HP StorageWorks 2/16V Brocade Web Tools Administrator's Guide (53-0000194-01, - Page 38

Admin Domains and Zoning, Role-Based Access Control

Page 38 highlights

1 For example, if the switch WWN is: 10:00:00:60:69:e4:24:e0 then the converted WWN for that switch in AD1 is: 50:06:06:9e:42:4e:09:01 Admin Domains and Zoning Each Admin Domain has its own zone database, with both defined and effective zone configurations and all related zone objects (zones, zone aliases, and zone members). Within an Admin Domain, you can configure zoning only with the devices that are present in that Admin Domain. Before you implement Admin Domains, you must set the default zoning mode. See "Implementing Administrative Domains" on page 8-3 for additional information. You cannot perform all zoning operations from AD255. Role-Based Access Control Role-Based Access Control (RBAC) defines the capabilities that a user account has based on the role the account has been assigned. For each role, there is a set of pre-defined permissions on the jobs and tasks that can be performed on a fabric and its associated fabric elements. When you log in to a switch, your user account is associated with a pre-defined role. The role that your account is associated with determines the level of access you have on that switch and in the fabric. Following is a description of each of the roles: Admin You have full access to all of the Web Tools features. Operator You can perform any actions on the switch that do not affect the stored configuration. SwitchAdmin You can perform all actions on the switch, except the following: • You cannot modify zoning configurations. • You cannot create new accounts. • You cannot view or change account information for any accounts. You can only view your own account and change your account password. ZoneAdmin You can only create and modify zones. FabricAdmin You can do everything the Admin role can do except create new users. BasicSwichAdmin You have a subset of Admin level access. User You have nonadministrative access and can perform tasks such as monitoring system activity. For information about changing user account roles, see "Creating and Maintaining User-Defined Accounts" on page 17-1. 1-12 Web Tools Administrator's Guide Publication Number: 53-0000194-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308

1-12
Web Tools Administrator’s Guide
Publication Number: 53-0000194-01
1
For example, if the switch WWN is:
10:00:00:60:69:e4:24:e0
then the converted WWN for that switch in AD1 is:
50:06:06:9e:42:4e:09:01
Admin Domains and Zoning
Each Admin Domain has its own zone database, with both defined and effective zone configurations
and all related zone objects (zones, zone aliases, and zone members). Within an Admin Domain, you
can configure zoning only with the devices that are present in that Admin Domain.
Before you implement Admin Domains, you must set the default zoning mode. See
“Implementing
Administrative Domains”
on page 8-3 for additional information.
You cannot perform all zoning operations from AD255.
Role-Based Access Control
Role-Based Access Control (RBAC) defines the capabilities that a user account has based on the role
the account has been assigned. For each role, there is a set of pre-defined permissions on the jobs and
tasks that can be performed on a fabric and its associated fabric elements.
When you log in to a switch, your user account is associated with a pre-defined role. The role that your
account is associated with determines the level of access you have on that switch and in the fabric.
Following is a description of each of the roles:
Admin
You have full access to all of the Web Tools features.
Operator
You can perform any actions on the switch that do not affect the stored configuration.
SwitchAdmin
You can perform all actions on the switch, except the following:
You cannot modify zoning configurations.
You cannot create new accounts.
You cannot view or change account information for any accounts. You can only
view your own account and change your account password.
ZoneAdmin
You can only create and modify zones.
FabricAdmin
You can do everything the Admin role can do except create new users.
BasicSwichAdmin
You have a subset of Admin level access.
User
You have nonadministrative access and can perform tasks such as monitoring system
activity.
For information about changing user account roles, see
“Creating and Maintaining User-Defined
Accounts”
on page 17-1.