HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.X Procedures User Guide (AA- - Page 124

Controlling access, Displaying the management server ACL, Adding a member to the ACL

Page 124 highlights

For example: switch:admin> msplmgmtdeactivate MS Platform Service is currently enabled. This will erase MS Platform Service configuration information as well as database in the entire fabric. Would you like to continue this operation? (yes, y, no, n): [no] y Request to deactivate MS Platform Service in progress...... *Completed deactivating MS Platform Service in the fabric! switch:admin> Controlling access You can use the msConfigure command to control access to the management server database. An ACL of WWN addresses determines which systems have access to the management server database. The ACL typically contains those WWNs of host systems that are running management applications. If the list is empty (the default), the management server is accessible to all systems connected in-band to the fabric. For more access security, you can specify WWNs in the ACL so that access to the management server is restricted only to those WWNs listed. The ACL is switch-based. Therefore, only hosts that are connected directly to the switch are affected by the ACL. A host that is somewhere else in the fabric and is connected to a switch with an empty ACL is allowed to access the management server. NOTE: The msConfigure command is disabled if the switch is in secure mode. See the HP StorageWorks Secure Fabric OS administrator guide for more information. Displaying the management server ACL 1. Connect to the switch and log in as admin. 2. Issue the msConfigure command. The command becomes interactive. 3. At the select prompt, enter 1 to display the access list. A list of WWNs that have access to the management server is displayed. In the following example, the list is empty: switch:admin> msconfigure 0 Done 1 Display the access list 2 Add member based on its Port/Node WWN 3 Delete member based on its Port/Node WWN select : (0..3) [1] 1 MS Access list is empty. 0 Done 1 Display the access list 2 Add member based on its Port/Node WWN 3 Delete member based on its Port/Node WWN done ... switch:admin> Adding a member to the ACL 1. Connect to the switch and log in as admin. 2. Issue the msConfigure command. The command becomes interactive. 124 Configuring the Distributed Management Server

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

124
Configuring the Distributed Management Server
For example:
Controlling access
You can use the
msConfigure
command to control access to the management server database.
An ACL of WWN addresses determines which systems have access to the management server database.
The ACL typically contains those WWNs of host systems that are running management applications.
If the list is empty (the default), the management server is accessible to all systems connected in-band to
the fabric. For more access security, you can specify WWNs in the ACL so that access to the
management server is restricted only to those WWNs listed.
The ACL is switch-based. Therefore, only hosts that are connected directly to the switch are affected by the
ACL. A host that is somewhere else in the fabric and is connected to a switch with an empty ACL is
allowed to access the management server.
NOTE:
The
msConfigure
command is disabled if the switch is in secure mode. See the
HP
StorageWorks Secure Fabric OS administrator guide
for more information.
Displaying the management server ACL
1.
Connect to the switch and log in as admin.
2.
Issue the
msConfigure
command.
The command becomes interactive.
3.
At the
select
prompt, enter
1
to display the access list.
A list of WWNs that have access to the management server is displayed.
In the following example, the list is empty:
Adding a member to the ACL
1.
Connect to the switch and log in as admin.
2.
Issue the
msConfigure
command.
The command becomes interactive.
switch:admin>
msplmgmtdeactivate
MS Platform Service is currently enabled.
This will erase MS Platform Service configuration
information as well as database in the entire fabric.
Would you like to continue this operation? (yes, y, no, n): [no]
y
Request to deactivate MS Platform Service in progress
......
*Completed deactivating MS Platform Service in the fabric!
switch:admin>
switch:admin>
msconfigure
0
Done
1
Display the access list
2
Add member based on its Port/Node WWN
3
Delete member based on its Port/Node WWN
select : (0..3) [1]
1
MS Access list is empty.
0
Done
1
Display the access list
2
Add member based on its Port/Node WWN
3
Delete member based on its Port/Node WWN
done ...
switch:admin>