Gebruiksaanwijzing /service van het product 53-1002745-02 van de fabrikant Brocade Communications Systems
Ga naar pagina of 666
53-1002 7 45-02 25 March 20 13 ® Fa b r i c O S Administrat or’s Guide Suppor ting F abric OS 7 .1.0.
Copyright © 20 13 Brocade Communications Sys tems, Inc. All Rights Reser ved. ADX, An yIO, Brocade, Brocad e Assurance, t he B-wing symb ol, DCX, F abri c OS, ICX, MLX, MyBrocade, OpenScript, VCS, VD.
Fabric OS Administrator ’s Guide 3 53-1002745-02 Contents (High Level) Section I Standard Features Chapter 1 Understanding Fibre Channel Services . . . . . . . . . . . . . . . . . . . . . . . . . 43 Chapter 2 Performing Basic Configuration Ta sks . .
4 Fabric OS A dministr ator’s Guide 53-1002745-02 Appendix A Port Indexing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 11 Appendix B FIPS Support . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Fabric OS Administrator ’s Guide 5 53-1002745-02 Contents About This Document How this document is organized . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 Suppor ted har dware and sof tware . . . . . . . . . . . . . . . . . . . . . . . .
6 Fabric OS A dministr ator’s Guide 53-1002745-02 Chapter 2 Performing Basic Configuration Ta sks Fabric OS ov er view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55 Fabric OS command line int er face. . . . . . . .
Fabric OS Administrator ’s Guide 7 53-1002745-02 Chapter 3 Performing Advanced Configuration Tasks Port Identifiers (PIDs) and PID binding ov er view . . . . . . . . . . . . . . . 79 Core PID addressing mode . . . . . . . . . . . . . . . . . . . . .
8 Fabric OS A dministr ator’s Guide 53-1002745-02 Audit log configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 0 7 V e rifying host syslog prior to configuring the audit log . . . . . . 1 08 Configuring an a udit log for specific event classes .
Fabric OS Administrator ’s Guide 9 53-1002745-02 Local database user accounts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 7 Default accounts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .138 Local account passwor ds .
10 Fabric OS A dministr ator’s Guide 53-1002745-02 T elnet pr otocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .190 Blocking T elnet . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .190 Unblocking T elne t .
Fabric OS Administrator ’s Guide 11 53-1002745-02 IP Filter policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 1 7 Creating an IP Filt er policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 18 Cloning an IP Filt er policy .
12 Fabric OS A dministr ator’s Guide 53-1002745-02 Chapter 9 Installing and Maintaining Firmware Firmw are download pr ocess overview . . . . . . . . . . . . . . . . . . . . . . .255 Upgrading and downg rading firmw are . . . . . . . . . . . . . . .
Fabric OS Administrator ’s Guide 13 53-1002745-02 Limitations and restrictions of Vir tual F abrics . . . . . . . . . . . . . . . .288 Restrictions on XI SLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .289 Restrictions on mo ving por ts .
14 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone creation and maint enance . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 1 6 Displaying e xisting zones . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31 6 Creating a zone .
Fabric OS Administrator ’s Guide 15 53-1002745-02 General rules f or TI zones . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .356 T raffic Isolation Zone violation ha ndling f o r trunk ports . . . . . 35 7 Suppor ted configurations f or T raf fic Isolation Zoning .
16 Fabric OS A dministr ator’s Guide 53-1002745-02 Changing bottleneck de tection paramet ers . . . . . . . . . . . . . . . . . .384 Examples of applying and ch anging bottleneck dete ction paramet ers . . . . . . . . . . . . . . . . . . . . . . . .
Fabric OS Administrator ’s Guide 17 53-1002745-02 Chapter 16 Dynamic Fabric Prov isioning: Fabric-Assigned PWWN Introducti on to Dynam ic Fabric Pr o visioning using F A-PWWN . . . .425 User- and auto-assigned F A-PWW N behavior . . . . . . . . . . .
18 Fabric OS A dministr ator’s Guide 53-1002745-02 SAN management with Admin Domains . . . . . . . . . . . . . . . . . . . . .454 CLI commands in an AD conte xt . . . . . . . . . . . . . . . . . . . . . . . .455 Executing a command in a differe nt AD conte x t .
Fabric OS Administrator ’s Guide 19 53-1002745-02 Ports on Demand . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .483 Displaying installed licenses . . . . . . . . . . . . . . . . . . . . . . . . . . .484 Activ ating Ports on Demand .
20 Fabric OS A dministr ator’s Guide 53-1002745-02 T op T alker monitors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 1 0 T op T alk er monitors and FC-FC routing . . . . . . . . . . . . . . . . . . . 5 11 Limitations of T op T alker monito rs .
Fabric OS Administrator ’s Guide 21 53-1002745-02 Chapter 22 Managing Trunking Connections T runking o verview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .533 T ypes of trunking . . . . . . . . . . . . . . . . . . . .
22 Fabric OS A dministr ator’s Guide 53-1002745-02 Buffer credit management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .555 Buffer -to-buff er flow contr ol . . . . . . . . . . . . . . . . . . . . . . . . . . .555 Optimal buffer credit allocation .
Fabric OS Administrator ’s Guide 23 53-1002745-02 LSAN zone configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .590 Use of Admin Domains with LSAN zones and FC-FC r outing .590 Zone definition and naming . . . . . . . . . .
24 Fabric OS A dministr ator’s Guide 53-1002745-02.
Fabric OS Administrator ’s Guide 25 53-1002745-02 Figures Figure 1 Well-known addresses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43 Figure 2 Identifying the blades . . . . . . . . . . . . . . . . . .
26 Fabric OS A dministr ator’s Guide 53-1002745-02 Figure 36 Illegal ETIZ configuration: two paths from on e port to two devices on the same remote domain 351 Figure 3 7 Illegal ETIZ configuration: two paths from one port . . . . . . . . . . . . . .
Fabric OS Administrator ’s Guide 27 53-1002745-02 Figure 7 7 MetaSAN with imported devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 576 Figure 78 Sample topology (physical topology) . . . . . . . . . . . . . . . . . .
28 Fabric OS A dministr ator’s Guide 53-1002745-02.
Fabric OS Administrator ’s Guide 29 53-1002745-02 Tables Ta b l e 1 Daemons that are automatically restarted . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53 Ta b l e 2 Terminal port parameters . . . . . . . . . . . . . . . . . . . . .
30 Fabric OS A dministr ator’s Guide 53-1002745-02 Ta b l e 37 Supported services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 220 Ta b l e 3 8 Implicit IP Filter rules . . . . . . . . . . . . . . .
Fabric OS Administrator ’s Guide 31 53-1002745-02 Ta b l e 7 8 VCs assigned to QoS priority for frame prio ritization in CS_CTL auto mode . . 521 Ta b l e 7 9 Trunking over long-distance for the Backbones and blade s . . . . . . . . . . . . . . . 541 Ta b l e 8 0 F_Port masterless trunking consider ations .
32 Fabric OS A dministr ator’s Guide 53-1002745-02.
Fabric OS Administrator ’s Guide 33 53-1002745-02 About This Document In this chapter • How this document is organized . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 • Suppor ted har dware and software. . . . . . . . . . .
34 Fabric OS A dministr ator’s Guide 53-1002745-02 • Chapter 11 , “ Administering Advanced Zoning,” pro vides proc edures for use of the Br ocade Advanced Zoning f eature. • Chapter 12, “T raf fic Isolation Zoning,” provides concepts and procedures for use of T raf fic Isolation Zones within a fabric.
Fabric OS Administrator ’s Guide 35 53-1002745-02 The follo wing hardw are platf orms are suppor ted b y this release of Fabric OS: • Fixed-po r t switches: - Brocade 300 switch - Brocade 5 1 00 s.
36 Fabric OS A dministr ator’s Guide 53-1002745-02 • Updat ed the Not e in “In-flight en cr yption and compression overview” on page 393. • In “Encr yption and compression restrictions” on page 394, clarified the restrictio n about the number of ports suppor ted.
Fabric OS Administrator ’s Guide 37 53-1002745-02 Notes, cautions, and warnings The f ollowing notices and stat ements are used in this manual. They are list ed below in or der of increasing sev erity of pot ential hazards.
38 Fabric OS A dministr ator’s Guide 53-1002745-02 Additional information This section lists additional Br ocade and industr y-specific docu mentation that you might find helpful. Brocade resources T o get up-to-the-minute inf ormation, go to http://my .
Fabric OS Administrator ’s Guide 39 53-1002745-02 1. Gen eral Informa tion • Switch model • Switch operating system version • Error numbers and messages received • suppor tSav e co mmand out.
40 Fabric OS A dministr ator’s Guide 53-1002745-02 Document feedback Quality is our first concern at Brocade and we ha ve made ev er y ef fort to ensure the accuracy and complet eness of this document. Ho we ver , if y ou find an error or an omission, or y ou think that a topic need s fur ther de velopment, w e want to hear from y ou.
Fabric OS Administrator ’s Guide 41 53-1002745-02 Section I Standard Features This section describes standard F abric OS f e atures, and includes th e follo wing chapters: • Chapter 1, “Understa.
42 Fabric OS A dministr ator’s Guide 53-1002745-02.
Fabric OS Administrator ’s Guide 43 53-1002745-02 Chapter 1 Understanding Fibre Channel Services In this chapter • Fibre Channel services ov er view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43 • Management server . . .
44 Fabric OS A dministr ator’s Guide 53-1002745-02 Management server 1 Management server — The management server pro v ides a single point for managing the fabric.
Fabric OS Administrator ’s Guide 45 53-1002745-02 Management server database 1 Platform services and Virtual Fabrics Each logical switch has a sep arate platf orm databa se. All platform registrations done t o a logical switch are valid only in that par t icular logical switch’s Vir tual Fabric.
46 Fabric OS A dministr ator’s Guide 53-1002745-02 Management server database 1 If the list is empty ( the default), the manageme nt ser ver is accessible t o all systems connect ed in-band to the fabric. For more access security , you can specify WWNs in the ACL so that access to the management server is restricted to only those WWNs list ed.
Fabric OS Administrator ’s Guide 47 53-1002745-02 Management server database 1 Example of adding a member to the mana gement ser ver ACL switch:admin> msconfigure 0 Done 1 Display the access list 2 Add member based on its Port/Node WWN 3 Delete member based on its Port/Node WWN select : (0.
48 Fabric OS A dministr ator’s Guide 53-1002745-02 Management server database 1 5. At the “select” pr ompt, ent er 1 t o display the access list so y ou can verify that the WWN y ou entered w as delete d from the A CL. 6. Af ter verifying that the WWN was delet ed correctly , enter 0 at the “select” pr ompt to end the session.
Fabric OS Administrator ’s Guide 49 53-1002745-02 Topology discovery 1 Number of Associated Node Names: 1 Associated Node Names: 10:00:00:60:69:20:15:75 Clearing the management server database Use the f ollowing pr ocedure to clea r the management server database: NOTE The command msPlClearDB is allo wed only in AD0 and AD255.
50 Fabric OS A dministr ator’s Guide 53-1002745-02 Topology discovery 1 *MS Topology Discovery enabled locally. *MS Topology Discovery Enable Operation Complete!! Disabling topology discovery Use the f ollowing pr ocedure to disable t opology discov er y: 1.
Fabric OS Administrator ’s Guide 51 53-1002745-02 Device login 1 Device login A device can be storage, a host, or a switch. When new devices are introduced into the fabric, t hey must be powered on and, if a host or storage de vice, connected t o a switch.
52 Fabric OS A dministr ator’s Guide 53-1002745-02 Device login 1 Fabric login process A device p er forms a f abric login (FL OGI) to determine if a fabric is present. If a fabric is det ected then it ex changes ser vice parameters with the fabr ic controller .
Fabric OS Administrator ’s Guide 53 53-1002745-02 High availability of daemon proce sses 1 Duplicate Port World Wide Name Accor ding to Fibre Channel standards, the P o r t W orld Wide Name (PWWN) of a de vice cannot ov erlap with that of another device, thus ha ving duplicate PWWNs within the same fabric is an illegal configuratio n.
54 Fabric OS A dministr ator’s Guide 53-1002745-02 High availability of daemon proce sses 1 webd Webserver daemon used for W ebT ools (includes httpd as well). weblinkerd Weblinker daemon provides an HTTP i nter face to manageab ility applic ations for switch manageme nt and fabric di scovery .
Fabric OS Administrator ’s Guide 55 53-1002745-02 Chapter 2 Performing Basic Configuration Tasks In this chapter • Fabric OS o verview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55 • Fabric OS command line int er face .
56 Fabric OS A dministr ator’s Guide 53-1002745-02 Fabric OS c ommand line i nterface 2 Although many diffe rent sof tware and har dware configurations are test ed and suppor ted by Brocade Communications Systems, Inc., docu menting all possib le configurations a nd scenarios is bey ond the scope of this document.
Fabric OS Administrator ’s Guide 57 53-1002745-02 Fabric OS command line interface 2 • In a Windows envir onment enter the following parameters: • In a UNIX envir onment, enter the following str.
58 Fabric OS A dministr ator’s Guide 53-1002745-02 Fabric OS c ommand line i nterface 2 Connecting to Fabr ic OS using Telnet Use the f ollowing pr ocedure to connect t o the Fabric OS using T elnet: 1.
Fabric OS Administrator ’s Guide 59 53-1002745-02 Fabric OS command line interface 2 The commands in the f ollowing table pro vides help files f or the indicated specific t opics.
60 Fabric OS A dministr ator’s Guide 53-1002745-02 Fabric OS c ommand line i nterface 2 Example cliHistor y command output from admin login switch:admin> clihistory CLI history Date & Time Message Thu Sep 27 10:14:41 2012 admin, 10.70.12.101, clihistory Thu Sep 27 10:14:48 2012 admin, 10.
Fabric OS Administrator ’s Guide 61 53-1002745-02 Password modification 2 Notes: • SSH login CLI logs are not recor ded in the command line history .
62 Fabric OS A dministr ator’s Guide 53-1002745-02 The switch Ethernet interface 2 Changing the default acco unt passwords at login Use the f ollowing pr ocedure to chan ge the def ault account passwords: 1. Connect to the switch and log in usin g the defaul t administ rative ac count.
Fabric OS Administrator ’s Guide 63 53-1002745-02 The switch Ethernet interface 2 NOTE When you change the Etherne t interface settings, open connections su ch as SSH or T elnet may be dropped.
64 Fabric OS A dministr ator’s Guide 53-1002745-02 The switch Ethernet interface 2 Host Name: ecp1 Gateway IP Address: 10.1.2.3 IPFC address for virtual fabric ID 123: 11.1.2.3/24 IPFC address for virtual fabric ID 45: 13.1.2.4/20 Slot 7 eth0: 11.1.
Fabric OS Administrator ’s Guide 65 53-1002745-02 The switch Ethernet interface 2 Setting the static addresses for the Etherne t ne twork interface Use the f ollowing pr ocedure to set the Ethernet netw ork int e r face static addresses: 1. Connect to the switch and log in using an account assigned to the admin r ole.
66 Fabric OS A dministr ator’s Guide 53-1002745-02 The switch Ethernet interface 2 DHCP activation Some Br ocade switches ha ve DHCP enabled by defau lt. Fabric OS suppor t f or DHCP functionality is only pro vided for Br ocade fixed- por t switches.
Fabric OS Administrator ’s Guide 67 53-1002745-02 The switch Ethernet interface 2 5. Y ou can confirm that the change has been made using the ipAddrShow command. Example of enabling DHCP for IPv4 in tera ctivel y: switch:admin> ipaddrset Ethernet IP Address [10.
68 Fabric OS A dministr ator’s Guide 53-1002745-02 The switch Ethernet interface 2 DHCP [On]: off switch:admin> Example of disa bling DHCP for IPv4 usi ng a single comman d: switch:admin> ipaddrset –ipv4 -add -dhcp OFF switch:admin> ipaddrshow SWITCH Ethernet IP Address: 10.
Fabric OS Administrator ’s Guide 69 53-1002745-02 Date and time settings 2 Date and time settings Switches maintain the current dat e and time inside a battery -backed real-time clock (RT C) circuit that receives the dat e and time from the f abric ’s principal switch.
70 Fabric OS A dministr ator’s Guide 53-1002745-02 Date and time settings 2 When you set the time zone f or a switch, you can perform the f ollowing tasks: • Display all of the time zones supported in the firmw are. • Set the time zone based on a country and city combination or based on a time zone ID, such as PST .
Fabric OS Administrator ’s Guide 71 53-1002745-02 Date and time settings 2 Setting the time zone interactive ly Use the f ollowing pr ocedure to set the current time zone to PST using interactiv e mode: 1. Connect to the switch and log in using an account assigned to the admin role and with the chassis- rol e permissio n.
72 Fabric OS A dministr ator’s Guide 53-1002745-02 Domain IDs 2 Use the f ollowing pr ocedure to synchr onize the local time with an e xternal sour ce: 1. Connect to the switch and log in using an account assigned to the admin r ole. 2. Enter the tsClockSer ver command.
Fabric OS Administrator ’s Guide 73 53-1002745-02 Domain IDs 2 Displaying the domain IDs Use the f ollowing pr ocedure to displa y device d omain IDs: 1. Connect to the switch and log in using an account assigned to the admin r ole. 2. Enter the fabric Show command.
74 Fabric OS A dministr ator’s Guide 53-1002745-02 Switch names 2 Setting the domain ID Use the f ollowing pr ocedure to set the domain ID: 1. Connect to the switch and log in on an account assigned to the admin r ole. 2. Enter the switchDisable command to disable the switch.
Fabric OS Administrator ’s Guide 75 53-1002745-02 Chassis names 2 Chassis names Brocade recommends that you cust omize the chassi s n am e fo r e a c h pl a t fo r m . So m e s y s te m l og s i d e n t if y d evi c e s by p l a t fo rm n a m e s ; i f y o u a s s i g n meaningful platform names, logs are more useful.
76 Fabric OS A dministr ator’s Guide 53-1002745-02 Switch activation and deactivation 2 High availability considerations for fabric names Fabric names locally configured or obtained from a remote switch are sa ved in the configuration database, and then synchr onized to th e standby CP on dual-CP-based syst ems.
Fabric OS Administrator ’s Guide 77 53-1002745-02 Switch and Backbone shutdown 2 Powering off a Brocade switch Use the f ollowing pr ocedure to gracefully shut do wn a Bro cade switch. 1. Connect to the switch and log in using an account assigned to the admin r ole.
78 Fabric OS A dministr ator’s Guide 53-1002745-02 Basic connections 2 Basic connections Bef ore connecting a switch to a fa bric that contains switches running dif ferent firmw are versions, you must first set the same por t identifica tion (PID) f o rmat on all switches.
Fabric OS Administrator ’s Guide 79 53-1002745-02 Chapter 3 Performing Advanced Configuration Tasks In this chapter • Port Identifiers (PIDs) and PID binding o ver view . . . . . . . . . . . . . . . . . . . . . . 79 • Ports . . . . . . . . . . .
80 Fabric OS A dministr ator’s Guide 53-1002745-02 Port Identifiers (PIDs) and PID binding overview 3 Core PID addressing mode Core PID is the default PID format fo r Brocade platfo rms. It uses the entire 2 4-bit address space of the domain, area ID, and AL_P A to determine an o bject’s address within the fabric.
Fabric OS Administrator ’s Guide 81 53-1002745-02 Port Identifiers (PIDs) and PID binding overview 3 • Shared area limitations are remov e d on 48-port and 64-p ort blad es.
82 Fabric OS A dministr ator’s Guide 53-1002745-02 Port Identifiers (PIDs) and PID binding overview 3 WWN-based PID assignment WWN-based PID assignment is disa bled by def ault. When the f e ature is enabled, bindings are created dynamically; as new devices log in, they automatic ally enter the WWN-based PID database.
Fabric OS Administrator ’s Guide 83 53-1002745-02 Port Identifiers (PIDs) and PID binding overview 3 Use the f ollowing pr ocedure to en able automatic PID assignment: 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the configure command.
84 Fabric OS A dministr ator’s Guide 53-1002745-02 Ports 3 Ports Ports provide either a ph ysical or vir tual networ k connection point for a device.
Fabric OS Administrator ’s Guide 85 53-1002745-02 Ports 3 The different blades that can be inser ted into a chassis are described as f ollows: • Control pr ocessor blades (CPs) contain communicati on por ts for system management, and are used fo r low-level, platf orm-wide tasks.
86 Fabric OS A dministr ator’s Guide 53-1002745-02 Ports 3 Upgrade and Downgrade considerations For an upgrade, unless bo th CP8 ext e rnal Ethe rnet ports are upgraded and rebooted, the bonding fe ature will not be enabled.
Fabric OS Administrator ’s Guide 87 53-1002745-02 Ports 3 Port identification by slot and port number The por t nu mber is a num ber assigned to an external por t to give it a unique ident ifier in a switch.
88 Fabric OS A dministr ator’s Guide 53-1002745-02 Ports 3 Configuring a device-switch connection T o configu re an 8G (and 8G only) conn ecti on betw een a device and a switch, use the por tCfgFillWor d command.
Fabric OS Administrator ’s Guide 89 53-1002745-02 Ports 3 1. Connect to the switch and log in us ing an account with admin permissions. 2. Ena ble the por tSwapE nable command t o enable the f eature. 3. Enter the portDisable command on each of th e sourc e and destination por ts to be swapped.
