112 Configuring advanced security
2.
Enter the following command:
Distributing ACL policies to other switches
This section explains how to manually distribute local ACL policy databases to other Fabric 5.2.x and
higher switches. The distribute command has the following dependencies:
•
All target switches must be running Fabric OS 5.2.x or higher.
•
All target switches must accept the database distribution (see ”
Configuring the database distribution
settings
” on page 111).
•
The fabric must have a tolerant or no (absent) fabric-wide consistency policy (see ”
Setting the
consistency policy fabric-wide
” on page 113).
If the fabric-wide consistency policy for a database is strict, the database cannot be manually
distributed. When you set a strict fabric-wide consistency policy for a database, the distribution
mechanism is automatically invoked whenever the database changes.
•
The local distribution setting must be accepted. To be able to initiate the distribute command, set the
local distribution to accept.
Table 29
describes how the target switch database distribution settings affect the distribution:
To distribute the local ACL policies
1.
Connect to the switch.
fddCfg --localaccept
<database_ID>
localaccept
Default setting. Allows local database to be overwritten with databases
received from other switches. Allows local database to be manually or
automatically distributed to other switches.
database_id
A semicolon-separated list of the local databases to be distributed, either
SCC and/or DCC.
Table 29
ACL policy database distribution behavior
Target Switch
Distribution
Results
Fabric OS
version
Database
setting
5.1.0 or
earlier
NA
Fails
An error is returned. The entire transaction is aborted and
no databases are updated.
5.2.x
Reject
Fails
The target switch explicitly refuses the distribution.
The entire transaction is aborted and no databases are
updated.
Accept
Succeeds
The target switch accepts the distribution.
Summary of Contents for AE370A - Brocade 4Gb SAN Switch 4/12
Page 18: ...18 ...
Page 82: ...82 Managing user accounts ...
Page 102: ...102 Configuring standard security features ...
Page 126: ...126 Maintaining configurations ...
Page 198: ...198 Routing traffic ...
Page 238: ...238 Using the FC FC routing service ...
Page 260: ...260 Administering FICON fabrics ...
Page 280: ...280 Working with diagnostic features ...
Page 332: ...332 Administering Extended Fabrics ...
Page 414: ...398 Configuring the PID format ...
Page 420: ...404 Configuring interoperability mode ...
Page 426: ...410 Understanding legacy password behaviour ...
Page 442: ...426 ...
Page 444: ......
Page 447: ......