HP StorageWorks 8/80 HP StorageWorks Fabric OS 6.2 administrator guide (5697-0 - Page 504

Preparing a switch for FICON

Page 504 highlights

Preparing a switch for FICON To verify and prepare a switch for use in a FICON environment, complete the following steps. 1. Connect to the switch and log in using an account assigned to the admin role. 2. Enter the switchShow command to verify that the switch and devices are online. 3. Change the routing policy on the switch from the default exchange-based policy to the required port-based policy for those switches with FICON devices directly attached using the aptPolicy command when working from the command line. For GUI-based procedures, see the Web Tools Administrator's Guide for configuring the routing policy using the FICON tab in WebTools. 4. Enter the ficonShow rnid command to verify that the FICON devices are registered with the switch. 5. Enter the ficonShow lirr command to verify that the FICON host channels are registered to listen for link incidents. See "FICON CUP" on page 503 for details about using FICON CUP. Single switch configuration Single-switch configuration does not require IDID or fabric binding, provided that connected channels are configured for single-byte addressing. However, you should configure IDID to ensure that domain IDs are maintained. Configuring a high-integrity fabric Perform the following steps to configure a high-integrity fabric for a cascaded configuration. 1. Disable each switch in the fabric. 2. For each switch: a. Enable the IDID flag. b. Set the domain ID. 3. Enable the switches; this builds the fabric. 4. Set the SCC policy, as described in Chapter 4, "Configuring advanced security features" on page 117. 5. Configure the Switch Connection Control policies on all switches to limit connectivity only to the switches in the selected fabric using the secPolicyCreate command. switch:admin> secPolicyCreate SCC_POLICY, member;...;member where: member indicates a switch that is permitted to join the fabric. Specify switches by WWN, domain ID, or switch name. Enter an asterisk (*) to indicate all the switches in the fabric. To create a policy that includes all the switches in the fabric, enter the following: switch:admin> secPolicyCreate SCC_POLICY "*" 6. Save or activate the new policy, enter either the secPolicySave or the secPolicyActivate command. If neither of these commands is entered, the changes are lost when the session is logged out. To activate the SCC policy: switch:admin> secPolicyActivate 7. Enable ACL Fabric Wide Consistency Policy and enforce a strict SCC policy switch:admin> fddcfg --fabwideset "SCC:S" 8. Connect and enable channel and control unit (CU) devices. The Query for Security Attributes (QSA) response to the channel indicates that the fabric binding and IDID are enabled. Figure 84 and Figure 85 show two viable cascaded configurations. These configurations require Channel A to be configured for two-byte addressing and require IDID and fabric binding. HP recommends that there are only 2 domains in a path from a FICON Channel interface to a FICON Control Unit interface. 500 FICON fabrics

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576

500
FICON fabrics
Preparing a switch for FICON
To verify and prepare a switch for use in a FICON environment, complete the following steps.
1.
Connect to the switch and log in using an account assigned to the admin role.
2.
Enter the
switchShow
command to verify that the switch and devices are online.
3.
Change the routing policy on the switch from the default exchange-based policy to the required
port-based policy for those switches with FICON devices directly attached using the
aptPolicy
command when working from the command line. For GUI-based procedures, see the
Web Tools
Administrator’s Guide
for configuring the routing policy using the FICON tab in WebTools
.
4.
Enter the
ficonShow rnid
command to verify that the FICON
devices are registered with the switch.
5.
Enter the
ficonShow lirr
command to verify that the FICON
host channels are registered to listen
for link incidents.
See ”
FICON CUP
” on page 503 for details about using FICON CUP.
Single switch configuration
Single-switch configuration does not require IDID or fabric binding, provided that connected channels are
configured for single-byte addressing. However, you should configure IDID to ensure that domain IDs are
maintained.
Configuring a high-integrity fabric
Perform the following steps to configure a high-integrity fabric for a cascaded configuration.
1.
Disable each switch in the fabric.
2.
For each switch:
a.
Enable the IDID flag.
b.
Set the domain ID.
3.
Enable the switches; this builds the fabric.
4.
Set the SCC policy, as described in Chapter 4, ”
Configuring advanced security features
” on page117.
5.
Configure the Switch Connection Control policies on all switches to limit connectivity only to the
switches in the selected fabric using the secPolicyCreate command.
switch:admin>
secPolicyCreate SCC_POLICY, member;...;member
where:
member
indicates a switch that is permitted to join the fabric. Specify switches by WWN, domain ID,
or switch name. Enter an asterisk (*) to indicate all the switches in the fabric. To create a policy that
includes all the switches in the fabric, enter the following:
switch:admin>
secPolicyCreate SCC_POLICY ”*”
6.
Save or activate the new policy, enter either the
secPolicySave
or the
secPolicyActivate
command. If neither of these commands is entered, the changes are lost when the session is logged
out. To activate the SCC policy:
switch:admin>
secPolicyActivate
7.
Enable ACL Fabric Wide Consistency Policy and enforce a strict SCC policy
switch:admin>
fddcfg --fabwideset ”SCC:S”
8.
Connect and enable channel and control unit (CU) devices. The Query for Security Attributes (QSA)
response to the channel indicates that the fabric binding and IDID are enabled.
Figure 84
and
Figure 85
show two viable cascaded configurations. These configurations require Channel
A to be configured for two-byte addressing and require IDID and fabric binding. HP recommends that
there are only 2 domains in a path from a FICON Channel interface to a FICON Control Unit interface.