HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.3.x administrator guide (569 - Page 258

Preparing a switch, Configuring a single switch, Configuring a high-integrity fabric

Page 258 highlights

• Some 1-Gbit/sec storage devices cannot auto-negotiate speed with the 4/256 SAN Director, SAN Switch 4/32 or SAN Switch 4/32B ports. For these types of devices, configure ports that are connected to 1-Gbit/sec storage devices for fixed 1-Gbit/sec speed. Preparing a switch To verify and prepare a switch for use in a FICON environment, complete the following steps: 1. Connect to the switch and log in as admin. 2. If not in a cascaded environment, proceed to step 3. If in a FICON cascaded environment, enter the following commands: • licenseShow to verify that required licenses (Secure Fabric OS and Zoning) are activated • secModeShow to determine if Secure Fabric OS is enabled; if it is disabled, enable it • secPolicyShow to verify that the SCC_POLICY is active • pkiShow to determine the existence of PKI objects, such as switch private key, private key passphrase, CSR, root certificate, and switch certificate. If none of these objects exists, refer to the Secure Fabric OS Administrator's Guide for information about creating the PKI objects and obtaining the digital certificate file. 3. Enter the switchShow command to verify that the switch and devices are online. 4. Change the routing policy on the switch from the default exchange-based policy to the required port-based policy for those switches with FICON devices directly attached. For the SAN Switch 4/32 and SAN Switch 4/32B, refer to the Fabric OS Command Reference Manual for details about the aptPolicy command. For the 4/256 SAN Director, refer to the Web Tools Administrator's Guide. 5. Enter the ficonshow rnid command to verify that the FICON devices are registered with the switch. 6. Enter the ficonshow lirr command to verify that the FICON host channels are registered to listen for link incidents. 7. Optionally, refer to "Using FICON CUP" on page 274 for details about using FICON CUP. Configuring a single switch Single-switch configuration does not require IDID or fabric binding, provided that connected channels are configured for single-byte addressing. However, you should configure IDID to ensure that domain IDs are maintained. Configuring a high-integrity fabric To configure a high-integrity fabric (cascaded configuration): 1. Disable each switch in the fabric. 2. For each switch: a. Enable the IDID flag. b. Set the domain ID. c. Install security certificates and keys. 3. Enable the switches; this builds the fabric. 4. Set up security on the primary FCS switch. Use the secModeEnable command. The security policies are distributed to each switch in the fabric. (For details on the Quickmode procedure, refer to the Secure Fabric OS Administrator's Guide. 270 Administering FICON fabrics

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465

270
Administering FICON fabrics
Some 1-Gbit/sec storage devices cannot auto-negotiate speed with the 4/256 SAN Director, SAN
Switch 4/32 or SAN Switch 4/32B ports. For these types of devices, configure ports that are
connected to 1-Gbit/sec storage devices for fixed 1-Gbit/sec speed.
Preparing a switch
To verify and prepare a switch for use in a FICON environment, complete the following steps:
1.
Connect to the switch and log in as admin.
2.
If not in a cascaded environment, proceed to
step 3
.
If in a FICON cascaded environment, enter the following commands:
licenseShow
to verify that required licenses (Secure Fabric OS and Zoning) are activated
secModeShow
to determine if Secure Fabric OS is enabled; if it is disabled, enable it
secPolicyShow
to verify that the SCC_POLICY is active
pkiShow
to determine the existence of PKI objects, such as switch private key, private key
passphrase, CSR, root certificate, and switch certificate. If none of these objects exists, refer to the
Secure Fabric OS Administrator’s Guide
for information about creating the PKI objects and
obtaining the digital certificate file.
3.
Enter the
switchShow
command to verify that the switch and devices are online.
4.
Change the routing policy on the switch from the default exchange-based policy to the required
port-based policy for those switches with FICON devices directly attached. For the SAN Switch 4/32
and SAN Switch 4/32B, refer to the
Fabric OS Command Reference Manual
for details about the
aptPolicy
command. For the 4/256 SAN Director, refer to the
Web Tools Administrator’s Guide
.
5.
Enter the
ficonshow
rnid
command to verify that the FICON
devices are registered with the switch.
6.
Enter the
ficonshow
lirr
command to verify that the FICON
host channels are registered to listen
for link incidents.
7.
Optionally, refer to ”
Using FICON CUP
” on page 274 for details about using FICON CUP.
Configuring a single switch
Single-switch configuration does not require IDID or fabric binding, provided that connected channels are
configured for single-byte addressing. However, you should configure IDID to ensure that domain IDs are
maintained.
Configuring a high-integrity fabric
To configure a high-integrity fabric (cascaded configuration):
1.
Disable each switch in the fabric.
2.
For each switch:
a.
Enable the IDID flag.
b.
Set the domain ID.
c.
Install security certificates and keys.
3.
Enable the switches; this builds the fabric.
4.
Set up security on the primary FCS switch.
Use the
secModeEnable
command. The security policies are distributed to each switch in the fabric.
(For details on the Quickmode procedure, refer to the
Secure Fabric OS Administrator’s Guide
.