Configuring Storage Area Network Switches: Netact™

Download as pdf or txt
Download as pdf or txt
You are on page 1of 41
At a glance
Powered by AI
The document discusses configuring Storage Area Network switches.

The document is about configuring Storage Area Network switches including managing the switch and configuring SNMP.

Table 2 lists important management commands for configuring switches like configure, zoneCreate, cfgCreate, etc.

NetAct™

19

Configuring Storage Area Network Switches


Issue: 2-0
Configuring Storage Area Network Switches 2-0 Disclaimer

The information in this document applies solely to the hardware/software product (“Product”) specified herein, and only as specified herein.

This document is intended for use by Nokia ' customers (“You”) only, and it may not be used except for the purposes defined in the
agreement between You and Nokia (“Agreement”) under which this document is distributed. No part of this document may be used, copied,
reproduced, modified or transmitted in any form or means without the prior written permission of Nokia . If you have not entered into an
Agreement applicable to the Product, or if that Agreement has expired or has been terminated, You may not use this document in any
manner and You are obliged to return it to Nokia and destroy or delete any copies thereof.

The document has been prepared to be used by professional and properly trained personnel, and You assume full responsibility when using
it. Nokia welcome Your comments as part of the process of continuous development and improvement of the documentation.

This document and its contents are provided as a convenience to You. Any information or statements concerning the suitability, capacity,
fitness for purpose or performance of the Product are given solely on an “as is” and “as available” basis in this document, and Nokia reserves
the right to change any such information and statements without notice. Nokia has made all reasonable efforts to ensure that the content of
this document is adequate and free of material errors and omissions, and Nokia will correct errors that You identify in this document. But,
Nokia ' total liability for any errors in the document is strictly limited to the correction of such error(s). Nokia does not warrant that the use of
the software in the Product will be uninterrupted or error-free.

N O WA RRA NT Y O F AN Y KI ND , EI T HER EXPR ES S OR I M P L I E D , I N C L U D I N G B U T N O T L I M I T E D TO A N Y


WARR ANT Y OF AVA IL ABI LI T Y, AC CU RAC Y, R EL I A B I L IT Y, T I T L E , N O N - I N F R I N G E M E N T, M E R C H A N TA B I L I TY
OR F IT NE SS FO R A PA RT ICU LAR PU RPO SE, I S M A D E IN R E L AT I O N TO T H E C O N T E N T O F T H I S D O C U M E N T.
IN NO EVEN T WI L L NOK IA B E LI ABLE F OR AN Y DA M A G E S , I N C L U D I N G B U T N O T L I M I T E D TO S P E C I A L ,
D IRE CT, IN D IRECT, I NCI DE NTAL OR C ON SEQ UE N T IA L OR A N Y L O S S E S , S U C H A S B U T N O T L I M I T E D TO LO SS
OF PRO F IT, REVE NU E, B US IN ESS IN T ER RU PT I ON , B U S I NE S S O P P O RT U N I T Y O R D ATA T H AT M AY A R I S E
FRO M T HE USE O F TH IS DO CU M EN T O R T HE IN F OR M AT IO N I N I T, E V E N I N T H E C A S E O F E R R O R S I N O R
OM IS SI O NS FRO M T HI S DOC UM EN T O R IT S CO NT E N T.

This document is Nokia ’ proprietary and confidential information, which may not be distributed or disclosed to any third parties without the
prior written consent of Nokia .

Nokia is a registered trademark of Nokia Corporation. Other product names mentioned in this document may be trademarks of their
respective owners, and they are mentioned for identification purposes only.

Copyright © 2019 Nokia . All rights reserved.

Important Notice on Product Safety


This product may present safety risks due to laser, electricity, heat, and other sources of danger.
Only trained and qualified personnel may install, operate, maintain or otherwise handle this product and only after having carefully read the
safety information applicable to this product.
The safety information is provided in the Safety Information section in the “Legal, Safety and Environmental Information” part of this
document or documentation set.

Nokia is continually striving to reduce the adverse environmental effects of its products and services. We would like to encourage you
as our customers and users to join us in working towards a cleaner, safer environment. Please recycle product packaging and follow the
recommendations for power use and proper disposal of our products and their components.
If you should have questions regarding our Environmental Policy or any of the environmental services we offer, please contact us at Nokia for
any additional information.
Configuring Storage Area Network 2-0 Table of Contents
Switches

Contents
1 Summary of changes...................................................................................................................................... 4

2 About this document...................................................................................................................................... 5


2.1 SAN solution overview.............................................................................................................................. 5
2.2 Zoning overview........................................................................................................................................ 5
2.3 Terms......................................................................................................................................................... 6

3 Prerequisites.................................................................................................................................................... 8
3.1 Initial cabling..............................................................................................................................................8

4 Creating SAN configuration........................................................................................................................... 9


4.1 Finding IP address of the switch.............................................................................................................. 9
4.2 Defining domain ID................................................................................................................................... 9
4.3 EMC recommendation for SAN switch external port configuration.........................................................11
4.4 Disable RDP feature from SAN switch...................................................................................................16
4.4.1 Checking the current RDP status in the SAN switch..................................................................... 16
4.4.2 Verifying existing NetAct system before disabling RDP in the SAN switch.................................... 17
4.4.3 Checking the overall SAN switch status........................................................................................ 18
4.4.4 Checking current FOS version running on the SAN switch........................................................... 19
4.4.5 Checking the current RDP polling status in the SAN switch..........................................................20
4.4.6 Taking a local copy of SAN switch current configuration............................................................... 20
4.4.7 Disabling the SAN switch and checking the status of the switch...................................................21
4.4.8 Disabling the RDP polling in the SAN switch and checking the status.......................................... 22
4.4.9 Enabling the SAN switch and checking the RDP polling status.....................................................23
4.4.10 Verifying that ESXi sees both links are up...................................................................................25
4.5 Disabling RDP feature on the second SAN switch................................................................................ 26
4.6 Configuring fillword value for 8GB FC SAN switch................................................................................ 26
4.7 Configuring Port Zoning.......................................................................................................................... 27
4.8 Configuring WWN Zoning....................................................................................................................... 30
4.9 Disabling telnet access to SAN switch (BROCADE) using IPv4 address...............................................32
4.10 Disabling telnet access to SAN switch (BROCADE) using IPv6 address.............................................34
4.11 Enabling https and disabling http..........................................................................................................35

5 Managing the switch..................................................................................................................................... 37

6 Configure SNMP............................................................................................................................................ 39

7 Appendix: Configuring QLogic Fast!UTIL BIOS settings for SAN switch zoning...................................40

NetAct™ 19 © 2019 Nokia 3


Configuring Storage Area Network 2-0 Summary of changes
Switches

1 Summary of changes
Version Date Description of changes

02 2019-06-10 Updated the reference links.

01 2019-05-30 First version of NetAct 19.

Table 1: Summary of changes

NetAct™ 19 © 2019 Nokia 4


Configuring Storage Area Network 2-0 About this document
Switches

2 About this document

This document describes the setup procedure for Storage Area Network (SAN) switches in NetAct.
The topics covered here include the basic standardized installation of embedded Brocade switches in
a HPE Blade system and an introduction with guidelines on more specialized setups. This document
does not cover advanced SAN architectures such as, OpenSAN.

