HP StorageWorks 2/16V Brocade Secure Fabric OS Administrator's Guide (53-10002 - Page 103

Removing Secure Fabric OS Capability, Preparing the Fabric for Removal of Secure Fabric OS Policies

Page 103 highlights

Removing Secure Fabric OS Capability Appendix A You cannot remove Secure Fabric OS capability from a fabric by disabling secure mode and deactivating the Secure Fabric OS license keys on the individual switches. Removing Secure Fabric OS capability is not recommended unless absolutely required. If at all possible, consider disabling only secure mode and leaving the Secure Fabric OS feature available so that secure mode can be reenabled if desired. One possible reason for disabling secure mode or removing Fabric OS capability includes the addition of new switches to the fabric that do not support Secure Fabric OS. Disabling secure mode includes the following tasks: • "Preparing the Fabric for Removal of Secure Fabric OS Policies," next • "Disabling Secure Mode" on page A-2 In addition, undertake the following tasks if desired: • "Deactivating the Secure Fabric OS License on Each Switch" on page A-3 • "Uninstalling Related Items from the Host" on page A-3 Preparing the Fabric for Removal of Secure Fabric OS Policies Note This section provides general recommendations only. For best-practice information, refer to the SOLUTIONware and other documentation provided on the Brocade Partner Web site. The following tasks are recommended to prepare the fabric before disabling secure mode: • Review the current Secure Fabric OS policies and the devices and users affected by each policy. The current policy set can be displayed by entering the secPolicyDump command. • Review the types of attempted policy violations that have been occurring. The current Secure Fabric OS statistics can be displayed by entering the secStatsShow command. • Evaluate the zoning configuration and other aspects of the fabric for any changes that could be implemented to decrease the chance of security violations when Secure Fabric OS is disabled. • Educate users to minimize security risks and the impact of any security violations. Secure Fabric OS Administrator's Guide A-1 Publication Number: 53-1000244-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

Secure Fabric OS Administrator’s Guide
A-1
Publication Number: 53-1000244-01
Appendix
A
Removing Secure Fabric OS Capability
You cannot remove Secure Fabric OS capability from a fabric by disabling secure mode and
deactivating the Secure Fabric OS license keys on the individual switches. Removing Secure Fabric OS
capability is not recommended unless absolutely required. If at all possible, consider disabling only
secure mode and leaving the Secure Fabric OS feature available so that secure mode can be reenabled if
desired.
One possible reason for disabling secure mode or removing Fabric OS capability includes the addition
of new switches to the fabric that do not support Secure Fabric OS.
Disabling secure mode includes the following tasks:
“Preparing the Fabric for Removal of Secure Fabric OS Policies,”
next
“Disabling Secure Mode”
on page A-2
In addition, undertake the following tasks if desired:
“Deactivating the Secure Fabric OS License on Each Switch”
on page A-3
“Uninstalling Related Items from the Host”
on page A-3
Preparing the Fabric for Removal of
Secure Fabric OS Policies
The following tasks are recommended to prepare the fabric before disabling secure mode:
Review the current Secure Fabric OS policies and the devices and users affected by each policy.
The current policy set can be displayed by entering the
secPolicyDump
command.
Review the types of attempted policy violations that have been occurring. The current Secure
Fabric OS statistics can be displayed by entering the
secStatsShow
command.
Evaluate the zoning configuration and other aspects of the fabric for any changes that could be
implemented to decrease the chance of security violations when Secure Fabric OS is disabled.
Educate users to minimize security risks and the impact of any security violations.
Note
This section provides general recommendations only. For best-practice information, refer to the
SOLUTIONware and other documentation provided on the Brocade Partner Web site.