HP StorageWorks 2/24 FW 07.00.00/HAFM SW 08.06.00 McDATA Products in a SAN Env - Page 55

Serviceability Features, Serviceability, Features

Page 55 highlights

Serviceability Features Introduction to McDATA Multi-Protocol Products 1 • Audit log tracking - Configuration changes to a director or fabric switch are recorded in an audit log stored on the management server. Users can display the audit log through the Element Manager application. Log entries include the date and time of the configuration change, a description of the change, and the source of the change. NOTE: SAN routers do not support audit log tracking. • Zoning - System administrators can create zones that provide product access control to increase network security, differentiate between operating systems, and prevent data loss or corruption. Zoning can be implemented in conjunction with server-level access control and storage device access control. • SANtegrity® Authentication - This feature enhances SAN security by providing password safety; challenge handshake authentication protocol (CHAP) verification for fabric elements, management servers, and devices; a product control point (PCP) user database; common transport (CT) authentication for the open-system management server (OSMS) interface; remote authentication dial-in user service (RADIUS) server support (to store and authenticate passwords and CHAP secrets); inband and out-of-band access controls lists; encrypted secure shell (SSH) protocol; and security logging. • SANtegrity Binding - This feature enhances data security (in addition to SANtegrity Authentication) in large and complex SANs that are comprised of numerous fabrics and devices provided by multiple OEMs. The feature allows or prohibits director or fabric switch attachment to fabrics (fabric binding) and allows Fibre Channel device attachment to directors or fabric switches (switch binding). NOTE: SAN routers do not support the SANtegrity Binding feature. SAN routers support port binding only for R_Ports. McDATA directors, fabric switches, SAN routers, and the SAN management and Element Manager applications offer the following general serviceability features. Products or product classes that do not support a serviceability feature are noted. Introduction to McDATA Multi-Protocol Products 1-29

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322

1
Introduction to McDATA Multi-Protocol Products
1-29
Introduction to McDATA Multi-Protocol Products
Audit log tracking -
Configuration changes to a director or fabric
switch are recorded in an audit log stored on the management
server. Users can display the audit log through the Element
Manager application. Log entries include the date and time of the
configuration change, a description of the change, and the source
of the change.
NOTE:
SAN routers do not support audit log tracking.
Zoning -
System administrators can create zones that provide
product access control to increase network security, differentiate
between operating systems, and prevent data loss or corruption.
Zoning can be implemented in conjunction with server-level
access control and storage device access control.
SANtegrity
®
Authentication -
This feature enhances SAN
security by providing password safety; challenge handshake
authentication protocol (CHAP) verification for fabric elements,
management servers, and devices; a product control point (PCP)
user database; common transport (CT) authentication for the
open-system management server (OSMS) interface; remote
authentication dial-in user service (RADIUS) server support (to
store and authenticate passwords and CHAP secrets); inband and
out-of-band access controls lists; encrypted secure shell (SSH)
protocol; and security logging.
SANtegrity Binding -
This feature enhances data security
(in addition to SANtegrity Authentication) in large and complex
SANs that are comprised of numerous fabrics and devices
provided by multiple OEMs. The feature allows or prohibits
director or fabric switch attachment to fabrics (fabric binding) and
allows Fibre Channel device attachment to directors or fabric
switches (switch binding).
NOTE:
SAN routers do not support the SANtegrity Binding feature.
SAN routers support port binding only for R_Ports.
Serviceability
Features
McDATA directors, fabric switches, SAN routers, and the SAN
management and Element Manager applications offer the following
general serviceability features. Products or product classes that do
not support a serviceability feature are noted.