HP StorageWorks 8/80 Brocade Web Tools Administrator's Guide v6.2.0 (53-100119 - Page 243

Configuring Standard Security Features, In this User-defined accounts

Page 243 highlights

Chapter Configuring Standard Security Features 17 In this chapter •User-defined accounts 215 •Access control list policy configuration 225 •Authentication policy configuration 229 •SNMP configuration 232 •RADIUS service management 234 •Active Directory service management 237 •IPSec Concepts 239 •IPSec over FCIP 246 •IPSec over management ports 249 •Establishing authentication policies for HBAs 259 User-defined accounts In addition to the default accounts-root, factory, admin, and user-Fabric OS supports up to 256 user-defined accounts in each logical switch (domain). These accounts expand your ability to track account access and audit administrative activities. When the Virtual Fabrics capability is enabled, each user-defined account is associated with the following: • Virtual Fabric ID-Specifies which Virtual Fabrics a user account is allowed to log in to. • Home Virtual Fabric-Specifies the Virtual Fabric that the user is logged in to by default. • Role-Determines functional access levels within the Virtual Fabric. When the Admin Domain capability is enabled, each user-defined account is associated with the following: • Admin Domain list-Specifies what Admin Domains a user account is allowed to log in to. • Home Admin Domain-Specifies the Admin Domain that the user is logged in to by default. The home Admin Domain must be a member of the user's Admin Domain list. • Role-Determines functional access levels within the bounds of the user's current Admin Domain. NOTE Virtual Fabrics and Admin Domains are mutually exclusive. Access rights for any user session are determined both by the user's role-based access rights. See Chapter 1, "Introducing Web Tools" for additional information about Role-Based Access Control (RBAC). Web Tools Administrator's Guide 215 53-1001194-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314

Web Tools Administrator’s Guide
215
53-1001194-01
Chapter
17
Configuring Standard Security Features
In this chapter
User-defined accounts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215
Access control list policy configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . 225
Authentication policy configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 229
SNMP configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 232
RADIUS service management. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 234
Active Directory service management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 237
IPSec Concepts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 239
IPSec over FCIP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 246
IPSec over management ports. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 249
Establishing authentication policies for HBAs. . . . . . . . . . . . . . . . . . . . . . . 259
User-defined accounts
In addition to the default accounts—root, factory, admin, and user—Fabric OS supports up to 256
user-defined accounts in each logical switch (domain). These accounts expand your ability to track
account access and audit administrative activities.
When the Virtual Fabrics capability is enabled, each user-defined account is associated with the
following:
Virtual Fabric ID—Specifies which Virtual Fabrics a user account is allowed to log in to.
Home Virtual Fabric—Specifies the Virtual Fabric that the user is logged in to by default.
Role—Determines functional access levels within the Virtual Fabric.
When the Admin Domain capability is enabled, each user-defined account is associated with the
following:
Admin Domain list—Specifies what Admin Domains a user account is allowed to log in to.
Home Admin Domain—Specifies the Admin Domain that the user is logged in to by default. The
home Admin Domain must be a member of the user’s Admin Domain list.
Role—Determines functional access levels within the bounds of the user’s current Admin
Domain.
NOTE
Virtual Fabrics and Admin Domains are mutually exclusive.
Access rights for any user session are determined both by the user’s role-based access rights. See
Chapter 1, “Introducing Web Tools”
for additional information about Role-Based Access Control
(RBAC).