90 Fabric OS A dministr ator’s Guide 53-1002745-02 Ports 3 Disabling a port Use the f ollowing pr ocedure to disable a port: 1. Connect to the switch and log in us ing an account with admin permissions.
Fabric OS Administrator ’s Guide 91 53-1002745-02 Ports 3 • When selecting autonegotiation, y ou can choose the specific link operating modes that are advertised to the link par tner . At least one mode mu st be adver tise d in commo n by both sides of the link.
92 Fabric OS A dministr ator’s Guide 53-1002745-02 Ports 3 Example of setting the por t mode to 1 0 Mbps half-dupl ex operation T o f o rce the link f or the eth0 interface fr om au tonego tiation t.
Fabric OS Administrator ’s Guide 93 53-1002745-02 Blade terminology and compatibility 3 Setting port speed for a port octet Y ou can use the portCfgOctetSpeedCombo command t o configure the speed f or a por t octet. Be aw are that in a Vir tual Fabrics envir onment, th is comm and applies chassis-wide and not just to the logical switch.
94 Fabric OS A dministr ator’s Guide 53-1002745-02 Blade terminology and compatibility 3 TA B L E 6 Por t blade terminology , numbering, and platform support Supported on: Blade Blade ID (slotshow) DCX family DCX 8510 family Ports D efinit ion FC8-1 6 1 2 1 Y es No 16 8- Gbps port blade suppor ting 1, 2, 4, and 8 Gbps port speeds.
Fabric OS Administrator ’s Guide 95 53-1002745-02 Blade terminology and compatibility 3 CP blades The control processor (CP) blade provides r edundancy and acts as the main contr oller on the Brocade Backbone. The Brocade DCX and DCX 85 10 Backbone families suppor t the CP8 blades .
96 Fabric OS A dministr ator’s Guide 53-1002745-02 Enabling and di sabling blades 3 Port and application blade compatibility Ta b l e 6 on page 94 identifies which port and applic ation blades are supported f or each Brocade Backbone .
Fabric OS Administrator ’s Guide 97 53-1002745-02 Blade swapping 3 Enabling blades Use the f ollowing pr ocedure to enable a blade: 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the bladeEnable command with the slo t number of the port blade you want to enable.
98 Fabric OS A dministr ator’s Guide 53-1002745-02 Blade swapping 3 • Blade swapping is not supported when swapping to a different model o f blade or a different por t count. For e xample, you canno t swap an FC8-32 blade with an FC8-48 port blade.
Fabric OS Administrator ’s Guide 99 53-1002745-02 Blade swapping 3 The preparation process al so includes any special handling of por ts associated with logical switches.
100 Fabric OS A dministr ator’s Guide 53-1002745-02 Enabling and disabling switches 3 FIGURE 4 Blade swap with V ir tual Fabrics af ter the swap Swapping blade s Use the f ollowing pr ocedure to swap blades: 1. Connect to the Backbone and log in us ing an account with admin permissions.
Fabric OS Administrator ’s Guide 101 53-1002745-02 Power management 3 Using switchCfgPersistentDisable Entering switchCfgPersistentDisable with no arguments disables the switch immediat ely.
102 Fabric OS A dministr ator’s Guide 53-1002745-02 Equipmen t status 3 The power monit or compares the available po wer with the power req u ired to det ermine if there will be enough pow er to operat e. If it is predicted t o be less power a vailable than required, the pow er-off list is pr ocessed until there is enough pow er f or operation.
Fabric OS Administrator ’s Guide 103 53-1002745-02 Equipment status 3 4. Use the switchStatusShow command to further check the status of the switch. Verifying High Availability features (Backbones only) High Av ailability (HA) features provide maximum reliability and nondis ruptive management of key hardware and software modules.
104 Fabric OS A dministr ator’s Guide 53-1002745-02 Track and control switch changes 3 Verifying device connectivity Use the f ollowing pr ocedure to verify device co nnectivity: 1. Connect to the switch and log in us ing an account with admin permissions.
Fabric OS Administrator ’s Guide 105 53-1002745-02 Track and control switch changes 3 switch:admin> trackchangesset 1 Committing configuration...done. 3. View the log using the co mmands errDump |more to displa y a page at a time or errShow to view one line at a time.
106 Fabric OS A dministr ator’s Guide 53-1002745-02 Track and control switch changes 3 Flash 0 0 MarginalPorts 0.00%[0] 0.00%[0] FaultyPorts 0.00%[0] 0.
Fabric OS Administrator ’s Guide 107 53-1002745-02 Audit log configuration 3 Bad Fans contributing to DOWN status: (0..2) [2] Bad Fans contributing to MARGINAL status: (0..2) [1] (output truncated) NOTE On the Broc ade Backbones, the co mmand output includes parameters relat ed to CP blades.
108 Fabric OS A dministr ator’s Guide 53-1002745-02 Audit log configuratio n 3 NOTE Only the active CP can generate audit messages because eve nt classes being audited occur only on the active CP . Audit messages cannot origin ate fr om other blades in a Backbone.
Fabric OS Administrator ’s Guide 109 53-1002745-02 Duplicate PWWN handling during device login 3 4. Enter the auditCfg -- show command to vie w the filter co nfiguration and confirm that the correct ev ent classes are being audited, and the co rrect filter stat e appears (enabled or disabled).
110 Fabric OS A dministr ator’s Guide 53-1002745-02 Duplicate PWWN handling during device login 3 Setting 2, Mixed precedence When setting 2 is select ed, the precedence d e pends on the port type of the first login. • If the previo us por t is an F_Port, the first login takes precedence.
Fabric OS Administrator ’s Guide 111 53-1002745-02 Chapter 4 Routing Traffic In this chapter • Routing o ver view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 1 • Inter -switch links . . . . . . .
112 Fabric OS A dministr ator’s Guide 53-1002745-02 Routing overview 4 Paths and route selection Paths are possible ways to get fr om one switch to another . Each inter -switch lin k (ISL) has a metric cost based on bandwidth. The cumu lativ e cost is based on the sum of all costs of all tra versed ISLs.
Fabric OS Administrator ’s Guide 113 53-1002745-02 Routing overview 4 FSPF makes minimal use of the ISL bandwidth, leaving vir tually all of it available f or traf f ic. In a stable fabric, a switch transmits 64 bytes e very 20 seconds in each direction.
114 Fabric OS A dministr ator’s Guide 53-1002745-02 Inter-swi tch links 4 Inter-switch links An inter -switch link (ISL) is a link between tw o switch es, E_Port-to-E_Po r t. The por ts of the two switches automatically come o nline as E_Por ts on ce the login pr ocess finishes successfully.
Fabric OS Administrator ’s Guide 115 53-1002745-02 Inter-switch links 4 Buffer credits In or der to pre vent the dro pping of frames in the fabric, a device can ne ver send frames without the receiving device being able to receive them, so an end-to-end flow contr o l is used on the switch.
116 Fabric OS A dministr ator’s Guide 53-1002745-02 Inter-swi tch links 4 FIGURE 7 Vir tual channels on a Qo S-enabled ISL.
Fabric OS Administrator ’s Guide 117 53-1002745-02 Gateway links 4 Gateway links A gate way merges SANs int o a single fabric by establishing point-to-point E_P or t connectivity between tw o Fibre Channel switches that are separat ed by a ne twork wi th a prot ocol such as IP or SONET .
118 Fabric OS A dministr ator’s Guide 53-1002745-02 Routing policies 4 Configuring a link through a gateway 1. Connect to the switch at one end of the gat ewa y and log in using an account assig ned to the admin role. 2. Enter the por tCfgIISLMode command.
Fabric OS Administrator ’s Guide 119 53-1002745-02 Routing policies 4 Displaying the current routing policy 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the aptPolicy command wi th no paramet e rs. The current policy is displa yed, follo wed b y the suppor t ed policies for th e switch.
120 Fabric OS A dministr ator’s Guide 53-1002745-02 Routing policies 4 Device-based routing Devic e-based routing optimizes r outing path select ion and utilization based on the Source ID (SID) and Destination ID (DID) of the path source and destina tion ports.
Fabric OS Administrator ’s Guide 121 53-1002745-02 Routing policies 4 CAUTION Setting the r outing policy is disruptive t o the fabr ic because it requires that y ou disable the switch where the routing policy is being c hanged. Setting the routing policy Use the f ollowing pr ocedure to set the r outing policy: 1.
122 Fabric OS A dministr ator’s Guide 53-1002745-02 Route selection 4 Route selection Selection of s pecific routes can be dynamic, so that the router can constantly adjust to changing network conditions; or it may be static, so that data pack ets alwa ys follo w a predetermined path.
Fabric OS Administrator ’s Guide 123 53-1002745-02 Frame order delivery 4 Frame order delivery The order in which frames are deliv ered is main tained within a switch and determined b y the routing policy in effect.
124 Fabric OS A dministr ator’s Guide 53-1002745-02 Frame order delivery 4 Using Frame Viewer to understand why frames are dropped When a frame is unable t o reach its destination due t o timeout, it is discar ded.
Fabric OS Administrator ’s Guide 125 53-1002745-02 Lossless Dynamic Load Sharing on ports 4 The -txpor t and -r xpor t options accept the arguments “-1” (f or fixed-port switches) or “-1/-1” (f or modular switches). These stand for “ any back -e nd port.
126 Fabric OS A dministr ator’s Guide 53-1002745-02 Lossless Dynamic Load Sharing on ports 4 Y ou can disable or enable IOD when Lossless DL S is enabled.
Fabric OS Administrator ’s Guide 127 53-1002745-02 Lossless Dynamic Load Sharing on ports 4 ICL limitations If ICL ports are connected during a c ore blade remov a l, it is equi valent to remo ving external E_Ports which may c ause I/O disruption on th e ICL ports that have been removed.
128 Fabric OS A dministr ator’s Guide 53-1002745-02 Enabling forward e rror correction (FEC) 4 T o av o id this behavior , it is recommended to define your logical switches as follows: • Define logical switches that req uir e Lossless DLS at the blade bounda r y .
Fabric OS Administrator ’s Guide 129 53-1002745-02 Enabling forward e rror correction (FEC) 4 Use the f ollowing pr ocedure to enable and disable FEC: 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the por tCfgFec c ommand, specifying the port or range of por ts on which FEC is to be enabled.
130 Fabric OS A dministr ator’s Guide 53-1002745-02 Frame Redirection 4 Frame Redirection F rame Redirection pr ovides a means to redirect tr affic flow betw een a host and a target that use vir tua.
Fabric OS Administrator ’s Guide 131 53-1002745-02 Frame Redirection 4 Example of creating a frame redirect zone T h e f o l l o w i ng e x a m p le cr e at e s a r e di re ct zo n e , g i v e n a h.
132 Fabric OS A dministr ator’s Guide 53-1002745-02 Frame Redirection 4.
Fabric OS Administrator ’s Guide 133 53-1002745-02 Chapter 5 Managing User Accounts In this chapter • User accounts ov er view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 133 • Local database user accounts . .
134 Fabric OS A dministr ator’s Guide 53-1002745-02 User accounts overview 5 Fabric OS pr ovides f our opt ions for authenticating users: remote RADIUS service, remote LD AP service, remote T A CA CS+ service, and the local-swit ch user database.
Fabric OS Administrator ’s Guide 135 53-1002745-02 User accounts overview 5 Admin Domain considerations Legacy users with no Admin Domain specified and whose current r ole is admin will hav e access to AD0 through AD2 55 (physical f abric admin); otherwise, they will ha ve access to AD0 only .
136 Fabric OS A dministr ator’s Guide 53-1002745-02 User accounts overview 5 The management channel The management channel is the com municati on established between the manageme nt workstation and the switch. Ta b l e 1 4 shows the number of simu ltaneous login ses sions allowed f or each role when authenticat ed locally .
Fabric OS Administrator ’s Guide 137 53-1002745-02 Local database us er accounts 5 The assigned permissions can be no higher than th e admin role permission assigned t o the class. The admin role permission f or the Security class is Observe/ Modify .
138 Fabric OS A dministr ator’s Guide 53-1002745-02 Local database user accounts 5 Default accounts Ta b l e 1 5 lists the predefined accounts offered by Fabr ic OS that are a vailable in the local-switch user database. The passwo rd f or all default ac counts should be changed during the initial installation and configurat ion of each switch.
Fabric OS Administrator ’s Guide 139 53-1002745-02 Local database us er accounts 5 3. In response to the pr ompt, ent er a passwor d f or the account. The passwor d is not displa yed when you ent er it on the command line. Deleting an account This proced ure can be per for med on local user accounts.
140 Fabric OS A dministr ator’s Guide 53-1002745-02 Local user account database distribution 5 Changing the password fo r a different account 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the passwd command specifying the name of the account for which the passwor d is being changed.
Fabric OS Administrator ’s Guide 141 53-1002745-02 Password policies 5 Rejecting distributed user databases on the local switch 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the fddCfg -- localreject PWD command.
142 Fabric OS A dministr ator’s Guide 53-1002745-02 Password policies 5 • Punctuation Specifies the minimum numb er of punctuation ch aracters that must appear in the passwor d. All printable, non-alphanumeric punctuation char acters ex cept the colon ( : ) are allowed.
Fabric OS Administrator ’s Guide 143 53-1002745-02 Password policies 5 Password expiration policy The passwor d expiration policy f orces the e xpirati on of a passwor d after a configurable peri od of time. The e xpiration policy can be enf orced acr oss all user accounts or on specified users only .
144 Fabric OS A dministr ator’s Guide 53-1002745-02 Password policies 5 A failed login att empt counter is maintained f or ea ch user on e ach switch instance. The counters for all user accounts are reset to zero when the account lock out policy is enabled.
Fabric OS Administrator ’s Guide 145 53-1002745-02 The boot PROM password 5 Denial of service implications The account lock out mechanism ma y be used to crea te a denial of ser vice condition when a user repeatedly att empts t o log in to an account by using an incorrect passwor d.
146 Fabric OS A dministr ator’s Guide 53-1002745-02 The boot PROM password 5 4. Enter 2. • If no password was pre viously set, the following message is display ed: Recovery password is NOT set.
Fabric OS Administrator ’s Guide 147 53-1002745-02 The boot PROM password 5 • If a password w as previously set, the f ollowing messages are displayed: Send the following string to Customer Support for password recovery: afHTpyLsDo1Pz0Pk5GzhIw== Enter the supplied recovery password.
148 Fabric OS A dministr ator’s Guide 53-1002745-02 The boot PROM password 5 The f ollowing options are a vailable: 4. Enter 3. 5. At the shell pr ompt, ent er the passwd command. The passwd command o nly applies to the boot PROM passwor d when it is entered fr om the boot inter face.
Fabric OS Administrator ’s Guide 149 53-1002745-02 Remote authentication 5 The passwd command applies only to the boot PROM password when it is entered from the boot interface. 8. Enter the boot PR OM password at the pr ompt, and then re-enter it when pr ompted.
150 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 The suppor ted management access channels that integrat e with RADIUS, LD AP , and T A CA CS+ include serial por t, T elnet, SSH, Web T ools, and API. All these access channels require the switch I P address or name to connect.
Fabric OS Administrator ’s Guide 151 53-1002745-02 Remote authentication 5 Supported LDAP options Ta b l e 16 su mmarizes the variou s LDAP options and Brocade suppor t for each. Command options Ta b l e 17 outlines the aaaConfig command options used to set the authentication mode.
152 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 Setting the switch authentication mode 1. Connect to the switch and log in us ing an account with admin permissions.
Fabric OS Administrator ’s Guide 153 53-1002745-02 Remote authentication 5 RADIUS, LD AP , and T A CA CS+ suppor t all the defined RBA C roles described in Ta b l e 1 2 on page 134.
154 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 Fabric OS users on the RADIUS server All existing Fabric OS mechanisms for managing lo cal-switch user acco unts and passwor ds remain functional when the switch is configured to use RAD IUS.
Fabric OS Administrator ’s Guide 155 53-1002745-02 Remote authentication 5 Brocade-AVPairs2 = "LFRoleList=admin:2,4-8,70,80,128;ChassisRole=admin", Brocade-Passwd-ExpiryDate = "11/10/.
156 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 For e xample, on a Linux F reeRADIUS Server , the user (user-za) with the f ollowing settings takes the “zoneAdmin ” permissions, with AD m ember list: 1, 2 , 4, 5, 6, 7, 8, 9, 12 ; the Home Admin Do main will be 1.
Fabric OS Administrator ’s Guide 157 53-1002745-02 Remote authentication 5 Configuring RADIUS ser vice on Linux consist s of the f ollowing tasks: • Adding the Br ocade attributes to the ser ver • Creating the user • Enabling clients Adding the Brocade attributes to the server 1.
158 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 When y ou use netw ork informati on service (NIS) for authen tication, the only wa y to enable authentication with the pas.
Fabric OS Administrator ’s Guide 159 53-1002745-02 Remote authentication 5 If CHAP authentication is require d, then Wind o ws must be configured to store passwor ds wi th rev ersible encr yption. Reverse password encr yption is not the default behavior; it must be enabled.
160 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 e. Af ter returning to the Int ernet Authentication Service window , add additional policies for all Brocade login types for which you want t o use the RADIUS ser ver . After this is done, yo u can configure the switch.
Fabric OS Administrator ’s Guide 161 53-1002745-02 Remote authentication 5 c. Add Brocade-VSA macro and define the attributes as f o llows: • vid (V endor-ID): 1588 • type1 (V endor- T ype): 1 .
162 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 FIGURE 12 Example of the dictiona.dcm f ile d. When selecting it ems from the Add R eturn List A ttribute , select Brocade-Auth-R ole and type the string Admi n . The string will equal the r ole on the switch.
Fabric OS Administrator ’s Guide 163 53-1002745-02 Remote authentication 5 • LDAP authentication is used on the loca l switch only and not f or the entire fabric. • Y ou can use the User- Principal-Name and not th e Common-Name f or AD LDAP authentication.
164 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 4. Associate the user t o the group b y adding the user to the g roup. For instructions on ho w to creat e a user ref er to www .micr osoft .com or Micr osoft documentation t o create a user in y our Active Direct or y .
Fabric OS Administrator ’s Guide 165 53-1002745-02 Remote authentication 5 3. Right click on select Properties . Click the Attribute Edit or tab. 4. Double-click the adminDescription attribute.
166 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 T w o operational modes exist in LD AP authenticati on: FIPS mo de and non-FIPS mode. This section discusse s LDAP au thentica tion in non- FIPS mode. F or information on LD AP in FIPS mode, refer t o Chapter 7, “Configuring Security Policies” .
Fabric OS Administrator ’s Guide 167 53-1002745-02 Remote authentication 5 include /usr/local/etc/openldap/schema/cosine.schema include /usr/local/etc/openldap/schema/local.schema ############################################### TLSCACertificateFile /root/sachin/ldapcert/cacert.
168 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 Assigning a user to a group Bef ore you can assign a user t o a group, the memberOf o verlay must be adde d to the slapd.conf file. R ef er t o “Enabling group membership” on page 166 f or details.
Fabric OS Administrator ’s Guide 169 53-1002745-02 Remote authentication 5 Example to add a gr oup member 1. Create or edit a .ldif file with an entry similar to the f ollowing. ##########Adding an attr value dn: cn=admin,ou=groups,dc=mybrocade,dc=com changetype: modify add: member member: cn=test1,cn=Users,dc=mybrocade,dc=com 2.
170 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 DESC 'Brocade specific data for LDAP authentication' EQUALITY caseIgnoreIA5Match SUBSTR caseIgnoreIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{256} ) objectclass ( 1.
Fabric OS Administrator ’s Guide 171 53-1002745-02 Remote authentication 5 objectClass: uidObject cn: Sachin sn: Mishra description: First user brcdAdVfData: HomeLF=30;LFRoleList=admin:1-128;ChassisRole=admin userPassword: pass uid: mishras@mybrocade.
172 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 Configuring the TACACS+ server on LINUX FabricOS software suppor ts T ACA CS+ authentication on a LINUX ser ver running the Open Source T ACA CS + LINUX package v4.0.4 from Cisco.
Fabric OS Administrator ’s Guide 173 53-1002745-02 Remote authentication 5 Configuring A dmin Domain lis ts If your netw ork uses Admin Domains, y o u should create A dmin Domain lists f or each user to identify the Admin Domains t o which the user has acc ess.
174 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 Configuring the pass word expiration date FabricOS lets you configure a passwor d expiration dat e for each user account and to configure a warning period f or notifying the user that the ac co unt password is about to e xpire.
Fabric OS Administrator ’s Guide 175 53-1002745-02 Remote authentication 5 Adding an authentication server to the switch configuration 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the aaaConfig -- add command.
176 Fabric OS A dministr ator’s Guide 53-1002745-02 Remote authentication 5 Displaying the current au thentication configuration 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the aaaConfig -- show command. If a configuration exists, its paramet ers are display ed.
Fabric OS Administrator ’s Guide 177 53-1002745-02 Chapter 6 Configuring Protocols In this chapter • Security pr otocols . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 7 7 • Secure Copy . . . . . . . .
178 Fabric OS A dministr ator’s Guide 53-1002745-02 Secure Copy 6 Ta b l e 2 2 des cribes additional sof tware or cer tificates that you must obtain to deplo y secure pro tocols. The security pro tocols ar e designed with the f our main use cases described in Ta b l e 2 3 .
