HP StorageWorks 8/80 HP StorageWorks Fabric OS 6.2 administrator guide (5697-0 - Page 121

Displaying ACL policies, FCS policies

Page 121 highlights

and switches that are not listed in that policy. You can remove one or more members from a policy. If all members are removed from a policy, that aspect of the fabric becomes closed to all access. • "Policy database distribution" on page 139 discusses the configuration of a switch to accept or reject the distribution of polices. • "ACL policy distribution to other switches" on page 142 discusses the configuration of the distribution of policies to switches within the fabric. Displaying ACL policies 1. Connect to the switch and log in using an account assigned to the admin role. 2. Enter the secPolicyShow command: switch:admin> secPolicyShow ACTIVE POLICY SET DEFINED POLICY SET FCS policies Fabric Configuration Server (FCS) policy in base Fabric OS may be performed on a local switch basis and may be performed on any switch in the fabric with Fabric OS 6.0.0 or later. Any switch with a pre-5.3.0 version of Fabric OS cannot be included in the FCS list. The FCS policy is not present by default, but must be created. When the FCS policy is created, the WWN of the local switch is automatically included in the FCS list. Additional switches can be included in the FCS list. The first switch in the list becomes the Primary FCS switch. Only the Primary FCS switch is allowed to modify and distribute the database within the fabric. Automatic distribution is supported, and you can either configure the switches in your fabric to accept the FCS policy or manually distribute the FCS policy. Changes made to the FCS policy are saved to permanent memory only after the changes have been saved or activated; they can be aborted later if you have set your fabric to distribute the changes manually. Table 26 shows the characteristics of policy states. Table 26 FCS policy states Policy state Characteristics No active policy Any switch can perform fabric-wide configuration changes. Active policy with one entry Active policy with multiple entries A Primary FCS switch is designated (local switch), but there are no backup FCS switches. If the Primary FCS switch becomes unavailable for any reason, the fabric is left without an FCS switch. A Primary FCS switch and one or more backup FCS switches are designated. If the Primary FCS switch becomes unavailable, the next switch in the list becomes the Primary FCS switch. The FCS policy is designed to accommodate mixed fabric environments that contain switches with pre-5.3.0 and later versions of Fabric OS. By setting the configuration parameters to accept fabric distribution, Fabric OS 6.0.0 and later switches may enforce FCS policy and perform database distribution among 5.3.0 and 6.0.0 and later switches while still allowing pre-5.3.0 switches to join the fabric. The following items describe distribution behavior for pre-5.3.0. • Distribution to pre-5.3.0 switches with specific domain IDs When specific domain IDs are given for the distribution, all domains must be on a switch with Fabric OS 5.3.0 or later. If one of the domains is pre-5.3.0 the distribution operation will fail. • Distribution to pre-5.3.0 switches using the wild card (*) character When the wild card character is specified, distribution succeeds even if the fabric contains pre-5.3.0 switches. However, the FCS database is sent only to switches with a Fabric OS of 5.2.0 or later in the Fabric OS 6.2 administrator guide 119

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576

Fabric OS 6.2 administrator guide
119
and switches that are not listed in that policy. You can remove one or more members from a policy. If all
members are removed from a policy, that aspect of the fabric becomes closed to all access.
Policy database distribution
” on page 139 discusses the configuration of a switch to accept or reject
the distribution of polices.
ACL policy distribution to other switches
” on page 142 discusses the configuration of the distribution of
policies to switches within the fabric.
Displaying ACL policies
1.
Connect to the switch and log in using an account assigned to the admin role.
2.
Enter the
secPolicyShow
command:
switch:admin>
secPolicyShow
____________________________________________________
ACTIVE POLICY SET
____________________________________________________
DEFINED POLICY SET
FCS policies
Fabric Configuration Server (FCS) policy in base Fabric OS may be performed on a local switch basis and
may be performed on any switch in the fabric with Fabric OS 6.0.0 or later. Any switch with a pre-5.3.0
version of Fabric OS cannot be included in the FCS list.
The FCS policy is not present by default, but must be created. When the FCS policy is created, the WWN
of the local switch is automatically included in the FCS list. Additional switches can be included in the FCS
list. The first switch in the list becomes the Primary FCS switch.
Only the Primary FCS switch is allowed to modify and distribute the database within the fabric. Automatic
distribution is supported, and you can either configure the switches in your fabric to accept the FCS policy
or manually distribute the FCS policy. Changes made to the FCS policy are saved to permanent memory
only after the changes have been saved or activated; they can be aborted later if you have set your fabric
to distribute the changes manually.
Table 26
shows the characteristics of policy states.
The FCS policy is designed to accommodate mixed fabric environments that contain switches with
pre-5.3.0 and later versions of Fabric OS. By setting the configuration parameters to accept fabric
distribution, Fabric OS 6.0.0 and later switches may enforce FCS policy and perform database distribution
among 5.3.0 and 6.0.0 and later switches while still allowing pre-5.3.0 switches to join the fabric. The
following items describe distribution behavior for pre-5.3.0.
Distribution to pre-5.3.0 switches with specific domain IDs
When specific domain IDs are given for the distribution, all domains must be on a switch with Fabric
OS 5.3.0 or later. If one of the domains is pre-5.3.0 the distribution operation will fail.
Distribution to pre-5.3.0 switches using the wild card (*) character
When the wild card character is specified, distribution succeeds even if the fabric contains pre-5.3.0
switches. However, the FCS database is sent only to switches with a Fabric OS of 5.2.0 or later in the
Table 26
FCS policy states
Policy state
Characteristics
No active policy
Any switch can perform fabric-wide configuration changes.
Active policy with one entry
A Primary FCS switch is designated (local switch), but there are no
backup FCS switches. If the Primary FCS switch becomes unavailable
for any reason, the fabric is left without an FCS switch.
Active policy with multiple
entries
A Primary FCS switch and one or more backup FCS switches are
designated. If the Primary FCS switch becomes unavailable, the next
switch in the list becomes the Primary FCS switch.