HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.3.x administrator guide (569 - Page 257

Security considerations, Configuring switches

Page 257 highlights

NOTE: The Fabric OS CLI supports only a subset of the management features for FICON fabrics. The full set of FICON CUP administrative procedures is available using the Fabric Manager and Web Tools software features. You can also use an SNMP agent and the FICON Management Information Base (MIB). For information on these tools, refer to: • Web Tools-Web Tools Administrator's Guide • Fabric Manager-Fabric Manager Administrator's Guide • SNMP Agent and FICON Management Information Base (MIB)-Fabric OS MIB Reference Manual Security considerations To administer FICON, you must have one of the following roles: • Admin • Operator • SwitchAdmin • FabricAdmin The User and BasicSwitchAdmin roles are view-only. The ZoneAdmin and SecurityAdmin roles have no access. In an Admin Domain-aware fabric, if you use the FICON commands (ficonshow, ficonclear, ficoncupshow, and ficoncupset) for any Admin Domain other than AD0 and AD255, the current switch must be a member of that Admin Domain. The output is not filtered based on the Admin Domain. Configuring switches This section describes how to configure a switch in a FICON environment. Use Table 63 on page 282 to record your configuration information. Following are recommended FICON environment configuration settings: • Disable dynamic load sharing (dlsReset command). If DLS is enabled, traffic on existing ISL ports might be affected when one or more new ISLs is added between the same two switches. Specifically, adding the new ISL might result in dropped frames as routes are adjusted to take advantage of the bandwidth provided. By disabling DLS, you ensure that there will be no dropped frames. A similar situation occurs when an ISL port is taken offline and then brought back online. When the ISL port goes offline, the traffic on that port is rerouted to another ISL with a common destination. When the ISL port comes back online and DLS is enabled, the rerouting of traffic back to the ISL port might result in dropped frames. If DLS is not enabled, traffic will not be routed back. • Configure ports that are connected to 1-Gbit/sec channels for fixed 1-Gbit/sec speed. Otherwise, when using fixed 1-Gbit/sec channels (both G5 and FICON Express), the FICON host might generate erroneous link incidents when the channels are coming online. These link incidents will result in a call home. Other than the generated link incident, the channel will come online and function normally. • Enable in-order delivery (iodSet command). • Enable VC translation link initialization on Extended Fabrics links, to stabilize them. Refer to "Administering Extended Fabrics" on page 351 for details on this option for the portCfgLongDistance command. • Although there are no specific zoning rules related to FICON environments, it is recommended that you follow standard FCP zoning practices. For management purposes, when operating in a mixed environment put FCP devices in one zone and FICON devices in another zone. • The port-based routing policy is recommended for the SAN Switch 4/32, SAN Switch 4/32B and 4/256 SAN Director on any switch that has FICON devices attached. Other switches in the fabric with Open Systems devices exclusively can still use exchange-based routing. Fabric OS 5.3.0 administrator guide 269

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465

Fabric OS 5.3.0 administrator guide
269
NOTE:
The Fabric OS CLI supports only a subset of the management features for FICON fabrics. The full
set of FICON CUP administrative procedures is available using the Fabric Manager and Web Tools
software features. You can also use an SNMP agent and the FICON Management Information Base (MIB).
For information on these tools, refer to:
Web Tools—
Web Tools Administrator’s Guide
Fabric Manager—
Fabric Manager Administrator’s Guide
SNMP Agent and FICON Management Information Base (MIB)—
Fabric OS MIB Reference Manual
Security considerations
To administer FICON, you must have one of the following roles:
Admin
Operator
SwitchAdmin
FabricAdmin
The
User
and
BasicSwitchAdmin
roles are view-only. The
ZoneAdmin
and
SecurityAdmin
roles
have no access.
In an Admin Domain-aware fabric, if you use the FICON commands (
ficonshow, ficonclear,
ficoncupshow
, and
ficoncupset
)
for any Admin Domain other than AD0 and AD255, the current
switch must be a member of that Admin Domain. The output is not filtered based on the Admin Domain.
Configuring switches
This section describes how to configure a switch in a FICON environment. Use
Table 63
on page 282 to
record your configuration information.
Following are recommended FICON environment configuration settings:
Disable dynamic load sharing (
dlsReset
command).
If DLS is enabled, traffic on existing ISL ports might be affected when one or more new ISLs is added
between the same two switches. Specifically, adding the new ISL might result in dropped frames as
routes are adjusted to take advantage of the bandwidth provided. By disabling DLS, you ensure that
there will be no dropped frames.
A similar situation occurs when an ISL port is taken offline and then brought back online. When the ISL
port goes offline, the traffic on that port is rerouted to another ISL with a common destination. When the
ISL port comes back online and DLS is enabled, the rerouting of traffic back to the ISL port might result
in dropped frames. If DLS is not enabled, traffic will not be routed back.
Configure ports that are connected to 1-Gbit/sec channels for fixed 1-Gbit/sec speed. Otherwise, when
using fixed 1-Gbit/sec channels (both G5 and FICON Express), the FICON host might generate
erroneous link incidents when the channels are coming online. These link incidents will result in a call
home. Other than the generated link incident, the channel will come online and function normally.
Enable in-order delivery (
iodSet
command).
Enable VC translation link initialization on Extended Fabrics links, to stabilize them. Refer to
Administering Extended Fabrics
” on page 351 for details on this option for the
portCfgLongDistance
command.
Although there are no specific zoning rules related to FICON environments, it is recommended that you
follow standard FCP zoning practices. For management purposes, when operating in a mixed
environment put FCP devices in one zone and FICON
devices in another zone.
The port-based routing policy is recommended for the SAN Switch 4/32, SAN Switch 4/32B and
4/256 SAN Director on any switch that has FICON devices attached. Other switches in the fabric with
Open Systems devices exclusively can still use exchange-based routing.