Modifying The Vsan Policy - Cisco DS-X9530-SF1-K9 - Supervisor-1 Module - Control Processor Configuration Manual

Mds 9000 family
Table of Contents

Advertisement

Role-Based Authorization
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m .

Modifying the VSAN Policy

To modify the VSAN policy for an existing role, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# role name sangroup
switch(config-role)#
Step 3
switch(config)# vsan policy deny
switch(config-role-vsan)
switch(config-role)# no vsan policy
deny
Step 4
switch(config-role-vsan)# permit vsan
10-30
switch(config-role-vsan)# no permit
vsan 15-20
Distributing Role-Based Configurations
Role-based configurations use the Cisco Fabric Services (CFS) infrastructure to enable efficient
database management, provide a single point of configuration for the entire fabric (see
the CFS
The following configurations are distributed:
Database Implementation
Role-based configurations uses two databases to accept and implement configurations.
Locking The Fabric
The first action that modifies the database creates the pending database and locks the feature in the entire
fabric. Once you lock the fabric, the following situations apply:
Cisco MDS 9000 Family Configuration Guide
26-4
Infrastructure").
Role names and descriptions
List of rules for the roles
VSAN policy and the list of permitted VSANs
Configuration database—The database currently enforced by the fabric.
Pending database—Your subsequent configuration changes are stored in the pending database. If
you modify the configuration, you need to commit or discard the pending database changes to the
configuration database. The fabric remains locked during this period. Changes to the pending
database are not reflected in the configuration database until you commit the changes.
No other user can make any configuration changes to this feature.
A copy of the configuration database becomes the pending database along with the first change.
Chapter 26
Purpose
Enters configuration mode.
Places you in sangroup role submode.
Changes the VSAN policy of this role to deny and places
you in a submode where VSANs can be selectively
permitted.
Deletes the configured VSAN role policy and reverts to
the factory default (permit).
Permits this role to perform the allowed commands for
VSANs 10 through 30.
Removes the permission for this role to perform
commands for vsan 15 to 20. So, the role is now permitted
to perform commands for VSAN 10 to 14, and 21 to 30.
OL-6973-03, Cisco MDS SAN-OS Release 2.x
Configuring Users and Common Roles
Chapter 5, "Using

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the DS-X9530-SF1-K9 - Supervisor-1 Module - Control Processor and is the answer not in the manual?

Questions and answers

Table of Contents