
168 Managing administrative domains
that are not part of the current zone enforcement table. A member might not be part of the zone
enforcement table because:
•
The device is offline.
•
The device is online, but is connected to an AD-unaware switch.
•
The device is online but is not part of the current Admin Domain.
For more information about the
zone
command and its use with Admin Domains, see the
Fabric OS
Command Reference Manual
.
Admin Domain interactions
The administrative domain feature provides interaction with other Fabric OS features and across third-party
applications. You can manage Admin Domains with Web Tools applications and with Fabric Manager. If
the current Admin Domain owns the switch, you can perform Fabric Watch operations.
Admin Domain interactions do not extend to user session tunneling across switches. A user logged into a
switch can control only the local switch ports as specified in the Admin Domain.
When the fabric is in secure mode, the following applies:
•
There is no support for ACL configuration under each Administrative Domain.
•
ACL configuration commands are allowed only in AD0 and AD255. None of the policy configurations
are validated with AD membership.
•
You cannot use Admin Domains and Secure Fabric OS in combination. The Secure Fabric OS
environment does not support Admin Domains:
• If Secure Fabric OS is active, you cannot configure Admin Domains.
• If Admin Domains are configured, you cannot use Secure Fabric OS.
Table 48
lists some of the Fabric OS features and considerations that apply when using Admin Domains.
Table 48
Admin Domain interaction with Fabric OS features
Fabric OS feature
Admin Domain interaction
ACLs
If no user-defined Admin Domains exist, you can run ACL configuration
commands in only AD0 and AD255. If any user-defined Admin Domains exist,
you can run ACL configuration commands only in AD255.
You
cannot
use ACL configuration commands or validate ACL policy
configurations against AD membership under each Admin Domain.
Advanced
Performance
Monitoring (APM)
All APM-related filter setup and statistics viewing is allowed only if the local switch
is part of the current Admin Domain.
Fabric Watch
Fabric Watch configuration operations are allowed only if the local switch is part
of the current Admin Domain.
FCR
You can create LSAN zones as a physical fabric administrator or as an individual
AD administrator. The LSAN zone can be part of the root zone database or the
AD zone database.
•
FCR collects the LSAN zones from all ADs. If both edge fabrics have matching
LSAN zones and both devices are online, FCR triggers a device import.
•
LSAN zone enforcement in the local fabric occurs only if the AD member list
contains both of the devices (local and imported device) specified in the
LSAN zone.
To support legacy applications, WWNs are reported based on the AD context
using NAA=5. As a result, you cannot use the NAA=5 field alone in the WWN
to detect an FC Router.
FDMI
FDMI operations are allowed only in AD0 and AD255.
Summary of Contents for AA979A - StorageWorks SAN Switch 2/8V
Page 1: ...HP StorageWorks Fabric OS 5 3 x administrator guide Part number 5697 0244 November 2009 ...
Page 16: ...16 ...
Page 20: ...18 ...
Page 24: ...24 Introducing Fabric OS CLI procedures ...
Page 116: ...118 Maintaining configurations ...
Page 170: ...172 Managing administrative domains ...
Page 200: ...202 Installing and maintaining firmware ...
Page 222: ...224 Routing traffic ...
Page 274: ...286 Administering FICON fabrics ...
Page 294: ...306 Working with diagnostic features ...
Page 350: ...362 Administering Extended Fabrics ...
Page 438: ...440 Configuring the PID format ...
Page 444: ...446 Configuring McData Open Fabric mode ...
Page 450: ...452 Understanding legacy password behaviour ...