110 Configuring advanced security
Aborting all uncommitted changes
Use the
secPolicyAbort
command to abort all ACL policy changes that have not yet been saved.
To abort all unsaved changes
1.
Connect to the switch and log in.
2.
Type the
secPolicyAbort
command:
All changes since the last time the
secPolicySave
or
secPolicyActivate
commands were entered
are aborted.
Distributing the policy database
Fabric OS lets you manage and enforce the ACL policy database on either a per-switch or fabric-wide
basis. The local switch distribution setting and the fabric-wide consistency policy affect the switch's ACL
policy database and related distribution behavior.
The ACL policy database is managed as follows:
•
Switch database distribution setting
—Controls whether or not the switch accepts or rejects
databases distributed from other switches in the fabric. The distribution command sends the database
from one switch to another, overwriting the target switches database with the distributed one. To send
or receive a database the setting must be accept. For configuration instructions, see ”
Configuring the
database distribution settings
” on page 111.
•
Manually distribute an ACL policy database
—Run the distribute command to push the local
database of the specified policy type to target switches. ”
Distributing ACL policies to other switches
” on
page 112
•
Fabric-wide consistency policy
—Use to ensure that switches in the fabric enforce the same
policies. Set a strict or tolerant fabric-wide consistency policy for each ACL policy type to automatically
distribute that database when a policy change is activated. If a fabric-wide consistency policy is not set,
then the policies are managed on per switch basis. For configuration instructions, see”
Setting the
consistency policy fabric-wide
” on page 113
Table 27
explains the how the local database distribution settings and the fabric-wide consistency policy
affect the local database when the switch is the target of a distribution command.
switch:admin>
secpolicyabort
Unsaved data has been aborted.
Table 27
Interaction between fabric-wide consistency policy and distribution settings
Distribution
setting
Fabric-wide consistency policy
Absent (default)
Tolerant
Strict
Reject
Database is protected, it
cannot be overwritten.
Might not match other
databases in the fabric.
Invalid configuration.
1
Invalid configuration.
a
Accept
(default)
Database is not protected,
the database can be
overwritten.
If the switch initiating a
distribute command has a
strict or tolerant
fabric-wide consistency
policy, the fabric-wide
policy is also overwritten.
Might not match other
databases in the fabric.
Database is not protected.
Automatically distributes
activated changes to other
55.20 switches in fabric.
Allows switches running
Fabric OS 5.1.x and earlier
in fabric.
Might not match other
databases in the fabric.
Database is not protected.
Automatically distributes
activated changes to all
switches in the fabric.
Fabric can only contain
switches running Fabric OS
5.2.x or higher.
Active database is the same
for all switches in fabric.
Содержание AE370A - Brocade 4Gb SAN Switch 4/12
Страница 1: ...HP StorageWorks Fabric OS 5 2 x administrator guide Part number 5697 0014 Fifth edition May 2009 ...
Страница 18: ...18 ...
Страница 82: ...82 Managing user accounts ...
Страница 102: ...102 Configuring standard security features ...
Страница 126: ...126 Maintaining configurations ...
Страница 198: ...198 Routing traffic ...
Страница 238: ...238 Using the FC FC routing service ...
Страница 260: ...260 Administering FICON fabrics ...
Страница 280: ...280 Working with diagnostic features ...
Страница 332: ...332 Administering Extended Fabrics ...
Страница 414: ...398 Configuring the PID format ...
Страница 420: ...404 Configuring interoperability mode ...
Страница 426: ...410 Understanding legacy password behaviour ...
Страница 442: ...426 ...
Страница 444: ......
Страница 447: ......