HP StorageWorks MSA 2/8 HP StorageWorks Secure Fabric OS V1.0 User Guide (AA-R - Page 74

Creating an SCC Policy, Table 13: SCC Policy States, An E_Port to E_Port connection is made.

Page 74 highlights

Creating Secure Fabric OS Policies Creating an SCC Policy You can create an SCC policy to manage which switches can join the fabric. Switches are checked against the policy each time: ■ Secure Mode is enabled. ■ The fabric is initialized with Secure Mode enabled. ■ An E_Port to E_Port connection is made. The policy is named SCC_POLICY, and can accept members listed as WWNs, Domain IDs, or switch names. You can only create one SCC policy. By default, any switch is allowed to join the fabric; the SCC policy does not exist until it is created by the administrator. Note: Once an SCC policy is created, it must list all the switches in the fabric to prevent switches from being segmented from the fabric. In particular, ensure that the SCC policy lists all the members of the FCS policy, to ensure consistent access to the Primary FCS switch. The possible SCC policy states are shown in Table 13. Table 13: SCC Policy States Policy State No policy Policy with no entries Policy with entries Characteristics All switches can be in the fabric. The SCC policy cannot be empty. The policy must contain all the FCS switches. The SCC policy must contain all the FCS switches but it can also contain additional switches. To create an SCC policy: 1. Log into the Primary FCS switch as Admin from a sectelnet or SSH session. 2. Enter the following: secpolicycreate SCC_POLICY, "member;...;member" Where member indicates a switch that you want to be able to join the fabric. Switches can be specified by WWN, Domain ID, or switch name. You can enter an asterisk (*) to indicate all switches in the fabric. 74 Secure Fabric OS Version 1.0 User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129

Creating Secure Fabric OS Policies
74
Secure Fabric OS Version 1.0 User Guide
Creating an SCC Policy
You can create an SCC policy to manage which switches can join the fabric.
Switches are checked against the policy each time:
Secure Mode is enabled.
The fabric is initialized with Secure Mode enabled.
An E_Port to E_Port connection is made.
The policy is named SCC_POLICY, and can accept members listed as WWNs,
Domain IDs, or switch names. You can only create one SCC policy.
By default, any switch is allowed to join the fabric; the SCC policy does not exist
until it is created by the administrator.
Note:
Once an SCC policy is created, it must list all the switches in the fabric to prevent
switches from being segmented from the fabric.
In particular, ensure that the SCC policy lists all the members of the FCS policy, to
ensure consistent access to the Primary FCS switch.
The possible SCC policy states are shown in
Table 13
.
To create an SCC policy:
1.
Log into the Primary FCS switch as Admin from a sectelnet or SSH session.
2.
Enter the following:
secpolicycreate
SCC_POLICY, “member;...;member”
Where
member
indicates a switch that you want to be able to join the fabric.
Switches can be specified by WWN, Domain ID, or switch name. You can
enter an asterisk (*) to indicate all switches in the fabric.
Table 13:
SCC Policy States
Policy State
Characteristics
No policy
All switches can be in the fabric.
Policy with no entries
The SCC policy cannot be empty. The policy must contain all
the FCS switches.
Policy with entries
The SCC policy must contain all the FCS switches but it can
also contain additional switches.