Dell Brocade G620 Brocade 8.0.1 Fabric OS Administratiors Guide - Page 502

FC router authentication, Enable all the EX_Ports.

Page 502 highlights

Using FC-FC Routing to Connect Fabrics switches can either be merged with the fabric using a different domain ID (front or translate domain ID) or they are segmented from the fabric. ∙ If preferred domain ID is configured on an FC router for front and/or translate domain, the FC router requests the preferred domain ID. Phantom domain IDs are stored persistently and used in RDI request. To utilize the new range (160 to 239), do one of the following tasks: Option 1: 1. Convert the EX_Port to non-FC router port remove existing Xlate configuration using the fcrXlateConfig command. 2. Apply the default configuration, and then configure the EX_Ports again and remove existing Xlate configuration using the fcrXlateConfig command.. Option 2: 1. Disable all EX_Ports in the same edge farbic and persistent XD feature, and then reset the persistent phantom domain using the fcrConfigure -resetPhantomDomain command. switch:admin> fcrconfigure --resetphantomdomain This operation will reset all the phantom domain to be default range Do you want to continue (Y/N):y Phantom Domain IDs were successfully reset to default range Using the -force option to force the reset phantom domain. switch:admin> fcrconfigure -resetphantomdomain -force Phantom Domain IDs were successfully reset to default range 2. Enable all the EX_Ports. TABLE 93 Front and translate domain IDs Firmware version in FC router Front domain ID requested Prior to Fabric OS 7.4.0 160 Fabric OS 7.4.0 and later 160 Translate domain ID requested 1 200 When an FC router is running Fabric OS 7.4.0 and the edge FC router is running Fabric OS 7.3.0, or vice versa, you need to use a different FID to reconstruct the EX_Ports or disable the EX_Port or use the fcrXlateConfig command to delete the stale translate domains when moving from Fabric OS 7.3.0 to Fabric OS 7.4.0 as the old translate domains are still in effect. FC router authentication A Brocade FC router is capable of forming a secure link across fabrics. The EX_Port-enabled router exchanges DH-CHAP information with the edge fabric to enable authentication. Note that while setting secret keys in the edge switch, the front phantom WWN should be used as the remote switch WWN in the edge fabric. The front phantom domain's WWN is available through the portCfgExport command of the EX_Port connecting to the edge fabric. The FC router switch should use the edge switch's WWN to configure the secret keys. Refer to Secret key pairs for DH-CHAP on page 232 for more details. FC-FC routing behaves passively to the authentication requests received from edge fabric switches. An FC router never initiates authentication on an EX_Port and only responds to the edge fabric requests. NOTE Changing the switch authentication policy mode does not affect online EX_Ports, so it is acceptable to leave the default Passive policy configured on the FC router while the Active or On policy is required on the edge switch. 502 Brocade Fabric OS Administration Guide, 8.0.1 53-1004111-02

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551

switches can either be merged with the fabric using a different domain ID (front or translate domain ID) or they are segmented
from the fabric.
If preferred domain ID is configured on an FC router for front and/or translate domain, the FC router requests the preferred
domain ID. Phantom domain IDs are stored persistently and used in RDI request. To utilize the new range (160 to 239), do one
of the following tasks:
Option 1:
1.
Convert the EX_Port to non-FC router port remove existing Xlate configuration using the
fcrXlateConfig
command.
2.
Apply the default configuration, and then configure the EX_Ports again and remove existing Xlate configuration using the
fcrXlateConfig
command..
Option 2:
1.
Disable all EX_Ports in the same edge farbic and persistent XD feature, and then reset the persistent phantom domain
using the
fcrConfigure –resetPhantomDomain
command.
switch:admin> fcrconfigure --resetphantomdomain
This operation will reset all the phantom domain to be default range
Do you want to continue (Y/N):y
Phantom Domain IDs were successfully reset to default range
Using the
–force
option to force the reset phantom domain.
switch:admin> fcrconfigure –resetphantomdomain -force
Phantom Domain IDs were successfully reset to default range
2.
Enable all the EX_Ports.
TABLE 93
Front and translate domain IDs
Firmware version in FC router
Front domain ID requested
Translate domain ID requested
Prior to Fabric OS 7.4.0
160
1
Fabric OS 7.4.0 and later
160
200
When an FC router is running Fabric OS 7.4.0 and the edge FC router is running Fabric OS 7.3.0, or vice versa, you need to use a
different FID to reconstruct the EX_Ports or disable the EX_Port or use the
fcrXlateConfig
command to delete the stale translate
domains when moving from Fabric OS 7.3.0 to Fabric OS 7.4.0 as the old translate domains are still in effect.
FC router authentication
A Brocade FC router is capable of forming a secure link across fabrics. The EX_Port-enabled router exchanges DH-CHAP information
with the edge fabric to enable authentication.
Note that while setting secret keys in the edge switch, the front phantom WWN should be used as the remote switch WWN in the edge
fabric. The front phantom domain's WWN is available through the
portCfgExport
command of the EX_Port connecting to the edge
fabric. The FC router switch should use the edge switch's WWN to configure the secret keys. Refer to
Secret key pairs for DH-CHAP
on
page 232 for more details.
FC-FC routing behaves passively to the authentication requests received from edge fabric switches. An FC router never initiates
authentication on an EX_Port and only responds to the edge fabric requests.
NOTE
Changing the switch authentication policy mode does not affect online EX_Ports, so it is acceptable to leave the default Passive
policy configured on the FC router while the Active or On policy is required on the edge switch.
Using FC-FC Routing to Connect Fabrics
Brocade Fabric OS Administration Guide, 8.0.1
502
53-1004111-02