HP StorageWorks 2/16V Brocade Fabric Manager Administrator's Guide (53-1000019 - Page 253

Managing Secure Fabrics, Enabling Secure Mode

Page 253 highlights

Managing Secure Fabrics Chapter 17 This chapter provides information on enabling secure mode for a fabric, adding a switch to a secure fabric, and checking secure fabrics prior to merging them. It also includes information about using the policy editor to configure security policies, and provides instructions on how to configure no node WWN zoning, how to change admin security passwords (for FCS or non-FCS switches/directors), and how to use telnet on a secure fabric. See the following sections for specific secure fabric information: • "Enabling Secure Mode" on page 17-1 • "Using the Policy Editor" on page 17-3 • "Adding a Switch to a Secure Fabric" on page 17-17 • "Merging Secure Fabrics" on page 17-18 • "Using Telnet on a Secure Fabric" on page 17-19 Enabling Secure Mode This section describes how to create a secure fabric using the Secure Fabric wizard. To use the Secure Fabric wizard, your primary FCS switch must be running Fabric OS v5.0.0 or later, Fabric OS v4.4.0 or later, or Fabric OS v3.2x or later. If your primary FCS switch is not running one of these operating systems, you must enable or disable secure mode using the CLI. See the Secure Fabric OS Administrator's Guide for CLI information. All switches in the fabric must be running Fabric OS v5.0.0 or later, Fabric OS v4.1x or later, Fabric OS V3.1x or later, or Fabric OS v2.6.1x or later regardless of whether you are using CLI or the Secure Fabric wizard. If you enable secure mode on a fabric that contains any Fabric OS v5.2.x switches, any switch local ACL policies (SCC, DCC, and Distributed Passwords) are discarded. You cannot enable secure mode under the following conditions: • You cannot enable secure mode on a fabric unless all switches in the fabric have a Secure Fabric OS license, a zoning license, and security certificates installed. For more information about security certificates, see the Secure Fabric OS Administrator's Guide. • You cannot enable secure mode for an edge fabric that is configured for Fibre Channel routing. See "FC-FC Routing and Secure Fabrics" on page 19-12 for additional limitations when using the FCFC Routing Service and secure fabrics. • You cannot enable secure mode on Admin Domain-aware fabrics. • You cannot enable secure mode if a fabric-wide consistency policy is configured on the switch. Fabric Manager Administrator's Guide Publication Number: 53-1000196-01-HP 17-1

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406

Fabric Manager Administrator’s Guide
17-1
Publication Number: 53-1000196-01-HP
Chapter
17
Managing Secure Fabrics
This chapter provides information on enabling secure mode for a fabric, adding a switch to a secure
fabric, and checking secure fabrics prior to merging them. It also includes information about using the
policy editor to configure security policies, and provides instructions on how to configure no node
WWN zoning, how to change admin security passwords (for FCS or non-FCS switches/directors), and
how to use telnet on a secure fabric. See the following sections for specific secure fabric information:
“Enabling Secure Mode” on page 17-1
“Using the Policy Editor” on page 17-3
“Adding a Switch to a Secure Fabric” on page 17-17
“Merging Secure Fabrics” on page 17-18
“Using Telnet on a Secure Fabric” on page 17-19
Enabling Secure Mode
This section describes how to create a secure fabric using the Secure Fabric wizard.
To use the Secure Fabric wizard, your primary FCS switch must be running Fabric OS v5.0.0 or later,
Fabric OS v4.4.0 or later, or Fabric OS v3.2x or later. If your primary FCS switch is not running one of
these operating systems, you must enable or disable secure mode using the CLI. See the
Secure Fabric
OS Administrator’s Guide
for CLI information.
All switches in the fabric must be running Fabric OS v5.0.0 or later, Fabric OS v4.1x or later, Fabric OS
V3.1x or later, or Fabric OS v2.6.1x or later regardless of whether you are using CLI or the Secure
Fabric wizard.
If you enable secure mode on a fabric that contains any Fabric OS v5.2.x switches, any switch local
ACL policies (SCC, DCC, and Distributed Passwords) are discarded.
You cannot enable secure mode under the following conditions:
You cannot enable secure mode on a fabric unless all switches in the fabric have a Secure Fabric OS
license, a zoning license, and security certificates installed. For more information about security
certificates, see the
Secure Fabric OS Administrator’s Guide
.
You cannot enable secure mode for an edge fabric that is configured for Fibre Channel routing. See
“FC-FC Routing and Secure Fabrics” on page 19-12
for additional limitations when using the FC-
FC Routing Service and secure fabrics.
You cannot enable secure mode on Admin Domain-aware fabrics.
You cannot enable secure mode if a fabric-wide consistency policy is configured on the switch.