Policy Members; Acl Policy Management; Table 28 Valid Methods For Specifying Policy Members - HP StoreFabric SN6500B Administrator's Manual

Fabric os administrator's guide, 7.1.0 (53-1002745-02, march 2013)
Hide thumbs Also See for StoreFabric SN6500B:
Table of Contents

Advertisement

7

ACL policy management

Policies with the same state are grouped together in a Policy Set. Each switch has the following two
sets:
When a policy is activated, the defined policy either replaces the policy with the same name in the
active set or becomes a new active policy. If a policy appears in the defined set but not in the active
set, the policy was saved but has not been activated. If a policy with the same name appears in
both the defined and active sets but they have different values, then the policy has been modified
but the changes have not been activated.
Admin Domain considerations: ACL management can be done on AD255 and in AD0 only if there
are no user-defined Admin Domains. Both AD0 (when no other user-defined Admin Domains exist)
and AD255 provide an unfiltered view of the fabric.
Virtual Fabric considerations: ACL policies such as DCC, SCC, and FCS can be configured on each
logical switch. The limit for security policy database size is set to 1Mb per logical switch.

Policy members

The FCS, DCC and SCC policy members are specified by device port WWN, switch WWN, domain
IDs, or switch names, depending on the policy. The valid methods for specifying policy members
are listed in
TABLE 28
Policy name
FCS_POLICY
DCC_POLICY_nnn
SCC_POLICY

ACL policy management

All policy modifications are temporarily stored in volatile memory until those changes are saved or
activated. You can create multiple sessions to the switch from one or more hosts. It is
recommended you make changes from one switch only to prevent multiple transactions from
occurring. Each logical switch will have its own access control list.
The FCS, SCC and DCC policies in Secure Fabric OS are not interchangeable with Fabric OS FCS,
SCC and DCC policies. Uploading and saving a copy of the Fabric OS configuration after creating
policies is strongly recommended. For more information on configuration uploads, see
"Maintaining the Switch Configuration
NOTE
All changes, including the creation of new policies, are saved and activated on the local switch only—
unless the switch is in a fabric that has a strict or tolerant fabric-wide consistency policy for the ACL
policy type for SCC or DCC. See
the database settings and fabric-wide consistency policy.
196
Active policy set, which contains ACL policies being enforced by the switch.
Defined policy set, which contains a copy of all ACL policies on the switch.
Table
28.
Valid methods for specifying policy members
Device port WWN or
Switch WWN
Fabric port WWN
No
Yes
Yes
Yes
No
Yes
File".
"Policy database distribution"
Domain ID
Switch name
Yes
Yes
Yes
Yes
Yes
Yes
on page 224 for more information on
Fabric OS Administrator's Guide
53-1002745-02
Chapter 8,

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fabric os 7.1.0

Table of Contents