HP A7533A HP StorageWorks Fabric OS 6.1.1 administrator guide (5697-0235, Dece - Page 110

FCS policy restrictions

Page 110 highlights

Table 25 FCS policy states (continued) Policy state Characteristics Active policy with one entry Active policy with multiple entries A primary FCS switch is designated (local switch), but there are no backup FCS switches. If the primary FCS switch becomes unavailable for any reason, the fabric is left without an FCS switch. A primary FCS switch and one or more backup FCS switches are designated. If the primary FCS switch becomes unavailable, the next switch in the list becomes the primary FCS switch. The FCS policy is designed to accommodate mixed fabric environments that contain switches with pre-5.3.0 and later versions of Fabric OS. By setting the configuration parameters to accept fabric distribution, Fabric OS 6.0.0 and later switches may enforce FCS policy and perform database distribution among 5.3.0 and 6.0.0 and later switches while still allowing pre-5.3.0 switches to join the fabric. The following items describe distribution behavior for pre-Fabric OS 5.3.0: • Distribution to pre-5.3.0 switches with specific Domain IDs When specific Domain IDs are given for the distribution, all domains must be on a switch with Fabric OS 5.3.0 or later. If one of the domains is pre-5.3.0 the distribution operation will fail. • Distribution to pre-5.3.0 switches using the wild card (*) character When the wild card character is specified, distribution succeeds even if the fabric contains pre-5.3.0 switches. However, the FCS database will be sent only to switches with a Fabric OS of 5.2.0 or later in the fabric and not to pre-5.2.0 switches. Fabric OS 5.2.0 switches receive the distribution and will ignore the FCS database. FCS policy restrictions The backup FCS switches normally cannot modify the policy. However, if the primary FCS switch in the policy list is not reachable, a back-up FCS switch will be allowed to modify the policy. Once an FCS policy is configured and distributed across the fabric, only the primary FCS switch can perform certain operations. Operations which affect fabric-widefabric-wide configuration are allowed only from the primary FCS switch. Backup and non-FCS switches cannot perform security, zoning and AD operations that affect the fabric configuration. The following error message is returned if a backup or non-FCS switch tries to perform these operations: Can only execute this command on the primary FCS switch. Operations that do not affect the fabric configuration, such as show or local switch commands, would be allowed on back-up and non-FCS switches. FCS enforcement applies only for user-initiated fabric-widefabric-wide operations. Internal fabric data propagation because of a fabric merge is not blocked. Consequently, a new switch which joins the FCS enabled fabric could still propagate the AD and zone database. Table 26 shows the commands for switch operations for a Primary FCS enforcement. Table 26 Switch operations Allowed on FCS switches Allowed on all switches secPolicyAdd (Allowed on all switches for secPolicyShow SCC/DCC policies as long as it is not fabric-wide) secPolicyCreate (Allowed on all switches for fddcfg -localaccept/localreject SCC/DCC policies as long as it is not fabric-wide) secPolicyDelete (Allowed on all switches for SCC/DCC policies as long as its not fabric-wide) userconfig, Passwd, Passwdcfg (Fabric-wide distribution is not allowed from a backup or non-FCS switch.) secPolicyRemove (Allowed on all switches for secPolicyActivate SCC/DCC policies as long as its not fabric-wide) fddcfg --fabwideset secPolicySave 110 Configuring advanced security features

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496

110
Configuring advanced security features
The FCS policy is designed to accommodate mixed fabric environments that contain switches with
pre-5.3.0 and later versions of Fabric OS. By setting the configuration parameters to accept fabric
distribution, Fabric OS 6.0.0 and later switches may enforce FCS policy and perform database distribution
among 5.3.0 and 6.0.0 and later switches while still allowing pre-5.3.0 switches to join the fabric. The
following items describe distribution behavior for pre-Fabric OS 5.3.0:
Distribution to pre-5.3.0 switches with specific Domain IDs
When specific Domain IDs are given for the distribution, all domains must be on a switch with Fabric
OS 5.3.0 or later. If one of the domains is pre-5.3.0 the distribution operation will fail.
Distribution to pre-5.3.0 switches using the wild card (*) character
When the wild card character is specified, distribution succeeds even if the fabric contains pre-5.3.0
switches. However, the FCS database will be sent only to switches with a Fabric OS of 5.2.0 or later in
the fabric and not to pre-5.2.0 switches. Fabric OS 5.2.0 switches receive the distribution and will
ignore the FCS database.
FCS policy restrictions
The backup FCS switches normally cannot modify the policy. However, if the primary FCS switch in the
policy list is not reachable, a back-up FCS switch will be allowed to modify the policy.
Once an FCS policy is configured and distributed across the fabric, only the primary FCS switch can
perform certain operations. Operations which affect fabric-widefabric-wide configuration are allowed only
from the primary FCS switch. Backup and non-FCS switches cannot perform security, zoning and AD
operations that affect the fabric configuration. The following error message is returned if a backup or
non-FCS switch tries to perform these operations:
Can only execute this command on the primary FCS switch
.
Operations that do not affect the fabric configuration, such as
show
or local switch commands, would be
allowed on back-up and non-FCS switches.
FCS enforcement applies only for user-initiated fabric-widefabric-wide operations. Internal fabric data
propagation because of a fabric merge is not blocked. Consequently, a new switch which joins the FCS
enabled fabric could still propagate the AD and zone database.
Table 26
shows the commands for switch operations for a Primary FCS enforcement.
Active policy with one entry
A primary FCS switch is designated (local switch), but there are no
backup FCS switches. If the primary FCS switch becomes unavailable
for any reason, the fabric is left without an FCS switch.
Active policy with multiple
entries
A primary FCS switch and one or more backup FCS switches are
designated. If the primary FCS switch becomes unavailable, the next
switch in the list becomes the primary FCS switch.
Table 25
FCS policy states (continued)
Policy state
Characteristics
Table 26
Switch operations
Allowed on FCS switches
Allowed on all switches
secPolicyAdd
(Allowed on all switches for
SCC/DCC policies as long as it is not fabric-wide)
secPolicyShow
secPolicyCreate
(Allowed on all switches for
SCC/DCC policies as long as it is not fabric-wide)
fddcfg –localaccept/localreject
secPolicyDelete
(Allowed on all switches for
SCC/DCC policies as long as its not fabric-wide)
userconfig
,
Passwd
,
Passwdcfg
(Fabric-wide
distribution is not allowed from a backup or
non-FCS switch.)
secPolicyRemove
(Allowed on all switches for
SCC/DCC policies as long as its not fabric-wide)
secPolicyActivate
fddcfg –-fabwideset
secPolicySave