[ Applies to ] StorageGuard 9.x and later / Dell PowerStore systems / PowerStore Manager
StorageGuard collects configuration data from Dell PowerStore storage systems by running read-only REST API calls over HTTPS. This article describes the requirements and how to create the scan account.
In this article
Requirements
| Requirement | Details |
|---|---|
| Manager address | The network name or IP address of each PowerStore Manager. |
| Credentials | A REST API user name and password for each PowerStore Manager. |
| Role and permissions | The account needs an unlimited read-only role that can run all GET API calls, such as api/rest/cluster?select=*, api/rest/policy?select=*, api/rest/smtp_config?select=*, api/rest/snmp_server?select=*, and api/rest/login_banner?select=*. See the role recommendations below. |
| Network access | HTTPS connectivity (port 443) from the StorageGuard server to each PowerStore Manager. |
Create a scan account
The following procedure is a suggested way to create the scan account in PowerStore Manager.
- Sign in to PowerStore Manager.
- Go to Settings, and under Security, click Users.
- Click Add.
- Enter a user name in the Username field, and select a role from the User Role list. See the following table.
- Enter a password in the New Password and Verify Password fields.
- Click Apply.
| Role | What StorageGuard can check |
|---|---|
| Operator (read-only) | Most configuration checks. Some checks, such as local user configuration, can't run with this role. |
| Security Administrator | All configuration checks, including local user configuration. |
Note: Because of current PowerStore role limitations, the read-only Operator role doesn't allow every StorageGuard check to run. Whichever role you choose, StorageGuard runs only read-only API calls.
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.