HP StorageWorks 8/20q HP StorageWorks 8/20q Fibre Channel Switch command line - Page 98

Creating a group, Adding members to a group, Table 9

Page 98 highlights

Creating a group Creating a group involves specifying a group name and a group type. There are three types of groups: • ISL group-secures connected switches • Port group-secures connected devices • MS group-secures management server commands To create a new port group, enter the group create command, as shown in the following example: 8/20q FC Switch (admin-security) #> group create group_port port Deleting a group To delete group_port from the security database, enter the group delete command, as shown in the following example: 8/20q FC Switch (admin-security) #> group delete group_port Renaming a group To rename group_port to port_1, enter the group rename command, as shown in the following example: 8/20q FC Switch (admin-security) #> group rename group_port port_1 Copying a group To copy the contents of an existing group (group_port) to a new group (port_1), enter the group copy command, as shown in the following example: 8/20q FC Switch (admin-security) #> group copy group_port port_1 Adding members to a group Adding a member to a group involves specifying a group, the member worldwide name, and the member attributes. The member attributes define the authentication method, encryption method, secrets, and fabric binding, depending on the group type. • For ISL member attributes, see Table 9. • For Port member attributes, see Table 10. • For MS member attributes, see Table 11. To add a member to a group, enter the group add command, as shown in the following example: 8/20q FC Switch #> admin start 8/20q FC Switch (admin) #> security edit 8/20q FC Switch (admin-security) #> group add Group_1 A list of attributes with formatting and default values will follow Enter a new value or simply press the ENTER key to accept the current value with exception of the Group Member WWN field which is mandatory. If you wish to terminate this process before reaching the end of the list press 'q' or 'Q' and the ENTER key to do so. Group Name Group_1 Group Type ISL Member (WWN) 10:00:00:c0:dd:00:90:a3 [00:00:00:00:00:00:00:00] Authentication (None / Chap) [None ] chap PrimaryHash (MD5 / SHA-1) [MD5 ] PrimarySecret (32 hex or 16 ASCII char value) [ ] 0123456789abcdef SecondaryHash (MD5 / SHA-1 / None) [None ] SecondarySecret (40 hex or 20 ASCII char value) [ ] Binding (domain ID 1-239, 0=None) [0 ] Finished configuring attributes. To discard this configuration use the security cancel command. 98 Device security configuration

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332

98
Device security configuration
Creating a group
Creating a group involves specifying a group name and a group type. There are three types of groups:
ISL group—secures connected switches
Port group—secures connected devices
MS group—secures management server commands
To create a new port group, enter the
group create
command, as shown in the following example:
8/20q FC Switch (admin-security) #> group create group_port port
Deleting a group
To delete group_port from the security database, enter the
group delete
command, as shown in the
following example:
8/20q FC Switch (admin-security) #> group delete group_port
Renaming a group
To rename group_port to port_1, enter the
group rename
command, as shown in the following example:
8/20q FC Switch (admin-security) #> group rename group_port port_1
Copying a group
To copy the contents of an existing group (group_port) to a new group (port_1), enter the
group copy
command, as shown in the following example:
8/20q FC Switch (admin-security) #> group copy group_port port_1
Adding members to a group
Adding a member to a group involves specifying a group, the member worldwide name, and the member
attributes. The member attributes define the authentication method, encryption method, secrets, and fabric
binding, depending on the group type.
For ISL member attributes, see
Table 9
.
For Port member attributes, see
Table 10
.
For MS member attributes, see
Table 11
.
To add a member to a group, enter the
group add
command, as shown in the following example:
8/20q FC Switch #> admin start
8/20q FC Switch (admin) #> security edit
8/20q FC Switch (admin-security) #> group add Group_1
A list of attributes with formatting and default values will follow
Enter a new value or simply press the ENTER key to accept the current value
with exception of the Group Member WWN field which is mandatory.
If you wish to terminate this process before reaching the end of the list
press 'q' or 'Q' and the ENTER key to do so.
Group Name
Group_1
Group Type
ISL
Member
(WWN)
[00:00:00:00:00:00:00:00]
10:00:00:c0:dd:00:90:a3
Authentication
(None / Chap)
[None
] chap
PrimaryHash
(MD5 / SHA-1)
[MD5
]
PrimarySecret
(32 hex or 16 ASCII char value)
[
] 0123456789abcdef
SecondaryHash
(MD5 / SHA-1 / None)
[None
]
SecondarySecret (40 hex or 20 ASCII char value)
[
]
Binding
(domain ID 1-239, 0=None)
[0
]
Finished configuring attributes.
To discard this configuration use the security cancel command.