HP StorageWorks MSA 2/8 HP StorageWorks Secure Fabric OS V1.0 User Guide (AA-R - Page 72

Table 12: DCC Policy States, characters to differentiate it from any other DCC policies.

Page 72 highlights

Creating Secure Fabric OS Policies Table 12: DCC Policy States Policy State No policy Policy with no entries Policy with entries Characteristics Any device can connect to any switch port in the fabric. Any device can connect to any switch port in the fabric. An empty policy is the same as no policy. If a device WWN is specified in a DCC policy, that device is only allowed access to the fabric if connected to a switch port listed in the same policy. If a switch port is specified in a DCC policy, it permits connections only from devices that are listed in the policy. WWNs that are not specified in a DCC policy are allowed to connect to the fabric at any switch ports that are not specified in a DCC policy. Switch ports and WWNs may exist in multiple DCC policies. Note: When a DCC violation occurs, the related port is automatically disabled and must be re-enabled using the portenable command. To create a DCC policy: 1. From a sectelnet or SSH session, log into the Primary FCS switch as Admin. 2. Enter the following: secpolicycreate DCC_POLICY_nnn, "member;...;member" Where: ■ DCC_POLICY_nnn is the name of the DCC policy you want to create, and nnn is a string consisting of up to 19 alphanumeric or underscore characters to differentiate it from any other DCC policies. ■ member contains device and switch port information; deviceWWN; switch(port). - The "switch" can be the switch WWN, Domain ID, or switch name. - The port can be specified by port or area number. Designating ports automatically includes the devices currently attached to those ports. The ports can be specified using any of the following syntax methods: (1-6) Selects ports 1 through 6. (*) Selects all ports on the switch. 72 Secure Fabric OS Version 1.0 User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129

Creating Secure Fabric OS Policies
72
Secure Fabric OS Version 1.0 User Guide
Note:
When a DCC violation occurs, the related port is automatically disabled and
must be re-enabled using the
portenable
command.
To create a DCC policy:
1.
From a sectelnet or SSH session, log into the Primary FCS switch as Admin.
2.
Enter the following:
secpolicycreate
DCC_POLICY_nnn,
member;...;member”
Where:
DCC_POLICY_nnn
is the name of the DCC policy you want to create,
and
nnn
is a string consisting of up to 19 alphanumeric or underscore
characters to differentiate it from any other DCC policies.
member
contains device and switch port information; deviceWWN;
switch(port).
The “switch” can be the switch WWN, Domain ID, or switch name.
The port can be specified by port or area number. Designating ports
automatically includes the devices currently attached to those ports.
The ports can be specified using any of the following syntax methods:
(1-6) Selects ports 1 through 6.
(*) Selects all ports on the switch.
Table 12:
DCC Policy States
Policy State
Characteristics
No policy
Any device can connect to any switch port in the fabric.
Policy with no entries
Any device can connect to any switch port in the fabric. An
empty policy is the same as no policy.
Policy with entries
If a device WWN is specified in a DCC policy, that device is
only allowed access to the fabric if connected to a switch
port listed in the same policy.
If a switch port is specified in a DCC policy, it permits
connections only from devices that are listed in the policy.
WWNs that are not specified in a DCC policy are allowed
to connect to the fabric at any switch ports that are not
specified in a DCC policy.
Switch ports and WWNs may exist in multiple DCC policies.