HP StorageWorks 8/80 HP StorageWorks Fabric OS 6.2 administrator guide (5697-0 - Page 196

User-defined Administrative Domains, System-defined Administrative Domains

Page 196 highlights

Table 51 lists each Admin Domain user type and describes its administrative access and capabilities. Table 51 AD user types User type Description Physical fabric administrator Administrative Domain user User account with admin role and with access to all Admin Domains (AD0 through AD255). Creates and manages all Admin Domains. Assigns other administrators or users to each Admin Domain. Only a physical fabric administrator can create other physical fabric administrators. Can be assigned to one or more Admin Domains. Manages the resources within their Admin Domains. If its role permits, can create user accounts and assign them to Admin Domains on their list. Cannot view other Admin Domain definitions. Can view only members of their own Admin Domains. User-defined Administrative Domains AD1 through AD254 are user-defined Admin Domains. These user-defined Admin Domains can be created only by a physical fabric administrator (see "Admin Domain access levels" on page 193 for more information). In Figure 20 on page 192, AD1 and AD2 are user-defined Admin Domains. System-defined Administrative Domains AD0 and AD255 are special, system-defined Admin Domains. When you install Fabric OS 6.1.0, the switch enters AD-capable mode with domains AD0 and AD255 automatically created. AD0 and AD255 always exist and cannot be deleted or renamed. They are reserved for use in creation and management of Admin Domains. AD0 AD0 is a system-defined Admin Domain that contains all online devices, switch ports, and switches that are not assigned to any user-defined Admin Domain. AD0 also contains members that you explicitly add (similar to user-defined Admin Domains). Unlike user-defined Admin Domains, AD0 has an implicit and an explicit membership list. User-defined Admin Domains have explicit members only. • The implicit membership list contains all devices, switch ports, and switches that have not been assigned to any other Admin Domain. Initially, the AD0 implicit membership list contains all devices, switch ports, and switches in the fabric. This list includes all non-AD-capable switches and the devices attached to them. When you explicitly create AD1 through AD254, the devices, switch ports, and switches used to create these user-defined Admin Domains disappear from the AD0 implicit membership list. • The explicit membership list contains all devices, switch ports, and switches that you explicitly add to AD0 and that can be used to force device and switch sharing between AD0 and other Admin Domains. AD0 can be managed like any user-defined Admin Domain. The only difference between AD0 and user-defined Admin Domains is the implicit membership list. The list of implicit members of AD0 change dynamically as the membership of other Admin Domains changes. The explicit members of AD0 are not deleted unless you explicitly remove them. For example, if you explicitly add DeviceA to AD0 and it is not a member of any other Admin Domain, DeviceA is both an implicit and an explicit member of AD0. If you add DeviceA to AD2, DeviceA is deleted from the AD0 implicit membership list, but is not deleted from the AD0 explicit membership list. If you then remove DeviceA from AD2, DeviceA is added back to the AD0 implicit membership list (assuming DeviceA is not in any other Admin Domain). 194 Managing administrative domains

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576

194
Managing administrative domains
Table 51
lists each Admin Domain user type and describes its administrative access and capabilities.
User-defined Administrative Domains
AD1 through AD254 are user-defined Admin Domains. These user-defined Admin Domains can be created
only by a physical fabric administrator (see ”
Admin Domain access levels
” on page 193 for more
information).
In
Figure 20
on page 192, AD1 and AD2 are user-defined Admin Domains.
System-defined Administrative Domains
AD0 and AD255 are special, system-defined Admin Domains. When you install Fabric OS 6.1.0, the
switch enters AD-capable mode with domains AD0 and AD255 automatically created. AD0 and AD255
always exist and cannot be deleted or renamed. They are reserved for use in creation and management of
Admin Domains.
AD0
AD0 is a system-defined Admin Domain that contains all online devices, switch ports, and switches that are
not assigned to any user-defined Admin Domain. AD0 also contains members that you explicitly add
(similar to user-defined Admin Domains).
Unlike user-defined Admin Domains, AD0 has an implicit and an explicit membership list. User-defined
Admin Domains have explicit members only.
The
implicit membership list
contains all devices, switch ports, and switches that have not been
assigned to any other Admin Domain.
Initially, the AD0 implicit membership list contains all devices, switch ports, and switches in the fabric.
This list includes all non-AD-capable switches and the devices attached to them. When you explicitly
create AD1 through AD254, the devices, switch ports, and switches used to create these user-defined
Admin Domains disappear from the AD0 implicit membership list.
The
explicit membership list
contains all devices, switch ports, and switches that you explicitly add to
AD0 and that can be used to force device and switch sharing between AD0 and other Admin
Domains.
AD0 can be managed like any user-defined Admin Domain. The only difference between AD0 and
user-defined Admin Domains is the implicit membership list.
The list of implicit members of AD0 change dynamically as the membership of other Admin Domains
changes. The explicit members of AD0 are not deleted unless you explicitly remove them.
For example, if you explicitly add DeviceA to AD0 and it is not a member of any other Admin Domain,
DeviceA is both an implicit and an explicit member of AD0. If you add DeviceA to AD2, DeviceA is
deleted from the AD0 implicit membership list, but is
not
deleted from the AD0 explicit membership list. If
you then remove DeviceA from AD2, DeviceA is added back to the AD0 implicit membership list (assuming
DeviceA is not in any other Admin Domain).
Table 51
AD user types
User type
Description
Physical fabric
administrator
User account with admin role and with access to all Admin Domains (AD0 through
AD255).
Creates and manages all Admin Domains.
Assigns other administrators or users to each Admin Domain.
Only a physical fabric administrator can create other physical fabric administrators.
Administrative
Domain user
Can be assigned to one or more Admin Domains.
Manages the resources within their Admin Domains.
If its role permits, can create user accounts and assign them to Admin Domains on their
list.
Cannot view other Admin Domain definitions. Can view only members of their own
Admin Domains.