Modifying The Vsan Policy; Role Distributions - HP Cisco MDS 9020 - Fabric Switch Configuration Manual

Cisco mds 9000 family cli configuration guide, release 3.x (ol-16184-01, april 2008)
Hide thumbs Also See for Cisco MDS 9020 - Fabric Switch:
Table of Contents

Advertisement

Role Distributions

S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Tip
Roles can be used to create VSAN administrators. Depending on the configured rules, these VSAN
administrators can configure MDS features (for example, zone, fcdomain, or VSAN properties) for their
VSANs without affecting other VSANs. Also, if the role permits operations in multiple VSANs, then the
VSAN administrators can change VSAN membership of F or FL ports among these VSANs.
Users belonging to roles in which the VSAN policy is set to deny are referred to as VSAN-restricted
users.

Modifying the VSAN Policy

To modify the VSAN policy for an existing role, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# role name sangroup
switch(config-role)#
Step 3
switch(config)# vsan policy deny
switch(config-role-vsan)
switch(config-role)# no vsan policy
deny
Step 4
switch(config-role-vsan)# permit vsan
10-30
switch(config-role-vsan)# no permit
vsan 15-20
Role Distributions
Role-based configurations use the Cisco Fabric Services (CFS) infrastructure to enable efficient
database management and to provide a single point of configuration for the entire fabric (see
"Using the CFS
The following configurations are distributed:
This section includes the following topics:
Cisco MDS 9000 Family CLI Configuration Guide
39-4
Infrastructure").
Role names and descriptions
List of rules for the roles
VSAN policy and the list of permitted VSANs
About Role Databases, page 39-5
Locking the Fabric, page 39-5
Committing Role-Based Configuration Changes, page 39-5
Discarding Role-Based Configuration Changes, page 39-5
Enabling Role-Based Configuration Distribution, page 39-6
Chapter 39
Purpose
Enters configuration mode.
Places you in role configuration submode for the sangroup
role.
Changes the VSAN policy of this role to deny and places
you in a submode where VSANs can be selectively
permitted.
Deletes the configured VSAN role policy and reverts to
the factory default (permit).
Permits this role to perform the allowed commands for
VSANs 10 through 30.
Removes the permission for this role to perform
commands for VSANs 15 to 20. So, the role is now
permitted to perform commands for VSAN 10 to 14, and
21 to 30.
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Configuring Users and Common Roles
Chapter 6,

Advertisement

Table of Contents
loading

Table of Contents