Fabric OS Administrator ’s Guide 179 53-1002745-02 Secure Shell protocol 6 Setting up SCP for configur ation uploads and downloads Use the f ollowing pr ocedure to configure SC P for configuration uploads a nd downloads. 1. Connect to the switch and log in us ing an account with admin permissions.
180 Fabric OS A dministr ator’s Guide 53-1002745-02 Secure Shell pr otocol 6 SSH public key authentication OpenSSH public ke y authentication pro vides passw or d-less logins, known as SSH authentication, that uses public and private k ey pairs for incoming and outgoing authentication.
Fabric OS Administrator ’s Guide 181 53-1002745-02 Secure Shell protocol 6 Enter login name: auser Password: Public key is imported successfully. 4. T est the setup by logging in to the switch from a remote de vice, or by running a command remotely using SSH.
182 Fabric OS A dministr ator’s Guide 53-1002745-02 Secure Sockets Layer p rotocol 6 Deleting public keys on the switch Use the f ollowing pr ocedure to delet e public k eys fr om the switch. 1. Connect to the switch and log in us ing an account with admin permissions.
Fabric OS Administrator ’s Guide 183 53-1002745-02 Secure Sockets Layer protocol 6 Y ou should upgrade t o the Ja va 1.6.0 plug-in on your management w orkstation. T o find the Jav a version that is currently running, open t he Jav a consol e and look at the fir st line of the window.
184 Fabric OS A dministr ator’s Guide 53-1002745-02 Secure Sockets Layer p rotocol 6 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the secCer tUtil genkey com ma nd to g en er ate a p ub li c/p r iva te key p ai r .
Fabric OS Administrator ’s Guide 185 53-1002745-02 Secure Sockets Layer protocol 6 Obtaining certificates Once you ha ve generated a CSR, y ou will need t o follow the instructions on the websit e of the cer tificate issuing authority that you want to use; and then obtain the certif icate.
186 Fabric OS A dministr ator’s Guide 53-1002745-02 Secure Sockets Layer p rotocol 6 1. Connect to the switch and log in us ing an account with admin permissions.
Fabric OS Administrator ’s Guide 187 53-1002745-02 Secure Sockets Layer protocol 6 4. Cl ick the Intermediate or T rust ed Root tab and scroll the list to see if the r oot cer tificate is listed. T ak e the appropriat e follo wing action based on whe ther you find the certificate: • If the cer tificate is listed, you do not need to install it.
188 Fabric OS A dministr ator’s Guide 53-1002745-02 Simple Network Management Prot ocol 6 Issuer: CN=Brocade, OU=Software, O=Brocade Communications, L=San Jose, ST=California, C=US Serial number: 0 .
Fabric OS Administrator ’s Guide 189 53-1002745-02 Simple Network Management Protocol 6 • SW-EXTTRAP Includes the swSsn (Sof tware Serial Nu mber) as a part of Brocade SW traps. For inf ormation on Brocade MIBs, ref er to the Fab r ic O S M IB R ef er e n c e .
190 Fabric OS A dministr ator’s Guide 53-1002745-02 Telnet protocol 6 SNMP security levels Use the snm pConfig -- set seclev el command to set the security le vel. For more inf orma tion about using the Br ocade SNMP agent, ref er to the Fab ri c O S M I B Ref e re n c e .
Fabric OS Administrator ’s Guide 191 53-1002745-02 Telnet protocol 6 ATT ENTI ON The rule number assigned must precede the def a ult rule number f or this protocol. F or exam ple, in the defined policy , the T elnet rule number is 2. Theref ore, to ef f ectively bloc k T elnet, the rule number to assign m ust be 1.
192 Fabric OS A dministr ator’s Guide 53-1002745-02 Listener applications 6 Refe r to “Deleting a rule from an IP Filt er policy” on page 223 for more inf ormation on deleting IP filter rules. 3. T o permanently delete the policy , type the ipfilt er -- sa ve command.
Fabric OS Administrator ’s Guide 193 53-1002745-02 Ports and applications used by switches 6 Port configuration Ta b l e 27 pro vides information on por ts that the switch uses.
194 Fabric OS A dministr ator’s Guide 53-1002745-02 Ports and applications used by switches 6.
Fabric OS Administrator ’s Guide 195 53-1002745-02 Chapter 7 Configuring Security Policies In this chapter • A CL policies ov er view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 195 • A CL policy management .
196 Fabric OS A dministr ator’s Guide 53-1002745-02 ACL policy management 7 Policies with the same stat e are grouped toge ther in a Policy Set . Each switch has the following two sets: • Active policy set, which contains A CL policies be ing enfor ced by the switc h.
Fabric OS Administrator ’s Guide 197 53-1002745-02 ACL policy manag ement 7 Displaying ACL policies Y ou can view the active and defined policy sets at an y time. Additionally , in a defined policy set, policies created in the same login session also appear but these policies are automatically delet ed if the you log out without sa vi ng them.
198 Fabric OS A dministr ator’s Guide 53-1002745-02 ACL policy management 7 Example of deleting an A CL policy switch:admin> secpolicydelete "DCC_POLICY_010" About to delete policy Finance_Policy. Are you sure (yes, y, no, n):[no] y Finance_Policy has been deleted.
Fabric OS Administrator ’s Guide 199 53-1002745-02 FCS policies 7 Example of abor ting unsaved changes switch:admin> secpolicyabort Unsaved data has been aborted. All changes since the last time the secPolicySav e or secPolicyA ctivate commands w e re entered are abor ted.
200 Fabric OS A dministr ator’s Guide 53-1002745-02 FCS policies 7 Ta b l e 3 0 shows the commands fo r switch operations f or Primar y FCS enforcement. In Fabric OS v7 . 1.0 an d later , to a void segmentat ion of por ts due to a member-list order mismatch, security policy members are sor ted based on WWN .
Fabric OS Administrator ’s Guide 201 53-1002745-02 FCS policies 7 Creating an FCS policy 1. Co nnect to the switch and log in using an acc o unt with admin permissions, or an account with OM permissions fo r the Securi ty RBA C class of commands. 2.
202 Fabric OS A dministr ator’s Guide 53-1002745-02 FCS policies 7 FCS policy distribution The FCS policy can be auto ma tically distribute d using the fddCfg -- fab wideset command or it can be manually distributed t o the switches using the distribut e -p command.
Fabric OS Administrator ’s Guide 203 53-1002745-02 Device Connection Control policies 7 Device Connection Control policies Multiple Device Connection Control (DCC) policies can be used to restrict which device por ts can connect to which switch por ts.
204 Fabric OS A dministr ator’s Guide 53-1002745-02 Device Connection Control policies 7 Creating a DCC policy DCC policies must f ollow the naming con vention “DCC_POLICY_ nnn , ” where nnn represents a unique string. The maximum length is 30 ch aracters, including the prefix DCC_POLICY_.
Fabric OS Administrator ’s Guide 205 53-1002745-02 Device Connection Control policies 7 Deleting a DCC policy 1. Co nnect to the switch and log in using an acc o unt with admin permissions, or an account with OM permissions fo r the Securi ty RBA C class of commands.
206 Fabric OS A dministr ator’s Guide 53-1002745-02 SCC Policies 7 Ta b l e 3 4 shows the behavior of a DCC policy creat ed ma nually with the ph ysical PWWN of a devi ce. The configurations shown in this table are the recommended configu rations when an F A-PWW N is logged into the switch.
Fabric OS Administrator ’s Guide 207 53-1002745-02 Authentication policy for fabric elements 7 Creating an SCC policy 1. Co nnect to the switch and log in using an acc o unt with admin permissions, or an account with OM permissions fo r the Securi ty RBA C class of commands.
208 Fabric OS A dministr ator’s Guide 53-1002745-02 Authenticatio n policy for fabric eleme nts 7 FIGURE 13 DH-CHA P authentication If you use DH-CHAP authen tication, then a secret k ey pair must be installed only in connect ed fabric elements.
Fabric OS Administrator ’s Guide 209 53-1002745-02 Authentication policy for fabric elements 7 Virt ual F abrics consideration s The switch authentication policy appli es to all E_P or ts in a logical switch.
210 Fabric OS A dministr ator’s Guide 53-1002745-02 Authenticatio n policy for fabric eleme nts 7 Re-authenticating E_Ports Use the authUtil -- authinit command to re-initiat e the authentica tion on selected ports. It pro vides flexibility to initiat e authentication for specified E_Ports, a set of E_Por ts, or all E_Por ts on the switch.
Fabric OS Administrator ’s Guide 211 53-1002745-02 Authentication policy for fabric elements 7 and CT frames, ex cept the A UTH_NEGO TIA TE ELS fr ame, are blocked b y the switch. During this time, the Fibre Channel driv er rejects all other ELS frames.
212 Fabric OS A dministr ator’s Guide 53-1002745-02 Authenticatio n policy for fabric eleme nts 7 Authentication protocols Use the authUti l command to per form the f ollowing tasks: • Display the current authentication parameters. • Select the authentication pr o tocol used be tween switches.
Fabric OS Administrator ’s Guide 213 53-1002745-02 Authentication policy for fabric elements 7 Secret key pairs for DH-CHAP When you configure the switches at both ends of a link to use DH-CHAP f or authentication, you must also define a secret ke y pair —one for each end of the link.
214 Fabric OS A dministr ator’s Guide 53-1002745-02 Authenticatio n policy for fabric eleme nts 7 Setting a secret key pair 1. Log in to the switch using an account with admin permissions, or an account with OM permissions for the A uthentication RBAC class of commands.
Fabric OS Administrator ’s Guide 215 53-1002745-02 Authentication policy for fabric elements 7 FCAP configuration overview Beginning with Fabric OS re lease 7 .0.0, you must configure the switch t o use third-party cer t ificates for authentication with the peer switch.
216 Fabric OS A dministr ator’s Guide 53-1002745-02 Authenticatio n policy for fabric eleme nts 7 Exporting the CSR for FCAP Y ou will need to e xpor t the CSR file creat ed in “Generating the ke y and CSR for FCAP” section and send to a Certif icate A uthority (CA).
Fabric OS Administrator ’s Guide 217 53-1002745-02 IP Filter policy 7 Starting FCAP authentic ation 1. Log in to the switch using an account with admin permissions, or an account with OM permissions for the A uthentication RBAC class of commands. 2.
218 Fabric OS A dministr ator’s Guide 53-1002745-02 IP Filter po licy 7 Vir tual Fabrics con siderations: Each logical switch cannot have its o wn different IP Filt er policies. IP Filter polic ies are treated as a chassis-wide configuration and are common f o r all the logical switches in the chassis.
Fabric OS Administrator ’s Guide 219 53-1002745-02 IP Filter policy 7 1. Log in to the switch using an account with admin permissions, or an account associated with the chassis role and ha ving the OM permission s for the IPfilt er RBAC class of commands.
220 Fabric OS A dministr ator’s Guide 53-1002745-02 IP Filter po licy 7 Source address For an IPv4 filt er policy , the source address has to be a 32-bit IPv4 address in dot decimal no tation. The gro up prefix has t o be a CIDR block prefix representatio n.
Fabric OS Administrator ’s Guide 221 53-1002745-02 IP Filter policy 7 Protocol T CP and UDP protocols are valid prot ocol selecti ons. Fabric OS v6.2.
222 Fabric OS A dministr ator’s Guide 53-1002745-02 IP Filter po licy 7 Traffic type and destination IP The traf fic type and destina tion IP elements allow an IP policy rule to sp ecify filter enf orcement fo r IP f orwarding.
Fabric OS Administrator ’s Guide 223 53-1002745-02 IP Filter policy 7 IP Filter policy enforcement A n a c t i ve I P F i l te r p o l i c y i s a f i l t e r a p p l i e d to the I P packets thr ough the manage ment inter face.
224 Fabric OS A dministr ator’s Guide 53-1002745-02 Policy database distribution 7 1. Log in to the switch using an account with admin permissions, or an account associated with the chassis role and ha ving the OM permission s for the IPfilt er RBAC class of commands.
Fabric OS Administrator ’s Guide 225 53-1002745-02 Policy database distribu tion 7 • Manually distribute an A C L policy database — Ru n the distribut e command to push the local database of the specified policy type t o target switches. “ ACL policy distribution t o other switches” on page 22 7.
226 Fabric OS A dministr ator’s Guide 53-1002745-02 Policy database distribution 7 Use the chassisDistribute command to distribute IP fil ter po licies. T o distribute other security policies, us e the distribute command. Displaying the database distribution settings 1.
Fabric OS Administrator ’s Guide 227 53-1002745-02 Policy database distribu tion 7 ACL policy distribution to other switches This section explains how to manually di stribute local ACL policy databases. The distribute command has the f ollowing dependencies: • All target switches must be running Fabric OS v6.
228 Fabric OS A dministr ator’s Guide 53-1002745-02 Policy database distribution 7 Displaying the fabric-wide consistency policy 1. Co nnect to the switch and log in using an acc o unt with admin permissions, or an account with O permission fo r the FabricDistri b ution RBA C class of commands.
Fabric OS Administrator ’s Guide 229 53-1002745-02 Policy database distribu tion 7 Notes on joining a switch to the fabric When a switch is joined to a fabric with a t olerant SCC, DCC, or FCS f abric -wide consistency policy , the joining switch must hav e a m atching tolerant SC C, DCC, or FCS fabric-wide consistency policy .
230 Fabric OS A dministr ator’s Guide 53-1002745-02 Policy database distribution 7 Non-matching fabric-wid e consistency policies Y ou may encount er one of the follo wing two scenarios described in.
Fabric OS Administrator ’s Guide 231 53-1002745-02 Management interface security 7 Management interface security Y ou can secure an Ethernet management int er f ace betw een two Brocade switc hes or Backbones by implementing I P sec and IKE policies t o creat e a tunnel that pr ot ects traf fic flows.
232 Fabric OS A dministr ator’s Guide 53-1002745-02 Management interface security 7 FIGURE 1 4 Protected endpoints conf iguration A possible dra wback of end-t o-end security is that various applications that req uire the ability t o inspect or modify a transient packet will fail wh en end-t o-end confidential ity is employ ed.
Fabric OS Administrator ’s Guide 233 53-1002745-02 Management interface security 7 FIGURE 1 6 Endpoint-to-gateway tu nnel configuration RoadWarrior configuration In endpoint-to-endpoint sec urity , pack ets are encr ypted and decrypted by the host which pr oduces or consumes the traffic.
234 Fabric OS A dministr ator’s Guide 53-1002745-02 Management interface security 7 these values in negotiations t o create IP sec SAs. Y ou must creat e an SA prior to creating an SA-proposal.
Fabric OS Administrator ’s Guide 235 53-1002745-02 Management interface security 7 IP sec traffic selector The traf fic selector is a traffic filter that define s and identifies the traf fi c flow betw een two systems that hav e IP sec prot ection.
236 Fabric OS A dministr ator’s Guide 53-1002745-02 Management interface security 7 The IP secConfig command does not suppor t manipulating pre-shared ke ys corresponding to the identity of the IKE peer or gr oup of peers. Use the secCertUtil command to impor t, delete, o r display the pre-shared ke ys in the local switch database.
Fabric OS Administrator ’s Guide 237 53-1002745-02 Management interface security 7 Example of creating an IP sec SA policy This examp le creates an IP sec SA policy named AH0 1 , which uses AH pr otection with MD5. Y ou would run this command on each switch; on each side of the tunnel so that both si des hav e the same IP sec SA policy.
238 Fabric OS A dministr ator’s Guide 53-1002745-02 Management interface security 7 1 0. V erify traf fic is prot ected. a. Initiate a telnet , SSH, or ping session from the tw o switches.
Fabric OS Administrator ’s Guide 239 53-1002745-02 Management interface security 7 6. Impor t the pre-shared k ey file using the secCer tUtil command. The fil e name should ha ve a .psk ext ension. For more inf ormation on impor ting the pre-shared ke y file, ref er to “Installing a switch cer tificate” on page 185.
240 Fabric OS A dministr ator’s Guide 53-1002745-02 Management interface security 7 • Use the IP secConfig –-sho w policy ik e –a command with the specified operands to display IKE policies. • Use the IP secConfig –-flush manual-sa command with the specified op erands to flush the created SAs in the k ernel SADB.
Fabric OS Administrator ’s Guide 241 53-1002745-02 Chapter 8 Maintaining the Switch Configuration File In this chapter • Configuration settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 4 1 • Configuration file back up .
242 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuration settin gs 8 If your user account has chassis account permissions, you can use an y of the follo wing options when uploading or downl.
Fabric OS Administrator ’s Guide 243 53-1002745-02 Configuration sett ings 8 [Active Security policies] [cryptoDev] [FICU SAVED FILES] [Banner] [End] [Switch Configuration End : 0] date = Tue Mar 1 .
244 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuration file backup 8 • Licenses Lser vc – Sentinel License configuration • GE blade mode – GigE Mode configuration • FWD CHASSIS .
Fabric OS Administrator ’s Guide 245 53-1002745-02 Configuration file b ackup 8 Before you upload a configuration file, verify that y ou can reach the FTP ser ver fr om the switch. Using a T elnet connection, sa ve a back up copy of the configuration file from a logical switch to a host computer .
246 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuration file restorat ion 8 Configuration file restoration When you rest ore a configuratio n file, you o verwrite the existing configuration with a previously sav ed backup configuration file.
Fabric OS Administrator ’s Guide 247 53-1002745-02 Configuration file restoration 8 If you must set up your switch again, run the commands listed in Ta b l e 47 and s av e t he output i n a file fo rmat. Store the files in a saf e place f or emergency reference.
248 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuration file restorat ion 8 CAUTION Though the switch itself has advanced error checking, the configdownload feature within Fabric OS was not designed f or users to edit, and is limited in its ability.
Fabric OS Administrator ’s Guide 249 53-1002745-02 Configuration file restoration 8 Example of confi gDownload without Admin Doma ins switch:admin> configdownload Protocol (scp, ftp, local) [ftp]: Server Name or IP Address [host]: 10.1.2.3 User Name [user]: UserFoo Path/Filename [<home dir>/config.
250 Fabric OS A dministr ator’s Guide 53-1002745-02 Configurations across a fabric 8 Activating configDownload: Switch is disabled configDownload complete: Only zoning parameters are downloaded to ad5. Example of a non-int eractive download of all confi gurations (chassis and switches) configdownload -a -ftp 10.
Fabric OS Administrator ’s Guide 251 53-1002745-02 Configuration management for Virtual Fabrics 8 Uploading a configuration file from a switch with Virtual Fabrics enabled The configUpload command w.
252 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuration management for Virtual Fabrics 8 Wait f or the configuration f ile to do wnload on to th e s wi tc h. Y o u m ay ne ed to r ec on ne c t to t he switch. 4. Enter the configDownload command.
Fabric OS Administrator ’s Guide 253 53-1002745-02 Brocade configuration form 8 Brocade configuration form Use the form in Ta b l e 4 8 as a hard cop y ref erence f or your configuration information. In the har dware ref erence manuals for the Br ocade DCX and DCX-4S Backbones, the re is a guide for FC port-setting.
254 Fabric OS A dministr ator’s Guide 53-1002745-02 Brocade configuration form 8.
Fabric OS Administrator ’s Guide 255 53-1002745-02 Chapter 9 Installing and Maintaining Firmware In this chapter • Firmw are download pr ocess overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 255 • Preparing f or a firmw are download .
256 Fabric OS A dministr ator’s Guide 53-1002745-02 Firmware download process overview 9 Y ou can download Fabric OS to a Backbone, whic h is a chassis; and to a nonchassis-based system, also ref erred to as a fixed- por t switch. The dif f er ence in the download process is that Back bones hav e two CPs and fixed-port switches hav e one CP .
Fabric OS Administrator ’s Guide 257 53-1002745-02 Firmware download process overvi ew 9 Upgrading and downgrading firmware Upgr adin g means installing a new er version of firmw a re.
258 Fabric OS A dministr ator’s Guide 53-1002745-02 Preparing for a firmware download 9 Preparing for a firmware download Before ex ecuting a firmware do wnlo ad, it is recommen ded that you per form the tasks listed in this section.
Fabric OS Administrator ’s Guide 259 53-1002745-02 Preparing for a firmware download 9 5. Conn ect to the switch and log in using an account with admin pe rmissions. Enter the suppor tSav e command to retrieve all cu rrent core files prior to e xecuting the firmw are download.
260 Fabric OS A dministr ator’s Guide 53-1002745-02 Firmware downlo ad on switches 9 Firmware download on switches Brocade fixed-port switches maintain primar y and secondar y par titions for firmw are. The firm wareDo wnload command defaults to an aut o commit option that automatically copies the firmw are from one partition to the other .
Fabric OS Administrator ’s Guide 261 53-1002745-02 Firmware download on switches 9 Upgrading firmware for Br ocade fixed-port switches 1. T ake the f ollowing appropriat e action based on what ser v.
262 Fabric OS A dministr ator’s Guide 53-1002745-02 Firmware download on a Backbone 9 Firmware download on a Backbone ATTENTION T o successfully download firm ware, y ou must ha ve an active Ethernet co nnection o n each CP .
Fabric OS Administrator ’s Guide 263 53-1002745-02 Firmware download on a Backbone 9 Upgrading firmware on Back bones (including blades) There is only one chassis management IP address f or the Brocade Backbones.
