HP Surestore 64 FW 05.01.00 and SW 07.01.00 HP StorageWorks SAN High Availabil - Page 131

Security Provisions, Password Protection, Table 3: Types of User Rights

Page 131 highlights

Physical Planning Considerations Security Provisions Security provisions are available to restrict unauthorized access to a director, switch, or attached Fibre Channel devices. Access to the director or switch (through the HAFM application, Product Manager application, and Web server interface) is restricted by implementing password protection. Access to attached computing resources (including applications and data) is restricted by implementing name server zoning. Password Protection Access to the HAFM and Product Manager applications requires configuration of a user name and password. Up to 16 user names and associated passwords can be configured, although only 9 users can log in concurrently (8 remote and 1 local). Each user is assigned rights that allow access to specific sets of product management operations. Table 3 explains the types of user rights available. A user may have more than one set of user rights granted. Table 3: Types of User Rights User Right View Only Operator Product Administrator System Administrator Maintenance Operator Access Allowed The user may view product configurations and status, but may not make changes. These rights are the default if no other user rights are assigned. The operator may view status and configuration information through the Product Manager application, and perform operational control changes, such as blocking ports and placing the product online or offline. The product administrator can make control and configuration changes through the Product Manager application. The system administrator can make control and configuration changes, define users and passwords, and add or remove products through the HAFM application. The maintenance operator can perform product control and configuration changes through the Product Manager application, and perform diagnostics, maintenance functions, firmware loads, and data collection. SAN High Availability Planning Guide 131

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174

Physical Planning Considerations
131
SAN High Availability Planning Guide
Security Provisions
Security provisions are available to restrict unauthorized access to a director,
switch, or attached Fibre Channel devices. Access to the director or switch
(through the
HAFM
application,
Product Manager
application, and Web server
interface) is restricted by implementing password protection. Access to attached
computing resources (including applications and data) is restricted by
implementing name server zoning.
Password Protection
Access to the
HAFM
and
Product Manager
applications requires configuration of
a user name and password. Up to 16 user names and associated passwords can be
configured, although only 9 users can log in concurrently (8 remote and 1 local).
Each user is assigned rights that allow access to specific sets of product
management operations.
Table 3
explains the types of user rights available. A user may have more than one
set of user rights granted.
Table 3:
Types of User Rights
User Right
Operator Access Allowed
View Only
The user may view product configurations and status, but
may not make changes. These rights are the default if no
other user rights are assigned.
Operator
The operator may view status and configuration
information through the
Product Manager
application, and
perform operational control changes, such as blocking
ports and placing the product online or offline.
Product Administrator
The product administrator can make control and
configuration changes through the
Product Manager
application.
System Administrator
The system administrator can make control and
configuration changes, define users and passwords, and
add or remove products through the
HAFM
application.
Maintenance
The maintenance operator can perform product control
and configuration changes through the
Product Manager
application, and perform diagnostics, maintenance
functions, firmware loads, and data collection.