[ Applies to ] StorageGuard 9.x and later / HPE 3PAR, Primera, and Alletra 9000 storage systems / InForm CLI
StorageGuard collects configuration data from HPE 3PAR, Primera, and Alletra 9000 systems by running read-only InForm CLI commands, either directly on the storage system or through a proxy server with the InForm CLI installed (an InForm CLI proxy). This article describes the requirements for both options and how to create the scan account.
Requirements
The following requirements apply whether you scan the storage systems directly or through an InForm CLI proxy.
| Requirement | Details |
|---|---|
| System address | The network name or IP address of each HPE storage system. |
| Credentials | A storage system user account, either existing or created for StorageGuard. |
| Role and permissions | Read-only privileges. The service role is recommended; see the role comparison below. Examples of CLI commands used: showsys -d, showversion -a, and shownode. |
| Encrypted password | Provide StorageGuard with the encrypted password of the storage system account. See Generating encrypted password for HP 3PAR scan. |
| Network access | SSH connectivity (port 22 by default) from the StorageGuard server to each storage system. |
localhost as the proxy IP address in StorageGuard.Additional requirements for an InForm CLI proxy
| Requirement | Details |
|---|---|
| Proxy address | The network name or IP address of the InForm CLI proxy. |
| Proxy credentials | An OS user account on the InForm CLI proxy. |
| Network access | SSH connectivity (port 22 by default) from the StorageGuard server to the proxy, and IP connectivity from the proxy to each HPE storage system it scans. |
Create a scan account
The following procedure is a suggested way to create a user named sguard with the service role. You can use any user name.
- Log in to the storage system CLI with an administrator account.
-
Create the user. Replace
<password>with the account password and<domain>with the domain name:createuser -c <password> sguard <domain> service
| Role | What StorageGuard can check |
|---|---|
| service (recommended) | All checks. This role is required to run the read-only controlencryption status and controlsecurity fips status commands, which are essential for security hardening checks. |
| browse | Most checks. Not recommended, because the encryption and FIPS checks can't run. |
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.