264 Fabric OS A dministr ator’s Guide 53-1002745-02 Firmware download on a Backbone 9 If an AP blade is present : A t the point of the failo ver , an aut o lev eling process is activ ated. Aut ole veling is triggered when the activ e CP dete cts a blade that contains a different v ersion of the firmw are, regardless of which version is olde r .
Fabric OS Administrator ’s Guide 265 53-1002745-02 Firmware download from a USB device 9 Slot 7 (CP1, active): Firmware has been downloaded to the secondary partition of the switch. [5]: Mon Mar 22 04:37:24 2010 Slot 7 (CP1, standby): The firmware commit operation has started.
266 Fabric OS A dministr ator’s Guide 53-1002745-02 FIPS support 9 Downloading from the USB device using the relative path 1. Log in to the switch using an account assigned to the admin role. 2. Enter the firmw areDownload -U command. ecp:admin> firmwaredownload –U v7.
Fabric OS Administrator ’s Guide 267 53-1002745-02 FIPS support 9 NOTE If FIPS mode is enabled, all logins should be ha ndle d through SSH o r direct serial method, and the transf er pro tocol shoul d be SCP . Updating the firmware key 1. Log in to the switch as admin.
268 Fabric OS A dministr ator’s Guide 53-1002745-02 Testing and re storing firmware on switches 9 Power-on firmware checksum test FIPS requires the ch ecksums of the e xecutables an d libraries on the filesystem to be v alidated before F a bric OS modules a re launched.
Fabric OS Administrator ’s Guide 269 53-1002745-02 Testing and restoring firmware on switches 9 User Name: userfoo File Name: /home/userfoo/v7.0.0 Password: <hidden> Do Auto-Commit after Reboot [Y]: n Reboot system after download [N]: y Firmware is being downloaded to the switch.
270 Fabric OS A dministr ator’s Guide 53-1002745-02 Testing and rest oring fi rmware on Backbones 9 Testing and restoring firmware on Backbones This procedure enables you to perform a firm ware download on each CP and v erify that the procedure w as successful before committing to the ne w f irmw are .
Fabric OS Administrator ’s Guide 271 53-1002745-02 Testing and rest oring fi rmware on Backbones 9 8. Verify the f ailo ver . a. Connect to the Ba ckbone on the active CP , which is the f o rmer standby CP . b. Enter the haShow command to v erify that the HA sync hronization is complete.
272 Fabric OS A dministr ator’s Guide 53-1002745-02 Testing and rest oring fi rmware on Backbones 9 ATT ENTI ON Stop! If yo u hav e completed st ep 11 , then y ou hav e committ ed the firmw are on both CPs and you ha ve complete d the firmw are download pr ocedure.
Fabric OS Administrator ’s Guide 273 53-1002745-02 Validating a firmware download 9 Validating a firmware download V alidate the firm ware download b y running the f ollowing commands: firmwareSho w , firm wareDo wnloadStatus , nsSho w , nsAllShow , and fabricSh ow .
274 Fabric OS A dministr ator’s Guide 53-1002745-02 Validating a firmware download 9.
Fabric OS Administrator ’s Guide 275 53-1002745-02 Chapter 10 Managing Virtual Fabrics In this chapter • Vir tual Fabrics ov erview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 75 • Logical switch ov er view .
276 Fabric OS A dministr ator’s Guide 53-1002745-02 Logical switch overview 10 This chapter describes the log ical switch and logi cal fabric features. F or information about device sharing with Vir tual Fabrics, ref er to “FC-FC r outing and Vir tual Fabrics” on p age 606.
Fabric OS Administrator ’s Guide 277 53-1002745-02 Logical switch overview 10 Af ter y ou enable Vir tual Fabrics, y ou can create up t o sev en additional logical switches, depending on the switch mo del. Figure 18 shows a Vir tual Fabrics-enabled switch before and af ter it is divided into logical switches.
278 Fabric OS A dministr ator’s Guide 53-1002745-02 Logical switch overview 10 FIGURE 19 Fabric IDs assigned to logical switc hes Port assignment in logical switches Initially , all por ts belong to the default logical sw itch. When you creat e additional logical switches, they are em pty and y ou must assign por ts to those logical switches.
Fabric OS Administrator ’s Guide 279 53-1002745-02 Logical switch overview 10 A given port is always in one (and only one) lo gical switch. The following scenarios ref er to the chassis af ter port assignment in Figure 20 : • If you assign P2 to logical switch 2 , you ca nnot assign P2 to an y other logical switch.
280 Fabric OS A dministr ator’s Guide 53-1002745-02 Logical switch overview 10 FIGURE 2 1 Logical switches connected to devices and non-Virtual Fabrics switch Figure 22 shows a logical representation of the physical chassis and devices in Figure 2 1 .
Fabric OS Administrator ’s Guide 281 53-1002745-02 Management model for logical switches 10 Management model for logical switches Y ou can use one common I P address for the hardw are that is shared b y all of the logical switches in the chassis and you can set up individual IP v4 addresses f or each Vir tual F abric.
282 Fabric OS A dministr ator’s Guide 53-1002745-02 Logical fabric overview 10 Logical fabric and ISLs Figure 23 shows two physical chassis divi de d into logical switches. In Figure 23 , ISLs are used to connect the logical switches with F ID 1 and the lo gical switches with FID 1 5.
Fabric OS Administrator ’s Guide 283 53-1002745-02 Logical fabric overview 10 Base switch and extended ISLs Another wa y to connect logical switches is t o use ext ended ISLs and base switc hes. When you divide a chassis into logical switches, y o u can designate one of the switches to be a base switch.
284 Fabric OS A dministr ator’s Guide 53-1002745-02 Logical fabric overview 10 Think of the logical switches as be ing connected with logical ISLs, as sho wn in Figure 26 . In this diagram, the logical ISLs are not connect ed to por t s because they are not ph ysical cables.
Fabric OS Administrator ’s Guide 285 53-1002745-02 Logical fabric overview 10 By default, the physical ISL path is fa vored o ver the logical path (o ver the XISL) because the physical path has a lo wer cost. This beha vior can be changed by configuring the cost of the dedicated ph ysical ISL to match the cost of the logic al ISL.
286 Fabric OS A dministr ator’s Guide 53-1002745-02 Account management and Virtual Fabrics 10 Account management and Virtual Fabrics When user accounts are created, th ey are assigned a list of logical fa brics t o which they can log in and a home logical fabric (home FID).
Fabric OS Administrator ’s Guide 287 53-1002745-02 Supported platforms for Virtual Fabrics 10 Supported port configuratio ns in Brocade Backbones Some of the ports in the Brocade DCX and DCX 85 1 0 Backb one families are not suppor ted on all types of logical switches.
288 Fabric OS A dministr ator’s Guide 53-1002745-02 Limitations and restrict ions of Virtual Fabrics 10 Virtual Fabrics interaction with other Fabric OS features Ta b l e 51 lists some F a bric OS features and considerat ions that apply when using V ir tual F abrics.
Fabric OS Administrator ’s Guide 289 53-1002745-02 Limitations and restrictions of Virtual Fabrics 10 Refe r to “Supported por t configurat ions in Brocade Backbones” on page 287 f or restrictions on the default logical switch.
290 Fabric OS A dministr ator’s Guide 53-1002745-02 Enabling Virtual Fabrics mode 10 Enabling Virtual Fabrics mode A fabric is said to be in Vir tual Fabrics mode (VF mode) when the Vir tual F abrics f eature is enabled. Before you can use the Virtual Fabrics f eatures, such as logical switch and logical fabric, you must enable VF mode.
Fabric OS Administrator ’s Guide 291 53-1002745-02 Configuring logical switches to use basic configuration values 10 Use the f ollowing pr ocedure to disable Virtual Fabrics mode: 1. Connect to the physical chassi s and log in using an account wi th the chassis-role permission.
292 Fabric OS A dministr ator’s Guide 53-1002745-02 Creating a logical switch or base switch 10 3. Enter n at the prompts to configure syst em and cfgload attribut es. Enter y at the pr ompt t o configure custom attributes. System (yes, y, no, n): [no] n cfgload attributes (yes, y, no, n): [no] n Custom attributes (yes, y, no, n): [no] y 4.
Fabric OS Administrator ’s Guide 293 53-1002745-02 Executing a command in a diffe rent logical switch c ontext 10 Example The f ollowing e xample creates a logical switch w ith FID 4 , and then assigns domain ID 1 4 to it. sw0:FID128:admin> lscfg --create 4 About to create switch with fid=4.
294 Fabric OS A dministr ator’s Guide 53-1002745-02 Deleting a lo gical switch 10 switchMode: Native switchRole: Principal switchDomain: 14 switchId: fffc0e switchWwn: 10:00:00:05:1e:82:3c:2b zoning.
Fabric OS Administrator ’s Guide 295 53-1002745-02 Adding and moving ports on a logical switch 10 Example of deleting the logical switch with FID 7 switch_4:FID4:admin> lscfg --delete 7 All active login sessions for FID 7 have been terminated. Switch successfully deleted.
296 Fabric OS A dministr ator’s Guide 53-1002745-02 Displaying logical switch configuration 10 Displaying logical switch configuration Use the f ollowing pr ocedure to displa y the configuration f or a logical switch: 1. Connect to the physical chassi s and log in using an account wi th the chassis-role permission.
Fabric OS Administrator ’s Guide 297 53-1002745-02 Changing a logical switch to a base switch 10 Checking and logging message: fid = 5. Please enable your switch.
298 Fabric OS A dministr ator’s Guide 53-1002745-02 Setting up IP addresses for a Virtual Fabric 10 Configure... Fabric parameters (yes, y, no, n): [no] y WWN Based persistent PID (yes, y, no, n): [no] Allow XISL Use (yes, y, no, n): [yes] n WARNING!! Disabling this parameter will cause removal of LISLs to other logical switches.
Fabric OS Administrator ’s Guide 299 53-1002745-02 Configuring a logical switch to use XISLs 10 Configuring a logical switch to use XISLs When you creat e a logical switch, it is config ured t o use XISLs b y default. Use the follo w ing procedure to allow o r disallow the logical switch t o use XISLs in the base fabric.
300 Fabric OS A dministr ator’s Guide 53-1002745-02 Creating a logical fabric using XISLs 10 Creating a logical fabric using XISLs This procedure describes ho w to creat e a logical fa bric using multiple chassis and XISLs and refers to the configuration shown in Figure 28 as an exam ple.
Fabric OS Administrator ’s Guide 301 53-1002745-02 Creating a logical fabric using XISLs 10 4. Configure the logical switches in each chassis: a. Connect to the ph ysical ch assis and log in using an ac count with the chassis-role permission. b. Create a logical switch and assign it a fabric ID f o r the logical fabric.
302 Fabric OS A dministr ator’s Guide 53-1002745-02 Creating a logical fabric using XISLs 10.
Fabric OS Administrator ’s Guide 303 53-1002745-02 Chapter 11 Administering Advanced Zoning In this chapter • Zone types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 303 • Zoning ov er view .
304 Fabric OS A dministr ator’s Guide 53-1002745-02 Zoning overview 11 • QoS zones Assign high or low priority t o designated tr aff ic flows. QoS zones are regular zones with additional QoS attributes specified b y a dding a QOS prefix t o the zone name.
Fabric OS Administrator ’s Guide 305 53-1002745-02 Zoning overview 11 FIGURE 29 Zoning example Approaches to zoning Ta b l e 5 3 lis ts the various appr oaches you can tak e when implementing zo ning in a fabric.
306 Fabric OS A dministr ator’s Guide 53-1002745-02 Zoning overview 11 Zone objects A zone object is any de vice in a zone, such as: • Physical port numb er or por t index on the switch • Node W.
Fabric OS Administrator ’s Guide 307 53-1002745-02 Zoning overview 11 The types of zone objects u sed to define a zone ca n be mixed. F or exam ple, a zone defined with the zone objects 2, 12; 2, 14.
308 Fabric OS A dministr ator’s Guide 53-1002745-02 Zoning overview 11 The different types of zone co nfigurations are: • Defined Configur ation The complet e set of all zone objects defined in the fabric. • Ef fectiv e Configuratio n A single zone configuration that is currentl y in ef f ect.
Fabric OS Administrator ’s Guide 309 53-1002745-02 Zoning overview 11 Identifying the enforced zone type Use the f ollowing pr ocedure to i dentify zone s and zone types: 1. Connect to the switch and log in us ing an account with admin permissions. 2.
310 Fabric OS A dministr ator’s Guide 53-1002745-02 Broadcast zones 11 Best practices for zoning The f ollowing are recommendations for using zo ning: • Alwa ys zone using the highest Fabric OS-lev el switch.
Fabric OS Administrator ’s Guide 311 53-1002745-02 Broadcast zones 11 Figure 30 illu strates how br oadcast zones work with Admin Domains. Figure 30 shows a fabric wi th five de vices and two Admin Domains, AD1 and AD 2. Each Ad min Domain has two de vices and a broadcast zone.
312 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone aliases 11 High availability considerat ions with broadcast zones If a switch has broadcast zone-cap able firmw are on the active CP (Fabric OS v5.3.x or lat er) and broadcast zone-incapable firm ware on the standb y CP (Fabric OS v ersion earlier than v5.
Fabric OS Administrator ’s Guide 313 53-1002745-02 Zone aliases 11 Creating an alias Use the f ollowing pr ocedure to creat e an alias: 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the aliCreate command, using the f ollowing syntax: alicreate " aliasname ", " member [; member.
314 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone aliases 11 inconsistent. The inconsistency will result in different Effective Zoning configurations for switches in the fabric if a zone merge or HA failover happens. To avoid inconsistency it is recommended to commit the configurations using the 'cfgenable' command.
Fabric OS Administrator ’s Guide 315 53-1002745-02 Zone aliases 11 The cfgSav e command ends and commits the current zo nin g transaction buf fer to non volatile memor y . If a transaction is open on a dif ferent switch in the fabric when this command is run, the transaction on the other switch is automati cally aborted.
316 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone creation and maintenance 11 Zone creation and maintenance Fabric OS allo ws you t o create zones to bett er manage de vices. Notes • Broadcast Zone : T o create a br oadcast zone, use the reser ved name “br oadcast”.
Fabric OS Administrator ’s Guide 317 53-1002745-02 Zone creation and maintenance 11 T o creat e a br oadcast zone, use the rese r ved name “br oadcast”. 3. Enter the cfgSav e command to sav e the change to the defined configuratio n. The cfgSav e command ends and commits the current zo nin g transaction buf fer to non volatile memor y .
318 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone creation and maintenance 11 Example Adding members to a zone switch:admin> zoneadd matt, "ze*; bond*; j*" switch:admin> cfgsa.
Fabric OS Administrator ’s Guide 319 53-1002745-02 Zone creation and maintenance 11 alias: jeff 30:00:00:05:1e:a1:cd:02; 40:00:00:05:1e:a1:cd:04 alias: jones 7,3; 4,5 alias: zeus 4,7; 6,8; 9,2 Effec.
320 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone creation and maintenance 11 alias: jake 4,7; 8,9; 14,11 alias: jeff 30:00:00:05:1e:a1:cd:02; 40:00:00:05:1e:a1:cd:04 alias: jones 7,3; 4,5 al.
Fabric OS Administrator ’s Guide 321 53-1002745-02 Zone creation and maintenance 11 The cfgSav e command ends and commits the current zo nin g transaction buf fer to non volatile memor y . If a transaction is open on a dif ferent switch in the fabric when this command is run, the transaction on the other switch is automati cally aborted.
322 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone creation and maintenance 11 Viewing a zone in the defined configuration Use the f ollowing pr ocedure to vie w a zone in the configuration: 1. Connect to the switch and log in us ing an account with admin permissions.
Fabric OS Administrator ’s Guide 323 53-1002745-02 Zone creation and maintenance 11 1,1; 1,2 alias: array1 21:00:00:20:37:0c:76:8c; 21:00:00:20:37:0c:71:02 alias: array2 21:00:00:20:37:0c:76:22; 21:.
324 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone creation and maintenance 11 alias: loop1 21:00:00:20:37:0c:76:85; 21:00:00:20:37:0c:71:df 3. Enter the zone -- val ida te command to li st all zone members that are not part of the current zone enfo rcement table.
Fabric OS Administrator ’s Guide 325 53-1002745-02 Zone creation and maintenance 11 If you ent er yes, and the cfgSav e operation complet es successfully then the fo llowing RASlog message [ZONE-1 062 ] will be posted.
326 Fabric OS A dministr ator’s Guide 53-1002745-02 Default zoning mode 11 Default zoning mode The default zoning mode controls de vice access if zoning is not implement ed or if there is no effectiv e zone configuration.
Fabric OS Administrator ’s Guide 327 53-1002745-02 Zone database size 11 switch:admin> cfgsave WARNING!!! The changes you are attempting to save will render the Effective configuration and the Defined configuration inconsistent.
328 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone configurations 11 Zone configurations Y ou can store a number of zones in a zone conf iguration database. The maximum number of items that can be stored in the zone configuration database depends on the f ollowing criteria: • Number of switches in the f abric.
Fabric OS Administrator ’s Guide 329 53-1002745-02 Zone configurations 11 Adding zones (members) to a zone configuration Use the f ollowing pr ocedure to add members t o a zone configuration: 1. Connect to the switch and log in us ing an account with admin permissions.
330 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone configurations 11 Enabling a zone configuration The f ollowing pr ocedure ends and commits the curre nt zoning transaction buf fer t o nonv olat ile memor y .
Fabric OS Administrator ’s Guide 331 53-1002745-02 Zone configurations 11 Deleting a zone configuration Use the f ollowing pr ocedure to delet e a zone configuration: 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the cfgDelete c ommand, using the f ollow ing syntax: cfgdelete " cfgname " 3.
332 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone configurations 11 alias: array1 21:00:00:20:37:0c:76:8c; 21:00:00:20:37:0c:71:02 alias: array2 21:00:00:20:37:0c:76:22; 21:00:00:20:37:0c:76:.
Fabric OS Administrator ’s Guide 333 53-1002745-02 Zone object maintena nce 11 Clearing all zone configurations Use the f ollowing pr ocedure to clear all zone configurations: 1. Connect to the switch and log in usin g an account with admin permissions.
334 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone object maintenance 11 4. Enter the cfgShow command t o verify the new zone object is present. switch:admin> cfgshow "Test*" cfg: Test1 Blue_zone cfg: Test_cfg Purple_zone; Blue_zone switch:admin> cfgShow "US_Test1" cfg: US_Test1 Blue_zone 5.
Fabric OS Administrator ’s Guide 335 53-1002745-02 Zone object maintena nce 11 You are about to expunge one configuration or member. This action could result in removing many zoning configurations recursively. [Removing the last member of a configuration removes the configuration.
336 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone configuration management 11 Zone configuration management Y ou can add, delet e, or remove individual elements in an existing zone configurat ion to create an appropriat e configuration for your SAN en vironment.
Fabric OS Administrator ’s Guide 337 53-1002745-02 Zone merging 11 Adding a ne w fabric that has no zone configuration inf ormation to an existing fabric is v er y similar to adding a new switch. All switch es in the ne w fa bric inherit the zone configuration data.
338 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone merging 11 • Merging two fabrics Both fabrics hav e iden tical zones and configurations enabl ed, including the default zone mode. The two fabrics will join to mak e one larger fabric with the same zone config uration across the newly created fabric.
Fabric OS Administrator ’s Guide 339 53-1002745-02 Zone merging 11 Zone merging scenarios The following tables pro vide information on merging zones and the expect ed results.
340 Fabric OS A dministr ator’s Guide 53-1002745-02 Zone merging 11 Switch A and Switch B ha ve different define d configur ations. Switch B has an ef fective configuration. defined: cfg2 zone2: ali3; ali4 effectiv e: none defined: cf g1 zone1: ali1; ali2 effective: cf g1 Clean merge.
Fabric OS Administrator ’s Guide 341 53-1002745-02 Zone merging 11 TA B L E 5 8 Zone merging scenarios: TI zones Description Switch A Swi tch B Expected results Switch A does not h av e T raffic Isolation (TI) zones . Switch B has TI zones. defined: cfg1 effectiv e: cfg1 defined: cf g1 TI_zone 1 effective: cfg1 Clean merge.
342 Fabric OS A dministr ator’s Guide 53-1002745-02 Concurrent zone transactions 11 NOTE When merging mixed v e rsions of F abric OS where bo th side s hav e default zone mode No A ccess set , the merge results vary depending on which switch initiates the merge.
Fabric OS Administrator ’s Guide 343 53-1002745-02 Concurrent zone transactions 11 u30:FID128:admin> cfgsave You are about to save the Defined zoning configuration. This action will only save the changes on Defined configuration. Multiple open transactions are pending in this fabric.
344 Fabric OS A dministr ator’s Guide 53-1002745-02 Concurrent zone transactions 11.
Fabric OS Administrator ’s Guide 345 53-1002745-02 Chapter 12 Traffic Isolation Zoning In this chapter • T raffic Isolation Zoning ov er view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 345 • Enhanced TI zones . . . . . . .
346 Fabric OS A dministr ator’s Guide 53-1002745-02 Traffic Isolation Zoning overview 12 Figure 3 1 shows a fabric with a TI zone consisting of the follo wing: • N_Ports: “1,7”, “1,8”, “.
