HP StorageWorks 2/16V Brocade Web Tools Administrator's Guide - Supporting Fab - Page 33

Admin Domains and switch WWN, Admin domains and zoning, Role-Based access control

Page 33 highlights

Role-Based access control 1 ADMIN DOMAINS AND SWITCH WWN Admin Domains are treated as fabrics. Because switches cannot belong to more than one fabric, switch WWNs (world-wide names) are converted so that they appear as unique entities in different Admin Domains (fabrics). The switch WWN is in the following format: 10:00:nn:nn:nn:nn:nn:nn In an Admin Domain context, the switch WWN is converted from NAA=1 to NAA=5 format, with the Admin Domain number added, using the following syntax: 5n:nn:nn:nn:nn:nn:n9:xx where xx is the AdminDomain_number. For example, if the switch WWN is: 10:00:00:60:69:e4:24:e0 then the converted WWN for that switch in AD1 is: 50:06:06:9e:42:4e:09:01 ADMIN DOMAINS AND ZONING Each Admin Domain has its own zone database, with both defined and effective zone configurations and all related zone objects (zones, zone aliases, and zone members). Within an Admin Domain, you can configure zoning only with the devices that are present in that Admin Domain. Before you implement Admin Domains, you must set the default zoning mode. See "Implementing administrative domains" on page 83 for additional information. You cannot perform any zoning operations from AD255. Role-Based access control Role-Based Access Control (RBAC) defines the capabilities that a user account has based on the role the account has been assigned. For each role, there is a set of pre-defined permissions on the jobs and tasks that can be performed on a fabric and its associated fabric elements. When you log in to a switch, your user account is associated with a pre-defined role. The role that your account is associated with determines the level of access you have on that switch and in the fabric. Following is a description of each of the roles: admin You have full access to all of the Web Tools features. operator You can perform any actions on the switch that do not affect the stored configuration. securityadmin You can perform actions that do not affect the stored configuration. Web Tools Administrator's Guide 11 Publication Number: 53-1000435-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266

Web Tools Administrator’s Guide
11
Publication Number: 53-1000435-01
Role-Based access control
1
ADMIN DOMAINS AND SWITCH WWN
Admin Domains are treated as fabrics. Because switches cannot belong to more than one fabric,
switch WWNs (world-wide names) are converted so that they appear as unique entities in different
Admin Domains (fabrics).
The switch WWN is in the following format:
10:00:
nn
:
nn
:
nn
:
nn
:
nn
:
nn
In an Admin Domain context, the switch WWN is converted from NAA=1 to NAA=5 format, with the
Admin Domain number added, using the following syntax:
5
n
:
nn
:
nn
:
nn
:
nn
:
nn
:
n
9:
xx
where
xx
is the AdminDomain_number.
For example, if the switch WWN is:
10:00:00:60:69:e4:24:e0
then the converted WWN for that switch in AD1 is:
50:06:06:9e:42:4e:09:01
ADMIN DOMAINS AND ZONING
Each Admin Domain has its own zone database, with both defined and effective zone
configurations and all related zone objects (zones, zone aliases, and zone members). Within an
Admin Domain, you can configure zoning only with the devices that are present in that Admin
Domain.
Before you implement Admin Domains, you must set the default zoning mode. See
“Implementing
administrative domains”
on page 83 for additional information.
You cannot perform any zoning operations from AD255.
Role-Based access control
Role-Based Access Control (RBAC) defines the capabilities that a user account has based on the
role the account has been assigned. For each role, there is a set of pre-defined permissions on the
jobs and tasks that can be performed on a fabric and its associated fabric elements.
When you log in to a switch, your user account is associated with a pre-defined role. The role that
your account is associated with determines the level of access you have on that switch and in the
fabric. Following is a description of each of the roles:
admin
You have full access to all of the Web Tools features.
operator
You can perform any actions on the switch that do not affect the stored
configuration.
securityadmin
You can perform actions that do not affect the stored configuration.