Note: If the Fibre Channel (FC) switches are delivered and connected to the customer’s SAN
in the OpenSAN concept, the customer is responsible for doing the entire FC configuration to
the FC switches as well.

This document does not apply to Compact configurations with rack-mounted servers because they do
not normally need to use a Fiber Channel (FC) switch.

2.1 SAN solution overview


A Storage Area Network (SAN) solution consists of two independent Fiber Channel (FC) switches
within a blade system enclosure.

SAN switches are the infrastructure for interconnecting servers and storage devices on site. To guar-
antee high-availability for the entire solution, every attached external device (such as a server or a
disk array) has to be connected to both FC switches. Inside the enclosure, each server is connected to
both FC switches, which automatically guarantees high-availability.

The FC switch must be connected to both the storage processors.

It is mandatory to follow the instructions in System Cabling Guide document for connecting external
storages to SAN switches.

Note: Use the number of cables mentioned in the System Cabling Guide document. Do not
use more cables than technically necessary to connect the array to the switch. While it might
seem harmless or even reasonable to use multiple cables, it only adds complexity to the zon-
ing and multipath.

2.2 Zoning overview


Single initiator zoning is a stability-enhancement technology introduced in the storage industry several
years ago.

Nokia recommends to use hard zoning (or port zoning) instead of soft zoning (or World Wide Name
zoning), which was previously prevalent.

NetAct™ 19 © 2019 Nokia 5


Configuring Storage Area Network 2-0 About this document
Switches

In single initiator zoning, each zone has only one initiator (the server) but possibly multiple FC ports
and is still recommended. This is because in most cases, the structure of the blade chassis creates an
identical and repeatable configuration.

Port zoning allows the physical blades and Host Bus Adapter (HBA) cards to be changed without the
need to rezone. Port zoning is also easier to implement manually than soft zoning because you do
not need to enter the World Wide Names (WWNs) manually into command-line interface of the Fibre
Channel (FC) switch.

The main idea behind single initiator zoning is that a single zone is created for each server port con-
necting to the switched fabric (that is, a system of one or more interconnected switches). This zone
contains the server port itself, along with the port addresses of all the storage devices the server port
is supposed to access. All created zones are then assigned as members of the same switch configura-
tion profile (possibly with other existing zone definitions) and activated simultaneously.

After the zones are created and assigned into a profile, every server port will grant access to each of
its storage devices. However, no traffic between individual server ports, intentional or ad-hoc is permit-
ted, which completely eliminates the possibility of server-to-server attacks, making the entire storage
area network safer and eventually, more stable.

With the emergence of ESXi/Linux OS, the use of zones is mandatory. The way Fiber Channels are
implemented in ESXi/Linux, zones are required to prevent changes in the fabric from altering the order
and identifying the discovered logical unit numbers (LUN) when the HBA kernel module is loaded. This
requirement also applies to implementations that use the OpenSAN concept.

Note: The NetAct SAN switch installation does not use the inter-switch link (ISL) method
used in some of the recommended fabric topologies of hardware vendors. It uses two
independent switched fabrics that still serve the same group of servers and storage
devices. This storage subsystem layout is called the Redundant Fiber Channel switch fabric
architecture.

2.3 Terms

Term Explanation

SAN Storage Area Network

FC Fiber Channel. A protocol used in SAN.

RAID Redundant Array of Inexpensive Disks. A technology for ensuring data


availability by means of mirroring and parity calculation.

Disk Array A dedicated hardware appliance that implements the RAID algorithm.

RAID controller A processor card or an independent unit that implements the disk array
logic. Typically, mid-range disk arrays contain two RAID controllers for
failover capability.

NetAct™ 19 © 2019 Nokia 6


Configuring Storage Area Network 2-0 About this document
Switches

Term Explanation

SP Storage Processor. Another name for RAID controller.

JBOD Just a Bunch Of Disks. A single enclosure containing typically 10-15


disks (depending on model). JBOD, and the installed disks, represent
the raw capacity behind the disk array they are part of.

LUN Logical Unit. A virtual disk device acting as an ordinary disk from the
server perspective.

SNMP Simple Network Management Protocol. A protocol used to remotely


manage and monitor network devices in IP networks.

MIB Management Information Base. A collection of managed objects nec-


essary for SNMP management of the network.

NetAct™ 19 © 2019 Nokia 7


Configuring Storage Area Network 2-0 Prerequisites
Switches

3 Prerequisites

These items must be collected in advance for every switch:

• IP address assigned to both Storage Area Network (SAN) switches by the HP Onboard
Administrator.
• A unique switch domain number (a number between 1-7 or 9-239).

Note: Do not use 8 as the unique switch domain number. Also, it is necessary to have
unique switch domain numbers when interconnecting individual distributed SANs. Since
changing the switch domain numbers later might cause changes in the logical LUN
addresses, it is highly recommended to develop a site-wide SAN addressing concept
beforehand.

• A unique descriptive name.

In addition, the following hardware components are needed:

• 16 or 8 GBIC modules (4 per switch) and 4 optical fibre cables per every disk array to be
connected (depends on the disk array model). Newer devices use 16 GBIC modules to support
16Gbits/s data rate FC host.

Note: When ordered from Nokia Networks, FC switches should come with four gigabit
interface converter (GBIC) modules pre-installed in both Brocade SAN blade switches.

3.1 Initial cabling


For information on system cabling, see NetAct system cabling.

NetAct™ 19 © 2019 Nokia 8


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

4 Creating SAN configuration

• Finding IP address of the switch


• Defining domain ID
• EMC recommendation for SAN switch external port configuration
• Disable RDP feature from SAN switch
• Disabling RDP feature on the second SAN switch
• Configuring fillword value for 8GB FC SAN switch
• Configuring Port Zoning
• Configuring WWN Zoning
• Disabling telnet access to SAN switch (BROCADE) using IPv4 address
• Disabling telnet access to SAN switch (BROCADE) using IPv6 address
• Enabling https and disabling http

4.1 Finding IP address of the switch


Provides the instructions to find the IP address of the SAN switch.

1. With a web browser, log in to HP Onboard Administrator with the username Administrator.

You can find the default password on a tag on the Onboard Administrator module.

Rack Overview page appears.

2. In the left pane, click Enclosure Information → Interconnect Bays.

3. Select the Brocade SAN Switch whose IP address you want to find out.

Interconnect Bay Information - Bay <bay number> section appears in right pane.

4. Click Information tab.

5. Write down the IP address mentioned in the Management IP Address field.

6. Repeat steps 3 to 5 for the second SAN switch.

Expected outcome

The IP address of the SAN switches are available.

NetAct™ 19 © 2019 Nokia 9


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

4.2 Defining domain ID


Provides the instructions to define the domain ID.

1. Log in to the first SAN switch through SSH. Use the username admin and the password
password.

After you have logged in, press ENTER and follow the instructions on the screen.