Fabric OS Administrator ’s Guide 347 53-1002745-02 Traffic Isolation Zoning overview 12 For ex a mp l e , in Figure 3 1 on page 346, if the dedicated ISL be tween Domain 1 and Domain 3 goes of fline.
348 Fabric OS A dministr ator’s Guide 53-1002745-02 Traffic Isolation Zoning overview 12 • Ensure that there are multiple paths be tween switches. Disabling failo ver locks the specified r oute so that only TI zone traffic can use it. Non-TI zone traf fic is excluded fr om using the dedicated path.
Fabric OS Administrator ’s Guide 349 53-1002745-02 Traffic Isolation Zoning overview 12 FSPF routing rules and traffic isolation All traffic must use the lowest cost path. FSPF r out ing rules take pr ecedence o ver the TI zones, as described in th e follo wing situations.
350 Fabric OS A dministr ator’s Guide 53-1002745-02 Enhanced TI zones 12 FIGURE 34 Dedicated path is not the sh or test path NOTE For inf ormat ion about setting or displaying the FSPF cost of a path, see the linkCost and top olo gy Sh ow commands in the F abric OS Command Reference .
Fabric OS Administrator ’s Guide 351 53-1002745-02 Enhanced TI zones 12 Illegal configurations with enhanced TI zones When you creat e TI zones, ensure that all traffi c fr om a port to all destinations on a remote domain ha ve the same path. Do no t create separate paths from a local por t to tw o or more ports on the same remot e domain.
352 Fabric OS A dministr ator’s Guide 53-1002745-02 Traffic Isolation Zoning over FC routers 12 In this example traffic from the T arget to Domain 2 is routed c orrectly . Only one TI zone describes a path to Domain 2. Howe ver , bo th TI zones describe differ ent, valid paths fr om the T arget to Domain 1.
Fabric OS Administrator ’s Guide 353 53-1002745-02 Traffic Isolation Zoning over FC routers 12 FIGURE 38 Traff ic Isolation Zoning over FCR In addition to setting up TI zones , you must also ensure that the devices are in an LSAN zone so that they can communicat e with each other .
354 Fabric OS A dministr ator’s Guide 53-1002745-02 Traffic Isolation Zoning over FC routers 12 TI zones within an edge fabric A TI zone within an edge fabric is used to r out e traffic between a real de vice and a proxy device through a par ticular EX_Port.
Fabric OS Administrator ’s Guide 355 53-1002745-02 Traffic Isolation Zoning over FC routers 12 TI zones within a backbone fabric A TI zone within a backbone fabric is used to r oute traffic within the b ackbone fabric through a par ticular ISL.
356 Fabric OS A dministr ator’s Guide 53-1002745-02 General rules for TI zones 12 Limitations of TI zones over FC routers Be aw are of the f ollowing when configuring TI zones o ver FC r outers: • A TI zone defined within the backbone fabric do es not guarant ee that edge fabric traffic will arrive at a particu lar EX_Port.
Fabric OS Administrator ’s Guide 357 53-1002745-02 General rules for TI zones 12 For ex a mp l e , in Figure 4 1 , th e TI zone was confi gured incorrectly and E_Por t “3,9” was errone ously omitted fr om the zone.
358 Fabric OS A dministr ator’s Guide 53-1002745-02 Supported configurations for Traffic Isolation Zoning 12 E-Port Trunks Trunk members in TI zone: 8 Trunk members not in TI zone: 9 10 E-Port Trunk.
Fabric OS Administrator ’s Guide 359 53-1002745-02 Limitations and restrict ions of Traffic Isolation Zoning 12 Trunking with TI zones If you implement trunking and TI z ones, you should k eep the following points in mind: • T o include a trunk group in a TI zone, you must include all por ts of the trunk in the TI zone.
360 Fabric OS A dministr ator’s Guide 53-1002745-02 Admin Domain considerations for Traffic Isolation Zoning 12 • T o include a trunk group in a TI zone, you must include all por ts of the trunk in the TI zone.
Fabric OS Administrator ’s Guide 361 53-1002745-02 Virtual Fabrics considerat ions for Traffic Isolation Zoning 12 Virtual Fabrics considerations for Traffic Isolation Zoning This section describes how TI zones work with Vir tual Fabrics.
362 Fabric OS A dministr ator’s Guide 53-1002745-02 Virtual Fabrics considerations for Traffic Is olation Zoning 12 FIGURE 43 Creating a TI zone in a logical fabric Y ou must also create and ac tivat e a TI zone in the base fabric to reserve the XISLs f or the dedicated path.
Fabric OS Administrator ’s Guide 363 53-1002745-02 Traffic Isolation Zoning over FC routers with Virtual Fabrics 12 Traffic Isolation Zoning over FC routers with Virtual Fabrics This section describes how you can set u p TI zones over FC rout er s in logical fab rics.
364 Fabric OS A dministr ator’s Guide 53-1002745-02 Creating a TI zone 12 Creating a TI zone Y ou create and modify T I zones using the zone command. Other zoning commands, such as zoneCrea te , aliCreat e , and cfgCreate , cannot be used to manag e TI zones.
Fabric OS Administrator ’s Guide 365 53-1002745-02 Creating a TI zone 12 Example TI zone creation The follo wing examples creat e a TI zone named “bluezone”, which contains E_Ports 1, 1 and 2,4 and N_Port s 1,8 and 2,6.
366 Fabric OS A dministr ator’s Guide 53-1002745-02 Creating a TI zone 12 Creating a TI zone in a base fabric 1. Connect to the switch and log in us ing an account with admin permissions. 2. Create a “dummy” zone configuration in the base fabric.
Fabric OS Administrator ’s Guide 367 53-1002745-02 Modifying TI zones 12 Modifying TI zones Using the zone -- add command, y ou can add ports to an e xisting TI zone, change the failo ver option, or bo th.Y ou can also activ ate o r deactivat e the TI zone.
368 Fabric OS A dministr ator’s Guide 53-1002745-02 Changing the state of a TI zone 12 Example of modifying a TI zone T o add port members to the existing TI zone bluezone: switch:admin> zone --a.
Fabric OS Administrator ’s Guide 369 53-1002745-02 Deleting a TI zone 12 Deleting a TI zone Use the zone -- delet e command t o delet e a TI zone fr om the defined configuration.
370 Fabric OS A dministr ator’s Guide 53-1002745-02 Troubleshooting TI zone routing problems 12 Example displaying information about all TI zones in the defined conf iguration in ascendi ng order sw.
Fabric OS Administrator ’s Guide 371 53-1002745-02 Setting up TI over FCR (sample proce dure) 12 Setting up TI over FCR (sample procedure) The f ollowing e xample shows how to se t up TI zones ov er FCR to pr ovide a dedicat ed path shown in Figure 4 7 .
372 Fabric OS A dministr ator’s Guide 53-1002745-02 Setting up TI over FCR (sample procedure) 12 The Fabric has 3 switches b. Enter the follo wing commands to create and displa y a TI zone: E1switch.
Fabric OS Administrator ’s Guide 373 53-1002745-02 Setting up TI over FCR (sample proce dure) 12 c. E nte r t he fo llo wi ng co mm and s to re ac ti vate your current ef fective configuration and enfor ce the TI zones.
374 Fabric OS A dministr ator’s Guide 53-1002745-02 Setting up TI over FCR (sample procedure) 12.
Fabric OS Administrator ’s Guide 375 53-1002745-02 Chapter 13 Bottleneck Detection In this chapter • Bottleneck det ection overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 75 • Suppor ted configurations f or bottleneck dete ct ion .
376 Fabric OS A dministr ator’s Guide 53-1002745-02 Bottleneck detection overview 13 • If the bottleneck det ection feature det ects ISL co ngestion, you can use ingress rat e limiti ng to slow down lo w priority application traf fic, if it is contribu ting to the congestion.
Fabric OS Administrator ’s Guide 377 53-1002745-02 Supported configurations for bottleneck detection 13 Y ou can use the bot tleneckMon command to speci fy aler ting paramet ers for the fol lowing: .
378 Fabric OS A dministr ator’s Guide 53-1002745-02 Supported configurations for bottleneck detection 13 High availability consideratio ns for bottleneck detection The bottleneck detection configuration is ma intained across a failo ver or reboot; how ev er , bottleneck statis tics collected are lost .
Fabric OS Administrator ’s Guide 379 53-1002745-02 Credit Loss 13 Credit Loss Fabric OS v7 . 1 and later support s back-end credit lo ss det ection back-end por ts and core blades as well as on the Br ocade 5300 and 6520 switches, alth ough the support is slightly dif ferent on each devic e.
380 Fabric OS A dministr ator’s Guide 53-1002745-02 Enabling bottleneck detecti on on a switch 13 The f ollowing credit loss reco ver y methods are supported for Brocade 6 520 back-end por ts: • For all the credit loss me thods described abo ve, a link reset will automatically be per formed, assuming that this option was enabled.
Fabric OS Administrator ’s Guide 381 53-1002745-02 Displaying bottleneck detec tion configuration details 13 3. Repeat step 1 and step 2 on every sw itch in the fabric. NOTE Best practice is t o use the default v alues f o r the aler ting and sub-seco nd latency criterion parameters.
382 Fabric OS A dministr ator’s Guide 53-1002745-02 Setting bottleneck detection alerts 13 Switch-wide sub-second latency bottleneck criterion: ==================================================== Time threshold - 0.
Fabric OS Administrator ’s Guide 383 53-1002745-02 Setting bottleneck detection alerts 13 FIGURE 48 Af fe cted seconds for bottleneck d etection The -time parameter specifies the time window.
384 Fabric OS A dministr ator’s Guide 53-1002745-02 Changing bottleneck dete ction parameters 13 Setting a congestion alert only This exam ple enables a congesti on aler t and shows its values.
Fabric OS Administrator ’s Guide 385 53-1002745-02 Changing bottleneck dete ction parameters 13 NOTE Entering a -- c o n f i g command changes only those settings spec if ied in the com mand; all others are lef t alone. The only e xceptions are for the -aler t (restores aler ts using recorded v alues) or -noaler t (disables all aler ts) switches.
386 Fabric OS A dministr ator’s Guide 53-1002745-02 Changing bottleneck dete ction parameters 13 Switch-wide sub-second latency bottleneck criterion: ==================================================== Time threshold - 0.800 Severity threshold - 50.
Fabric OS Administrator ’s Guide 387 53-1002745-02 Changing bottleneck dete ction parameters 13 Congestion threshold for alert - 0.700 Averaging time for alert - 200 seconds Quiet time for alert - 1.
388 Fabric OS A dministr ator’s Guide 53-1002745-02 Advanced bottleneck detection settings 13 Switch-wide alerting parameters: ================================ Alerts - Yes Latency threshold for alert - 0.
Fabric OS Administrator ’s Guide 389 53-1002745-02 Excluding a port from bottleneck detection 13 • Y ou want great er-than-default (sub-second) latency sensitivity on your fabric, so you set sub-second latency crit erion parameters at the time y ou enable bottleneck det ection.
390 Fabric OS A dministr ator’s Guide 53-1002745-02 Excluding a port from bottleneck detection 13 For trunking, if you e xclude a sla ve por t from bo tt leneck det ect ion, the ex clusion has no effect as long as the por t is a trunk slav e. The exclusion ta kes effect only if the port becomes a trunk m aster or lea ves the trunk.
Fabric OS Administrator ’s Guide 391 53-1002745-02 Displaying bottleneck statistics 13 Switch-wide sub-second latency bottleneck criterion: ==================================================== Time threshold - 0.
392 Fabric OS A dministr ator’s Guide 53-1002745-02 Disabling bottleneck detection on a switch 13 Disabling bottleneck detection on a switch When you disable bo ttleneck detection on a sw itch, all bottleneck co nfiguration details are discarded, including the list of ex cluded por ts and non-def ault values of alerting parameters.
Fabric OS Administrator ’s Guide 393 53-1002745-02 Chapter 14 In-flight Encryption and Compression In this chapter • In-flight encryption and compression ov erview . . . . . . . . . . . . . . . . . . . . . . 393 • Configuring encryption and compression .
394 Fabric OS A dministr ator’s Guide 53-1002745-02 In-flight en cryption and compre ssion overview 14 FIGURE 49 Encr yption and compressio n on 1 6 Gbps ISLs The encr yption and compression feat ures are designed t o work only with E_P or ts, EX_Por ts, and XISL por ts (in VF mode).
Fabric OS Administrator ’s Guide 395 53-1002745-02 In-flight encryption and compression overview 14 Bandwidth limits Fabric OS support s up to 32 Gbps of data en cr yption and 32 Gbps of data compression per 1 6G-capable FC platf orm. This limi ts the numbe r of por ts that can hav e these f eatures enabled at any one time.
396 Fabric OS A dministr ator’s Guide 53-1002745-02 In-flight en cryption and compre ssion overview 14 The por t level authentication security feature must be enabled before encr yption configuration can be enabled. Pre-shared secret ke ys should be co nfig ured on both ends of the ISL t o per for m authentication.
Fabric OS Administrator ’s Guide 397 53-1002745-02 In-flight encryption and compression overview 14 1 N oN oN o N o 2 N oN oN o N o 3 N oN oN o N o 4 N oN oN o N o 5 N oN oN o N o 6 N oN oN o N o 7 .
398 Fabric OS A dministr ator’s Guide 53-1002745-02 In-flight en cryption and compre ssion overview 14 portHealth: No Fabric Watch License Authentication: None portDisableReason: None portCFlags: 0x1 portFlags: 0x10000103 PRESENT ACTIVE E_PORT T_PORT T_MASTER G_PORT U_PORT ENCRYPT LOGIN LocalSwcFlags: 0x0 portType: 24.
Fabric OS Administrator ’s Guide 399 53-1002745-02 Configuring encryption and compression 14 Virtual Fabrics considerations The E_Ports and EX_Por ts in the user-c reated logi cal switch, base switch, or default switch; and EX_Ports on base switches can suppor t encr ypti on a nd compression.
400 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuring encryption and compression 14 Notes • If you ne ed to disable authentication on a por t that has encryption or compression c onfigured, you must first disable encr yption or compression on the port, and then disable authentication.
Fabric OS Administrator ’s Guide 401 53-1002745-02 Configuring encryption and compression 14 Viewing the encryption and compression configuration T o det ermine which por ts are av ailable for encrypti on or compression on each ASIC on the switch, follo w these steps: 1.
402 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuring encryption and compression 14 Changing port speed on encrypti on/compression enabled ports The por t speed values can be displa y ed through sev eral commands, including portStatsShow , por tEncCompShow , and por tCfgSpeed .
Fabric OS Administrator ’s Guide 403 53-1002745-02 Configuring encryption and compression 14 • Because enc r yption adds mo re payload to th e port in addition to compressio n, the compression ratio calculation is significantly af fected on ports con figured for both encryption and compression.
404 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuring encryption and compression 14 For additional inf ormation abou t configuring DH-C HAP authentication for E_Po r ts and EX_Por ts, see “ Authentication policy for fabric elements” on page 20 7.
Fabric OS Administrator ’s Guide 405 53-1002745-02 Configuring encryption and compression 14 4. Ena ble the por t with the por tEnable command. Af ter enabling the port, the new configu ration becomes active. Disabling encryption T o disable encryption on a por t, follo w these st eps: 1.
406 Fabric OS A dministr ator’s Guide 53-1002745-02 Encryption and compression examples 14 Encryption and compression examples The follo wing exam ples show configuring and enabli ng encryption and compression.
Fabric OS Administrator ’s Guide 407 53-1002745-02 Encryption and compression examples 14 Example of enabling encryption and compression on an E_Port This exam ple configures and enables encryption and compression on a giv en por t. The commands in this exam ple are shown e ntered on the Br ocade 65 10 name d ‘myswitch’.
408 Fabric OS A dministr ator’s Guide 53-1002745-02 Encryption and compression examples 14 Are you done? (yes, y, no, n): [no] y Saving data to key store.
Fabric OS Administrator ’s Guide 409 53-1002745-02 Encryption and compression examples 14 Rate Limit OFF EX Port OFF Mirror Port OFF Credit Recovery ON F_Port Buffers OFF Fault Delay: 0(R_A_TOV) NPI.
410 Fabric OS A dministr ator’s Guide 53-1002745-02 Encryption and compression examples 14 Examples of disabling encryption and compression This example disables the encryp tion and compression that were enabled in the previous e xample.
Fabric OS Administrator ’s Guide 411 53-1002745-02 Working with EX_Por ts 14 Working with EX_Ports An EX_Port is a type of E_Por t (expansion por t ) that connects a Fibre Channel r outer t o an edge fabric.
412 Fabric OS A dministr ator’s Guide 53-1002745-02 Working with EX_Ports 14 NOTE If trunking is enabled, be aw are that the por t s creating th e bandwidth limitation will f orm a trunk group, while the rest of the ports will be segmented.
Fabric OS Administrator ’s Guide 413 53-1002745-02 Working with EX_Por ts 14 This command is used to set up secret keys for the DH-CHAP authentication. The minimum length of a secret key is 8 characters and maximum 40 characters. Setting up secret keys does not initiate DH-CHAP authentication.
414 Fabric OS A dministr ator’s Guide 53-1002745-02 Working with EX_Ports 14 QOS Port AE Port Auto Disable: OFF Rate Limit OFF EX Port ON Mirror Port OFF Credit Recovery ON F_Port Buffers OFF Fault .
Fabric OS Administrator ’s Guide 415 53-1002745-02 Working with EX_Por ts 14 FCR:admin> portcfgexport 1 Port 1 info Admin: enabled State: OK Pid format: core(N) Operate mode: Brocade Native Edge .
416 Fabric OS A dministr ator’s Guide 53-1002745-02 Working with EX_Ports 14 characters. Setting up secret keys does not initiate DH-CHAP authentication. If switch is configured to do DH-CHAP, it is performed whenever a port or a switch is enabled. Warning: Please use a secure channel for setting secrets.
Fabric OS Administrator ’s Guide 417 53-1002745-02 Working with EX_Por ts 14 NPIV PP Limit: 126 CSCTL mode: OFF D-Port mode: OFF Compression: OFF Encryption: ON FEC: ON Example Enabli ng compression on the same port. The por tCfgShow command shows that both e ncr yption and compression are now enabled on this por t.
418 Fabric OS A dministr ator’s Guide 53-1002745-02 Working with EX_Ports 14 EX_Port commands See the F abric OS Command Refe rence f or more details on these EX_Po r t -valid commands.
Fabric OS Administrator ’s Guide 419 53-1002745-02 Chapter 15 NPIV In this chapter • NPIV ov er view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4 1 9 • Configuring NPIV . . . . . . . . . . . .
420 Fabric OS A dministr ator’s Guide 53-1002745-02 NPIV overview 15 Index Port Address Media Speed State Proto ============================================== 0 0 010000 id N4 Online FC F-Port 20:0c.
Fabric OS Administrator ’s Guide 421 53-1002745-02 Configuring NPIV 15 Configuring NPIV The NPIV f eature is enabled by default. Y ou can set the number of virtual N_Por t_IDs per por t to a value fr om 1 throug h 255 per por t. The default setting is 126.
422 Fabric OS A dministr ator’s Guide 53-1002745-02 Enabling and disab ling NPIV 15 VC Link Init OFF Locked L_Port OFF Locked G_Port OFF Disabled E_Port OFF Locked E_Port OFF ISL R_RDY Mode OFF RSCN.
Fabric OS Administrator ’s Guide 423 53-1002745-02 Viewing NPIV port con figuration information 15 Viewing NPIV port configuration information 1. Connect to the switch and log in using an account assigned to the admin r ole. 2. Enter the por tCfgShow command to vie w the switch por ts information.
424 Fabric OS A dministr ator’s Guide 53-1002745-02 Viewing NPIV port configuration information 15 switch:admin> portshow 2 portName: 02 portHealth: HEALTHY Authentication: None portDisableReason: None portCFlags: 0x1 portFlags: 0x24b03 PRESENT ACTIVE F_PORT G_PORT NPIV LOGICAL_ONLINE LOGIN NOELP LED ACCEPT portType: 10.
Fabric OS Administrator ’s Guide 425 53-1002745-02 Chapter 16 Dynamic Fabric Provisioning: Fabric-Assigned PWWN In this chapter • Introduction to Dynamic F abric Pro visioni ng using F A -P WWN . . . . . . . . . . 425 • User- and auto-assigned F A -PWWN behavior .
426 Fabric OS A dministr ator’s Guide 53-1002745-02 User- and auto-assigned FA-PWWN behavior 16 NOTE For the server to use the F A -PWWN feature , it must be using a Broc ade HBA or adapter . R efe r to the release note s f or the HBA or adapter v ersions that suppor t this feature.
Fabric OS Administrator ’s Guide 427 53-1002745-02 Configuring FA-PWWNs 16 This section includes an F A-PWWN configuration pr ocedure for each of the f ollowing two topologies: • An F A -PWWN f or an HBA de vice that is connect ed to an Acce ss Gate way switch.
428 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuring FA-PWWNs 16 3. Enter the fapwwn -- show -ag all command: Y ou should see ou tput similar to the following sample. (In this example, long lines of output are shown split acr oss two lines, f or bet ter readability .
Fabric OS Administrator ’s Guide 429 53-1002745-02 Supported switches and configurations for FA-PW WN 16 3. Enter the fapwwn -- show -por t all command: Y ou should see output simi lar to the f ollowing sample.
