Controlling access, Displaying the management server acl, Adding a member to the acl – HP StorageWorks 2.128 SAN Director Switch User Manual

Page 124

Advertising
background image

124 Configuring the Distributed Management Server

For example:

Controlling access

You can use the

msConfigure

command to control access to the management server database.

An ACL of WWN addresses determines which systems have access to the management server database.

The ACL typically contains those WWNs of host systems that are running management applications.
If the list is empty (the default), the management server is accessible to all systems connected in-band to

the fabric. For more access security, you can specify WWNs in the ACL so that access to the

management server is restricted only to those WWNs listed.
The ACL is switch-based. Therefore, only hosts that are connected directly to the switch are affected by the

ACL. A host that is somewhere else in the fabric and is connected to a switch with an empty ACL is

allowed to access the management server.

NOTE:

The

msConfigure

command is disabled if the switch is in secure mode. See the HP

StorageWorks Secure Fabric OS administrator guide for more information.

Displaying the management server ACL

1.

Connect to the switch and log in as admin.

2.

Issue the

msConfigure

command.

The command becomes interactive.

3.

At the

select

prompt, enter

1

to display the access list.

A list of WWNs that have access to the management server is displayed.

In the following example, the list is empty:

Adding a member to the ACL

1.

Connect to the switch and log in as admin.

2.

Issue the

msConfigure

command.

The command becomes interactive.

switch:admin> msplmgmtdeactivate

MS Platform Service is currently enabled.

This will erase MS Platform Service configuration

information as well as database in the entire fabric.

Would you like to continue this operation? (yes, y, no, n): [no] y

Request to deactivate MS Platform Service in progress......

*Completed deactivating MS Platform Service in the fabric!

switch:admin>

switch:admin> msconfigure

0 Done

1 Display the access list

2 Add member based on its Port/Node WWN

3 Delete member based on its Port/Node WWN

select : (0..3) [1] 1

MS Access list is empty.

0 Done

1 Display the access list

2 Add member based on its Port/Node WWN

3 Delete member based on its Port/Node WWN

done ...

switch:admin>

Advertising