Note: The default password for both the administrator account and the user account is
password. For security reasons, you should change the default passwords during the
switch installation. If you do not change the passwords, the switch prompts to change
them every time you log in with the administrator account.

For further information on password management, use the # help passwd command
or refer to the available Fabric OS documentation.

2. Temporarily disable switch operations by entering:

switchDisable

3. Open the switch configurator by entering:

configure

4. Press y to edit the fabric parameters.

5. In the Domain parameter, type the predefined DomainID. Press ENTER to dismiss all the other
prompts.

Domain parameter shows the sample output for the Domain parameter.

NetAct™ 19 © 2019 Nokia 10


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

Figure 1: Domain parameter

Note: You should only modify the Domain parameter. Do not change any of the other
parameters.

The DomainID in the switch must match the one used in the zoning. If not, all
communication between the server and the array is prevented.

In certain environments, Domain-ID 8 is reserved for a specific purpose. Do not use


this number as the switch identifier.

6. Re-enable the switch by entering:

switchenable

7. Repeat steps 2 to 6 on the second SAN switch.

Expected outcome

The domain ID is defined for the SAN switch.

4.3 EMC recommendation for SAN switch external port configuration


Provides the instructions to identify the G-port and to set the SAN switch to G-port.

EMC recommends that when the Storage Array Network (SAN) switch external port connects with
EMC Storage Processor, the switch port should be set to F-port permanently to ensure that the SAN

NetAct™ 19 © 2019 Nokia 11


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

switch comes up Point-to-Point. If F-port is not available, G-port will transition to F-port and None Loop
mode.

G-port can be used as default on the EMC connected SAN switch ports since HP Brocade switches
does not support setting F-port permanently.

To configure the SAN switch port as G-port ON state do the following steps:

Note: Set G-port to ON state only on SAN switch ports where EMC SPA/SPB FC ports are
connected.

1. Log in to SAN switch through SSH as an admin privileged user.

2. Identify the ports connected from both SAN switches to EMC Service Processors by entering:

sw0:admin > switchshow

Sample output:

In this case SAN switch ports 17-20 are used for EMC Service Processor connectivity.

switchName: sw0
switchType: 129.1
switchState: Online
switchMode: Native
switchRole: Principal
switchDomain: 1
switchId: fffc01
switchWwn: 10:00:c4:f5:7c:36:5a:13
zoning: ON (HPE18_SWITCH01_EMC05)
switchBeacon: OFF
FC Router: OFF
FC Router BB Fabric ID: 1
Address Mode: 0
HIF Mode: OFF
Index Port Address Media Speed State Proto
============================================================================
0 0 010000 id N16 No_Light FC (No POD License) Disabled
1 1 010100 cu N16 Online FC F-Port
50:01:43:80:36:85:69:68
2 2 010200 cu N16 Online FC F-Port
50:01:43:80:36:85:5f:e4
3 3 010300 cu N16 Online FC F-Port
50:01:43:80:36:85:60:0c
4 4 010400 cu N16 Online FC F-Port
50:01:43:80:36:85:5a:f4
5 5 010500 cu N16 In_Sync FC Disabled (Persistent)

NetAct™ 19 © 2019 Nokia 12


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

6 6 010600 cu N16 In_Sync FC Disabled (Persistent)


7 7 010700 cu N16 In_Sync FC Disabled (Persistent)
8 8 010800 cu N16 In_Sync FC Disabled (Persistent)
9 9 010900 cu N16 In_Sync FC Disabled (Persistent)
10 10 010a00 cu N16 In_Sync FC Disabled (Persistent)
11 11 010b00 cu N16 In_Sync FC (No POD License) Disabled
(Persistent)
12 12 010c00 cu N16 In_Sync FC (No POD License) Disabled
(Persistent)
13 13 010d00 cu N16 In_Sync FC (No POD License) Disabled
(Persistent)
14 14 010e00 cu N16 In_Sync FC (No POD License) Disabled
(Persistent)
15 15 010f00 cu N16 In_Sync FC (No POD License) Disabled
(Persistent)
16 16 011000 cu N16 In_Sync FC (No POD License) Disabled
(Persistent)
17 17 011100 id N8 Online FC F-Port
50:06:01:69:09:60:14:a7
18 18 011200 id N8 Online FC F-Port
50:06:01:60:09:60:14:a7
19 19 011300 id N8 Online FC F-Port
50:06:01:68:09:60:0c:4b
20 20 011400 id N8 Online FC F-Port
50:06:01:60:09:60:0c:4b
21 21 011500 id N16 No_Light FC
22 22 011600 id N16 No_Light FC
23 23 011700 id N16 No_Light FC (No POD License) Disabled
24 24 011800 id N16 No_Light FC (No POD License) Disabled
25 25 011900 id N16 No_Light FC (No POD License) Disabled
26 26 011a00 id N16 No_Light FC (No POD License) Disabled
27 27 011b00 id N16 No_Light FC (No POD License) Disabled

3. Identify the G_Port status of specific port number by entering:

sw0:admin > portcfgshow <SAN switch port number>

Repeat the same on all the SAN switch ports connected to EMC Service Processors.

Sample output:

In this case, SAN Switch port 17 is used for identifying the status.

sw0:admin> portcfgshow 17
Area Number: 17
Speed Level: AUTO(SW)

NetAct™ 19 © 2019 Nokia 13


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

AL_PA Offset 13: OFF


Trunk Port ON
Long Distance OFF
VC Link Init OFF
Locked L_Port OFF
Locked G_Port OFF
Disabled E_Port OFF
Locked E_Port OFF
ISL R_RDY Mode OFF
RSCN Suppressed OFF
Persistent Disable OFF
LOS TOV mode 0(OFF)
NPIV capability ON
QOS Port AE
Port Auto Disable: OFF
Rate Limit OFF
EX Port OFF
Mirror Port OFF
SIM Port OFF
Credit Recovery ON
F_Port Buffers OFF
E_Port Credits OFF
Fault Delay: 0(R_A_TOV)
NPIV PP Limit: 126
NPIV FLOGI Logout: OFF
CSCTL mode: OFF
TDZ mode: OFF
D-Port mode: OFF
D-Port over DWDM: OFF
Compression: OFF
Encryption: OFF
FEC: ON
FEC via TTS: OFF
8G Non-DFE: OFF(Auto)
sw0:admin>

4. Set SAN switch port to G_Port by entering:

NetAct™ 19 © 2019 Nokia 14


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

In this case, SAN Switch port 17 used for setting G_Port to enabled. Repeat the steps on all the
SAN switch ports connected to EMC Service Processors.

sw0:admin > portcfggport 17 1

5. Verify that locked G port state is now set to ON for specified SAN Switch ports by entering:

sw0:admin > portcfgshow <SAN switch port group>

Sample output:

In this case, status of SAN Switch port 17 is verified.

sw0:admin> portcfgshow 17
Area Number: 17
Speed Level: AUTO(SW)
AL_PA Offset 13: OFF
Trunk Port ON
Long Distance OFF
VC Link Init OFF
Locked L_Port OFF
Locked G_Port ON
Disabled E_Port OFF
Locked E_Port OFF
ISL R_RDY Mode OFF
RSCN Suppressed OFF
Persistent Disable OFF
LOS TOV mode 0(OFF)
NPIV capability ON
QOS Port AE
Port Auto Disable: OFF
Rate Limit OFF
EX Port OFF
Mirror Port OFF
SIM Port OFF
Credit Recovery ON
F_Port Buffers OFF
E_Port Credits OFF
Fault Delay: 0(R_A_TOV)
NPIV PP Limit: 126
NPIV FLOGI Logout: OFF
CSCTL mode: OFF
TDZ mode: OFF
D-Port mode: OFF
D-Port over DWDM: OFF

NetAct™ 19 © 2019 Nokia 15


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

Compression: OFF
Encryption: OFF
FEC: ON
FEC via TTS: OFF
8G Non-DFE: OFF(Auto)

6. Repeat this locked G port state setting to ON to the remaining EMC connected external SAN
Switch ports identified in step 2.

