HP StorageWorks 8/20q HP StorageWorks 8/20q Fibre Channel Switch installation - Page 24

Switch services - 24 san switch default password

Page 24 highlights

disabled (InteropMode=0). Other B-series switches in the remote fabric need not support NPIV, but the interoperability mode must also be disabled. 3. Map local devices to remote devices and activate the connection. The QuickTools mapping process creates an inter-fabric zone (IFZ) in the active zone set consisting of the local device, the remote device, and the TR_Port. When the mapping is complete, QuickTools activates the new zone set. The name of the inter-fabric zone begins with IFZ followed by the lowest device port WWN followed by the remaining port WWN, all uppercase, separated by underscores (_). For example, consider the following local and remote device WWNs: • Local device: 21:00:00:e0:8b:0e:d3:59 • Remote device: 22:00:00:04:cf:a8:7f:2d The inter-fabric zone name would be: IFZ_210000E08B0ED359_22000004CFA87F2D 4. Apply the same inter-fabric zone that was created on the local fabric to the active zoning on the remote fabric. QuickTools creates a list of commands during the mapping process that, when run on a remote fabric consisting of HP StorageWorks B-series switches, will make the necessary zoning changes to the remote fabric. When modifications to the active zoning on both fabrics are complete, the transparent routing connection becomes active, and the local devices will discover the remote devices. Switch services You can configure your switch to suit the demands of your environment by enabling or disabling a variety of switch services. Familiarize yourself with the following switch services and determine which ones you need. • Telnet: Provides for the management of the switch over a Telnet connection. Disabling this service is not recommended. The default is enabled. • Secure Shell (SSH): Provides for secure remote connections to the switch using SSH. Your workstation must also use an SSH client. The default is disabled. • GUI Management: Provides for out-of-band management of the switch with Simple SAN Connection Manager, QuickTools, SNMP, and SMI-S. If this service is disabled, the switch can only be managed inband or through the serial port. The default is enabled. • Inband Management: Provides for the management of the switch over an inter-switch link using Simple SAN Connection Manager, QuickTools, SNMP, or management server. If you disable inband management, you can no longer communicate with that switch by means other than an Ethernet or serial connection. The default is enabled. • Secure Socket Layer (SSL): Provides for secure SSL connections for the QuickTools web applet and SMI-S. This service must be enabled to authenticate users through a Remote Authentication Dial-in Service (RADIUS) server. To enable secure SSL connections, you must first synchronize the date and time on the switch and the workstation. Enabling SSL automatically creates a security certificate on the switch. The default is disabled. NOTE: Simple SAN Connection Manager version 1.0 does not support the SSL service. If SSL is enabled, you will be unable to manage the switch using this version of Simple SAN Connection Manager. • QuickTools web applet (EmbeddedGUI): Provides for access to the QuickTools web applet. QuickTools enables you to point at a switch with an internet browser and manage the switch through the browser. The default is enabled. • Simple Network Management Protocol (SNMP): Provides for the management of the switch through third-party applications that use the Simple Network Management Protocol (SNMP). Security consists of a read community string and a write community string that serve as passwords that control read and write access to the switch. These strings are set at the factory to these well-known defaults and should be changed if SNMP is to be enabled. Otherwise, you risk unwanted access to the switch. The switch supports SNMP versions 1, 2, and 3. The default configuration enables SNMP and disables SNMP version 3 security. 24

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82

24
disabled (InteropMode=0). Other B-series switches in the remote fabric need not support NPIV, but the
interoperability mode must also be disabled.
3.
Map local devices to remote devices and activate the connection. The QuickTools mapping process
creates an inter-fabric zone (IFZ) in the active zone set consisting of the local device, the remote device,
and the TR_Port. When the mapping is complete, QuickTools activates the new zone set.
The name of the inter-fabric zone begins with IFZ followed by the lowest device port WWN followed by
the remaining port WWN, all uppercase, separated by underscores (_). For example, consider the
following local and remote device WWNs:
Local device: 21:00:00:e0:8b:0e:d3:59
Remote device: 22:00:00:04:cf:a8:7f:2d
The inter-fabric zone name would be:
IFZ_210000E08B0ED359_22000004CFA87F2D
4.
Apply the same inter-fabric zone that was created on the local fabric to the active zoning on the remote
fabric. QuickTools creates a list of commands during the mapping process that, when run on a remote
fabric consisting of HP StorageWorks B-series switches, will make the necessary zoning changes to the
remote fabric. When modifications to the active zoning on both fabrics are complete, the transparent
routing connection becomes active, and the local devices will discover the remote devices.
Switch services
You can configure your switch to suit the demands of your environment by enabling or disabling a variety
of switch services. Familiarize yourself with the following switch services and determine which ones you
need.
Telnet
: Provides for the management of the switch over a Telnet connection. Disabling this service is not
recommended. The default is
enabled
.
Secure Shell (SSH)
: Provides for secure remote connections to the switch using SSH. Your workstation
must also use an SSH client. The default is
disabled
.
GUI Management
: Provides for out-of-band management of the switch with Simple SAN Connection
Manager, QuickTools, SNMP, and SMI-S. If this service is disabled, the switch can only be managed
inband or through the serial port. The default is
enabled
.
Inband Management
: Provides for the management of the switch over an inter-switch link using Simple
SAN Connection Manager, QuickTools, SNMP, or management server. If you disable inband
management, you can no longer communicate with that switch by means other than an Ethernet or
serial connection. The default is
enabled
.
Secure Socket Layer (SSL)
: Provides for secure SSL connections for the QuickTools web applet and
SMI-S. This service must be enabled to authenticate users through a Remote Authentication Dial-in
Service (RADIUS) server. To enable secure SSL connections, you must first synchronize the date and time
on the switch and the workstation. Enabling SSL automatically creates a security certificate on the
switch. The default is
disabled
.
NOTE:
Simple SAN Connection Manager version 1.0 does not support the SSL service. If SSL is
enabled, you will be unable to manage the switch using this version of Simple SAN Connection
Manager.
QuickTools web applet (EmbeddedGUI
)
: Provides for access to the QuickTools web applet. QuickTools
enables you to point at a switch with an internet browser and manage the switch through the browser.
The default is
enabled
.
Simple Network Management Protocol (SNMP)
: Provides for the management of the switch through
third-party applications that use the Simple Network Management Protocol (SNMP). Security consists
of a read community string and a write community string that serve as passwords that control read and
write access to the switch. These strings are set at the factory to these well-known defaults and should
be changed if SNMP is to be enabled. Otherwise, you risk unwanted access to the switch. The switch
supports SNMP versions 1, 2, and 3. The default configuration enables SNMP and disables SNMP
version 3 security.