HP StorageWorks 8/80 HP StorageWorks Fabric OS 6.2.0d release notes (5697-0353 - Page 23

FIPS, LDAP, FCAP, FICON, Port Mirroring, 10G interoperability

Page 23 highlights

FIPS FIPS mode should not be enabled on the 4/8 and 4/16 SAN Switches. If FIPS is enabled, the 4/8 and 4/16 SAN Switches will not boot. LDAP When using LDAP, downgrades from Fabric OS 6.2.x to earlier releases requires user intervention. Authentication must be set to local and back to LDAP in order to continue using LDAP authentication. FCAP • Due to limitations with the certificates, FCAP authentication cannot be supported on user-defined logical switches. FCAP will continue to function with existing certificates for non-VF and the default logical switch of VF enabled switches. Note that authutil is not restricted from other logical switches at this time, so it can still be enabled on unsupported LS. • The pkicert(1.06) utility may cause evm errors, so each new switch should be isolated from the fabric in non-VF mode to install new certificates. • For FIPS mode, certificates must be installed before FIPS activation. FICON • For the DC SAN Backbone Director, FICON CUP is not allowed with a 48-port blade in the Default Logical Switch. All ports on a 48-port blade must be assigned to a user-defined Logical Switch to use them in a FICON CUP enabled switch. • PDCM changes configured via Web Tools must be activated via the edit window if Active=Saved mode is enabled. • When RSCNs are sent out on behalf of the CUP for switchname changes in interopmode 2, the mainframe channels interpret the RSCNs as though paths may have gone down. This forces the channels into a form of recovery, whereby they send TINs to the CUP to verify the logical paths that are still established to the CUP. This results in mainframe console messages indicating that this type of recovery has occurred. Port Mirroring • On the 8/80 SAN Switch, the Port Mirroring feature has a limitation where all port mirror resources must remain in the same ASIC port group. The resources are the configure mirror port, Source Device, and Destination Device or ISL, if the Destination Device is located on another switch. The ASIC port groups are 0-15, 16-31, 32-47, 48-63, and 64-79. The routes will be broken if the port mirror resources are spread across multiple port groups. • Port Mirroring is not supported on a switch with the VF feature enabled. 10G interoperability 10G interop between HP StorageWorks SAN Director 6 Port 10Gb FC blade and McDATA blades is not supported due to a hardware limitation. However, the SAN Director 6 Port 10Gb FC blade is supported in a chassis running in interopmode 2 or 3 (SAN Director 6 Port 10Gb FC blade to SAN Director 6 Port 10Gb FC blade connections only). A SAN Director 6 Port 10Gb FC blade will not synchronize with a McDATA 10G blade, but will not negatively impact the system. HP StorageWorks Fabric OS 6.2.0d release notes 23

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48

FIPS
FIPS mode should not be enabled on the 4/8 and 4/16 SAN Switches. If FIPS is enabled, the 4/8
and 4/16 SAN Switches will not boot.
LDAP
When using LDAP, downgrades from Fabric OS 6.2.x to earlier releases requires user intervention.
Authentication must be set to local and back to LDAP in order to continue using LDAP authentication.
FCAP
Due to limitations with the certificates, FCAP authentication cannot be supported on user-defined
logical switches. FCAP will continue to function with existing certificates for non-VF and the default
logical switch of VF enabled switches. Note that
authutil
is not restricted from other logical
switches at this time, so it can still be enabled on unsupported LS.
The pkicert(1.06) utility may cause
evm
errors, so each new switch should be isolated from the
fabric in non-VF mode to install new certificates.
For FIPS mode, certificates must be installed before FIPS activation.
FICON
For the DC SAN Backbone Director, FICON CUP is not allowed with a 48-port blade in the Default
Logical Switch. All ports on a 48
port blade must be assigned to a user-defined Logical Switch
to use them in a FICON CUP enabled switch.
PDCM changes configured via Web Tools must be activated via the edit window if Active=Saved
mode is enabled.
When RSCNs are sent out on behalf of the CUP for switchname changes in interopmode 2, the
mainframe channels interpret the RSCNs as though paths may have gone down. This forces the
channels into a form of recovery, whereby they send TINs to the CUP to verify the logical paths
that are still established to the CUP. This results in mainframe console messages indicating that
this type of recovery has occurred.
Port Mirroring
On the 8/80 SAN Switch, the Port Mirroring feature has a limitation where all port mirror resources
must remain in the same ASIC port group. The resources are the configure mirror port, Source
Device, and Destination Device or ISL, if the Destination Device is located on another switch. The
ASIC port groups are 0-15, 16-31, 32-47, 48-63, and 64-79. The routes will be broken if the
port mirror resources are spread across multiple port groups.
Port Mirroring is not supported on a switch with the VF feature enabled.
10G interoperability
10G interop between HP StorageWorks SAN Director 6 Port 10Gb FC blade and McDATA blades
is not supported due to a hardware limitation. However, the SAN Director 6 Port 10Gb FC blade is
supported in a chassis running in interopmode 2 or 3 (SAN Director 6 Port 10Gb FC blade to SAN
Director 6 Port 10Gb FC blade connections only). A SAN Director 6 Port 10Gb FC blade will not
synchronize with a McDATA 10G blade, but will not negatively impact the system.
HP StorageWorks Fabric OS 6.2.0d release notes
23