430 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuration uplo ad and download considerations for FA-PWWN 16 • Access Gat ewa y platforms running F abric OS v7 .0.0 or later: - Brocade 300 - Brocade 5 1 00 - Br ocade 6505 - Brocade 65 10 • Brocade HBAs with driver version 3.
Fabric OS Administrator ’s Guide 431 53-1002745-02 Restrictions of FA-PWWN 16 NOTE When creating the DCC policy , use the ph ysical de vice WWN and not the F A-PWWN. If you use DCC, a policy check is do ne on the physic al PWWN on the ser vers. In the case of an HBA, the F A -PWWN is assigned to the HBA only af ter the DCC check is successful.
432 Fabric OS A dministr ator’s Guide 53-1002745-02 Access Gateway N_Port failover with FA-PWWN 16.
Fabric OS Administrator ’s Guide 433 53-1002745-02 Chapter 17 Managing Administrative Domains In this chapter • Administrativ e Domains ov er view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 433 • Admin Domai n management f or physical f a bric administrators .
434 Fabric OS A dministr ator’s Guide 53-1002745-02 Administrative Dom ains overview 17 NOTE Do not confuse an Admin Domain number with the domain ID of a switch. T hey are two different identifiers. The Admin Domain number identifies the Admin Domain and has a range from 0 through 255.
Fabric OS Administrator ’s Guide 435 53-1002745-02 Administrative Domai ns overview 17 Admin Domain features Admin Domains allow y ou to do the f ollowing: • Define the scope of an Admin Domain t o enco mpass ports and devices within a switch or a fab ric .
436 Fabric OS A dministr ator’s Guide 53-1002745-02 Administrative Dom ains overview 17 Ta b l e 6 5 lists each Admin Domain user type and describes its administ rative access and capabilities. User-defined Admin Domains AD1 through AD2 54 are user -defined Admin Do ma ins.
Fabric OS Administrator ’s Guide 437 53-1002745-02 Administrative Domai ns overview 17 For e xample, if De viceA is not a member of an y user -defined Admin Domain, then it is an implicit member of AD0. If you e xplicitly add Devic eA to AD0, then De viceA is both an implicit and an explicit member of AD0.
438 Fabric OS A dministr ator’s Guide 53-1002745-02 Administrative Dom ains overview 17 FIGURE 54 Fabric with AD0 and AD255 Home Admin Domains and login Y ou are alwa ys logged in to an Admin Domain, and yo u can vie w and modify only the de vices in that Admin Do main.
Fabric OS Administrator ’s Guide 439 53-1002745-02 Administrative Domai ns overview 17 • For user -defined accounts, the ho me Admin Domain defaults to AD0 but an administrator can set the home Admin Domain to an y Admin Domain to which the account is giv en access.
440 Fabric OS A dministr ator’s Guide 53-1002745-02 Administrative Dom ains overview 17 If a de vice is a member of an Admin D omain, th e switch port to which the de vice is connected becomes an indi rect member of that A dmin Domain and the domain,index is removed fr om the AD0 implicit membership list.
Fabric OS Administrator ’s Guide 441 53-1002745-02 Administrative Domai ns overview 17 Figure 55 on page 44 1 shows an unfilt ered view of a fa bric with tw o switches, three de vices, and two Admin Domains. The de vices are labeled with device WWNs and the switches are labeled with domain IDs and sw itch WWNs.
442 Fabric OS A dministr ator’s Guide 53-1002745-02 Admin Domain managem ent for physical fabric admini strators 17 Admin Domain compatibility, availability, and merging Admin Domains maintain continuity of ser vice for F abric OS features and operat e in mixed-re lease Fabric OS en vironments.
Fabric OS Administrator ’s Guide 443 53-1002745-02 Admin Domain m anagement for physical fabric administrato rs 17 Setting the default zoning mode for Admin Domains T o begin implementing an Admin Domain structure within your SAN, y ou must first set the default zoning mode t o No Access.
444 Fabric OS A dministr ator’s Guide 53-1002745-02 Admin Domain managem ent for physical fabric admini strators 17 ad --select 255 5. Enter the ad -- create command using the -d optio n to specify .
Fabric OS Administrator ’s Guide 445 53-1002745-02 Admin Domain m anagement for physical fabric administrato rs 17 Creating a new user account for managing Admin Domains 1. Connect to the switch and log in us ing an account with admin permissions. 2.
446 Fabric OS A dministr ator’s Guide 53-1002745-02 Admin Domain managem ent for physical fabric admini strators 17 Removing an Admin Domain from a user account When you remo ve an Admin Domain fr om an account, all of the currently active sessions for that account are logged out.
Fabric OS Administrator ’s Guide 447 53-1002745-02 Admin Domain m anagement for physical fabric administrato rs 17 Deactivating an Admin Domain If you d eactivat e an Admin Domain, the members assigned t o the Admin Domain c an no longer access their hosts or s torage unless those members are par t of another A dmin Domain.
448 Fabric OS A dministr ator’s Guide 53-1002745-02 Admin Domain managem ent for physical fabric admini strators 17 • T o sa ve the Admin Domain definition, ent er ad -- sav e . • T o sav e the Admin Domain definit ion and directly apply the definit ion to the fabric, enter ad -- apply .
Fabric OS Administrator ’s Guide 449 53-1002745-02 Admin Domain m anagement for physical fabric administrato rs 17 4. Enter the appropriate command based o n whether you want to sa ve or activat e the Admin Domain definition: • T o sa ve the Admin Domain definition, ent er ad -- sav e .
450 Fabric OS A dministr ator’s Guide 53-1002745-02 Admin Domain managem ent for physical fabric admini strators 17 Deleting all user-defined Admin Domains When you clear the A dmin Domain configura.
Fabric OS Administrator ’s Guide 451 53-1002745-02 Admin Domain m anagement for physical fabric administrato rs 17 3. Enter the zone -- copy command to cop y the zones from all user -defined Admin Domains to AD0.
452 Fabric OS A dministr ator’s Guide 53-1002745-02 Admin Domain managem ent for physical fabric admini strators 17 FIGURE 5 7 AD0 and tw o user-def ined Admin Doma ins, AD1 and A D2 At the conc lusion of the pr ocedure, all de vices and zones are mov e d to AD0, and the user -defined Admin Domains are delet ed, as shown in Figure 58 .
Fabric OS Administrator ’s Guide 453 53-1002745-02 Admin Domain m anagement for physical fabric administrato rs 17 10:00:00:00:02:00:00:00; 10:00:00:00:03:00:00:00 Effective configuration: cfg: AD1_.
454 Fabric OS A dministr ator’s Guide 53-1002745-02 SAN management with Admin Domains 17 Validating an Admin Domain member list Y ou can validat e the device and switch member li st. Y ou can list non-existing or offline Admin Domain memb ers. Y ou can also identify mis configurations of t he Admin Domain.
Fabric OS Administrator ’s Guide 455 53-1002745-02 SAN management with Adm in Domains 17 CLI commands in an AD context The CLI command input arguments are validat ed agains t the AD member list; they do not w ork with input argument s that specif y resour ces that are no t members of the current Admin Domain.
456 Fabric OS A dministr ator’s Guide 53-1002745-02 SAN management with Admin Domains 17 Displaying an Admin Domain configuration Y ou can displa y the membership information and zo ne database info rmation of a specified Admin Domain.
Fabric OS Administrator ’s Guide 457 53-1002745-02 SAN management with Adm in Domains 17 Y ou can not sw itc h to an othe r Admi n Do mai n conte x t from within the shell creat ed by ad -- select . Y ou must first exit the shell, and then issue the ad -- select command again.
458 Fabric OS A dministr ator’s Guide 53-1002745-02 SAN management with Admin Domains 17 Admin Domains, zones, and zone databases Admin Domains introduce two types of zone database nomenclature and behavior: • Roo t z o n e d a ta b as e If you do no t use Admin Domains, there is only one zone database.
Fabric OS Administrator ’s Guide 459 53-1002745-02 SAN management with Adm in Domains 17 The AD zone databas e also ha s the follo wing characteristics: - Each zone database has its own name spa ce. F or example, y ou can define a zone name of test_z1 in more than one Admin Domain.
460 Fabric OS A dministr ator’s Guide 53-1002745-02 SAN management with Admin Domains 17 LSAN zone names in AD0 are ne ver con ver ted f or backward-compatibility reasons. The auto-con verted LSAN zone name s might collide with LSAN zone names in AD0 (in the exam ple, if AD0 contains lsan_for_linux_farm_AD005, this causes a name collision).
Fabric OS Administrator ’s Guide 461 53-1002745-02 Section II Licensed Features This section describes optionally licensed Broca de Fabric OS features and in cludes t he following chapters: • Chap.
462 Fabric OS A dministr ator’s Guide 53-1002745-02.
Fabric OS Administrator ’s Guide 463 53-1002745-02 Chapter 18 Administering Licensing In this chapter • Licensing ov er view. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 463 • Brocade 7800 Upgrade license .
464 Fabric OS A dministr ator’s Guide 53-1002745-02 Licensing overview 18 Ta b l e 6 9 lis ts the optionally licensed features that are a vailable in Fabric OS 7 .
Fabric OS Administrator ’s Guide 465 53-1002745-02 Licensing overview 18 Advanced FICON Acceleration • Allows use of specializ ed data management t echniques and au tom a ted i nte ll ig e nc e to.
466 Fabric OS A dministr ator’s Guide 53-1002745-02 Licensing overview 18 Enterprise ICL Allows you to connect more than four chassis in a fabric using ICLs.
Fabric OS Administrator ’s Guide 467 53-1002745-02 Licensing overview 18 Ta b l e 7 0 lists licensed features, each f eature’s associ ated license name, and, if applicable, the location on the lo cal or any connecting swit ch on which the license must be installed.
468 Fabric OS A dministr ator’s Guide 53-1002745-02 Licensing overview 18 FCIP High Performance Extensio n ov er FCIP/FC NOTE: Local an d attached switches. License is needed on both s ides of tunnel. FCIP T runking Adv anced Extension Local and attached switches.
Fabric OS Administrator ’s Guide 469 53-1002745-02 Licensing overview 18 Logical switch No license required. N/A Long distance Extended Fabrics Local and attached switches. NO TE: License is needed on both sides of connection. NPIV No license require d.
470 Fabric OS A dministr ator’s Guide 53-1002745-02 Brocade 7800 Upgrade license 18 Brocade 7800 Upgrade license The Bro cade 7800 has f our Fibre Channel (FC) por ts and two GbE ports active by default. The number of physical por ts active on the Br ocade 7800 is fix ed.
Fabric OS Administrator ’s Guide 471 53-1002745-02 ICL licensing 18 ICL licensing Brocade ICL links operat e between the core blades of the DCX 85 10 Backbone f amily , or between th e c o r e b l a d e s o f t h e DC X a n d DC X - 4 S B a c k b on e s .
472 Fabric OS A dministr ator’s Guide 53-1002745-02 ICL licens ing 18 ICL 8-link license The ICL 8-link license activates half of the ICL bandwidth f or ea ch ICL port on the Brocade DCX platform b y enabling only half of the ICL links available.
Fabric OS Administrator ’s Guide 473 53-1002745-02 8G licensing 18 Example switchShow output if no En terprise ICL license is installed A message such as the following is displa yed if a required EI.
474 Fabric OS A dministr ator’s Guide 53-1002745-02 Slot-based licensing 18 Slot-based licensing Slot-based licensing is used on th e Brocade DCX and DCX 85 10 Backbone fa milies to support the FX8-2 4 blade, and on the Brocade DCX 85 1 0 Back bone family t o suppor t the 1 6 Gbps FC port blades (FC1 6-2 4 and FC1 6-48).
Fabric OS Administrator ’s Guide 475 53-1002745-02 10G licen sing 18 Assigning a license to a slot Use the f ollowing pr ocedure to assign a licence t o a slot: 1. Co nnect to the switch and log in using an acc o unt with admin permissions, or an account with OM permissions in the licens e class of RBA C commands.
476 Fabric OS A dministr ator’s Guide 53-1002745-02 10G licen sing 18 Af ter applying a 1 0 G license to the Brocade 65 10or 6520 chassis or t o a 16 Gbps FC blade, you must also configur e the por .
Fabric OS Administrator ’s Guide 477 53-1002745-02 10G licen sing 18 aTFPNFXGLmABANMGtT4LfSBJSDLWTYD3EFrr4WGAEMBA 10 Gigabit FCIP/Fibre Channel (FTR_10G) license Capacity 1 Consumed 1 Configured Bla.
478 Fabric OS A dministr ator’s Guide 53-1002745-02 Temporary licenses 18 aTFPNFXGLmABANMGtT4LfSBJSDLWTYD3EFrr4WGAEMBA 10 Gigabit FCIP/Fibre Channel (FTR_10G) license Capacity 1 Consumed 1 Configure.
Fabric OS Administrator ’s Guide 479 53-1002745-02 Temporary licenses 18 • FICON Management Ser ver (CUP) license • Extended F abrics license • High Performance Extension ov er FCIP/FC licen s.
480 Fabric OS A dministr ator’s Guide 53-1002745-02 Temporary licenses 18 Expired licenses Once a temporary license has expired, you can view it through the li censeShow command. Ex pired licenses ha ve an output string of “License ha s e x pired”.
Fabric OS Administrator ’s Guide 481 53-1002745-02 Viewing installed licenses 18 Viewing installed licenses Use the f ollowing pr ocedure to vie w all installed licenses: 1. Connect to the switch and log in us ing an account with admin permissions. 2.
482 Fabric OS A dministr ator’s Guide 53-1002745-02 Removing a licensed feature 18 Use the f ollowing pr ocedure to add a lic ensed f eature: 1. Connect to the switch and log in usin g an account with admin permissions. 2. Activate the license using the licenseA dd command.
Fabric OS Administrator ’s Guide 483 53-1002745-02 Ports on Demand 18 4. Enter the licenseShow command to v erify the license is disabled. switch:admin> licenseshow bQebzbRdScRfc0iK: Entry Fabric.
484 Fabric OS A dministr ator’s Guide 53-1002745-02 Ports on Demand 18 Ports on Demand is ready to be unlock ed in the swit ch firmware. Its licen se key ma y be par t of the licensed paperpack supplied with sw itch software, or y ou can purchase the license k ey separat ely from y our switch v endor .
Fabric OS Administrator ’s Guide 485 53-1002745-02 Ports on Demand 18 First Ports on Demand license - additional 16 port upgrade license SdSSc9SyRSTeXTdn: Second Ports on Demand license - additional.
486 Fabric OS A dministr ator’s Guide 53-1002745-02 Ports on Demand 18 For the embedded switch modules, the Dynamic PO D f eature detects and assigns ports to a POD license only if the ser ver blade is installed with an HBA present.
Fabric OS Administrator ’s Guide 487 53-1002745-02 Ports on Demand 18 switch:admin> licenseport --method dynamic The POD method has been changed to dynamic. Please reboot the switch now for this change to take effect. 3. Enter the reboot command t o restar t the switch.
488 Fabric OS A dministr ator’s Guide 53-1002745-02 Ports on Demand 18 Ports assigned to the full POD license: 0, 9, 10, 11, 12, 13, 14, 15, 16, 21, 22, 23 Reserving a port license Y ou can allo cate licenses by reser ving an d releas ing POD assignments to specific ports.
Fabric OS Administrator ’s Guide 489 53-1002745-02 Ports on Demand 18 Af ter a port is assigned to the POD set, the por t is li censed until it is ma nually remov ed from the POD por t set. When a port is released from its POD port set (Base, Single, or Double), it creat es a vacancy in that port set.
490 Fabric OS A dministr ator’s Guide 53-1002745-02 Ports on Demand 18.
Fabric OS Administrator ’s Guide 491 53-1002745-02 Chapter 19 Inter-chassis Links In this chapter • Inter -chassis links . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49 1 • ICLs f or the Broc ade DCX 85 1 0 Backbone family .
492 Fabric OS A dministr ator’s Guide 53-1002745-02 ICLs for the Brocade DCX 8510 Backbone family 19 NOTE Y ou cannot inter connect a Brocade DCX Backbone f amily chassis to a Br ocade DCX 85 10 Backbone fam il y ch as si s.
Fabric OS Administrator ’s Guide 493 53-1002745-02 ICLs for the Brocade DCX Backbone family 19 NOTE Brocade recommends that y o u ha ve a maximu m of eight ICLs connect ed to the same neighboring domain, with a maximum of four ICLs fr om each core blade.
494 Fabric OS A dministr ator’s Guide 53-1002745-02 Virtual Fabrics considerations for ICLs 19 FIGURE 60 DCX-4S allowed ICL connections The follo wing ICL connections are not allow ed: • ICL0 por .
Fabric OS Administrator ’s Guide 495 53-1002745-02 Supported topologies for ICL connections 19 Supported topologies for ICL connections Y ou can connect the Br ocade Backbones in a mesh topology and a core-edge t opology . A brief description of ea ch follows.
496 Fabric OS A dministr ator’s Guide 53-1002745-02 Supported topologies for ICL connections 19 FIGURE 62 Full nine-mesh topology During an ICL break in the triangular t opology , the chassis that has the connections of the other two is the main chassis.
Fabric OS Administrator ’s Guide 497 53-1002745-02 Supported topologies for ICL connections 19 FIGURE 63 64 Gbps ICL core-edge topology.
498 Fabric OS A dministr ator’s Guide 53-1002745-02 Supported topologies for ICL connections 19.
Fabric OS Administrator ’s Guide 499 53-1002745-02 Chapter 20 Monitoring Fabric Performance In this chapter • Advanced P er f ormance Monitoring ov erview . . . . . . . . . . . . . . . . . . . . . . . 499 • End-to-end per formance monit oring . .
500 Fabric OS A dministr ator’s Guide 53-1002745-02 Advanced Performance Monitoring overview 20 Restrictions for installing monitors • Advanced P er formance Monitoring is no t suppor ted on VE_Ports and EX_Por ts. If you issue commands f or any A dvanced P er f ormance Monit oring on VE_Ports or EX_Por ts, you will rece ive error messages.
Fabric OS Administrator ’s Guide 501 53-1002745-02 End-to-end performance monitoring 20 Access Gateway considerations for Advanced Performance Monitoring EE monitors and frame monit ors are suppor ted on switches in A ccess Gate way mode. T op T alker monitors are no t suppor t ed on these switches.
502 Fabric OS A dministr ator’s Guide 53-1002745-02 End-to-end performance monitoring 20 Virt ual F abrics consideration s: If Vir tual Fabrics is enabled, the Br ocade DCX, DCX-4 S, DCX 85 1 0 and 5300 models allo w up to 256 end-to- end moni tors on one logical switch.
Fabric OS Administrator ’s Guide 503 53-1002745-02 End-to-end performance monitoring 20 This monitor (Monitor 1) counts the frames that ha ve an SID of 0x0 11200 and a DID of 0x02 1e00. For Monit or 1, RX_COUNT is the number of wor ds from Host A to De v B, and TX_COUNT is the number of wo rds fr om Dev B t o Host A.
504 Fabric OS A dministr ator’s Guide 53-1002745-02 End-to-end performance monitoring 20 The per fSetPor tEEMask command sets a mask f or the domain ID, area ID, and AL_P A of the SIDs and DIDs f or frames transmitted from and received b y the por t.
Fabric OS Administrator ’s Guide 505 53-1002745-02 Frame monitoring 20 perfmonitorshow --class monitor_class [ slotnumber /] portnumber [ interval ] Example of displaying an end-to-end monitor on a .
506 Fabric OS A dministr ator’s Guide 53-1002745-02 Frame monitorin g 20 NOTE The Advanced Pe r formance Monitoring license is req uired to use the fmM onitor command.
Fabric OS Administrator ’s Guide 507 53-1002745-02 Frame monitoring 20 The value of the o f fset must be bet ween 0 and 63, in decimal format. Byte 0 indicates the fi rst byte of the Star t of F rame (SOF), byt e 4 is the first byte of the frame header , and byt e 28 is the first byte of the pa yload.
508 Fabric OS A dministr ator’s Guide 53-1002745-02 Frame monitorin g 20 Adding frame monitors to a port If the switch does not ha ve enough resour ces to ad d a frame monitor t o a port, then other frame monitors on that port may ha ve to be delet ed to free resour ces.
Fabric OS Administrator ’s Guide 509 53-1002745-02 Frame monitoring 20 Example The f ollowing e xample displays the e xisting frame types and associated bit patt erns on the switch.
510 Fabric OS A dministr ator’s Guide 53-1002745-02 Top Talker monitors 20 Top Talker monitors T op T alk er monitors det ermine the flows (SID and DID pairs) th at are the major users of bandwidth (after initial stabilization).
Fabric OS Administrator ’s Guide 511 53-1002745-02 Top Talker monitors 20 How do T op T alker monit ors dif fer fr om EE monitors? EE monitors pro vide counter statistics f or traf fic flowing be tween a giv e n SID and DID pair .
512 Fabric OS A dministr ator’s Guide 53-1002745-02 Top Talker monitors 20 FIGURE 66 Fabric mode Top T alker monit or s on FC r outer do not monitor any f low s FIGURE 67 Fabric mode Top T alker mon.
Fabric OS Administrator ’s Guide 513 53-1002745-02 Top Talker monitors 20 Adding a Top Talker monito r to a port (port mode) 1. Connect to the switch and log in us ing an account with admin permissions.
