HP StorageWorks 8/80 HP StorageWorks Fabric OS 6.2 administrator guide (5697-0 - Page 119

Configuring advanced security features

Page 119 highlights

4 Configuring advanced security features This chapter provides information and procedures for configuring advanced Fabric OS security features such as Access Control List (ACL) policies, authentication policies, and IP Filtering for HP's Fibre Channel switches. ACL policies overview Each supported Access Control List (ACL) policy listed below is identified by a specific name. Only one policy of each type can exist, except for DCC policies. Policy names are case-sensitive and must be entered in all uppercase. Fabric OS provides the following policies: • Fabric configuration server (FCS) policy - Used to restrict which switches can change the configuration of the fabric. • Device connection control (DCC) policies - Used to restrict which Fibre Channel device ports can connect to which Fibre Channel switch ports. • Switch connection control (SCC) policy - Used to restrict which switches can join with another switch. • IP filter policy (IPFilter) policy - Used to filter traffic based on IP addresses. NOTE: Run all commands in this chapter by logging in to Administrative Domain (AD) 255 with the suggested role. If Administrative Domains have not been implemented, log in to AD0. How the ACL policies are stored The ACL policies are stored in a local database. The database contains the ACL policy types FCS, DCC, SCC, and IPFilter. The number of policies that may be defined is limited by the size of the database. FCS, SCC, and DCC policies are all stored in the same database. When a Fabric OS 6.2.0 switch joins the fabric containing only pre-6.0.0 switches, the policy database size limit is restricted to the Fabric OS version's smallest database size. Table 24 shows the Fabric OS version and its associated database size restriction. Distribution of any of the given policies to pre-6.0.0 switches would fail if the size of the database being distributed is greater than the smallest database size in the fabric. In a fabric with Fabric OS 6.0.0 and later switches present, the limit for security policy database size is set to 1Mb. In this case, the pre-6.0.0 switches cannot join the fabric if the fabric security database size is greater than their Fabric OS database size. Table 24 Security database size restrictions Fabric OS version Security database size 4.4.0 5.1.0/5.2.0/5.3.0 6.0.0/6.1.0/6.1.1 6.2.0 256K 256K 1Mb 1Mb per switch and Logical Switch The policies are grouped by state and type. A policy can be in either of the following states: • Active, which means the policy is being enforced by the switch. • Defined, which means the policy has been set up but is not enforced. A group of policies is called a Policy Set. Each switch has the following two sets: • Active policy set, which contains ACL policies being enforced by the switch. • Defined policy set, which contains a copy of all ACL policies on the switch. Fabric OS 6.2 administrator guide 117

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576

Fabric OS 6.2 administrator guide
117
4
Configuring advanced security features
This chapter provides information and procedures for configuring advanced Fabric OS security features
such as Access Control List (ACL) policies, authentication policies, and IP Filtering for HP’s Fibre Channel
switches.
ACL policies overview
Each supported Access Control List (ACL) policy listed below is identified by a specific name. Only one
policy of each type can exist, except for DCC policies. Policy names are case-sensitive and must be entered
in all uppercase. Fabric OS provides the following policies:
Fabric configuration server
(FCS) policy — Used to restrict which switches can change the configuration
of the fabric.
Device connection control
(DCC) policies — Used to restrict which Fibre Channel device ports can
connect to which Fibre Channel switch ports.
Switch connection control
(SCC) policy — Used to restrict which switches can join with another switch.
IP filter policy
(IPFilter) policy — Used to filter traffic based on IP addresses.
NOTE:
Run all commands in this chapter by logging in to Administrative Domain (AD) 255 with the
suggested role. If Administrative Domains have not been implemented, log in to AD0.
How the ACL policies are stored
The ACL policies are stored in a local database. The database contains the ACL policy types FCS, DCC,
SCC, and IPFilter. The number of policies that may be defined is limited by the size of the database. FCS,
SCC, and DCC policies are all stored in the same database.
When a Fabric OS 6.2.0 switch joins the fabric containing only pre-6.0.0 switches, the policy database
size limit is restricted to the Fabric OS version’s smallest database size.
Table 24
shows the Fabric OS
version and its associated database size restriction. Distribution of any of the given policies to pre-6.0.0
switches would fail if the size of the database being distributed is greater than the smallest database size
in the fabric. In a fabric with Fabric OS 6.0.0 and later switches present, the limit for security policy
database size is set to 1Mb. In this case, the pre-6.0.0 switches cannot join the fabric if the fabric security
database size is greater than their Fabric OS database size.
The policies are grouped by state and type. A policy can be in either of the following states:
Active
, which means the policy is being enforced by the switch.
Defined
, which means the policy has been set up but is not enforced.
A group of policies is called a
Policy Set
. Each switch has the following two sets:
Active policy set
,
which contains ACL policies being enforced by the switch.
Defined policy set
,
which contains a copy of all ACL policies on the switch.
Table 24
Security database size restrictions
Fabric OS version
Security database size
4.4.0
256K
5.1.0/5.2.0/5.3.0
256K
6.0.0/6.1.0/6.1.1
1Mb
6.2.0
1Mb per switch and Logical Switch