NOTE:
FTP is not a secure protocol. File contents are in clear text during transfer, including remote login
information. This limitation affects the following commands:
saveCore
,
configUpload
,
configDownload
, and
firmwareDownload
.
IPFilter policy
The B-series IPFilter policy applies a set of rules to IP management interfaces as a packet filtering
firewall. The firewall permits or denies traffic through the IP management interfaces according to
policy rules.
Consider the following when setting IPFilter policies:
•
Fabric OS supports multiple IPFilter policies, which can be defined at the same time. Each policy
is identified by name and has an associated IPFilter type (IPv4 or IPv6). Do not mix IPFilter and IP
address types. You can have up to six IPFilter policies defined, but only one IPFilter policy for each
IPFilter type can be activated on the management IP interface.
•
Audit messages are generated for changes to the IPFilter policies.
•
The IPFilter policy rules are examined one by one in a list until the end of the list is reached.
•
To ensure optimal performance, the most important rules should be listed first.
Data protection
This section describes features for data protection with B-series Fabric OS.
Fibre Channel ACLs
B-series Fabric OS uses ACLs to restrict access to data resources based on defined policies.
Fabric OS provides the following policies:
•
FCS policy
—Determines which switches can change fabric configurations
•
DCC policies
—Determines which Fibre Channel device ports can connect to which switch ports
•
SCC policy
—Determines which switches can join with another switch
•
IPFilter policy
—Filters traffic based on IP addresses
Each supported policy is identified by name; only one policy of each type can exist (except for DCC
policies).
Table 196
describes the methods for identifying policy numbers.
Table 196 Methods for identifying policy numbers
Switch name
Domain ID
Switch port WWN
Device port
WWN
Policy
Yes
Yes
Yes
No
FCS_POLICY
Yes
Yes
Yes
Yes
DCC_POLICY_nnn
Yes
Yes
Yes
No
SCC_POLICY
SAN Design Reference Guide
413
Содержание StorageWorks 4000/6000/8000 - Enterprise Virtual Arrays
Страница 26: ......
Страница 34: ...SAN design overview 34 ...
Страница 60: ...SAN fabric topologies 60 ...
Страница 80: ...Fibre Channel routing 80 ...
Страница 82: ......
Страница 92: ...H series switches and fabric rules 92 ...
Страница 156: ...C series switches and fabric rules 156 ...
Страница 182: ...SAN fabric connectivity and switch interoperability rules 182 ...
Страница 184: ......
Страница 270: ...XP and VA storage system rules 270 ...
Страница 276: ...Enterprise Backup Solution 276 ...
Страница 278: ......
Страница 354: ...SAN extension 354 ...
Страница 398: ...Network Attached Storage 398 ...
Страница 400: ......
Страница 416: ...Storage security 416 ...
Страница 428: ...Best practices 428 ...
Страница 456: ...456 ...