[ Applies to ] StorageGuard 9.x and later / IBM DS8000 series / DSCLI proxy
StorageGuard collects configuration data from IBM DS8000 systems by running read-only DSCLI commands on one or more UNIX / Linux servers with DSCLI installed, known as DSCLI proxies. Together, the proxies must be able to query every DS8000 system in scope. This article describes the requirements and how to create the scan account.
In this article
Requirements
| Requirement | Details |
|---|---|
| DSCLI proxy address | The network name or IP address of each DSCLI proxy. |
| DSCLI proxy credentials | An OS user account on each DSCLI proxy. |
| DS8000 address | The network name or IP address of each IBM DS8000 system (HMC1). |
| DS8000 credentials | An IBM DS user account, either existing or created for StorageGuard, in the read-only monitor group. Examples of DSCLI commands used: lsarray, lssu, and lsflash. |
| Network access | SSH connectivity (port 22 by default) from the StorageGuard server to each DSCLI proxy, and IP connectivity from each proxy to the DS8000 systems it scans. |
Create a scan account
The following procedure is a suggested way to create a DS8000 user named sguard in the monitor group. You can use any user name.
- Log in to DSCLI with an administrator account.
-
Create the user. Replace
<password>with the account password and<policy_name>with the security policy name:mkuser -pw <password> -group monitor -pol <policy_name> sguard
| Parameter | Description |
|---|---|
-pw |
The initial password for the account. |
-group monitor |
Adds the user to the read-only monitor group. |
-pol |
The security policy to apply to the account. |
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.