address if ipperf is active and using the same local IP address (source IP address). • Unidirectional supported throughput is ~104Mbytes/sec and bidirectional supported throughput is ~90Mbytes/sec. • An IPSec tunnel takes longer to come online than a non-IPSec tunnel. Do not try to merge fabrics with conflicting domain IDs over a VE_Port. Before merging two fabrics over FC-IP with VE_Ports at each end, HP recommends that all domain ID and zoning conflicts be resolved. • Support for Default Zoning policies has been added to Fabric OS 5.1.0. Typically, when you issue the cfgDisable command in a large fabric with thousands of devices, the name server indicates to all hosts that they can communicate with each other. To ensure that all devices in a fabric do not see each other during a cfgDisable operation, you can activate a Default Zone with policy set to no access. If Default zoning policies show enabled, all cfgEnable/disable commands and zoning changes must be run from a switch in the fabric running Fabric OS 5.1.0/5.2.0a. • In large fabrics with more than 1,000 ports, HP recommends that the MS Platform Database be disabled. The Platform DB must also be disabled before downgrading to earlier versions of Fabric OS. This can be done using the msPLMgmtDeactivate command. The FW_FRU_INSERTED message is displayed twice when a power supply FRU is inserted and powered on. There is no functional impact. Not all Fabric OS services run when the prompt becomes available during boot up. Wait for all the services to come up before using the switch or performing zoning actions. If the user tries to save more than 512 monitors using the perfCfgSave command, some of the monitors may be lost. If you using a Fabric OS 4.x switch as an API or SMI-S proxy to manage a 5.1.0 switch, you must be running Fabric OS 4.4.0d. HP StorageWorks Fabric OS 5.3.0b release notes 13

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25

HA
If there is an already segmented port and backbone devices are exported to
an edge fabric, a build fabric/fabric recon
guration can occur after running
haFailover
. Ensure that there no segmented port exist before upgrading
rmware.
IPSec for B-Series MP
Router Blade (FR4–18i)
IPSec implementation details:
Pre-shared key
Main mode (IKE negotiation protocol)
Tunnel mode in Encapsulating Security Payload (ESP)
IPSec speci
c statistics not provided.
No NAT or IPV6 support
FastWrite and Tape Pipelining will not be supported in conjunction with secure
tunnels.
Jumbo frames will not be supported on secure tunnels.
ICMP redirect is not supported for IPSec-enabled tunnels.
Only a single secure tunnel will be allowed on a port. Non-secure tunnels will
not be allowed on the same port as secure tunnels.
Modify operations are not allowed on secure tunnels. To change the
con
guration of a secure tunnel, you must
rst delete the tunnel and then
re-create it with the desired options.
Only a single route is supported on an interface with a secure tunnel.
An IPSec tunnel cannot be created using the same local IP address if ipperf is
active and using the same local IP address (source IP address).
Unidirectional supported throughput is ~104Mbytes/sec and bidirectional
supported throughput is ~90Mbytes/sec.
An IPSec tunnel takes longer to come online than a non-IPSec tunnel.
Fabric Merge
Do not try to merge fabrics with con
icting domain IDs over a VE_Port. Before
merging two fabrics over FC-IP with VE_Ports at each end, HP recommends that
all domain ID and zoning con
icts be resolved.
Scalability
Support for Default Zoning policies has been added to Fabric OS 5.1.0.
Typically, when you issue the
cfgDisable
command in a large fabric with
thousands of devices, the name server indicates to all hosts that they can
communicate with each other. To ensure that all devices in a fabric do not see
each other during a
cfgDisable
operation, you can activate a Default Zone
with policy set to
no access
. If Default zoning policies show enabled, all
cfgEnable
/
disable
commands and zoning changes must be run from a
switch in the fabric running Fabric OS 5.1.0/5.2.0a.
In large fabrics with more than 1,000 ports, HP recommends that the MS
Platform Database be disabled. The Platform DB must also be disabled before
downgrading to earlier versions of Fabric OS. This can be done using the
msPLMgmtDeactivate
command.
FRU insertion
The
FW_FRU_INSERTED
message is displayed twice when a power supply FRU
is inserted and powered on. There is no functional impact.
System boot
Not all Fabric OS services run when the prompt becomes available during boot
up. Wait for all the services to come up before using the switch or performing
zoning actions.
Performance Monitoring
If the user tries to save more than 512 monitors using the
perfCfgSave
command, some of the monitors may be lost.
Management — Proxy
switches
If you using a Fabric OS 4.x switch as an API or SMI-S proxy to manage a 5.1.0
switch, you must be running Fabric OS 4.4.0d.
HP StorageWorks Fabric OS 5.3.0b release notes
13