HP StorageWorks MSA 2/8 HP StorageWorks Secure Fabric OS V1.0 User Guide (AA-R - Page 64

HTTP Policy, Table 6: HTTP Policy States, is HTTP_POLICY.

Page 64 highlights

Creating Secure Fabric OS Policies HTTP Policy You can create the HTTP policy to specify which workstations can use HTTP to access the fabric. This is useful for applications that use internet browsers, such as Web Tools. The policy is named HTTP_POLICY and contains a list of IP addresses for devices and workstations that are allowed to establish HTTP connections to the switches in the fabric. The possible HTTP policy states are shown in Table 6. Table 6: HTTP Policy States Policy State No policy Policy with no entries Policy with entries Characteristics All hosts can establish an HTTP connection to any switch in the fabric. No host can establish an HTTP connection to any switch in the fabric. Only specified hosts can establish an HTTP connection to any switch in the fabric. To create an HTTP policy: 1. From a sectelnet or SSH session, log into the Primary FCS switch as Admin. 2. Enter the following: secpolicycreate policy_name, "member;...;member" Where: ■ policy_name is HTTP_POLICY. ■ member is one or more IP addresses in dot-decimal notation. You can enter "0" in an octet to indicate that any number can be matched in that octet. 3. To save or activate the new policy, enter the secpolicysave or the secpolicyactivate command. If neither of these commands are entered, the changes are lost when you log out. For more information about these commands, see "Saving Changes to Secure Fabric OS Policies" on page 77 and "Activating Changes to Secure Fabric OS Policies" on page 77. 64 Secure Fabric OS Version 1.0 User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129

Creating Secure Fabric OS Policies
64
Secure Fabric OS Version 1.0 User Guide
HTTP Policy
You can create the HTTP policy to specify which workstations can use HTTP to
access the fabric. This is useful for applications that use internet browsers, such as
Web Tools.
The policy is named HTTP_POLICY and contains a list of IP addresses for
devices and workstations that are allowed to establish HTTP connections to the
switches in the fabric.
The possible HTTP policy states are shown in
Table 6
.
To create an HTTP policy:
1.
From a sectelnet or SSH session, log into the Primary FCS switch as Admin.
2.
Enter the following:
secpolicycreate
policy_name, “member;...;member”
Where:
policy_name
is HTTP_POLICY.
member
is one or more IP addresses in dot-decimal notation. You can
enter “0” in an octet to indicate that any number can be matched in that
octet.
3.
To save or activate the new policy, enter the
secpolicysave
or the
secpolicyactivate
command.
If neither of these commands are entered, the changes are lost when you log
out. For more information about these commands, see “
Saving Changes to
Secure Fabric OS Policies
” on page 77 and “
Activating Changes to Secure
Fabric OS Policies
” on page 77.
Table 6:
HTTP Policy States
Policy State
Characteristics
No policy
All hosts can establish an HTTP connection to any switch in
the fabric.
Policy with no entries
No host can establish an HTTP connection to any switch in
the fabric.
Policy with entries
Only specified hosts can establish an HTTP connection to
any switch in the fabric.