
Fabric OS Administrator’s Guide
141
53-1002446-01
DCC policies
7
DCC policy behavior with Fabric-Assigned PWWNs
A DCC policy check is always performed for the physical port WWN of a device when the HBA has
established that the device is attempting a normal FLOGI and has both a fabric-assigned port WWN
(FA-PWWN) and a physical port WWN.
DCC policies created with FA-PWWNs will result in the disabling of FA-PWWN assigned ports on
subsequent FLOGI. It is therefore recommended to create policies with the physical PWWN
DCC policies created with the lock down feature result in DCC policies with FA-PWWNs. It is
therefore recommended to avoid using the lock down feature in fabrics that are using FA-PWWNs.
A DCC policy created with a device WWN for a specific port allows the device to log in only on the
same port. The same device will not be allowed to log in on a different port. For devices that log in
across an AG, the policy should be created with all the NPIV ports, so even if failover occurs the
device will be allowed to log in on a different NPIV port.
Table 30
lists the behavior of the DCC policy with FA-PWWNs in the fabric when the DCC policy is
created using lockdown support.
Table 31
shows the behavior of a DCC policy created manually with the physical PWWN of a device.
The configurations shown in this table are the recommended configurations when an FA-PWWN is
logged into the switch.
TABLE 30
DCC policy behavior with FA-PWWN when created using lockdown support
Configuration
WWN seen on
DCC policy list
Behavior when DCC policy
activates
Behavior on portDisable and
portEnable
•
FA-PWWN has logged into the
switch
•
DCC policy creation with lock
down (uses FA-PWWN).
•
DCC policy activation.
FA-PWWN
Traffic will not be disrupted.
1
1.
Indicates a security concern, because devices that are logged in with FA-PWWNs will not be disabled after
activation of DCC policies that are created with FA-PWWNs. This is done to avoid disturbing any existing
management.
Ports will be disabled for
security violation.
2
2.
Any disruption in the port will disable the port for a security violation. As the traffic is already disrupted for this
port, you must enforce the DCC policy for a physical device WWN; otherwise, the device will not be allowed to login
again.
•
DCC policy creation with
lockdown (uses physical
PWWN).
•
FA-PWWN has logged into the
switch
•
DCC policy activation.
Physical PWWN Traffic will not be disrupted.
Ports will come up without
security issues.
•
DCC policy creation with
lockdown (uses physical
PWWN)
•
DCC policy activation
•
FA-PWWN has logged into the
switch
Physical PWWN Traffic will not be disrupted.
Ports will come up without
any security issues.
Summary of Contents for Fabric OS v7.0.1
Page 1: ...53 1002446 01 15 December 2011 Fabric OS Administrator s Guide Supporting Fabric OS v7 0 1 ...
Page 22: ...xxii Fabric OS Administrator s Guide 53 1002446 01 ...
Page 26: ...xxvi Fabric OS Administrator s Guide 53 1002446 01 ...
Page 30: ...xxx Fabric OS Administrator s Guide 53 1002446 01 ...
Page 38: ...xl Fabric OS Administrator s Guide 53 1002446 01 ...
Page 40: ...2 Fabric OS Administrator s Guide 53 1002446 01 ...
Page 214: ...176 Fabric OS Administrator s Guide 53 1002446 01 Management interface security 7 ...
Page 228: ...190 Fabric OS Administrator s Guide 53 1002446 01 Brocade configuration form 8 ...
Page 248: ...210 Fabric OS Administrator s Guide 53 1002446 01 Validating a firmware download 9 ...
Page 334: ...296 Fabric OS Administrator s Guide 53 1002446 01 Setting up TI over FCR sample procedure 12 ...
Page 360: ...322 Fabric OS Administrator s Guide 53 1002446 01 Encryption and compression example 14 ...
Page 404: ...366 Fabric OS Administrator s Guide 53 1002446 01 ...
Page 430: ...392 Fabric OS Administrator s Guide 53 1002446 01 Ports on Demand 18 ...
Page 502: ...464 Fabric OS Administrator s Guide 53 1002446 01 Buffer credit recovery 23 ...
Page 572: ...534 Fabric OS Administrator s Guide 53 1002446 01 Hexadecimal overview D ...
Page 584: ...546 Fabric OS Administrator s Guide 53 1002446 01 ...