7. Repeat steps 3 to 5 for the second SAN switch ports where EMC storage is connected.

Expected outcome

The SAN switch port is configured with G-port ON state.

4.4 Disable RDP feature from SAN switch


HPE Brocade Storage Area Network (SAN) switch introduced a new feature Read Diagnostics Para-
meters (RDP) from Fabric Operating System (FOS) version 7.3.x and above. RDP provides optics and
media diagnostics. From any point in the fabric, an administrator can use RDP to easily discover and
diagnose link-related errors and degrading conditions on any N_Port-to-F_Port link. This feature is not
required for NetAct, hence Nokia recommends to disable this feature from SAN switches.

RDP is enabled by default in SAN switches with FOS release 7.3.x but in later versions of FOS it is al-
so disabled by default, hence, it is mandatory to first check whether RDP is enabled or not. In case, if
RDP is enabled in the SAN switches, then it must be disabled as per NetAct recommendation.

RDP is an extended or additional diagnostic feature, hence there is no functional impacts on NetAct
storage IO.

To disable RDP, it is mandatory to disable the SAN switch. All the communication from that SAN switch
to servers and storage will be terminated, that is, one HBA port in every ESXi hosts will be down dur-
ing the activity. The SAN switch can be disabled without any application down time if NetAct is already
running since this is done one SAN switch at a time and other SAN switch is available to handle the
storage communication.

4.4.1 Checking the current RDP status in the SAN switch


Provides the instructions to check the current RDP status in the SAN switch.

1. Log in to the SAN switch as an admin privileged user through SSH.

2. Check the current RDP status in Storage Area Network (SAN) switch by entering:

admin> configshow | grep -i rdp

NetAct™ 19 © 2019 Nokia 16


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

Expected outcome

Sample output:

fabric.rdp_poll_cycle:1

Here in the output 1 means RDP poll cycle is enabled and it is set to 1 hour.

If the output is 0, it means that RDP poll cycle is disabled since it is set to 0 hour. If it is disabled
(fabric.rdp_poll_cycle:0), then no need to execute the remaining sections in this
document.

4.4.2 Verifying existing NetAct system before disabling RDP in the SAN switch
Provides instructions to verify the existing NetAct system before disabling RDP in SAN switch.

In case NetAct is already running and this change is required to be done as part of NetAct firmware
upgrade, then ensure that both the FC HBA links (link state) are up, before disabling one of the switch-
es in Storage Area Network (SAN).

1. Log in to the ESXi host as a root user through SSH.

2. Verify that both FC HBA links are up by entering:

[root@esx095:~] esxcli storage core adapter list

Sample output:

HBA Name Driver Link State UID Capabilities Description


-------- ---------- ---------- ----- ------------
vmhba0 hpsa link-n/a sas.500143803506f9a0
(0000:07:00.0) Hewlett-Packard Company
Smart Array P244br
vmhba1 qlnativefc link-up fc.5001438024d310f9:5001438024d310f8
Data Integrity, Second Level Lun ID (0000:09:00.0) QLogic Corp 2600
Series 16Gb Fibre Channel to PCI Express HBA
vmhba2 qlnativefc link-up fc.5001438024d310fb:5001438024d310fa
Data Integrity, Second Level Lun ID (0000:09:00.1) QLogic Corp 2600
Series 16Gb Fibre Channel to PCI Express HBA

3. Log in to the remaining ESXi hosts as a root user through SSH and execute the command in step
2 and verify that both the FC HBA links are up.

This needs to be checked all the ESXi hosts used in the Cluster and if any link is found to be bro-
ken in any of the ESXi host, do not execute the procedure Disable RDP feature from SAN switch
instead contact hardware vendor to check why the link is not available.

NetAct™ 19 © 2019 Nokia 17


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

Note: In NetAct running production systems executing this chapter without having Link
State as link-up for both HBA FC ports will create outage in NetAct system, hence it is
mandatory to check that the SAN cabling is done as per NetAct recommendation and
both FC HBA links are up before proceeding with the next steps.

4.4.3 Checking the overall SAN switch status


Provides instructions to check the overall Storage Area Network (SAN) switch status.

1. Log in to the first SAN switch through SSH as an admin privileged user.

2. Check the overall SAN switch status by entering:

admin> switchshow

Expected outcome

Sample output:

switchName: hpe14san1
switchType: 72.3
switchState: Online
switchMode: Native
switchRole: Principal
switchDomain: 1
switchId: fffc01
switchWwn: 10:00:50:eb:1a:29:a8:73
zoning: ON (HP3PAR2_HPE14_BLRVSE07)
switchBeacon: OFF
HIF Mode: OFF
Index Port Address Media Speed State Proto
==================================================
0 0 010000 id N8 No_Light FC
1 1 010100 cu N8 Online FC F-Port
50:01:43:80:24:d3:10:f8
2 2 010200 cu N8 Online FC F-Port
50:01:43:80:24:d3:11:08
3 3 010300 cu N8 Online FC F-Port
50:01:43:80:24:d3:0f:50
4 4 010400 cu N8 Online FC F-Port
50:01:43:80:24:d3:0f:84
5 5 010500 cu N8 Online FC F-Port
50:01:43:80:24:d3:0f:78

NetAct™ 19 © 2019 Nokia 18


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

6 6 010600 cu N8 Online FC F-Port


50:01:43:80:31:7f:d0:fc
7 7 010700 cu AN No_Sync FC Disabled (Persistent)
8 8 010800 cu N8 Online FC F-Port
50:01:43:80:14:0f:fa:c4
9 9 010900 cu AN No_Sync FC
10 10 010a00 cu AN No_Sync FC
11 11 010b00 cu AN No_Sync FC
12 12 010c00 cu N8 Online FC F-Port
50:01:43:80:29:6c:d8:28
13 13 010d00 cu AN No_Sync FC
14 14 010e00 cu N8 Online FC F-Port
50:01:43:80:29:6d:1b:9c
15 15 010f00 cu AN No_Sync FC Disabled (Persistent)
16 16 011000 cu N8 Online FC F-Port
50:01:43:80:14:0f:fa:44
17 17 011100 id N8 Online FC F-Port
20:11:00:02:ac:00:7f:0c
18 18 011200 id N8 Online FC F-Port
21:11:00:02:ac:00:7f:0c
19 19 011300 id N8 Online FC F-Port
20:70:00:c0:ff:27:08:e7
20 20 011400 id N8 No_Light FC
21 21 011500 id N8 Online FC F-Port
22:23:00:02:ac:00:7e:8b
22 22 011600 id N8 Online FC F-Port
23:24:00:02:ac:00:7e:8b
23 23 011700 id N8 No_Light FC

4.4.4 Checking current FOS version running on the SAN switch


Provides the instructions to check the current Fabric Operating System (FOS) version running on the Storage Area Network
(SAN) switch.

