Brocade Communications Systems Encryption Switch Service Manual Page 175

  • Download
  • Add to my manuals
  • Print
  • Page
    / 326
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 174
Fabric OS Encryption Administrator’s Guide (DPM) 157
53-1002720-02
Zoning considerations
3
No HA cluster membership
EE Attributes:
Media Type : DISK
EE Slot: 12
SP state: Online
Current Master KeyID:
a3:d7:57:c7:54:66:65:05:61:7a:35:2c:59:af:a5:dc
Alternate Master KeyID:
e9:e4:3a:f8:bc:4e:75:44:81:35:b8:90:d0:1f:6f:4d
HA Cluster Membership: hacDcx3
EE Attributes:
Media Type : DISK
Zoning considerations
When encryption is implemented, frames sent between a host and a target LUN are redirected to a
virtual target within an encryption switch or blade. Redirection zones are created to route these
frames. When redirection zones are in effect, direct access from host to target should not be
allowed to prevent data corruption.
Set zone hosts and targets together before configuring them for encryption. Redirection zones are
automatically created to redirect the host-target traffic through the encryption engine, but
redirection zones can only be created if the host and target are already zoned.
Setting default zoning to no access
Initially, default zoning for all Brocade Encryption Switches is set to All Access. The All Access
setting allows the Brocade Encryption Switch or DCX Backbone chassis to join the fabric and be
discovered before zoning is applied. If there is a difference in this setting within the fabric, the
fabric will segment.
Before committing an encryption configuration in a fabric, default zoning must be set to No Access
within the fabric. The No Access setting ensures that no two devices on the fabric can
communicate with one another without going through a regular zone or a redirection zone.
1. Check the default zoning setting. Commonly, it will be set to All Access.
switch:admin> defzone --show
Default Zone Access Mode
committed - All Access
transaction - No Transaction
2. From any configured primary FCS switch, change the default zoning setting to No Access.
switch:admin> defzone --noaccess
switch:admin> cfgfsave
The change will be applied within the entire fabric.
Page view 174
1 2 ... 170 171 172 173 174 175 176 177 178 179 180 ... 325 326

Comments to this Manuals

No comments