HP StorageWorks 2/24 FW 07.00.00/HAFM SW 08.06.00 McDATA Products in a SAN Env - Page 221

Security Provisions, Password Protection

Page 221 highlights

Physical Planning Considerations 5 Security Provisions Security provisions are available to restrict unauthorized access to a director, switch, or attached Fibre Channel devices. Access to the director or switch (through the SAN management application, Element Manager application, or SANpilot interface) is restricted by implementing password protection. Access to attached computing resources (including applications and data) is restricted by implementing one or more of the following security provisions: - SANtegrity Authentication. - SANtegrity Binding. - Prohibit dynamic connectivity mask (PDCM) arrays. - Preferred path. - Zoning. - Server and storage-level access control. Password Protection Access to the SAN management and Element Manager applications requires configuration of a user name and password. Up to 16 user names and associated passwords can be configured. Each user is assigned rights that allow access to specific sets of product management operations. Table 5-2 explains the types of user rights available. A user may have more than one set of user rights granted. Table 5-2 Types of User Rights User Right View Only Operator Product Administrator System Administrator Maintenance Operator Access Allowed The user may view product configurations and status but may not make changes. These rights are the default if no other user rights are assigned. The operator may view status and configuration information through the Element Manager application and perform operational control changes such as blocking ports and placing the product online or offline. The product administrator can make control and configuration changes through the Element Manager application. The system administrator can make control and configuration changes, define users and passwords, and add or remove products through the SAN management application. The maintenance operator can perform product control and configuration changes through the Element Manager application and perform diagnostics, maintenance functions, firmware loads, and data collection. Physical Planning Considerations 5-15

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322

5
Physical Planning Considerations
5-15
Physical Planning Considerations
Security Provisions
Security provisions are available to restrict unauthorized access to
a director, switch, or attached Fibre Channel devices. Access to the
director or switch (through the SAN management application,
Element Manager application, or SANpilot interface) is restricted by
implementing password protection. Access to attached computing
resources (including applications and data) is restricted by
implementing one or more of the following security provisions:
SANtegrity Authentication.
SANtegrity Binding.
Prohibit dynamic connectivity mask (PDCM) arrays.
Preferred path.
— Zoning.
Server and storage-level access control.
Password Protection
Access to the SAN management and Element Manager applications
requires configuration of a user name and password. Up to 16 user
names and associated passwords can be configured. Each user is
assigned rights that allow access to specific sets of product
management operations.
Table 5-2
explains the types of user rights
available. A user may have more than one set of user rights granted.
Table 5-2
Types of User Rights
User Right
Operator Access Allowed
View Only
The user may view product configurations and status but may not make changes. These rights are the default
if no other user rights are assigned.
Operator
The operator may view status and configuration information through the Element Manager application and
perform operational control changes such as blocking ports and placing the product online or offline.
Product
Administrator
The product administrator can make control and configuration changes through the Element Manager
application.
System
Administrator
The system administrator can make control and configuration changes, define users and passwords, and add
or remove products through the SAN management application.
Maintenance
The maintenance operator can perform product control and configuration changes through the Element
Manager application and perform diagnostics, maintenance functions, firmware loads, and data collection.