1. Log in to the SAN switch through SSH as an admin privileged user.

2. Check the current Fabric Operating System (FOS) version running on the SAN switch by entering:

admin> firmwareshow

NetAct™ 19 © 2019 Nokia 19


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

Expected outcome

Sample output:

Appl Primary/Secondary Versions


------------------------------------------
FOS v7.4.1c
v7.4.1c

Note: RDP Polling is only available on SAN Switch having FOS version 7.3.x onwards.

4.4.5 Checking the current RDP polling status in the SAN switch
Provides the instructions to check the current RDP polling status in the Storage Area Network (SAN) switch.

1. Log in to the SAN switch through SSH as an admin privileged user.

2. Check the current RDP polling status in the SAN switch by entering:

admin> configshow | grep -i rdp

Expected outcome

Sample output:

fabric.rdp_poll_cycle:1

Here in the output 1 means RDP poll cycle is enabled and it is set to 1 hour.

4.4.6 Taking a local copy of SAN switch current configuration


Provides the instructions to take a local copy of the current Storage Area Network (SAN) switch configuration.

1. Log in to the SAN switch through SSH as an admin privileged user.

2. Take a backup of the current configuration locally by entering:

admin> configupload -all -local config.txt

Note: If ftp or sftp server is available, it is recommended to take a backup of the


configuration in the remote sftp or ftp server.

Expected outcome

Sample output:

NetAct™ 19 © 2019 Nokia 20


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

configUpload complete: All selected config parameters are uploaded

4.4.7 Disabling the SAN switch and checking the status of the switch
Provides the instructions to disable the Storage Area Network (SAN) switch and to verify the status of the switch.

1. Log in to the SAN switch through SSH as an admin privileged user.

2. Disable the SAN switch by entering:

admin> switchdisable

Note: The above command disables the switch and no storage communication is
possible from the switch towards both servers and storages.

3. Check the status of the SAN switch by entering:

admin> switchshow

Sample output:

switchName: hpe14san1
switchType: 72.3
switchState: Offline
switchMode: Native
switchRole: Disabled
switchDomain: 1 (unconfirmed)
switchId: fffc01
switchWwn: 10:00:50:eb:1a:29:a8:73
zoning: ON (HP3PAR2_HPE14_BLRVSE07)
switchBeacon: OFF
HIF Mode: OFF
Index Port Address Media Speed State Proto
=====================================================================
0 0 010000 id N8 No_Light FC Disabled
1 1 010100 cu AN No_Sync FC Disabled
2 2 010200 cu AN No_Sync FC Disabled
3 3 010300 cu AN No_Sync FC Disabled
4 4 010400 cu AN No_Sync FC Disabled
5 5 010500 cu AN No_Sync FC Disabled
6 6 010600 cu AN No_Sync FC Disabled
7 7 010700 cu AN No_Sync FC Disabled (Persistent)
8 8 010800 cu AN No_Sync FC Disabled
9 9 010900 cu AN No_Sync FC Disabled

NetAct™ 19 © 2019 Nokia 21


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

10 10 010a00 cu AN No_Sync FC Disabled


11 11 010b00 cu AN No_Sync FC Disabled
12 12 010c00 cu AN No_Sync FC Disabled
13 13 010d00 cu AN No_Sync FC Disabled
14 14 010e00 cu AN No_Sync FC Disabled
15 15 010f00 cu AN No_Sync FC Disabled (Persistent)
16 16 011000 cu AN No_Sync FC Disabled
17 17 011100 id N8 In_Sync FC Disabled
18 18 011200 id N8 In_Sync FC Disabled
19 19 011300 id N8 No_Sync FC Disabled
20 20 011400 id N8 No_Light FC Disabled
21 21 011500 id N8 In_Sync FC Disabled
22 22 011600 id N8 No_Light FC Disabled
23 23 011700 id N8 No_Light FC Disabled

Expected outcome

The SAN switch is disabled.

4.4.8 Disabling the RDP polling in the SAN switch and checking the status
Provides the instructions to disable the RDP polling in the SAN switch and to verify the status.

The configure command is used to disable RDP polling in the SAN switch. Ensure that only the
RDP Polling option alone is modified to 0 (zero) and rest all other options are not modified when
prompted. By just pressing ENTER key from the keyboard for any option prompted does not make any
changes. If not familiar with Brocade SAN fabric OS commands, it is recommended to take help from
HPE hardware vendor. Refer to Brocade Fabric OS Administration Guide for Fabric OS commands.

Only enter 0 (zero) when prompted for RDP Polling Cycle(hours)[0 = Disable Polling]:
(0..24) [1] and for remaining other options just press ENTER key from the keyboard when it is
prompted to keep the current value.

1. Log in to the SAN switch through SSH as an admin privileged user.

2. Disable the RDP polling by entering:

admin> configure

Set the parameter RDP Polling Cycle(hours)[0 = Disable Polling]: (0..24) [1] value to 0 to disable
RDP polling.

Sample output:

Configure...
Fabric parameters (yes, y, no, n): [no]
Virtual Channel parameters (yes, y, no, n): [no]
F-Port login parameters (yes, y, no, n): [no]

NetAct™ 19 © 2019 Nokia 22


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

D-Port Parameters (yes, y, no, n): [no]


RDP Polling Cycle(hours)[0 = Disable Polling]: (0..24) [1] 0
Zoning Operation parameters (yes, y, no, n): [no]
RSCN Transmission Mode (yes, y, no, n): [no]
Arbitrated Loop parameters (yes, y, no, n)n: [no]
System services (yes, y, no, n): [no]
Portlog events enable (yes, y, no, n): [no]
ssl attributes (yes, y, no, n): [no]
rpcd attributes (yes, y, no, n): [no]
cfgload attributes (yes, y, no, n): [no]
webtools attributes (yes, y, no, n): [no]

3. Verify that RDP Polling is disabled by entering:

admin> configshow | grep -i rdp

Expected outcome

fabric.rdp_poll_cycle:0

Changing the RDP polling cycle to 0 is an offline action. It can be done one switch in fabric at a
time without application down time.

4.4.9 Enabling the SAN switch and checking the RDP polling status
Provides instructions to enable the Storage Area Network (SAN) switch and to check the RDP polling status.

