© Copyright Lenovo 2017
Chapter 39: Secure Input/Output Module
583
Switch Access in SIOM Mode
After
the
embedded
switch
is
provisioned
by
the
CMM
in
the
SIOM
mode,
the
switch
will
automatically
update
its
LDAP
settings
(
startTLS
,
LDAPS
or
LDAP
)
to
the
ones
configured
on
the
CMM.
When
no
external
LDAP
server
is
configured
on
the
CMM,
CMM
itself
will
serve
as
the
local
LDAP
server.
The
LDAP
client
configured
on
the
CMM
is
pushed
onto
the
switch
and
the
LDAP
credentials
used
to
access
the
CMM
can
also
be
used
to
access
the
switch.
To
access
the
switch,
you
may
now
use
one
of
the
following
methods:
The
CMM
credentials
Other
user
credentials
which
depend
on
the
SIOM
security
policy
setting,
as
follows:
In
legacy
mode,
if
RADIUS
or
is
enabled,
they
will
replace
LDAP
as
the
authentication
method.
If
LDAP
backdoor
mode
is
enabled,
you
can
still
use
local
authentication
by
using
noldap
as
the
username.
In
secure
mode,
you
may
use
the
provisioned
LDAP
credentials.
Notes:
Once
the
switch
is
provisioned
by
the
CMM
in
SIOM
mode,
it
cannot
be
accessed
using
the
switch
local
user
accounts.
The
switch
may
perform
an
additional
reboot
automatically
after
changing
the
SIOM
state
or
upgrading
the
CMM
software.
Using SIOM with Stacking
In
stacking
mode,
configuring
SIOM
is
only
supported
on
the
Master
switch.
Hence,
the
command:
is
only
supported
on
the
Master
switch.
On
stack
member
switches,
SIOM
is
configured
by
the
Master
switch,
and
the
member
switches
automatically
inherit
the
Master
switch
SIOM
setting.
When
upgrading
to
SIOM
‐
capable
software:
The
Master,
Backup,
and
member
switches
need
to
be
rebooted
for
SIOM
to
take
effect.
When
SIOM
is
enabled
on
the
Master,
it
is
applied
on
all
stack
members
automatically.
If
a
new
switch
with
a
different
boot
SIOM
configuration
is
attached
to
the
stack,
the
switch
will
inherit
the
boot
SIOM
configuration
from
the
Master
and
will
automatically
reboot.
When
two
stacks
are
joined,
the
selected
Master
for
the
two
stacks
will
push
its
own
boot
SIOM
configuration,
and
the
added
members
will
automatically
reboot.
There
will
be
no
changes
in
the
SIOM
policy
on
members
if
the
stack
is
split.
Note:
Lenovo
recommends
using
staggered
upgrade.
In
this
case,
the
upgrade
will
take
more
time,
depending
on
how
large
the
stack
setup
is,
but
the
traffic
loss
will
be
minimal.
CN 4093#
[no] boot siom enable
Содержание Flex System Fabric CN4093
Страница 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Страница 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Страница 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Страница 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Страница 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Страница 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Страница 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Страница 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Страница 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Страница 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Страница 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Страница 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Страница 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Страница 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Страница 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Страница 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Страница 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Страница 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Страница 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Страница 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Страница 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Страница 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Страница 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Страница 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Страница 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Страница 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Страница 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Страница 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Страница 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Страница 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Страница 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Страница 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Страница 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Страница 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Страница 633: ......
Страница 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...