HP StorageWorks MSA 2/8 HP StorageWorks Secure Fabric OS V1.0 User Guide (AA-R - Page 68

Front Panel Policy, Saving Changes to, Secure Fabric OS Policies, Activating Changes to Secure

Page 68 highlights

Creating Secure Fabric OS Policies To create a Serial Port policy: 1. From a sectelnet or SSH session, log into the Primary FCS switch as Admin. 2. Enter the following: secpolicycreate policy_name, "member;...;member" Where: ■ policy_name is SERIAL_POLICY. ■ member is a switch WWN, domain ID, or switch name. If a domain ID or switch name is used to specify a switch, the associated switch must be present in the fabric for the command to succeed. 3. To save or activate the new policy, enter the secpolicysave or the secpolicyactivate command. If neither of these commands are entered, the changes are lost when you log out. For more information about these commands, see "Saving Changes to Secure Fabric OS Policies" on page 77 and "Activating Changes to Secure Fabric OS Policies" on page 77. Example, creating a SERIAL_POLICY that allows serial port access to a switch that has a WWN of 12:24:45:10:0a:67:00:40: primaryfcs:admin> secPolicyCreate "SERIAL_POLICY", "12:24:45:10:0a:67:00:40" SERIAL_POLICY has been created. primaryfcs:admin> Front Panel Policy You can create the Front Panel policy to restrict front panel access to switches that are physically secure. This policy applies only to SAN Switch 2/16, since no other switches contain front panels. The policy is named FRONTPANEL_POLICY and contains a list of switch WWNs, Domain IDs, or switch names for which front panel access is enabled. The possible Front Panel policy states are shown in Table 10. 68 Secure Fabric OS Version 1.0 User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129

Creating Secure Fabric OS Policies
68
Secure Fabric OS Version 1.0 User Guide
To create a Serial Port policy:
1.
From a sectelnet or SSH session, log into the Primary FCS switch as Admin.
2.
Enter the following:
secpolicycreate
policy_name, “member;...;member”
Where:
policy_name
is SERIAL_POLICY.
member
is a switch WWN, domain ID, or switch name. If a domain ID
or switch name is used to specify a switch, the associated switch must be
present in the fabric for the command to succeed.
3.
To save or activate the new policy, enter the
secpolicysave
or the
secpolicyactivate
command.
If neither of these commands are entered, the changes are lost when you log
out. For more information about these commands, see “
Saving Changes to
Secure Fabric OS Policies
” on page 77 and “
Activating Changes to Secure
Fabric OS Policies
” on page 77.
Example, creating a SERIAL_POLICY that allows serial port access to a
switch that has a WWN of 12:24:45:10:0a:67:00:40:
Front Panel Policy
You can create the Front Panel policy to restrict front panel access to switches that
are physically secure. This policy applies only to SAN Switch 2/16, since no other
switches contain front panels. The policy is named FRONTPANEL_POLICY and
contains a list of switch WWNs, Domain IDs, or switch names for which front
panel access is enabled.
The possible Front Panel policy states are shown in
Table 10
.
primaryfcs:admin> secPolicyCreate "SERIAL_POLICY",
"12:24:45:10:0a:67:00:40"
SERIAL_POLICY has been created.
primaryfcs:admin>