Fabric OS 5.2.x administrator guide 145
The following example switches to the AD12 context. Note that the prompt changes to display the
Admin Domain.
Performing zone validation
If you are working with zones, you should be aware that there is an Admin Domain impact. Zone objects
can be part of an Admin Domain. You can use the
zone --validate
command to list all zone members
that are not part of the current zone enforcement table. A member might not be part of the zone
enforcement table because:
•
The device is offline.
•
The device is online, but is connected to an AD-unaware switch.
•
The device is online but is not part of the current Admin Domain.
For more information about the
zone
command and its use with Admin Domains, see the
Fabric OS
Command Reference Manual
.
Admin Domain interactions
The administrative domain feature provides interaction with other Fabric OS features and across third-party
applications. You can manage Admin Domains with Web Tools applications and with Fabric Manager. If
the current Admin Domain owns the switch, you can perform Fabric Watch operations.
Admin Domain interactions do not extend to user session tunneling across switches. A user logged into a
switch can control only the local switch ports as specified in the Admin Domain.
When the fabric is in secure mode, the following applies:
•
There is no support for ACL configuration under each Administrative Domain.
•
ACL configuration commands are allowed only in AD0 and AD255. None of the policy configurations
are validated with AD membership.
•
You cannot use Admin Domains and Secure Fabric OS in combination. The Secure Fabric OS
environment does not support Admin Domains:
• If Secure Fabric OS is active, you cannot configure Admin Domains.
• If Admin Domains are configured, you cannot use Secure Fabric OS.
Table 41
lists some of the Fabric OS features and considerations that apply when using Admin Domains.
sw5:admin>
ad --select 12
sw5:AD12:admin>
Table 41
Admin Domain interaction with Fabric OS features
Fabric OS feature
Admin Domain interaction
ACLs
If no user-defined Admin Domains exist, you can run ACL configuration
commands in only AD0 and AD255. If any user-defined Admin Domains exist,
you can run ACL configuration commands only in AD255.
You
cannot
use ACL configuration commands or validate ACL policy
configurations against AD membership under each Admin Domain.
Advanced
Performance
Monitoring (APM)
All APM-related filter setup and statistics viewing is allowed only if the local switch
is part of the current Admin Domain.
Fabric Watch
Fabric Watch configuration operations are allowed only if the local switch is part
of the current Admin Domain.
Summary of Contents for AE370A - Brocade 4Gb SAN Switch 4/12
Page 18: ...18 ...
Page 82: ...82 Managing user accounts ...
Page 102: ...102 Configuring standard security features ...
Page 126: ...126 Maintaining configurations ...
Page 198: ...198 Routing traffic ...
Page 238: ...238 Using the FC FC routing service ...
Page 260: ...260 Administering FICON fabrics ...
Page 280: ...280 Working with diagnostic features ...
Page 332: ...332 Administering Extended Fabrics ...
Page 414: ...398 Configuring the PID format ...
Page 420: ...404 Configuring interoperability mode ...
Page 426: ...410 Understanding legacy password behaviour ...
Page 442: ...426 ...
Page 444: ......
Page 447: ......