Administering ficon fabrics, User security considerations, Meeting high-integrity fabric requirements – Brocade FICON Administrator’s Guide (Supporting Fabric OS v7.3.0) User Manual

Page 35: Created

Advertising
background image

Administering FICON Fabrics

User security considerations........................................................................................... 33

Meeting high-integrity fabric requirements...................................................................... 33

Preparing a switch for FICON......................................................................................... 36

Configuring switched point-to-point FICON.....................................................................37

Configuring cascaded FICON......................................................................................... 41

FCR and FICON cascading............................................................................................ 42

FICON and FICON CUP in Virtual Fabrics..................................................................... 43

Addressing modes.......................................................................................................... 44

Disabling and enabling ports - persistent states............................................................. 46

Clearing the FICON management database...................................................................47

Automating CS_CTL mapping........................................................................................ 47

FICON best practices......................................................................................................49

Latency guideline............................................................................................................ 50

User security considerations

To administer FICON, you must have one of the following roles associated with your login name on the
switch:

Admin

Operator

SwitchAdmin

FabricAdmin

The User and BasicSwitchAdmin roles are view-only. The ZoneAdmin and SecurityAdmin roles have no
access.

In an Admin Domain-aware fabric, if you use the FICON commands (ficonShow, ficonClear,
ficonCupShow, and ficonCupSet) for any Admin Domain other than AD0 and AD255, the current
switch must be a member of that Admin Domain. The output is not filtered based on the Admin Domain.
In Virtual Fabrics, these commands apply to the current logical or specified switch only.

Meeting high-integrity fabric requirements

In a cascaded switch configuration, FICON channels use an Extended Link Service Query Security
Attributes (ELS QSA) function to determine whether they are connected to a high-integrity fabric. Each
switch in a high integrity fabric must have the following attributes configured:

An insistent domain ID (IDID)

A valid SCC policy (configured and activated)

A fabric-wide consistency policy greater to or equal than switch connection control - strict mode
(SCC:S)

FICON Administrator's Guide

33

53-1003144-01

Advertising