514 Fabric OS A dministr ator’s Guide 53-1002745-02 Top Talker monitors 20 The output is sorted based on the data rate of each flo w . If you do not specify the number of flows t o display , then the command displa ys the top 8 flows or the total number of flo ws, whichev er is less.
Fabric OS Administrator ’s Guide 515 53-1002745-02 Trunk monitoring 20 Deleting all fabric mode Top Talker monitors 1. Connect to the switch and log in us ing an account with admin permissions. 2. Enter the per fTTmon -- delete f abricmode command. perfttmon --delete fabricmode All T op T alk er monito rs are deleted.
516 Fabric OS A dministr ator’s Guide 53-1002745-02 Performance data collection 20 1. Connect to the switch and log in us ing an account with admin permissions.
Fabric OS Administrator ’s Guide 517 53-1002745-02 Chapter 21 Optimizing Fabric Behavior In this chapter • Adaptiv e Networking ov er view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 1 7 • Ingress Rate Limiting. . . .
518 Fabric OS A dministr ator’s Guide 53-1002745-02 Ingress Rate Limiting 21 • Ingress Rate Limiting Ingress Rate Limiting restricts the speed of traf fi c from a particular device to the switch por t. Ingress Rate Limiting req uires an Adap tiv e Netw orking license.
Fabric OS Administrator ’s Guide 519 53-1002745-02 QoS: SID/DID traffic prioritization 21 Virtual Fabrics considerations If Vir tual Fabrics is enabled, the rate limit configuration o n a por t is on a per -logical switc h basis.
520 Fabric OS A dministr ator’s Guide 53-1002745-02 QoS: SID/DID traffic prioritization 21 Ta b l e 76 sho ws a basic comparison between CS-CTL -based and QoS zone- based prioritization.
Fabric OS Administrator ’s Guide 521 53-1002745-02 CS_CTL-based frame prioritization 21 CS_CTL-based frame prioritization CS_CTL -based frame prioritization al lows you t o prioritize the frames betw een a host and target as having high, medium, or low priority , depending on the v alue of the CS_CTL field in the FC frame header .
522 Fabric OS A dministr ator’s Guide 53-1002745-02 CS_CTL-based frame prioritization 21 NOTE If a switch is running a firm ware version earl ier than Fabric OS v6.
Fabric OS Administrator ’s Guide 523 53-1002745-02 QoS zone-based traffic prioritization 21 Set CSCTL QoS Mode to 1 to enable aut o mode, establ ishing the set tings sho wn in Ta b l e 7 8 on page 52 1. Set CSCTL QoS Mode to 0 to disable aut o mode and rev er t t o default settings, sho wn in Ta b l e 7 7 on page 52 1.
524 Fabric OS A dministr ator’s Guide 53-1002745-02 QoS zone-based traffic prioritization 21 T o preserve existing trunk groups, bef ore you in stall the Adaptive Networking license, manually disable QoS on these po r ts, as described in “Manually disabling QoS on trunk ed por ts” on page 52 4.
Fabric OS Administrator ’s Guide 525 53-1002745-02 QoS zones 21 switch:admin> portcfgshow (output truncated) Ports of Slot 0 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 -----------------+---+.
526 Fabric OS A dministr ator’s Guide 53-1002745-02 QoS zones 21 The switch automatically sets the priority for the “host,target” pairs specified in the zones according to the priority lev el (H or L) in the zone name.
Fabric OS Administrator ’s Guide 527 53-1002745-02 QoS zones 21 NOTE By default, QoS is enabled on 8-Gbps ports, except for long-distance 8-Gbps ports.
528 Fabric OS A dministr ator’s Guide 53-1002745-02 QoS zones 21 The following are requirements fo r establishing QoS o ver FCRs: • QoS ov er FC routers is supported in Br ocad e nativ e mode only . It is not supported in inter opmode 2 or int eropmode 3.
Fabric OS Administrator ’s Guide 529 53-1002745-02 QoS zones 21 FIGURE 70 Traff ic prioritization in a logical fabric Supported configurations for QoS zone-based traffic prioritization The follo wing configuration rules apply to QoS zone-based traffic prioritization: • All switches in the fabric must be running Fabric OS v6.
530 Fabric OS A dministr ator’s Guide 53-1002745-02 Setting QoS zone-based traffic prioritization 21 • T raffic prioritization is enfor ced on the eg ress ports only, not on the ingress ports. • T raff ic prioritization is not suppor t ed on 10-Gbps ISLs.
Fabric OS Administrator ’s Guide 531 53-1002745-02 Setting QoS zone-based traffic prioritization 21 The por tCfgQos command does not affect QoS prioritization . I t only enables or disables the link to pass QoS priority traffic. NOTE QoS is enabled b y default on all ports (e x cept long-distance po r ts).
532 Fabric OS A dministr ator’s Guide 53-1002745-02 Setting QoS zone-based traffic pr ioritization over FC routers 21 Setting QoS zone-based traffic prioritization over FC routers 1. Connect to the switch in the edg e fabric and log in using an account with admin permissions.
Fabric OS Administrator ’s Guide 533 53-1002745-02 Chapter 22 Managing Trunking Connections In this chapter • T runking o ver view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 533 • Suppor ted configurations f or trunking .
534 Fabric OS A dministr ator’s Guide 53-1002745-02 Trunking overview 22 Types of trunking T runking can be betw een two switches, between a switch and an Access Gat ew ay module, or between a switch and a Brocade adapt er .
Fabric OS Administrator ’s Guide 535 53-1002745-02 Supported configurations for trunking 22 License requirements for trunking A l l t y p e s o f t r u n k i n g r e q u i r e t h e Tru n k i n g l i c e n s e . T h i s l i c e ns e m u s t b e i n s ta l l e d o n e a c h s w it c h t h a t par ticipates in trunking.
536 Fabric OS A dministr ator’s Guide 53-1002745-02 Supported platforms for trunking 22 T runks operat e best when the cable length of each trunk ed link is r oughly equal t o the length of the others in the trunk. For optimal performance, no more than 30 meters dif ference is rec ommended.
Fabric OS Administrator ’s Guide 537 53-1002745-02 Recommendations for trunk groups 22 Recommendations for trunk groups T o identify the most useful tr unk gr oups, consider the f ollowin g recommendations along with the standard guidelines f or SAN design: • Evaluate the traffic patterns within the fabric.
538 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuring trunk groups 22 Configuring trunk groups Af ter y ou install the T runking license, you must re -initialize the por ts that are to be used in trunk groups so that the y recognize that trunking is en abled.
Fabric OS Administrator ’s Guide 539 53-1002745-02 Displaying trunking information 22 1. Connect to the switch and log in using an account assigned to the admin r ole. 2. Enter the p ort Cf g T r un k P ort command to disable trunking on a por t. Enter the switchCfgT runk command t o disable trunking on all por ts on the switch.
540 Fabric OS A dministr ator’s Guide 53-1002745-02 Trunk Area and Admin Dom ains 22 Rx: Bandwidth 16.00Gbps, Throughput 1.67Gbps (12.12%) Tx+Rx: Bandwidth 32.00Gbps, Throughput 3.33Gbps (12.12%) 3: 10-> 10 10:00:00:05:1e:81:56:8b 1 deskew 15 MASTER 11-> 11 10:00:00:05:1e:81:56:8b 1 deskew 15 Tx: Bandwidth 4.
Fabric OS Administrator ’s Guide 541 53-1002745-02 EX_Port trunking 22 For additional inf ormation on configuring long dis tance, see “Configuring an e xtended ISL ” on page 553. Ta b l e 7 9 sum marizes suppor t for T runking o ver long -distance f or the Backbones and suppor ted blades.
542 Fabric OS A dministr ator’s Guide 53-1002745-02 EX_Port trunking 22 Masterless EX_Port trunking EX_Por t trunking is masterless ex cept for EX_Ports on Backbones . For the Backbones, Vir tual Fabrics must be enabled f or masterless EX_Port trunkin g to tak e ef fect.
Fabric OS Administrator ’s Guide 543 53-1002745-02 F_Port trunking 22 The following is an e xample of a master EX_Port and a slave EX _Port display ed in swi tchShow .
544 Fabric OS A dministr ator’s Guide 53-1002745-02 F_Port trunking 22 FIGURE 72 Switc h in Access Gateway mode wi thout F_Por t mas terless trunking FIGURE 73 Switc h in Access Gateway mode with F_.
Fabric OS Administrator ’s Guide 545 53-1002745-02 F_Port trunking 22 Use the f ollowing pr ocedure on the edge switch connected t o the Access Gate wa y module to configure F_Por t trunking. 1. Connect to the switch and log in using an account assigned to the admin r ole.
546 Fabric OS A dministr ator’s Guide 53-1002745-02 F_Port trunking 22 c. Ena ble the trunk on the por ts by using the por tT runkArea command. switch:admin> porttrunkarea --enable 3/40-41 -index 296 Trunk index 296 enabled for ports 3/40 and 3/41.
Fabric OS Administrator ’s Guide 547 53-1002745-02 F_Port trunking 22 DCC Policy DCC policy enfor cement fo r the F_Port trunk is based on the T runk Area; the FDISC re quests to a t r u n k p o r t a r e a c c e p t e d o n l y i f th e W W N o f t h e a t t a c h e d d ev i c e i s p a r t o f th e DC C p o l i c y against the T A.
548 Fabric OS A dministr ator’s Guide 53-1002745-02 F_Port trunking 22 Ta b l e 81 describes the PWWN f ormat for F_P or t and N_P or t trunk ports. F_Port trunking in Virtual Fabrics F_Por t trunking functionality per forms the same in Vir tual Fabrics as it does in non-Vir tual Fabric platf orms ex cept for the Broc ade DCX and DCX 85 1 0 -8.
Fabric OS Administrator ’s Guide 549 53-1002745-02 Displaying F_Port tr unking informatio n 22 • If F_Port trunking is enabled on some por ts in the de fault switch, and y ou disable Vir tual Fabrics, all of the F_Por t trunki ng information is lost.
550 Fabric OS A dministr ator’s Guide 53-1002745-02 Enabling the DCC policy on a trunk area 22 switch:admin> portdisable 0-2 switch:admin> porttrunkarea --disable 0-2 Trunk index 2 disabled for ports 0, 1, and 2.
Fabric OS Administrator ’s Guide 551 53-1002745-02 Chapter 23 Managing Long-Distance Fabrics In this chapter • Long-distance fabrics o ver view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55 1 • Extended Fabrics de vice limitations .
552 Fabric OS A dministr ator’s Guide 53-1002745-02 Extended Fabrics device limitations 23 • Optimized switch buf fering When Extended F abrics is installed on gatew ay switches (with E_Port connectivity from one switch to ano ther), the ISLs (E_Ports) are config ured with a large pool of buffer c redits.
Fabric OS Administrator ’s Guide 553 53-1002745-02 Configuring an extended ISL 23 • Dynamic Mode ( LD ) — LD calculat es buf fer credits bas ed on the distance measured during por t initialization. Brocade switch es use a pr oprietary algorithm to estimat e distance across an ISL.
554 Fabric OS A dministr ator’s Guide 53-1002745-02 Configuring an extended ISL 23 portcfglongdistance [ slot /] port [ distance_level ] [ vc_translation_link_init ] [ -distance desired_distance ] 6. Repeat step 4 and step 5 for the r emote ext ended ISL por t.
Fabric OS Administrator ’s Guide 555 53-1002745-02 Buffer credit management 23 1. Connect to the switch and log in using an account assigned to the admin r ole. 2. Disable QoS. switch:admin> portcfgqos --disable [slot/]port If you do no t disable QoS, after the second or third Link Reset (LR), ARB fill wor d s display .
556 Fabric OS A dministr ator’s Guide 53-1002745-02 Buffer credit mana gement 23 B uff e r -t o- bu ff er f lo w co nt r ol i s fl ow co ntr o l be tw een adjacent por ts in the I/O path, fo r example, transmission control ov er individua l network links.
Fabric OS Administrator ’s Guide 557 53-1002745-02 Buffer credit management 23 Smaller frame sizes need more buf f er credits. T w o commands are a vailable t o help you det ermine whether you need to allocate more buf fer credits to handle the av erage frame size .
558 Fabric OS A dministr ator’s Guide 53-1002745-02 Buffer credit mana gement 23 Allocating buffer credit s based on full-sized frames Y ou can allo cate buffer credits based on distance using the portCfgLongDistance command.
Fabric OS Administrator ’s Guide 559 53-1002745-02 Buffer credit management 23 • If QoS is not enabled: (Reserved Buffer for Dis tance Y) = (X * LinkSpeed / 2 ) + 6 where X = the distance det ermined in step 1 (in km). LinkSpeed = the speed of the link determined in st ep 2.
560 Fabric OS A dministr ator’s Guide 53-1002745-02 Buffer credit mana gement 23 • 8 — the number of reserved buf f er credits already allocat ed to that por t. The floor of the resul ting number is ta k en because frac tions of a por t are not allowed.
Fabric OS Administrator ’s Guide 561 53-1002745-02 Buffer credit management 23 Configuring buffers for a single port directly T o configure the number of buffers directly , use the -buff ers option of the port CfgLongDistance command.
562 Fabric OS A dministr ator’s Guide 53-1002745-02 Buffer credit mana gement 23 T o det ermine the number of buf fers req uired, per f orm the fo llowing st eps: 1.
Fabric OS Administrator ’s Guide 563 53-1002745-02 Buffer credit management 23 switch:admin> por tbuffershow 1 7 User Port Lx Max/Resv Avg Buffer Usage & FrameSize Buffer Needed Link Remainin.
564 Fabric OS A dministr ator’s Guide 53-1002745-02 Buffer credit mana gement 23 For the FC8- x por t blades, the fi rst number in the Unreserved buffer credits c olumn designates the number of unre.
Fabric OS Administrator ’s Guide 565 53-1002745-02 Buffer credit management 23 NOTE The distances in this table assume that QoS is enabl ed. If QoS is di sabled the ma ximum suppor t ed distances are higher , because QoS req uires an a dditional 20 buffer credits per activ e por t.
566 Fabric OS A dministr ator’s Guide 53-1002745-02 Buffer credit recovery 23 Buffer credit recovery Buffer credit recov er y (CR) allows links t o recover after buf fe r credits are lost when the buffer credit recov er y logic is enabled. The buffer credit reco ve r y feature also maintains performance.
Fabric OS Administrator ’s Guide 567 53-1002745-02 Buffer credit recovery 23 For an F_P or t on a Br ocade switch or Access Ga t ewa y connected t o an adapte r , the follo wing conditions must be met : • The Bro cade switch or Access Gat ewa y must run F abric OS v7 .
568 Fabric OS A dministr ator’s Guide 53-1002745-02 Forward error correction on long-dis tance links 23 The f ollowing e xample enables buf f er credit reco very on por t 1/20.
Fabric OS Administrator ’s Guide 569 53-1002745-02 Chapter 24 Using FC-FC Routing to Connect Fabrics In this chapter • FC-FC routing ov erview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 569 • Fibre Channel r outing concepts .
570 Fabric OS A dministr ator’s Guide 53-1002745-02 FC-FC routing overview 24 A Fibre Channel router (FC r outer) is a switch running the FC-FC r outing ser vice. The FC-FC routing service can be simultaneously used as an FC rout er and as a SAN ext ension ov er wide area networks (WANs) using FCIP .
Fabric OS Administrator ’s Guide 571 53-1002745-02 FC-FC routi ng overview 24 • The Backbones hav e a limit of 128 EX_Por ts for each chassis. Refe r to th e Network OS A dministrat o r’s Guide f or suppor ted Network OS platfo rms.
572 Fabric OS A dministr ator’s Guide 53-1002745-02 Fibre Channel ro uting concepts 24 Fibre Channel routing concepts Fibre Channel routing intr oduces the following concepts: • Fi br e C ha n ne l rou te r (F C rou te r) A switch running the FC-FC routing ser vice.
Fabric OS Administrator ’s Guide 573 53-1002745-02 Fibre Channel routing concepts 24 • Logical SANs (LSANs) An LSAN is defined b y zones in two or more edg e or backbone fabrics that contain the same devic es. Y ou can creat e LSANs that span fabric s.
574 Fabric OS A dministr ator’s Guide 53-1002745-02 Fibre Channel ro uting concepts 24 • Fabric ID (FID) Every EX_Port and VEX_Por t uses the fabric ID (FI D) to identify the f abric at the opposite end o f the inter -fabric link. The FID f or ev er y edge fabric must be unique fr om the perspective of eac h backbone fabric.
Fabric OS Administrator ’s Guide 575 53-1002745-02 Fibre Channel routing concepts 24 FIGURE 7 6 Edge SANs connected thr ough a backbone fabric • Phantom domains A phantom domain is a domain emulated by the Fibre Channel rout er . The FC r outer can emulate tw o types of phantom domains: front phant om domains and translate phant o m domains.
576 Fabric OS A dministr ator’s Guide 53-1002745-02 Fibre Channel ro uting concepts 24 FIGURE 77 Met aSAN with impor ted devices FC-FC routing topologies The FC-FC routing service provides two types.
Fabric OS Administrator ’s Guide 577 53-1002745-02 Fibre Channel routing concepts 24 Phantom domains A phantom domain is a domain creat ed by the Fibre Channel r outer . The FC rout er creates two types of phantom domains: fr ont phantom domains and translat e phantom domains.
578 Fabric OS A dministr ator’s Guide 53-1002745-02 Fibre Channel ro uting concepts 24 FIGURE 79 EX_Por t phantom switch topology All EX_P or ts or VEX_Ports connected t o an edge f abric use the same xlat e domain ID f or an impor ted edge f abric; this value persists acro ss switch reboots and fabric reconfigurations.
Fabric OS Administrator ’s Guide 579 53-1002745-02 Setting up FC-FC routing 24 Identifying and deleting stale xlate domains If a remot e edge fabric goes unreachable, the xlat e domains created in other edge fabrics f or this remote edge f abric are retained and not remov ed unle ss th ere is any disruption in the local edg e fab ric .
580 Fabric OS A dministr ator’s Guide 53-1002745-02 Setting up FC-FC routing 24 4. Configure IFLs for edge and backbo ne fabric connection. (R ef er to “Inter-fabric link configuration” on page 583.) 5. Modify por t cost for EX_P or ts, if you want t o change fr om the def ault settings.
Fabric OS Administrator ’s Guide 581 53-1002745-02 Backbone fabric IDs 24 RyeSzRScycazfT0G: Integrated Routing license If you are connecting t o a Fabric OS or M-EOS fa bric and the Int egrated R outing license is not installed, you must inst all it, as described in Chapter 18, “ Administering Licensing” .
582 Fabric OS A dministr ator’s Guide 53-1002745-02 FCIP tunnel configuration 24 ATTENTION In a mult i-switch b ackbone fabric , modification of the FID within the backbone f abric will cause disruption to local traffic. Assigning backbone fabric IDs 1.
Fabric OS Administrator ’s Guide 583 53-1002745-02 Inter-fabric link configuration 24 Refe r to th e Fibre Cha nnel over IP A dministrator’s Guide f or ins tructions on how to configure FCIP tunnels.
584 Fabric OS A dministr ator’s Guide 53-1002745-02 Inter-fabric l ink configuration 24 Hash Algorithm: N/A Edge fabric's primary wwn: N/A Edge fabric's version stamp: N/A This por t can no w connect to ano ther switch. The following e x ample configures an E X_Port fo r connecting to a Brocade Network OS fabric.
Fabric OS Administrator ’s Guide 585 53-1002745-02 Inter-fabric link configuration 24 8. Af t e r identifying such por ts, ent er the por tCfgPersistentEnable command t o enable the port, and then the portCfgSho w command t o verify the port is enabled.
586 Fabric OS A dministr ator’s Guide 53-1002745-02 Inter-fabric l ink configuration 24 Edge fabric's primary wwn: N/A Edge fabric's version stamp: N/A portDisableReason: None portCFlags: 0x1 portFlags: 0x1 PRESENT U_PORT EX_PORT portType: 10.
Fabric OS Administrator ’s Guide 587 53-1002745-02 FC router port cost configuration 24 ------------------------------------------------------------------------ 4 95 10:00:00:05:1e:37:00:45 10.32.156.31 "5300" FCR WWN: 10:00:00:05:1e:12:e0:00, Dom ID: 100, Info: 10.
588 Fabric OS A dministr ator’s Guide 53-1002745-02 FC router port cost configuration 24 Port cost considerations The rout er por t cost has the following considerations: • Rout er port sets are d.
Fabric OS Administrator ’s Guide 589 53-1002745-02 EX_Port frame trunking configuration 24 ------------------------ 7/3 1000 7/4 1000 7/9 1000 7/10 1000 7/13 1000 10/0 1000 Yo u c a n a l s o u s e t h e fcrRouteShow command t o display the rout er port cost.
590 Fabric OS A dministr ator’s Guide 53-1002745-02 LSAN zone configuration 24 For inf orm ation about setting up E_Por t trun king on an edge fabric, refer t o Chapt er 22, “Managing Tr u n k i n g C o n n e c t i o n s ” .
Fabric OS Administrator ’s Guide 591 53-1002745-02 LSAN zone configuration 24 NOTE The "LSAN_" prefix must appear at the beginn ing of the zone name. LSAN zo nes ma y not be combined with QoS zones. R ef er to “QoS zones” on page 525 for more inf ormation about the naming conv ention for QoS zones.