1. Log in to the SAN switch through SSH as an admin privileged user.

2. Enable the SAN switch by entering:

admin> switchenable

3. Check the RDP Polling status by entering:

admin> configshow | grep -i rdp

Sample output:

fabric.rdp_poll_cycle:0

4. Verify that the switch is returning back to normal operation by entering:

admin> switchshow

NetAct™ 19 © 2019 Nokia 23


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

Note: Normally it takes 2 to 3 minutes to reflect the correct switch status change after
executing the switchenable command. Execute the switchshow command after two
minutes.

Expected outcome

Sample output:

switchName: hpe14san1
switchType: 72.3
switchState: Online
switchMode: Native
switchRole: Principal
switchDomain: 1
switchId: fffc01
switchWwn: 10:00:50:eb:1a:29:a8:73
zoning: ON (HP3PAR2_HPE14_BLRVSE07)
switchBeacon: OFF
HIF Mode: OFF
Index Port Address Media Speed State Proto
==================================================
0 0 010000 id N8 No_Light FC
1 1 010100 cu N8 Online FC F-Port
50:01:43:80:24:d3:10:f8
2 2 010200 cu N8 Online FC F-Port
50:01:43:80:24:d3:11:08
3 3 010300 cu N8 Online FC F-Port
50:01:43:80:24:d3:0f:50
4 4 010400 cu N8 Online FC F-Port
50:01:43:80:24:d3:0f:84
5 5 010500 cu N8 Online FC F-Port
50:01:43:80:24:d3:0f:78
6 6 010600 cu N8 Online FC F-Port
50:01:43:80:31:7f:d0:fc
7 7 010700 cu AN No_Sync FC Disabled (Persistent)
8 8 010800 cu N8 Online FC F-Port
50:01:43:80:14:0f:fa:c4
9 9 010900 cu N8 Online FC F-Port
50:01:43:80:29:6d:1b:5c
10 10 010a00 cu N8 Online FC F-Port
50:01:43:80:29:6d:1a:40
11 11 010b00 cu N8 Online FC F-Port
50:01:43:80:29:6d:1b:cc

NetAct™ 19 © 2019 Nokia 24


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

12 12 010c00 cu N8 Online FC F-Port


50:01:43:80:29:6c:d8:28
13 13 010d00 cu N8 Online FC F-Port
50:01:43:80:29:6d:1b:8c
14 14 010e00 cu N8 Online FC F-Port
50:01:43:80:29:6d:1b:9c
15 15 010f00 cu AN No_Sync FC Disabled (Persistent)
16 16 011000 cu N8 Online FC F-Port
50:01:43:80:14:0f:fa:44
17 17 011100 id N8 Online FC F-Port
20:11:00:02:ac:00:7f:0c
18 18 011200 id N8 Online FC F-Port
21:11:00:02:ac:00:7f:0c
19 19 011300 id N8 Online FC F-Port
20:70:00:c0:ff:27:08:e7
20 20 011400 id N8 No_Light FC
21 21 011500 id N8 Online FC F-Port
22:23:00:02:ac:00:7e:8b
22 22 011600 id N8 Online FC F-Port
23:24:00:02:ac:00:7e:8b
23 23 011700 id N8 No_Light FC

4.4.10 Verifying that ESXi sees both links are up


Provides instructions to verify that from ESXi both the Fibre Channel (FC) HBA links are up.

In case NetAct is already running and the Read Diagnostics Parameters (RDP) disabling instructions
are executed as mentioned in Disabling the RDP polling in the SAN switch and checking the status,
then ensure that both FC HBA links (Link state = link-up) are up which means server blade system
is back to normal state.

1. Log in to ESXi host through SSH as a root user.

2. Verify that both the FC HBA links are up by entering:

[root@esx095:~] esxcli storage core adapter list

Sample output:

HBA Name Driver Link State UID Capabilities Description


-------- ---------- ---------- ----- ------------ --------
vmhba0 hpsa link-n/a sas.500143803506f9a0
(0000:07:00.0) Hewlett-Packard
Company Smart Array P244br

NetAct™ 19 © 2019 Nokia 25


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

vmhba1 qlnativefc link-up fc.5001438024d310f9:5001438024d310f8


Data Integrity, Second Level Lun ID (0000:09:00.0) QLogic Corp 2600
Series 16Gb Fibre Channel to PCI Express HBA
vmhba2 qlnativefc link-up fc.5001438024d310fb:5001438024d310fa
Data Integrity, Second Level Lun ID (0000:09:00.1) QLogic Corp 2600
Series 16Gb Fibre Channel to PCI Express HBA

3. Log in to the remaining ESXi hosts through SSH as a root user and verify that both the FC HBA
links are up by entering:

esxcli storage core adapter list

4.5 Disabling RDP feature on the second SAN switch


Change the RDP polling intervals for the second Storage Area Network (SAN) switch by following the
instructions from sections Checking the current RDP status in the SAN switch to Verifying that ESXi
sees both links are up.

4.6 Configuring fillword value for 8GB FC SAN switch


Provides instructions to configure fillword for HPE Brocade 8GB Storage Area Network (SAN) switch.

Execute this procedure only if there any HPE Brocade 8GB SAN switches in use. This procedure is
not required for HPE Brocade 16GB SAN switches.

Due to excessive CRC and decode errors found in 8GB ports Brocade connected to Qlogic results
in device disconnection. Decode errors indicate failure on QLogic devices. Failure on a Brocade
switch may be indicated by a few er_enc_out errors and large number of er_bad_os errors. HPE
recommends to set the fillword parameter to value 3 on HP Brocade 8GB SAN switches.

1. Log in to SAN switch through SSH client an admin privileged user.

2. Set the fillword value in SAN switch by entering:

For example, example if the SAN port is connected to port 20, to set its fillword value to 3, enter:

Brocade:admin> portcfgfillword 20, 3

3. Confirm the changes by entering:

Brocade:admin> portcfgshow <port to which SAN port is connected>

For example:

Brocade:admin> portcfgshow 20

NetAct™ 19 © 2019 Nokia 26


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

Sample output:

Area Number: 1
Speed Level: AUTO(HW)
Fill Word(On Active) 3(Arbff-Arbff) Word(Current)
3(Arbff-Arbff)
AL_PA Offset 13: OFF
Trunk Port OFF
Long Distance OFF
VC Link Init OFF

4. Save the changes.

5. Repeat the steps 1 to 4 for the other ports or SAN switches.

Expected outcome

Fillword is configured for HPE Brocade 8GB SAN switch.

4.7 Configuring Port Zoning


Provides instructions to configure port zoning.

By default, NetAct uses port zoning, which is sufficient for most installation purposes and standard
configurations. If you need World Wide Names (WWN) zoning, see Configuring WWN Zoning.

Note: Each HBA port of the server should be zoned. Each zone definition contains the HBA
port and the respective storage ports where the server needs access and has connection.

WARNING! When there is a connection to the customer’s SAN or to other FC switches, be


very careful when configuring, because the commands you enter will affect the entire SAN.
For example, the cfgclear command clears all the configuration in the fabric.

1. Open an SSH session to the first SAN switch.

Use the username admin and the password password.

2. Give a name to the switch by entering:

switchname <SwitchName>

NetAct™ 19 © 2019 Nokia 27


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

For example:

switchname LAB_1_SAN2

3. Disable the configuration by entering:

cfgdisable

4. Optional: Clear the zone configuration by entering:

cfgclear

Note: cfgclear command clears all the configuration in the fabric.

