HP 8/20q HP StorageWorks 8/20q Fibre Channel Switch Command Line Interface Gui - Page 94

Modifying the security database, Managing security sets, Creating a security set

Page 94 highlights

Modifying the security database To modify the security database: 1. Open an Admin session with the admin start command. 8/20q FC Switch #> admin start An Admin session prevents other accounts from making changes at the same time either through Telnet, QuickTools, Enterprise Fabric Management Suite, or Simple SAN Connection Manager. 2. To open a Security Edit session, enter the security edit command. The Security Edit session provides access to the securityset, group, and security commands used to make modifications to the security database. 8/20q FC Switch (admin) #> security edit 8/20q FC Switch (admin-security)#> securityset . . . 8/20q FC Switch (admin-security)#> group . . . 8/20q FC Switch (admin-security)#> security . . . 3. When you finish making changes, take one of the following actions: • To save the changes and close the Security Edit session, enter the security save command. 8/20q FC Switch (admin-security)#> security save • To close the Security Edit session without saving changes, enter the security cancel command. 8/20q FC Switch (admin-security)#> security cancel 4. To activate the changes to the active security set, enter the security activate command. 8/20q FC Switch (admin)#> security activate 5. To release the Admin session for other administrators, enter the admin end command. 8/20q FC Switch (admin)#> admin end Resetting the security database There are two ways to remove all groups and security sets from the security database: • Enter the security clear command, as shown in the following example: 8/20q FC Switch (admin-security) #> security clear All security information will be cleared. Please confirm (y/n): [n] y 8/20q FC Switch (admin-security) #> security save • Enter the reset security command, as shown in the following example. 8/20q FC Switch (admin) #> reset security The security configuration values, Autosave and FabricBindingEnabled, remain unchanged. Managing security sets This sub-section describes the security set management tasks. All of these tasks except Activating a security set, page 95 and Deactivating a security set, page 95 require a Security Edit session. Creating a security set To create a new security set, enter the securityset create command, as shown in the following example: 8/20q FC Switch (admin-security) #> securityset create securityset_1 Deleting a security set To delete a security set, enter the securityset delete command, as shown in the following example: 8/20q FC Switch (admin-security) #> securityset delete securityset_1 Renaming a security set To rename a security set. enter the securityset rename command, as shown in the following example: 8/20q FC Switch (admin-security) #> securityset rename securityset_old securityset_new 94 Device Security Configuration

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330

94
Device Security Configuration
Modifying the security database
To modify the security database:
1.
Open an Admin session with the
admin start
command.
8/20q FC Switch #> admin start
An Admin session prevents other accounts from making changes at the same time either through Telnet,
QuickTools, Enterprise Fabric Management Suite, or Simple SAN Connection Manager.
2.
To open a Security Edit session, enter the
security edit
command. The Security Edit session
provides access to the
securityset
,
group
, and
security
commands used to make modifications
to the security database.
8/20q FC Switch (admin) #> security edit
8/20q FC Switch (admin-security)#> securityset . . .
8/20q FC Switch (admin-security)#> group . . .
8/20q FC Switch (admin-security)#> security . . .
3.
When you finish making changes, take one of the following actions:
To save the changes and close the Security Edit session, enter the
security save
command.
8/20q FC Switch (admin-security)#> security save
To close the Security Edit session without saving changes, enter the
security cancel
command.
8/20q FC Switch (admin-security)#> security cancel
4.
To activate the changes to the active security set, enter the
security activate
command.
8/20q FC Switch (admin)#> security activate
5.
To release the Admin session for other administrators, enter the
admin end
command.
8/20q FC Switch (admin)#> admin end
Resetting the security database
There are two ways to remove all groups and security sets from the security database:
Enter the
security clear
command, as shown in the following example:
8/20q FC Switch (admin-security) #> security clear
All security information will be cleared.
Please confirm (y/n): [n] y
8/20q FC Switch (admin-security) #> security save
Enter the
reset security
command, as shown in the following example.
8/20q FC Switch (admin) #> reset security
The security configuration values,
Autosave
and
FabricBindingEnabled
, remain unchanged.
Managing security sets
This sub-section describes the security set management tasks. All of these tasks except
Activating a security
set
, page 95 and
Deactivating a security set
, page 95 require a Security Edit session.
Creating a security set
To create a new security set, enter the
securityset create
command, as shown in the following
example:
8/20q FC Switch (admin-security) #> securityset create securityset_1
Deleting a security set
To delete a security set, enter the
securityset delete
command, as shown in the following example:
8/20q FC Switch (admin-security) #> securityset delete securityset_1
Renaming a security set
To rename a security set. enter the
securityset rename
command, as shown in the following
example:
8/20q FC Switch (admin-security) #> securityset rename securityset_old
securityset_new