HP StorageWorks MSA 2/8 HP StorageWorks Secure Fabric OS V1.0 User Guide (AA-R - Page 66

Management Server Policy, Table 8: Management Server Policy States, Saving Changes

Page 66 highlights

Creating Secure Fabric OS Policies 3. To save or activate the new policy, enter the secpolicysave or the secpolicyactivate command. If neither of these commands are entered, the changes are lost when you log out. For more information about these commands, see "Saving Changes to Secure Fabric OS Policies" on page 77 and "Activating Changes to Secure Fabric OS Policies" on page 77. Example, creating an API policy to allow anyone on a network "192.168.5.0/24" to establish an API connection to any switch in the fabric: primaryfcs:admin> secPolicyCreate "API_POLICY", "192.168.5.0" API_POLICY has been created. primaryfcs:admin> Management Server Policy You can create the Management Server policy to restrict management server access to specified devices. Fabric configuration and control functions can be performed only by requesters that are directly connected to the Primary FCS switch. The policy is named MS_POLICY and contains a list of device port WWNs for which the management server implementation in Fabric OS (designed according to FC-GS-3 standard) accepts and acts on requests. The possible Management Server policy states are shown in Table 8. Table 8: Management Server Policy States Policy State No policy Policy with no entries Policy with entries Characteristics All devices can access the management server. No devices can access the management server. Specified devices can access the management server. To create a Management Server policy: 1. From a sectelnet or SSH session, log into the Primary FCS switch as Admin. 2. Enter the following: secpolicycreate policy_name, "member;...;member" Where: ■ policy_name is MS_POLICY. ■ member is a device WWN. 66 Secure Fabric OS Version 1.0 User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129

Creating Secure Fabric OS Policies
66
Secure Fabric OS Version 1.0 User Guide
3.
To save or activate the new policy, enter the
secpolicysave
or the
secpolicyactivate
command.
If neither of these commands are entered, the changes are lost when you log
out. For more information about these commands, see “
Saving Changes to
Secure Fabric OS Policies
” on page 77 and “
Activating Changes to Secure
Fabric OS Policies
” on page 77.
Example, creating an API policy to allow anyone on a network
“192.168.5.0/24” to establish an API connection to any switch in the fabric:
Management Server Policy
You can create the Management Server policy to restrict management server
access to specified devices. Fabric configuration and control functions can be
performed only by requesters that are directly connected to the Primary FCS
switch.
The policy is named MS_POLICY and contains a list of device port WWNs for
which the management server implementation in Fabric OS (designed according
to FC-GS-3 standard) accepts and acts on requests.
The possible Management Server policy states are shown in
Table 8
.
To create a Management Server policy:
1.
From a sectelnet or SSH session, log into the Primary FCS switch as Admin.
2.
Enter the following:
secpolicycreate
policy_name, “member;...;member”
Where:
policy_name
is MS_POLICY.
member
is a device WWN.
primaryfcs:admin> secPolicyCreate "API_POLICY", "192.168.5.0"
API_POLICY has been created.
primaryfcs:admin>
Table 8:
Management Server Policy States
Policy State
Characteristics
No policy
All devices can access the management server.
Policy with no entries
No devices can access the management server.
Policy with entries
Specified devices can access the management server.