18-12
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
OL-7753-01
Chapter 18 Configuring Switch Security
Recovering Administrator Password
Configuring the VSAN Policy
Configuring the VSAN policy requires the ENTERPRISE_PKG license.
You can configure a role so that it only allows commands to be performed for a selected set of VSANs.
By default, the VSAN policy for any role is
permit
. In other words, the role can perform commands
configured by the rule in all VSANs. In order to selectively allow VSANs for a role, the VSAN policy
needs to be set to
deny
and then the appropriate VSANs need to be permitted.
Users configured in roles where the VSAN policy set to
deny
cannot modify configuration for E ports.
They can only modify configuration for F or FL ports (depending on whether the configured rules allow
such configuration to be made). This is to prevent such users from modifying configurations that may
impact the core topology of the fabric.
Tip
Roles can be used to create VSAN administrators. Depending on the configured rules, these VSAN
administrators can configure MDS features (for example, zone, fcdomain, VSAN properties) for their
VSANs without affecting other VSANs. Also, if the role permits operations in multiple VSANs, then the
VSAN administrators can change VSAN membership of F or FL ports among these VSANs.
Users belonging to roles in which the VSAN policy is set to
deny
are referred to as VSAN-restricted
users. These users cannot perform the following functions that require the startup configuration to be
viewed or modified:
•
copy running startup
•
show startup
•
show running-config diff
•
copy startup
<destination>
•
copy
<source>
startup
commands.
For information on these commands, refer to the
Cisco MDS 9000 Family Command Reference
.
Recovering Administrator Password
An administrator can recover a password from a local console connection.
The password recovery procedure must be performed on the supervisor module that becomes the active
supervisor module after the recovery procedure is completed. To ensure the other supervisor module
does not become the active module, you have two options:
Password recovery is not possible from a Telnet or SSH session.
To recover a administrator password, refer to the
Cisco MDS 9000 Family Command Reference
.
Configuring SSH Services
The Telnet service is enabled by default on all Cisco MDS 9000 Family switches. Before enabling the
SSH service, generate a host key pair.
Содержание DS-C9216I-K9
Страница 26: ...Contents xxvi Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 ...
Страница 42: ...xlii Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 New and Changed Information ...
Страница 128: ...10 8 Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 Chapter 10 Managing System Hardware ...