
Fabric OS Administrator’s Guide
ix
53-1002446-01
IP Filter policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .153
Creating an IP Filter policy. . . . . . . . . . . . . . . . . . . . . . . . . . . . .153
Cloning an IP Filter policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . .154
Displaying an IP Filter policy . . . . . . . . . . . . . . . . . . . . . . . . . . .154
Saving an IP Filter policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .154
Activating an IP Filter policy. . . . . . . . . . . . . . . . . . . . . . . . . . . .154
Deleting an IP Filter policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . .155
IP Filter policy rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .155
IP Filter policy enforcement. . . . . . . . . . . . . . . . . . . . . . . . . . . .158
Adding a rule to an IP Filter policy. . . . . . . . . . . . . . . . . . . . . . .159
Deleting a rule to an IP Filter policy . . . . . . . . . . . . . . . . . . . . .159
Aborting an IP Filter transaction . . . . . . . . . . . . . . . . . . . . . . . .159
IP Filter policy distribution . . . . . . . . . . . . . . . . . . . . . . . . . . . . .159
Managing filter thresholds . . . . . . . . . . . . . . . . . . . . . . . . . . . .160
Policy database distribution . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .160
Database distribution settings . . . . . . . . . . . . . . . . . . . . . . . . .161
ACL policy distribution to other switches . . . . . . . . . . . . . . . . .162
Fabric-wide enforcement. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .163
Notes on joining a switch to the fabric . . . . . . . . . . . . . . . . . . .164
Management interface security . . . . . . . . . . . . . . . . . . . . . . . . . . . .166
Configuration examples. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .167
IPsec protocols . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .168
Security associations. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .169
Authentication and encryption algorithms . . . . . . . . . . . . . . . .169
IPsec policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .170
IKE policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .170
Creating the tunnel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .172
Example of an End-to-end transport tunnel mode . . . . . . . . . 174
Chapter 8
Maintaining the Switch Configuration File
In this chapter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177
Configuration settings. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177
Configuration file format . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .178
Configuration file backup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .180
Uploading a configuration file in interactive mode . . . . . . . . .181
Configuration file restoration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .181
Restrictions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .182
Configuration download without disabling a switch . . . . . . . .184
Configurations across a fabric . . . . . . . . . . . . . . . . . . . . . . . . . . . . .185
Downloading a configuration file from one switch to
another same model switch . . . . . . . . . . . . . . . . . . . . . . . . . . .186
Security considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .186
Configuration management for Virtual Fabrics. . . . . . . . . . . . . . . .186
Uploading a configuration file from a switch with
Virtual Fabrics enabled . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .186
Restoring logical switch configuration using configDownload 187
Restrictions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .188
Brocade configuration form . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .189
Summary of Contents for Fabric OS v7.0.1
Page 1: ...53 1002446 01 15 December 2011 Fabric OS Administrator s Guide Supporting Fabric OS v7 0 1 ...
Page 22: ...xxii Fabric OS Administrator s Guide 53 1002446 01 ...
Page 26: ...xxvi Fabric OS Administrator s Guide 53 1002446 01 ...
Page 30: ...xxx Fabric OS Administrator s Guide 53 1002446 01 ...
Page 38: ...xl Fabric OS Administrator s Guide 53 1002446 01 ...
Page 40: ...2 Fabric OS Administrator s Guide 53 1002446 01 ...
Page 214: ...176 Fabric OS Administrator s Guide 53 1002446 01 Management interface security 7 ...
Page 228: ...190 Fabric OS Administrator s Guide 53 1002446 01 Brocade configuration form 8 ...
Page 248: ...210 Fabric OS Administrator s Guide 53 1002446 01 Validating a firmware download 9 ...
Page 334: ...296 Fabric OS Administrator s Guide 53 1002446 01 Setting up TI over FCR sample procedure 12 ...
Page 360: ...322 Fabric OS Administrator s Guide 53 1002446 01 Encryption and compression example 14 ...
Page 404: ...366 Fabric OS Administrator s Guide 53 1002446 01 ...
Page 430: ...392 Fabric OS Administrator s Guide 53 1002446 01 Ports on Demand 18 ...
Page 502: ...464 Fabric OS Administrator s Guide 53 1002446 01 Buffer credit recovery 23 ...
Page 572: ...534 Fabric OS Administrator s Guide 53 1002446 01 Hexadecimal overview D ...
Page 584: ...546 Fabric OS Administrator s Guide 53 1002446 01 ...