5. Create a zone by entering:

zonecreate "<Zone>", "<DID>,<Port>[;<DID>,<Port>]"

Where:

<Zone>: Unique name for zone.


<Port>: Server or Storage Controller port.
<DID>: Switch domain ID.

The zone contains the server port and the port addresses of all the storage devices the server port
is supposed to access.

Note: Repeat this command for every server that needs FC connectivity.

For example:

zonecreate "Zone_1", "127,1;127,19;127,20"

6. Create a zone for an SMA server if necessary by entering:

zonecreate "Zone_SMA", "<DID>,<Port>[;<DID>,<Port>]"

where:

<Port>: Server or Storage Controller port.


<DID>: Switch domain ID.

NetAct™ 19 © 2019 Nokia 28


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

Note: The HP 3PAR and DELL EMC storage arrays do not need an SMA zone.

For example:

cfgcreate "Switch_127_Zone", "Zone_1;Zone_2;Zone_SMA"

7. Create zone configuration by entering:

cfgcreate "<Config>, "<Zone>[;<Zone>]"

where:

<Config>: Unique name for zone configuration.


<Zone>: Unique name for zones.

For example:

cfgcreate "Switch_127_Zone", "Zone_1;Zone_2;Zone_SMA"

8. Enable zone configuration by entering:

cfgenable "<Config>"

where:

<Config> Unique name for zone configuration.

For example:

cfgenable "Switch_127_Zone"

9. Review the switch fabric configuration by entering:

cfgShow

10. Save the configuration by entering:

cfgSave

11. Close the management session by entering:

exit

12. Repeat this procedure on the other SAN switch.

NetAct™ 19 © 2019 Nokia 29


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

Expected outcome

The port zoning is configured for the SAN switch.

4.8 Configuring WWN Zoning


Provides the instructions to configure WWN zoning.

Prerequisites

• Ensure that all servers and storage devices are connected to Fibre Channel (FC) switches as
planned and are online.
• Ensure that all servers are booted to the QLogic BIOS and the FC connections are initialized. See
Appendix: Configuring QLogic Fast!UTIL BIOS settings for SAN switch zoning for the instructions
to boot servers to QLogic BIOS and to ensure that the FC connections are initialized.

If the default port zoning does not suit to the local requirements (especially in OpenSAN and shared
array implementations), you can use these instructions to use World Wide Names (WWN) zoning in-
stead of port zoning.

Note:

• If the FC switches are already configured to use port zoning, you can skip this section.
• Each HBA port of the server should be zoned and each zone definition contains the
HBA port and the respective storage ports where the server needs access and has
connection.

WARNING! When there is a connection to the customer’s SAN or to other FC switches, be


very careful when configuring, because the commands you enter will affect the entire SAN.
For example, the cfgclear command clears all the configuration in the fabric.

1. Open an SSH session to the first SAN switch.

Use the username admin and the password password.

2. Give a name to the switch by entering:

switchname <SwitchName>

NetAct™ 19 © 2019 Nokia 30


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

For example:

switchname LAB_1_SAN2

3. Disable the configuration by entering:

cfgdisable

4. Optional: Clear the zone configuration by entering:

cfgclear

Note: cfgclear command clears all the configuration in the fabric.

5. Check the WWNs of all attached devices by entering:

switchShow

Note: This command provides the WWNs of the devices attached to each port. Ensure
that the ports are denoted as F-ports (Fabric ports) and the state of the ports is online.

6. Create a single zone for each server port by entering:

zoneCreate "<zone_name>", "<server-port-WWN>; \


<stor1-port-WWN1>; …; <storN-port-WWN>"

For example:

zoneCreate "Zone_1", "00:11:22:33:44:55:66:77:88:99:AA:BB:CC:DD:EE:F0; \


00:11:22:33:44:55:66:77:88:99:AA:BB:CC:DD:EE:F1; …; \
00:11:22:33:44:55:66:77:88:99:AA:BB:CC:DD:EE:FF "

7. Create a new configuration (configuration profile) containing all of the above zones by entering:

cfgCreate "<cfg_name>", "<zone_name1>; …;<zone_nameN>"

Note: The first parameter is the name of the configuration profile. The second parameter
is an enumeration of the participating zones. You can define several configuration profiles
for each SAN fabric, but only one profile can be active at a time.

For example:

cfgCreate "LAB_1_SAN2_Zones", "Zone_1; …;Zone_N"

NetAct™ 19 © 2019 Nokia 31


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

Note: You can select the zone names freely, as long as they are unique within the
SAN. If necessary, the configuration of each zone can be further manipulated with the
zoneAdd and zoneRemove commands. For more information, use the zoneHelp
command.

Before using the zoneCreate command, use the aliCreate command to make an
alias from the WWN.

8. Activate the configuration profile by entering:

cfgEnable "<zone_name>"

9. Review the switch fabric configuration by entering:

cfgShow

10. Save the configuration by entering:

cfgSave

11. Close the management session by entering:

exit

12. Repeat this procedure on the other SAN switch.

Expected outcome

The WWN zoning of the SAN switch is configured.

4.9 Disabling telnet access to SAN switch (BROCADE) using IPv4


address
Provides instructions to disable telnet access to SAN switch using IPv4.

1. Log in to SAN switch as an admin privileged user.

2. As it is not possible to change the default filter sets, clone the default_ipv4 to new set by entering:

ipfilter --clone <profilename> -from default_ipv4

NetAct™ 19 © 2019 Nokia 32


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

For example:

ipfilter --clone BlockPort23 -from default_ipv4

3. Verify the rule number for the telnet port (23) by entering:

ipfilter --show

The default rule for telnet is 2.

4. Delete the old rule and create the new rule by entering:

Change the -rule 2 to the appropriate rule number from the previous step, if needed.

ipfilter --delrule <profilename> -rule 2 ipfilter --addrule


<profilename> -rule 2 -sip any -dp 23 -proto tcp -act deny

For example:

ipfilter --delrule BlockPort23 -rule 2 ipfilter --addrule BlockPort23


-rule 2 -sip any -dp 23 -proto tcp -act deny

5. Save and activate the new filter set by entering:

ipfilter --save <profilename> ipfilter --activate <profilename>

For example:

ipfilter --save BlockPort23 ipfilter --activate BlockPort23

6. Verify the changes by entering:

ipfilter --show

Sample output:

hpe14san1:admin> ipfilter --show


Name: BlockPort23, Type: ipv4, State: active
Rule Source IP Protocol Dest Port Action
1 any tcp 22 permit
2 any tcp 23 deny
3 any tcp 80 permit
4 any tcp 443 permit
5 any udp 161 permit
6 any udp 123 permit
7 any tcp 600 - 1023 permit

NetAct™ 19 © 2019 Nokia 33


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

8 any udp 600 - 1023 permit

7. Repeat the steps 1 to 6 on the second SAN switch.

Expected outcome

Telnet access to SAN switch is disabled.

