HP StorageWorks MSA 2/8 HP StorageWorks Secure Fabric OS V1.0 User Guide (AA-R - Page 107

Adding, Switches and, Merging Secure, Fabrics, Verifying Installation of the Digital, Certificates

Page 107 highlights

Managing Secure Fabric OS Table 18: Recovery Processes (Continued) Symptom A device listed in the DCC policy cannot be accessed. A policy that has been created is not listed by secpolicyshow command. One or more switches are segmented from the fabric. Note: For instructions on rejoining fabrics, see the instructions under "Adding Switches and Merging Secure Fabrics" on page 101. Likely Problem Port may be disabled. The new policy was not saved or activated. Incorrect policy name used. SCC_POLICY is excluding the segmented switches. Management Server services on the segmented switches are inconsistent with rest of fabric. The segmented switches are missing PKI objects. ISLs to the segmented switches are interrupted or a port failure occurred. FCS policies on the segmented switches are not identical to the FCS policy of the fabric. Recommended Actions Enter the switchshow command. If the port in question is disabled, enter the portenable command. Save or activate the policy changes by entering the secpolicysave or secpolicyactivate command. Verify the correct policy name was used. Policy names are case-sensitive and must be entered all uppercase. Use the secpolicyadd command on the Primary FCS switch to add the switches to the SCC_POLICY. Make the Management Server services consistent across all switches in the fabric by enabling or disabling the same services. Determine the status of the PKI objects by following the procedure under "Verifying Installation of the Digital Certificates" on page 38. If any objects are missing, replace as described under "Re-creating PKI Objects If Required" on page 39. Check the hardware connections and the port status for all ISLs between the segmented switches and the fabric. If one or more switches are segmented without any FCS switches, enter the secmodeenable command on a segmented switch and specify an FCS policy that is identical to the FCS policy of the rest of the fabric. The segmented switch or group of switches are automatically fastbooted. If one or more switches are segmented with a Primary FCS switch, modify the FCS policy as required until it is identical to the FCS policy in the rest of the fabric. Secure Fabric OS Version 1.0 User Guide 107

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129

Managing Secure Fabric OS
107
Secure Fabric OS Version 1.0 User Guide
A device listed in
the DCC policy
cannot be accessed.
Port may be
disabled.
Enter the
switchshow
command. If the port in
question is disabled, enter the
portenable
command.
A policy that has
been created is not
listed by
secpolicyshow
command.
The new policy
was not saved or
activated.
Save or activate the policy changes by entering the
secpolicysave
or
secpolicyactivate
command.
Incorrect policy
name used.
Verify the correct policy name was used. Policy names are
case-sensitive and must be entered all uppercase.
One or more
switches are
segmented from the
fabric.
Note:
For
instructions on
rejoining fabrics,
see the instructions
under “
Adding
Switches and
Merging Secure
Fabrics
” on
page 101.
SCC_POLICY is
excluding the
segmented
switches.
Use the
secpolicyadd
command on the Primary FCS
switch to add the switches to the SCC_POLICY.
Management
Server services
on the segmented
switches are
inconsistent with
rest of fabric.
Make the Management Server services consistent across
all switches in the fabric by enabling or disabling the
same services.
The segmented
switches are
missing PKI
objects.
Determine the status of the PKI objects by following the
procedure under “
Verifying Installation of the Digital
Certificates
” on page 38. If any objects are missing,
replace as described under “
Re-creating PKI Objects If
Required
” on page 39.
ISLs to the
segmented
switches are
interrupted or a
port failure
occurred.
Check the hardware connections and the port status for all
ISLs between the segmented switches and the fabric.
FCS policies on
the segmented
switches are not
identical to the
FCS policy of the
fabric.
If one or more switches are segmented without any FCS
switches, enter the
secmodeenable
command on a
segmented switch and specify an FCS policy that is
identical to the FCS policy of the rest of the fabric. The
segmented switch or group of switches are automatically
fastbooted.
If one or more switches are segmented with a Primary FCS
switch, modify the FCS policy as required until it is
identical to the FCS policy in the rest of the fabric.
Table 18:
Recovery Processes (Continued)
Symptom
Likely Problem
Recommended Actions