HP StorageWorks 2/16V Brocade Web Tools Administrator's Guide - Supporting Fab - Page 32

Admin domains and login, Accounting or Engineering.

Page 32 highlights

1 Administrative domains Admin Domains permit access to a configured set of users. If a switch is part of an Admin Domain, then when you log in with an account that has an administrator role, you can perform switch enable and disable functions and all switch port-level functions such as port enable and port disable. You cannot perform fabric-wide management, as switch membership within a zone does not provide zoning rights on the switch ports. NOTE Do not confuse an Admin Domain with the domain ID of a switch. They are two different identifiers. Admin Domains are identified by a numeric ID (0-255) and also by name. This name can be autogenerated based on the ID (for example AD1 or AD5) or you can specify a more informative name such as Accounting or Engineering. AD0 is a special Admin Domain that contains all switches, ports, and devices that have not been put into other Admin Domains. AD255, another special domain, is an unfiltered view of the entire physical fabric. NOTE Some features work only in AD255 when user-defined domains are present, such as ACL management. By default, all fabric elements belong to AD0. In Fabric OS v5.2.0 and higher, a physical fabric administrator with appropriate permissions can create up to 254 additional Admin Domains and assign fabric resources to them (see Chapter 7, "Managing Administrative Domains"). Only users who have been specifically assigned to those domains can view and modify the resources they contain. ADMIN DOMAINS AND LOGIN You are always logged in to an Admin Domain, and you can view and modify only the devices in that Admin Domain. You can log in to only one Admin Domain at a time. When you log in, you select the Admin Domain that you want to manage. You can later change the Admin Domain to which you are logged in. If you have more than one Admin Domain, one of them will have been specified as your "home Admin Domain." Your home Admin Domain is the one you are automatically logged in to unless you explicitly select a different one. If a home Admin Domain is deleted or deactivated, then by default you will be logged in to the lowest numbered Admin Domain in your Admin Domain list. A home Admin Domain, like the Admin Domain list, is a configurable property of a non-default user account. For default accounts such as admin and user, the home Admin Domain defaults to AD0 and cannot be changed. For user-defined accounts, the home Admin Domain also defaults to 0 but an administrator can set the home Admin Domain to any Admin Domain to which the account has been given access. The Admin Domain List for default admin accounts is 0-255, which gives automatic access to any Admin Domain as soon as it is created, and makes them physical fabric administrators. The Admin Domain list for the default user account is AD0 only. The Admin Domain list property for default accounts also cannot be changed. A "physical fabric administrator" is an admin role user whose account has access to all Admin Domains (AD0-255) as soon as they are created. Only physical fabric administrators can create, modify, delete, and activate or deactivate Admin Domains. 10 Web Tools Administrator's Guide Publication Number: 53-1000435-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266

10
Web Tools Administrator’s Guide
Publication Number: 53-1000435-01
Administrative domains
1
Admin Domains permit access to a configured set of users. If a switch is part of an Admin Domain,
then when you log in with an account that has an administrator role, you can perform switch enable
and disable functions and all switch port-level functions such as port enable and port disable. You
cannot perform fabric-wide management, as switch membership within a zone does not provide
zoning rights on the switch ports.
NOTE
Do not confuse an Admin Domain with the domain ID of a switch. They are two different identifiers.
Admin Domains are identified by a numeric ID (0–255) and also by name. This name can be
autogenerated based on the ID (for example AD1 or AD5) or you can specify a more informative
name such as
Accounting or Engineering.
AD0 is a special Admin Domain that contains all switches, ports, and devices that have not been
put into other Admin Domains. AD255, another special domain, is an unfiltered view of the entire
physical fabric.
NOTE
Some features work only in AD255 when user-defined domains are present, such as ACL
management.
By default, all fabric elements belong to AD0. In Fabric OS v5.2.0 and higher, a physical fabric
administrator with appropriate permissions can create up to 254 additional Admin Domains and
assign fabric resources to them (see
Chapter 7, “Managing Administrative Domains”
). Only users
who have been specifically assigned to those domains can view and modify the resources they
contain.
ADMIN DOMAINS AND LOGIN
You are always logged in to an Admin Domain, and you can view and modify only the devices in that
Admin Domain.
You can log in to only one Admin Domain at a time. When you log in, you select the Admin Domain
that you want to manage. You can later change the Admin Domain to which you are logged in.
If you have more than one Admin Domain, one of them will have been specified as your “home
Admin Domain.” Your home Admin Domain is the one you are automatically logged in to unless you
explicitly select a different one. If a home Admin Domain is deleted or deactivated, then by default
you will be logged in to the lowest numbered Admin Domain in your Admin Domain list. A home
Admin Domain, like the Admin Domain list, is a configurable property of a non-default user account.
For default accounts such as admin and user, the home Admin Domain defaults to AD0 and cannot
be changed. For user-defined accounts, the home Admin Domain also defaults to 0 but an
administrator can set the home Admin Domain to any Admin Domain to which the account has
been given access. The Admin Domain List for default admin accounts is 0–255, which gives
automatic access to any Admin Domain as soon as it is created, and makes them physical fabric
administrators. The Admin Domain list for the default user account is AD0 only. The Admin Domain
list property for default accounts also cannot be changed.
A “physical fabric administrator” is an admin role user whose account has access to all Admin
Domains (AD0-255) as soon as they are created. Only physical fabric administrators can create,
modify, delete, and activate or deactivate Admin Domains.