120 Configuring advanced security features
fabric and not to pre-5.2.0 switches. Fabric OS 5.2.0 switches receive the distribution and will ignore
the FCS database.
FCS policy restrictions
The backup FCS switches normally cannot modify the policy. However, if the Primary FCS switch in the
policy list is not reachable, a backup FCS switch is allowed to modify the policy.
Once an FCS policy is configured and distributed across the fabric, only the Primary FCS switch can
perform certain operations. Operations that affect fabric-wide configuration are allowed only from the
Primary FCS switch. Backup and non-FCS switches cannot perform security, zoning, and AD operations
that affect the fabric configuration. The following error message is returned if a backup or non-FCS switch
tries to perform these operations.
Can only execute this command on the Primary FCS switch.
Operations that do not affect the fabric configuration, such as
show
or local switch commands, are
allowed on backup and non-FCS switches.
FCS enforcement applies only for user-initiated fabric-wide operations. Internal fabric data propagation
because of a fabric merge is not blocked. Consequently, a new switch that joins the FCS-enabled fabric
could still propagate the AD and zone database.
Table 27
shows the commands for switch operations for Primary FCS enforcement.
FCS enforcement does not apply to pre-5.3.0 switches and they will be able to initiate all operations.
Overview of FCS policy management
Whether your intention is to create new FCS policies or manage your current FCS policies, you must follow
certain steps to ensure that the domains throughout your fabric have the same policy.
NOTE:
The local-switch WWN cannot be deleted from the FCS policy.
1.
Set the pre-5.3.0 switches in the fabric to accept the FCS policy using the
fddCfg
--
localaccept
or
fddCfg
--
localreject
command.
2.
Create the FCS policy using the
secPolicyCreate
command.
Table 27
Switch operations
Allowed on FCS switches
Allowed on all switches
secPolicyAdd
(Allowed on all switches for SCC
and DCC policies as long as it is not fabric-wide)
secPolicyShow
secPolicyCreate
(Allowed on all switches for
SCC and DCC policies as long as it is not
fabric-wide)
fddCfg –-localaccept
or
fddCfg
--localreject
secPolicyDelete
(Allowed on all switches for
SCC and DCC policies as long as its not
fabric-wide)
userconfig
,
Passwd
,
Passwdcfg
(Fabric-wide
distribution is not allowed from a backup or
non-FCS switch.)
secPolicyRemove
(Allowed on all switches for
SCC and DCC policies as long as its not
fabric-wide)
secPolicyActivate
fddCfg –-fabwideset
secPolicySave
Any fabric-wide commands
secPolicyAbort
All zoning commands except the show commands SNMP commands
All AD commands
configupload
Any local-switch commands
Any AD command that does not affect fabric-wide
configuration
Summary of Contents for A7533A - Brocade 4Gb SAN Switch Base
Page 1: ...HP StorageWorks Fabric OS 6 2 administrator guide Part number 5697 0016 Edition May 2009 ...
Page 24: ...24 ...
Page 99: ...Fabric OS 6 2 administrator guide 99 ...
Page 100: ...100 Managing user accounts ...
Page 118: ...116 Configuring standard security features ...
Page 164: ...162 Configuring advanced security features ...
Page 234: ...232 Installing and maintaining firmware ...
Page 268: ...266 Administering advanced zoning ...
Page 284: ...282 Configuring Enterprise class platforms ...
Page 292: ...290 Routing traffic ...
Page 294: ...292 Interoperability for merged SANs ...
Page 302: ...300 Configuring the Distributed Management Server ...
Page 334: ...332 iSCSI gateway service ...
Page 340: ...338 Administering NPIV ...
Page 407: ...Fabric OS 6 2 administrator guide 405 ...
Page 408: ...406 Using the FC FC routing service ...
Page 438: ...434 Administering extended fabrics ...
Page 460: ...456 Administering ISL trunking ...
Page 516: ...512 FICON fabrics ...
Page 526: ...522 Configuring and monitoring FICON Extension Services ...
Page 540: ...536 Configuring the PID format ...
Page 544: ...540 Understanding legacy password behavior ...
Page 546: ...542 Mixed fabric configurations for non merge SANs ...
Page 550: ...546 Migrating from an MP Router to a 400 MP Router ...
Page 558: ...554 Inband Management ...
Page 572: ...568 ...