HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.3.x administrator guide (569 - Page 364

Zone configurations, Zoning enforcement, Hardware-enforced Zoning

Page 364 highlights

Zone aliases also simplify repetitive entry of zone objects such as port numbers or a WWN. For example, you can use the name "Eng" as an alias for "10:00:00:80:33:3f:aa:11". A useful convention is to name zones for the initiator they contain. For example, if you use the alias SRV_MAILSERVER_SLT5 to designate a mail server in PCI slot 5, then the alias for the associated zone is ZNE_MAILSERVER_SLT5. This clearly identifies the server host bus adapter (HBA) associated with the zone. Zone configuration naming is more flexible. One configuration should be named PROD_fabricname, where fabricname is the name that the fabric has been designated. The purpose of the PROD configuration is to easily identify the configuration that can be implemented and provide the most generic services. If other configurations are used for specialized purposes, names such as "BACKUP_A," "RECOVERY_2," and "TEST_18jun02" can be used. Zone configurations A zone configuration is a group of one or more zones. A zone can be included in more than one zone configuration. When a zone configuration is in effect, all zones that are members of that configuration are in effect. The different types of zone configurations are: • Defined Configuration. The complete set of all zone objects defined in the fabric. • Effective Configuration. A single zone configuration that is currently in effect. The effective configuration is built when an administrator enables a specified zone configuration. • Saved Configuration. A copy of the defined configuration plus the name of the effective configuration, which is saved in flash memory by the cfgSave command. (You can also use the configUpload command to provide a backup of the Zoning configuration and the configDownload command to restore the Zoning configuration.) There might be differences between the saved configuration and the defined configuration if the system administrator has modified any of the zone definitions and has not saved the configuration. • Disabled Configuration. The effective configuration is removed from flash memory. On power-up, the switch automatically reloads the saved configuration. If a configuration was active when it was saved, the same configuration is reinstated on the local switch with an autorun of the cfgEnable command. You can establish a zone by identifying zone objects using one or more of the following Zoning schemes: • Domain, port number level. All members are specified by domain ID, port number, or domain, area number pair or aliases, described in "Zone aliases" on page 371. • World Wide Name (WWN) level. All members are specified only by World Wide Name (WWNs) or aliases of WWNs. They can be node or port versions of the WWN. • Mixed Zoning. A zone containing members specified by a combination of domain, port number, and/or domain, area number and WWN. Zoning enforcement Hardware and Software-enforced Zoning are supported. Hardware-enforced Zoning Hardware-enforced Zoning is specified without using the mixed Zoning scheme (mixed zones contain domains, ports and WWNs as zone members). The exact methodology varies on different switch models. Hardware-enforced Zoning (also called hard Zoning): • Prevents a host from accessing a device it is not authorized to access. • Checks each frame before it is delivered to a zone member and discards it if there is a zone mismatch. When hardware-enforced Zoning is active, the switch monitors the communications and blocks any frames that do not comply with the effective zone configuration. The switch performs this blocking at the transmit side of the port on which the destination device is located. • Is enforced at the ASIC level. Each ASIC maintains a list of source port IDs that have permission to access any of the ports on that ASIC. • Is available on 1 Gbit/sec, 2 Gbit/sec, and 4 Gbit/sec platforms. 372 Administering Advanced Zoning

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465

372
Administering Advanced Zoning
Zone aliases also simplify repetitive entry of zone objects such as port numbers or a WWN. For example,
you can use the name “Eng” as an alias for “10:00:00:80:33:3f:aa:11”.
A useful convention is to name zones for the initiator they contain. For example, if you use the alias
SRV_MAILSERVER_SLT5 to designate a mail server in PCI slot 5, then the alias for the associated zone is
ZNE_MAILSERVER_SLT5. This clearly identifies the server host bus adapter (HBA) associated with the zone.
Zone configuration naming is more flexible. One configuration should be named PROD_
fabricname
,
where
fabricname
is the name that the fabric has been designated. The purpose of the PROD configuration
is to easily identify the configuration that can be implemented and provide the most generic services. If
other configurations are used for specialized purposes, names such as “BACKUP_A,” “RECOVERY_2,” and
“TEST_18jun02” can be used.
Zone configurations
A
zone configuration
is a group of one or more zones. A zone can be included in more than one zone
configuration. When a zone configuration is in effect, all zones that are members of that configuration are
in effect.
The different types of zone configurations are:
Defined Configuration.
The complete set of all zone objects defined in the fabric.
Effective Configuration.
A single zone configuration that is currently in effect. The effective
configuration is built when an administrator enables a specified zone configuration.
Saved Configuration.
A copy of the defined configuration plus the name of the effective
configuration, which is saved in flash memory by the
cfgSave
command. (You can also use the
configUpload
command to provide a backup of the Zoning configuration and the
configDownload
command to restore the Zoning configuration.) There might be differences between
the saved configuration and the defined configuration if the system administrator has modified any of
the zone definitions and has not saved the configuration.
Disabled Configuration.
The effective configuration is removed from flash memory.
On power-up, the switch automatically reloads the saved configuration. If a configuration was active when
it was saved, the same configuration is reinstated on the local switch with an autorun of the
cfgEnable
command.
You can establish a zone by identifying zone objects using one or more of the following
Zoning schemes
:
Domain, port number level.
All members are specified by
domain ID
,
port number
, or
domain,
area number
pair or aliases, described in ”
Zone aliases
” on page 371.
World Wide Name (WWN) level.
All members are specified only by World Wide Name
(WWNs) or aliases of WWNs. They can be node or port versions of the WWN.
Mixed Zoning.
A zone containing members specified by a combination of
domain
,
port number
,
and/or
domain, area number
and WWN.
Zoning enforcement
Hardware and Software-enforced Zoning are supported.
Hardware-enforced Zoning
Hardware-enforced Zoning is specified without using the mixed Zoning scheme (mixed zones contain
domains, ports and WWNs as zone members). The exact methodology varies on different switch models.
Hardware-enforced Zoning (also called
hard Zoning
):
Prevents a host from accessing a device it is not authorized to access.
Checks each frame before it is delivered to a zone member and discards it if there is a zone mismatch.
When hardware-enforced Zoning is active, the switch monitors the communications and blocks any
frames that do not comply with the effective zone configuration. The switch performs this blocking at the
transmit side of the port on which the destination device is located.
Is enforced at the ASIC level. Each ASIC maintains a list of source port IDs that have permission to
access any of the ports on that ASIC.
Is available on 1 Gbit/sec, 2 Gbit/sec, and 4 Gbit/sec platforms.