Dell Brocade 6520 Web Tools Administrator's Guide Supporting Fabric OS v7.1.0 - Page 204

Moving an FCS policy switch position, Configuring Advanced Device Security policy, Distribute Policy

Page 204 highlights

15 Access control list policy configuration 4. Click Distribute Policy. 5. Select the switches that will receive the policy. 6. Select OK. If the policy distribution fails, an error dialog box displays. Moving an FCS policy switch position You can move the position of a primary switch in the FCS policy list. To move an FCS policy switch position, perform the following steps. 1. Open the Switch Administration window as described in "Opening the Switch Administration window" on page 31. 2. Click Show Advanced Mode. 3. Select the Security Policies tab. 4. Select the FCS tab. 5. Click Move FCS Switch. 6. Select the appropriate from and to positions. 7. Click Apply. 8. After you move all the member switches, click Apply and Close. Configuring Advanced Device Security policy The ADS policy allows you to restrict devices that are logged into the fabric using a particular F_Port. When this policy is enabled only authorized devices are allowed to login into the fabric. This can be achieved by allowing all the devices, blocking all the devices, or giving access to selected devices. ADS is supported only in Access Gateway mode. The restrictions to device login are: • All Access-Allows all the devices to login into the fabric through that F_Port. • No Access-Blocks all the devices trying to login into the fabric through that F_Port. • WWNs-Allows only selected WWNs to login into the fabric through that F_Port. NPIV capable device port WWN's can also be added to the allowed list of device port WWN's for the particular F_Port. When the ADS policy is enabled first time, all the F_Ports are set to All Access and all the devices are allowed to login into fabric. This configuration persists for subsequent logins from all devices. Existing devices that are already logged into the fabric are not affected. When the ADS policy is disabled, all the allowed lists are cleared and all the devices are allowed to login into the fabric. To configure ADS policy, perform the following steps. 1. Open the Switch Administration window as described in "Opening the Switch Administration window" on page 31. 2. Click Show Advanced Mode. 176 Web Tools Administrator's Guide 53-1002756-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268

176
Web Tools Administrator’s Guide
53-1002756-01
Access control list policy configuration
15
4.
Click
Distribute Policy
.
5.
Select the switches that will receive the policy.
6.
Select
OK
.
If the policy distribution fails, an error dialog box displays.
Moving an FCS policy switch position
You can move the position of a primary switch in the FCS policy list.
To move an FCS policy switch position, perform the following steps.
1.
Open the
Switch Administration
window as described in
“Opening the Switch Administration
window”
on page 31.
2.
Click
Show Advanced Mode
.
3.
Select the
Security Policies
tab.
4.
Select the
FCS
tab.
5.
Click
Move FCS Switch
.
6.
Select the appropriate from and to positions.
7.
Click
Apply
.
8.
After you move all the member switches, click
Apply
and
Close
.
Configuring Advanced Device Security policy
The ADS policy allows you to restrict devices that are logged into the fabric using a particular
F_Port. When this policy is enabled only authorized devices are allowed to login into the fabric. This
can be achieved by allowing all the devices, blocking all the devices, or giving access to selected
devices. ADS is supported only in Access Gateway mode.
The restrictions to device login are:
All Access
—Allows all the devices to login into the fabric through that F_Port.
No Access
—Blocks all the devices trying to login into the fabric through that F_Port.
WWNs
—Allows only selected WWNs to login into the fabric through that F_Port. NPIV capable
device port WWN’s can also be added to the allowed list of device port WWN’s for the
particular F_Port.
When the ADS policy is enabled first time, all the F_Ports are set to
All Access
and all the devices
are allowed to login into fabric. This configuration persists for subsequent logins from all devices.
Existing devices that are already logged into the fabric are not affected.
When the ADS policy is disabled, all the allowed lists are cleared and all the devices are allowed to
login into the fabric.
To configure ADS policy, perform the following steps.
1.
Open the
Switch Administration
window as described in
“Opening the Switch Administration
window”
on page 31.
2.
Click
Show Advanced Mode
.