HP StorageWorks 8/80 HP StorageWorks Fabric OS 6.1.x administrator guide (5697 - Page 110

Distributing an FCS policy

Page 110 highlights

This displays the WWNs of the current primary FCS switch and backup FCS switches. 3. Type secPolicyFCSMove; then provide the current position of the switch in the list and the desired position at the prompts. Alternatively, enter secPolicyFCSMove "From, To". From is the current position in the list of the FCS switch and To is the desired position in the list for this switch. For example, to move a backup FCS switch from position 2 to position 3 in the FCS list, using interactive mode: primaryfcs:admin> secpolicyfcsmove Pos Primary WWN DIdswName. 1 Yes 10:00:00:60:69:10:02:181switch5. 2 No 10:00:00:60:69:00:00:5a2switch60. 3 No 10:00:00:60:69:00:00:133switch73. Please enter position you'd like to move from : (1..3) [1] 2 Please enter position you'd like to move to : (1..3) [1] 3 DEFINED POLICY SET FCS_POLICY Pos PrimaryWWN DIdswName 1 Yes 10:00:00:60:69:10:02:181switch5. 2 No 10:00:00:60:69:00:00:133switch73. 3 No 10:00:00:60:69:00:00:5a2switch60. 4. Type secPolicyActivate. Distributing an FCS policy The FCS policy can be automatically distributed using the fddcfg --fabswideset command or it can be manually distributed to the switches using the distribute -p command. Each switch that receives the FCS policy must be configured to receive the policy. To configure the switch to accept distribution of the FCS policy, refer to "Configuring the database distribution settings" on page 129. Switches in the fabric are designated as either a Primary FCS, backup FCS, or non-FCS switch. Database distributions may be initiated from only the primary FCS switch. FCS policy configuration and management is performed using the command line or a manageability interface. Only the primary FCS switch is allowed to distribute the database. The FCS policy may need to be manually distributed across the fabric using the distribute -p command if there is no support for automatic distribution in a mixed environment with 5.3.0 and pre-5.3.0 switches. Since this policy is distributed manually, the command fddcfg --fabwideset is used to distribute a fabric-wide consistency policy for FCS policy in an environment consisting of only Fabric OS 6.0 and later switches. FCS enforcement for the distribute command is handled differently for FCS and other databases in an FCS fabric: • For an FCS database, the enforcement allows any switch to initiate the distribution. This is to support FCS policy creation specifying a remote switch as Primary. • For other database distributions, only the primary FCS switch can initiate the distribution. There will be FCS enforcement at the receiving switch, so the switch will verify whether the distribution is coming from the primary FCS switch before accepting it. Distribution is accepted only if it is coming from a primary FCS switch. Distribution of FCS policy can still be accepted from a backup FCS switch if the Primary is not reachable or from a non-FCS switch if the Primary FCS and none of the backup FCS switches are reachable. To learn more about how to distribute policies, refer to "Distributing ACL policies to other switches" on page 130. 110 Configuring advanced security features

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492

110
Configuring advanced security features
This displays the WWNs of the current primary FCS switch and backup FCS switches.
3.
Type
secPolicyFCSMove
; then provide the current position of the switch in the list and the desired
position at the prompts.
Alternatively, enter
secPolicyFCSMove
From, To
.
From
is the current position in the list of the
FCS switch and
To
is the desired position in the list for this switch.
For example, to move a backup FCS switch from position 2 to position 3 in the FCS list, using
interactive mode:
primaryfcs:admin>
secpolicyfcsmove
PosPrimary WWN
DIdswName.
=================================================
1 Yes
10:00:00:60:69:10:02:181switch5.
2 No
10:00:00:60:69:00:00:5a2switch60.
3 No
10:00:00:60:69:00:00:133switch73.
Please enter position you’d like to move from : (1..3) [1]
2
Please enter position you’d like to move to : (1..3) [1]
3
____________________________________________________
DEFINED POLICY SET
FCS_POLICY
PosPrimaryWWN
DIdswName
__________________________________________________
1 Yes
10:00:00:60:69:10:02:181switch5.
2 No
10:00:00:60:69:00:00:133switch73.
3 No
10:00:00:60:69:00:00:5a2switch60.
____________________________________________________
4.
Type
secPolicyActivate
.
Distributing an FCS policy
The FCS policy can be automatically distributed using the
fddcfg
--
fabswideset
command or it can
be manually distributed to the switches using the
distribute -p
command. Each switch that receives
the FCS policy must be configured to receive the policy. To configure the switch to accept distribution of the
FCS policy, refer to ”
Configuring the database distribution settings
” on page 129.
Switches in the fabric are designated as either a Primary FCS, backup FCS, or non-FCS switch. Database
distributions may be initiated from only the primary FCS switch. FCS policy configuration and management
is performed using the command line or a manageability interface.
Only the primary FCS switch is allowed to distribute the database. The FCS policy may need to be
manually distributed across the fabric using the
distribute -p
command if there is no support for
automatic distribution in a mixed environment with 5.3.0 and pre-5.3.0 switches. Since this policy is
distributed manually, the command
fddcfg –-fabwideset
is
used to distribute a fabric-wide
consistency policy for FCS policy in an environment consisting of only Fabric OS 6.0 and later switches.
FCS enforcement for the
distribute
command is handled differently for FCS and other databases in an
FCS fabric:
For an FCS database, the enforcement allows any switch to initiate the distribution. This is to support
FCS policy creation specifying a remote switch as Primary.
For other database distributions, only the primary FCS switch can initiate the distribution.
There will be FCS enforcement at the receiving switch, so the switch will verify whether the distribution is
coming from the primary FCS switch before accepting it. Distribution is accepted only if it is coming from a
primary FCS switch. Distribution of FCS policy can still be accepted from a backup FCS switch if the
Primary is not reachable or from a non-FCS switch if the Primary FCS and none of the backup FCS switches
are reachable. To learn more about how to distribute policies, refer to ”
Distributing ACL policies to other
switches
” on page 130.