4.10 Disabling telnet access to SAN switch (BROCADE) using IPv6


address
Provides instructions to disable telnet access to SAN switch using IPv6.

1. Log in to SAN switch as an admin privileged user.

2. As it is not possible to change the default filter sets, clone the default_ipv6 to new set by entering:

ipfilter --clone <profilename> -from default_ipv6

For example:

ipfilter --clone BlockPort23ipv6 -from default_ipv6

3. Verify the rule number for telnet port (23) by entering:

ipfilter --show

The default rule for telnet is 2.

4. Delete the old rule and create the new rule by entering:

Change the -rule 2 to the appropriate rule number from the previous step, if needed.

ipfilter --delrule <profilename> -rule 2 ipfilter --addrule


<profilename> -rule 2 -sip any -dp 23 -proto tcp -act deny

For example:

ipfilter --delrule BlockPort23ipv6 -rule 2ipfilter --addrule


BlockPort23ipv6 -rule 2 -sip any -dp 23 -proto tcp -act deny

5. Save and activate the new filter set by entering:

ipfilter --save <profilename> ipfilter --activate <profilename>

NetAct™ 19 © 2019 Nokia 34


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

For example:

ipfilter --save BlockPort23ipv6 ipfilter --activate BlockPort23ipv6

6. Verify the changes by entering:

ipfilter --show

Sample output:

hpe14san1:admin> ipfilter --show


Name: BlockPort23ipv6, Type: ipv6, State: active
Rule Source IP Protocol Dest Port Action
1 any tcp 22 permit
2 any tcp 23 deny
3 any tcp 80 permit
4 any tcp 443 permit
5 any udp 161 permit
6 any udp 123 permit
7 any tcp 600 - 1023 permit
8 any udp 600 - 1023 permit

7. Repeat the steps 1 to 6 on second SAN switch.

Expected outcome

Telnet access to SAN switch is disabled.

4.11 Enabling https and disabling http


Provides instructions to enable https and to disable http.

To enable https, SSL certificate must be installed in the switch.

To install third party signed SSL certificate, follow the instructions in Security Management > Security
Management Operating Procedures > Administering NetAct System Security > Managing certificates
for hardware devices in NetAct Operating Documentation.

1. Log in to SAN switch as an admin privileged user.

2. Disable http by entering:

switch:admin> ipfilter --clone BlockHTTP -from default_ipv4


switch:admin> ipfilter --save BlockHTTP
switch:admin> ipfilter –-show
switch:admin> ipfilter --addrule BlockHTTP -rule 2 -sip any -dp 80 -
proto tcp -act deny

NetAct™ 19 © 2019 Nokia 35


Configuring Storage Area Network 2-0 Creating SAN configuration
Switches

switch:admin> ipfilter --save BlockHTTP


switch:admin> ipfilter --activate BlockHTTP

Expected outcome

The http access is disabled and https access is enabled.

NetAct™ 19 © 2019 Nokia 36


Configuring Storage Area Network 2-0 Managing the switch
Switches

5 Managing the switch

Run these commands either from the command-line interface through SSH or from the web interface
(including the switch status overview).

Command Description

switchShow Provides the basic switch and port status. Ports with at-
tached servers or storage devices are denoted as "F-ports",
the inter-switch links are denoted as an "E-port".

nsShow / nsAllShow Lists the contents of a local/global routing table. This pro-
vides information about all the attached devices.

fabricShow Lists all the known switches in the fabric.

portDisable <N> Disables data routing through a certain port.

portEnable <N> Enables data routing through a certain port.

switchDisable Disables the switch functionality.

switchEnable Enables the switch functionality.

configure Configures critical parameters. The switch has to be dis-


abled for this command to work.

zoneCreate Creates a logical group of ports (zone).

cfgCreate Creates an individual configuration profile.

cfgEnable Makes certain configuration profile active.

cfgShow Reviews all configuration profiles.

cfgSave Declares currently active configuration as power-on default.

zoneHelp Provides an extensive help on all zoning-related com-


mands.

Killtelnet Terminates pending Telnet/SSH sessions. (FOS 4.x)

Reboot Reboots the switch.

tsTimeServer Defines the NTP server for obtaining reference time. (FOS
4.x)

tsTimeZone Converts the timezone from one format to another. For ex-
ample, UTC time into local time. (FOS 4.x)

Version Prints firmware (Fabric OS) version.

Exit Terminates switch management session.

NetAct™ 19 © 2019 Nokia 37


Configuring Storage Area Network 2-0 Managing the switch
Switches

Table 2: Important management commands

A comprehensive description of the commands in Fabric OS is available with the help command. Use
the help <commandname> command to view help for any of the commands in Table 2: Important
management commands.

NetAct™ 19 © 2019 Nokia 38


Configuring Storage Area Network 2-0 Configure SNMP
Switches

6 Configure SNMP

Switches are configured to send SNMP traps to HPSIM. Alarms with severity level of critical and major
are forwarded to NetAct Monitor.

For more information on how to configure SNMP, see Integrating Brocade SAN switch with HPSIM.

NetAct™ 19 © 2019 Nokia 39


Configuring Storage Area Network 2-0 Appendix: Configuring QLogic Fast!UTIL
Switches BIOS settings for SAN switch zoning

7 Appendix: Configuring QLogic Fast!UTIL BIOS


settings for SAN switch zoning
Provides instructions to configure SAN switch zoning to boot to Qlogic HBA FastUtil BIOS.

Prerequisites

To configure World Wide Names (WWN) based zoning the server must be powered on and booted to
Qlogic HBA FastUtil BIOS or to any operating system if the server is already installed with OS.

HPE C7000 configuration must be completed to access the servers and its iLO. Execute the instruc-
tions in the chapter Installing and configuring the HPE Blade System c7000 from the document In-
stalling and configuring HPE Blade System c7000.

To boot to Qlogic HBA FastUtil BIOS, do the following steps:

1. Log in to Onboard Administrator web page as a user with administrative privileges.

2. Navigate to Device Bays and select the server.

3. Click iLO on the respective server.

4. Click Integrated Remote Console or Remote Console.

5. Power on the server and follow the booting messages on the console. Press any key to get
optional boot options.

6. When the text Press< CTRL-Q> or <ALT-Q> for Fast!UTIL appears, use either key combination
to access QLogic Fast!UTIL BIOS screen.

7. Press ENTER to open the Fast!UTIL Options window.

8. Select the first adapter and then press ENTER.

9. Select Scan Fibre Devices and press ENTER.

10. Press ESC.

11. Select Select Host Adapter.

12. Select the second adapter and then press ENTER to update the second SAN switch zoning.

13. Select Scan Fibre Devices and press ENTER.

14. Press ESC.

Do not exit from the Qlogic HBA BIOS.

15. Repeat the steps 1 to 14 for all the other servers.

NetAct™ 19 © 2019 Nokia 40


Configuring Storage Area Network 2-0 Appendix: Configuring QLogic Fast!UTIL
Switches BIOS settings for SAN switch zoning

Expected outcome

The SAN switch zoning is configured to boot to Qlogic HBA FastUtil BIOS.

NetAct™ 19 © 2019 Nokia 41

You might also like