592 Fabric OS A dministr ator’s Guide 53-1002745-02 LSAN zone configuration 24 3. Enter the zoneCreat e command t o create the L SAN lsan_zone _fabric75 , which includes the host. switch:admin> zonecreate "lsan_zone_fabric75", "10:00:00:00:c9:2b:c9:0c" 4.
Fabric OS Administrator ’s Guide 593 53-1002745-02 LSAN zone configuration 24 This action will replace the old zoning configuration with the current configuration selected. Do you want to enable 'zone_cfg' configuration (yes, y, no, n): [no] y zone config "zone_cfg" is in effect Updating flash .
594 Fabric OS A dministr ator’s Guide 53-1002745-02 LSAN zone configuration 24 Setting the maximum LSAN count Y ou can se t the maximu m number of LS AN zones, or LSAN count, that can be configure d on the edge fabrics. By default, the maximum LSAN coun t is set t o 3000.
Fabric OS Administrator ’s Guide 595 53-1002745-02 LSAN zone configuration 24 Y ou can specify two types of tags: • Enfor ce tag – Specifies which LSANs are to be enf orced in an FC rout er . • Speed tag – Specifies whic h LSANs are to be imported or exported f aster than o ther LSANs.
596 Fabric OS A dministr ator’s Guide 53-1002745-02 LSAN zone configuration 24 lsan_f2_f1 (H1, D1) lsan_f2_f3 (H1, D2) The LSAN in the host f abric does not need the tag. 3. In Edge fabric 1, configure the following LSAN: lsan_super_f1_ f2 (H1, D1) 4.
Fabric OS Administrator ’s Guide 597 53-1002745-02 LSAN zone configuration 24 • The tag is from 1 thr o ugh 8 alphanumeric characters. • Y ou can configure only one Speed ta g on an FC rout er , and up to eight Enf orce tags on an FC rout er . The maximum number of tags (Enf orce and Speed) on an FC r outer is eight.
598 Fabric OS A dministr ator’s Guide 53-1002745-02 LSAN zone configuration 24 1. Log in to the FC r outer as admin. 2. Enter the fcrlsan -- remov e command to remo ve an e xisting LSAN tag . If you remo ve an Enfor ce LSAN tag, y ou must disable the switch first.
Fabric OS Administrator ’s Guide 599 53-1002745-02 LSAN zone configuration 24 W i t h LS AN zo n e b i n d i n g , ea ch F C ro u te r i n t h e ba c k b o n e fa b r i c s to r e s o n l y t h e L SA N z o n e en t r i e s of the remot e edge fabrics that can access its local edge fabrics.
600 Fabric OS A dministr ator’s Guide 53-1002745-02 LSAN zone configuration 24 LSAN zone binding considerations • Without LSAN zone binding, the maximu m number of LSAN devi ces is 1 0,000. • With LSAN zone binding, the metaSAN can impor t more than 1 0,000 devices and the backbone fabric can suppor t more FC r outers.
Fabric OS Administrator ’s Guide 601 53-1002745-02 LSAN zone configuration 24 FC router matrix definition Depending on the structure of the backbone fabric , y ou can specify pairs of FC routers that can access each other .
602 Fabric OS A dministr ator’s Guide 53-1002745-02 LSAN zone configuration 24 Setting up LSAN zone binding 1. Log in to the FC r outer as admin. 2. Enter the following command to add a pair of FC r outers that can access each other: FCR:Admin> fcrlsanmatrix --add -fcr wwn1 wwn2 The variables wwn 1 and wwn2 are the WWNs of the FC r outers.
Fabric OS Administrator ’s Guide 603 53-1002745-02 Proxy PID configuration 24 Proxy PID configuration When an FC router is first configured, the PIDs f or the proxy de vices are automatically assigned. Pro xy PIDs (as well as phantom domain IDs) persist acr oss reboots.
604 Fabric OS A dministr ator’s Guide 53-1002745-02 Inter-fabric broadcast frames 24 Inter-fabric broadcast frames The FC rout er can receive and f o rward br oadcas t frames between edge fabrics and betw een the b a c k b o n e f a b r i c a n d e d g e f a b r i c s .
Fabric OS Administrator ’s Guide 605 53-1002745-02 Resource monitoring 24 Y ou can monitor FC r outer resour ces using the fcrR esourceSho w command.
606 Fabric OS A dministr ator’s Guide 53-1002745-02 FC-FC routing and Virtual Fabrics 24 20 | 8 34 21 | 8 34 22 | 8 34 23 | 8 34 FC-FC routing and Virtual Fabrics If Virtual Fabrics is not enabled, FC-FC r outing beha vior is unchanged.
Fabric OS Administrator ’s Guide 607 53-1002745-02 FC-FC routing and Virtual Fabrics 24 • Although the Br ocade 65 1 0 and 6520 suppor ts up to f our logical switches, if you are using FC-FC r outing, they can ha ve a maximum of three logical switches.
608 Fabric OS A dministr ator’s Guide 53-1002745-02 FC-FC routing and Virtual Fabrics 24 FIGURE 83 Logical representation of EX_Por ts in a base switch Backbone-to-edge routing with Virtual Fabrics Backbone-to-ed ge routing is n ot suppor ted in th e ba se switch, unless you use a legacy FC rout er .
Fabric OS Administrator ’s Guide 609 53-1002745-02 Upgrade and downgrade co nsi derations for FC-FC routing 24 FIGURE 84 Backbone-to-edge r outing across base sw itc h using FC rout er in legacy mode Upgrade and downgrade considerations for FC-FC routing Wh e n yo u u pg r a d e t o Fa b r i c O S v 7 .
610 Fabric OS A dministr ator’s Guide 53-1002745-02 Displaying the range of output ports connected to xlate domains 24 1. Log in to a switch in the edge fabric. 2. Enter the lsDbShow command on the edge fabric. In the lsDbShow output, por ts in the range from 129 thr ough 255 are the output por ts on the front domain.
Fabric OS Administrator ’s Guide 611 53-1002745-02 Appendix A Port Indexing This appendix shows how t o us e the switchShow command t o det ermine the mapping among the por t index, slo t/por t numbers, and the 2 4-bit po r t ID (PID) on any Br oc ade Backbone.
612 Fabric OS A dministr ator’s Guide 53-1002745-02 Port Indexing A 740 3 20 5 ------ -- 16G No_Module FC 741 3 21 5 ------ -- 16G No_Module FC 742 3 22 5 ------ -- 16G No_Module FC 743 3 23 5 -----.
Fabric OS Administrator ’s Guide 613 53-1002745-02 Port Indexing A Example of port in dexing on an FC8-64 blade on a Br ocade DCX-4S Backbone. The Bro cade DCX-4S does no t need a mapping of port s on port blades becaus e it is a one-to-one mapping.
614 Fabric OS A dministr ator’s Guide 53-1002745-02 Port Indexing A Example of por t indexing on an FS8-18 blade on a DCX 85 10-8 Backbone This example sho ws the truncated swi tchShow output f or an FS8-18 encryption blade on the Brocade DCX 85 10-8 Backbone.
Fabric OS Administrator ’s Guide 615 53-1002745-02 Appendix B FIPS Support In this appendix • FIPS ov er view . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 15 • Zeroization functions . . . . .
616 Fabric OS A dministr ator’s Guide 53-1002745-02 Zeroization functions B FCSP Cha llenge Handshake Authentication Protocol (CHAP) Se cret secAuthSe cret –- remo ve The secAuthsecret -–create command is used to input the keys, and the secAuthsecret -–remo ve command is used to remo ve and zero ize the ke ys.
Fabric OS Administrator ’s Guide 617 53-1002745-02 FIPS mode confi guration B Power-on self tests A pow er-on self-t est (POST) is in vok ed by po wering on the switch in FIPS mode and does not require any operat or intervention. If any KA T s fail, the switch goes into a FIPS Error state, which reboo ts the syst em to star t the t est again.
618 Fabric OS A dministr ator’s Guide 53-1002745-02 FIPS mode configuration B LDAP in FIPS mode Y ou can configure your Microsoft Active Direct or y server t o use the Lightweight Direct or y Access Pro tocol (LDAP) while in FIPS mode. There is no option pro vided on the switch t o configure TLS ciphers f or LDAP in FIPS mode.
Fabric OS Administrator ’s Guide 619 53-1002745-02 FIPS mode confi guration B Setting up LDAP for FIPS mode 1. Log in to the switch using an account with ad min or securityadmin perm issions, or an account with OM permissions for the RADIUS and swit ch configuration RBAC classes of commands.
620 Fabric OS A dministr ator’s Guide 53-1002745-02 FIPS mode configuration B 4. Set up LDAP according t o the instructions in “LDAP configuration and Microsof t Act ive Directory” on page 162, and the n per form the f ollowing additional Micr osof t Active Directory settings a.
Fabric OS Administrator ’s Guide 621 53-1002745-02 Preparing a switch for FIPS B Exporting an LDAP switch certificate This proced ure exports the LDAP CA certificate fr om the switch t o the remot e host.
622 Fabric OS A dministr ator’s Guide 53-1002745-02 Preparing a switch for FIPS B Overview of steps 1. Remo ve legacy OpenSS H DSA ke ys. 2. Optional: Configure the RADIUS server or the LD AP ser ver . 3. Optional : Configure any authentication pr otocols.
Fabric OS Administrator ’s Guide 623 53-1002745-02 Preparing a switch for FIPS B 4. Optional: Set the authentication prot ocols. a. Enter the authUtil -- set -h sh a1 command to se t the hash type f or MD5, which is used in the DH-CHAP and FCAP authentication pro tocols.
624 Fabric OS A dministr ator’s Guide 53-1002745-02 Preparing a switch for FIPS B • System services: No • cfgload attributes: Y es • Enfor ce secure config Upload/Download: Press En ter to accept the default.
Fabric OS Administrator ’s Guide 625 53-1002745-02 Preparing a switch for FIPS B NOTE Passwor ds of the default accounts (admin and user) should be changed af ter e very zeroization operation to maintain FIPS 140-2 compliance. 3. Power -cycle the switc h.
626 Fabric OS A dministr ator’s Guide 53-1002745-02 Preparing a switch for FIPS B.
Fabric OS Administrator ’s Guide 627 53-1002745-02 Appendix C Hexadecimal Conversion Hexadecimal overview Hexadecimal, also known as he x, is a numeral syst em with a base of 1 6, usually written b y means of symbols 0–9 and A–F (or a–f).
628 Fabric OS A dministr ator’s Guide 53-1002745-02 Hexadecimal Conversion C Decimal-to-hexadecimal conversion table TA B L E 9 0 Decimal-to-hexadecimal conver sion t able Decimal 01 02 03 04 05 06 .
Fabric OS Administrator ’s Guide 629 53-1002745-02 Hexadecimal Conversion C H e x a b a c a d a e a f b 0b 1b 2b 3b 4 Decimal 181 18 2 183 184 185 18 6 18 7 18 8 189 19 0 Hex b5 b6 b7 b8 b9 ba bb bc.
630 Fabric OS A dministr ator’s Guide 53-1002745-02 Hexadecimal Conversion C.
Fabric OS Administrator ’s Guide 631 53-1002745-02 Index Numerics 10 Gbps operation on an FC port, enabling , 476 10-bit addressing mode , 80 10G lic ense , 475 – 478 128-bit encryption, in browse.
632 Fabric OS A dministr ator’s Guide 53-1002745-02 policy distribution to other switches , 227 policy manageme nt , 196 – 199 policy members , 196 removing polic y member , 198 resolving conflict.
Fabric OS Administrator ’s Guide 633 53-1002745-02 switch members , 440 switch port members , 439 switch WWN , 440 switching context , 456 system-defined , 436 TACACS+ service , 173 TI zone consider.
634 Fabric OS A dministr ator’s Guide 53-1002745-02 auto-assigned FA-PWWN behavior , 426 auto-leveling, FR4-18i blade , 264 , 270 automatic PID assignment, enabling , 82 B Backbone assigning fabric .
Fabric OS Administrator ’s Guide 635 53-1002745-02 bottleneckMon command , 376 , 380 , 381 , 382 , 385 , 390 , 391 , 392 Broadcast server, described , 44 broadcast zones , 303 , 310 name restriction.
636 Fabric OS A dministr ator’s Guide 53-1002745-02 chassis names , 75 chassis, changing name of , 75 chassisDistribute comm and , 224 , 226 chassisName command , 75 ChassisRole Microsoft Active Dir.
Fabric OS Administrator ’s Guide 637 53-1002745-02 frameLog , 124 haDisable , 146 haFailover , 147 , 272 haShow , 103 , 262 , 263 , 271 haSyncStart , 263 help , 58 ifModeSet , 91 iodReset , 123 iodS.
638 Fabric OS A dministr ator’s Guide 53-1002745-02 ssh-keygen , 180 sshUtil , 180 , 182 , 622 sshutil , 257 supportSave , 39 switchCfgPersistentDisable , 100 switchCfgSpeed , 92 switchCfgTrunk , 53.
Fabric OS Administrator ’s Guide 639 53-1002745-02 access methods, Web Tools , 55 audit log , 107 authentication , 403 authentication policy , 207 – 217 browser security certificates , 186 compres.
640 Fabric OS A dministr ator’s Guide 53-1002745-02 D D_Port, described , 84 daemon processes and High Availability , 53 daemon, tac_plus , 172 daemons automatically restarted , 53 date and time , 6.
Fabric OS Administrator ’s Guide 641 53-1002745-02 compressio n , 405 CS_CTL-based frame prioritization , 522 DHCP , 67 F_Port trunking , 549 failover in TI zones, consideratio ns , 347 in-flight en.
642 Fabric OS A dministr ator’s Guide 53-1002745-02 edge-to-edge routing , 581 EE monitors about , 501 adding , 502 clearing statistic counters , 505 defined , 499 deleting , 504 displaying counters.
Fabric OS Administrator ’s Guide 643 53-1002745-02 displayin g information , 542 masterless , 542 supported configurations and platforms , 542 Exchange Link Parameters mode.
644 Fabric OS A dministr ator’s Guide 53-1002745-02 command line interface , 56 , 56 – 59 default roles , 134 feature interaction with Virtual Fabrics , 288 interaction with Virtual Fabrics , 288 .
Fabric OS Administrator ’s Guide 645 53-1002745-02 See also: FC. Fibre Channel Authentication Protoco l. See: FCAP. Fibre Channel Common Transport (FC-CT) protoc ol service, described , 44 Fibre Channel fabrics, and port ID , 113 Fibre Channel Over IP service.
646 Fabric OS A dministr ator’s Guide 53-1002745-02 port configurations supported , 286 port restrictions , 286 FL_Port, described , 84 FLOGI , 52 defined , 51 FC-SP bit setting , 210 process , 52 r.
Fabric OS Administrator ’s Guide 647 53-1002745-02 TACACS+ , 173 home LF Microsoft Active Directory , 165 OpenLDAP , 170 RADIUS , 155 TACACS+ , 173 host syslog, verifying , 108 hosts, accessing , 19.
648 Fabric OS A dministr ator’s Guide 53-1002745-02 policy rules , 219 policy rules using service names , 220 saving policy , 218 supported actions , 221 supported protocols , 221 supported services.
Fabric OS Administrator ’s Guide 649 53-1002745-02 in FIPS mode , 618 installing certificates , 620 IPv4 and IPv6 support , 162 non-FIPS mode restrictions , 162 role mapping and OpenLDAP , 168 role .
650 Fabric OS A dministr ator’s Guide 53-1002745-02 blocked chargen , 192 daytime , 192 discard , 192 echo , 192 ftp , 192 rexec , 192 rlogin , 192 rsh , 192 rstats , 192 rusers , 192 time , 192 blo.
Fabric OS Administrator ’s Guide 651 53-1002745-02 management server displaying ACL , 46 viewing database , 48 management server database , 45 – 49 Management server, described , 44 managing Admin.
652 Fabric OS A dministr ator’s Guide 53-1002745-02 null encryption suppo rt for IKE policies , 240 O on-demand ports , 483 – 489 activating , 485 available ports , 484 disabling dynamic , 487 displaying installed licenses , 484 dynamic , 485 enabling dynamic , 486 supported devices , 483 Open LDAP See also: LDAP.
Fabric OS Administrator ’s Guide 653 53-1002745-02 disabling , 45 enabling , 45 Virtual Fabrics , 45 platforms, FC-FC routing supported , 570 PLOGI , 52 defined , 51 POD enabling ports , 89 releasing a port from a set , 488 reserving a port license , 488 See also: ports on demand.
654 Fabric OS A dministr ator’s Guide 53-1002745-02 deactivation , 89 decommissioning , 90 deleting To p Talker mo nitor on , 514 disabling , 90 disabling dynamic POD , 487 disabling on blades , 96 .
Fabric OS Administrator ’s Guide 655 53-1002745-02 portDecom comm and , 90 portDisable comman d , 90 , 538 portEnable command , 89 , 485 portEncCompShow command , 396 , 399 , 401 , 402 , 404 PortFec.
656 Fabric OS A dministr ator’s Guide 53-1002745-02 QoS zone-based traffic prioritization , 523 disabling , 532 High Availability co nsiderations , 528 limitations and restrictions , 529 setting , 5.
Fabric OS Administrator ’s Guide 657 53-1002745-02 upgrading temporary slot-based licenses , 479 Virtual Fabrics , 288 XISLs , 289 rexec listener application , 192 rlogin listener applicat ion , 192 Role-Based Access Control.
658 Fabric OS A dministr ator’s Guide 53-1002745-02 length , 213 setting , 214 viewing list of , 213 secure copy protocol. See: SCP. Secure Fabric OS policies , 196 secure LDAP , 150 secure protocol HTTPS , 178 items needed to deploy , 178 SCP , 178 SNMPv1 , 178 SNMPv2 , 178 SNMPv3 , 178 SSHv2 , 178 Secure Shell protoco l.
Fabric OS Administrator ’s Guide 659 53-1002745-02 security levels , 190 SNMPv1 secure protocol , 178 SNMPv2 secure protocol , 178 SNMPv3 secure protocol , 178 switch and chassis context enforcement.
660 Fabric OS A dministr ator’s Guide 53-1002745-02 switch database distribution setting , 224 unique names for logical , 74 user-defined accounts , 137 viewing status policy threshold values , 105 switch authentication m ode, setting , 152 switch authentication policy , 20 8 See also: AUTH.
Fabric OS Administrator ’s Guide 661 53-1002745-02 setting interactively , 71 time zone settings , 69 – 71 time, synchronizing local and ext ernal , 71 time-based licenses , 478 – 480 Top Talker.
662 Fabric OS A dministr ator’s Guide 53-1002745-02 U U_Port, described , 84 unblocking telnet acce ss , 191 universal temporary license defined , 478 described , 48 0 extending , 480 shelf life , 4.
Fabric OS Administrator ’s Guide 663 53-1002745-02 configDownload restrictions , 252 configUpload restrictions , 252 configuration management , 250 configuring SNMP for , 189 – 190 considerations for Adv.
664 Fabric OS A dministr ator’s Guide 53-1002745-02 Z zeroization functions for FIPS , 615 zeroizing for FIPS , 624 zone access mode, viewing current , 327 accessing , 192 adding a new switch or fab.
Fabric OS Administrator ’s Guide 665 53-1002745-02 zoneRemove command , 31 8 zoneShow command , 322 zoning advanced , 303 – 342 advanced commands , 304 defined , 304 enforcement , 308 on logical p.
666 Fabric OS A dministr ator’s Guide 53-1002745-02.
Een belangrijk punt na aankoop van elk apparaat Brocade Communications Systems 53-1002745-02 (of zelfs voordat je het koopt) is om de handleiding te lezen. Dit moeten wij doen vanwege een paar simpele redenen:
Als u nog geen Brocade Communications Systems 53-1002745-02 heb gekocht dan nu is een goed moment om kennis te maken met de basisgegevens van het product. Eerst kijk dan naar de eerste pagina\'s van de handleiding, die je hierboven vindt. Je moet daar de belangrijkste technische gegevens Brocade Communications Systems 53-1002745-02 vinden. Op dit manier kan je controleren of het apparaat aan jouw behoeften voldoet. Op de volgende pagina's van de handleiding Brocade Communications Systems 53-1002745-02 leer je over alle kenmerken van het product en krijg je informatie over de werking. De informatie die je over Brocade Communications Systems 53-1002745-02 krijgt, zal je zeker helpen om een besluit over de aankoop te nemen.
In een situatie waarin je al een beziter van Brocade Communications Systems 53-1002745-02 bent, maar toch heb je de instructies niet gelezen, moet je het doen voor de hierboven beschreven redenen. Je zult dan weten of je goed de alle beschikbare functies heb gebruikt, en of je fouten heb gemaakt die het leven van de Brocade Communications Systems 53-1002745-02 kunnen verkorten.
Maar de belangrijkste taak van de handleiding is om de gebruiker bij het oplossen van problemen te helpen met Brocade Communications Systems 53-1002745-02 . Bijna altijd, zal je daar het vinden Troubleshooting met de meest voorkomende storingen en defecten #MANUAl# samen met de instructies over hun opplosinge. Zelfs als je zelf niet kan om het probleem op te lossen, zal de instructie je de weg wijzen naar verdere andere procedure, bijv. door contact met de klantenservice of het dichtstbijzijnde servicecentrum.