StorageGuard 10.1 collects configuration data from Hitachi VSP storage systems, and from the Hitachi Ops Center management layer, through four dedicated Hitachi REST data sources. Depending on your environment, StorageGuard connects directly to each array, to a central Configuration Manager server, or to Ops Center Common Services.
All collection is read-only. The StorageGuard collector sends GET requests over HTTPS and never writes data to Ops Center or the arrays.
Note: Running StorageGuard 9.2.x or 10.0.x? Those versions use the legacy Hitachi VSP (HiCommand) probe. See Hitachi VSP | Scan Requirements (StorageGuard 9.2.x–10.0.x). If you are upgrading to 10.1, follow Upgrading from an earlier version.
In this article
- How StorageGuard collects Hitachi storage configurations
- Choose a connection option
- Network and security requirements
- Option A: Direct to a single array
- Option B: Centralized Configuration Manager
- Option C: Ops Center Common Services
- Create the scan service accounts
- Verify access before you scan
- Add the data source and run the first scan
- Upgrading from an earlier version
- Troubleshooting
How StorageGuard collects Hitachi storage configurations
StorageGuard 10.1 replaces the legacy Hitachi VSP probe with one data source per Hitachi component. The arrays themselves are collected by the Configuration Manager data source (Options B and C) or by the Hitachi VSP One Block data source (Option A).
| Data source | Connects to | Default port | What StorageGuard collects |
|---|---|---|---|
| Configuration Manager | A Configuration Manager server, in Ops Center or external | 23451 |
Storage configuration for each array it reaches: inventory, users and user groups, external authentication, certificates, encryption, audit log and syslog, SNMP and alert settings, licenses, ports, host groups, pools, volumes, snapshots, and replication |
| Hitachi VSP One Block | The array's SVP, GUM, or controller, directly | 443 |
Storage configuration for that array |
| OpsCenter Common Services | The Common Services (portal and IAM) server | 443 |
Users, user groups and role mappings, password policy, external user storage (LDAP/AD), Kerberos, identity providers, and session settings |
| OpsCenter Administrator | The Ops Center Administrator server | 443 |
Managed storage systems and their ports, volumes, pools and licenses, Administrator users and groups, and SNMP managers |
Choose a connection option
Pick the option that matches which Hitachi management software is installed in your environment.
| Option | Data source you add | Use when | Covers Ops Center |
|---|---|---|---|
| A – Direct to a single array | Hitachi VSP One Block, one data source per array | Neither Ops Center nor a centralized Configuration Manager is installed | No |
| B – Centralized Configuration Manager | Configuration Manager, pointed at the Configuration Manager server | Configuration Manager is deployed centrally, in Ops Center or as an external server, but the wider Ops Center suite is not | No |
|
C – Ops Center Common Services Recommended |
OpsCenter Common Services (also requires the Option B preparation) | The Ops Center suite is deployed | Yes – Common Services and Administrator |
Tip: Use Option C wherever it is available. It is the fastest way to onboard everything, and the only option that also extends coverage to the Ops Center management layer.
Network and security requirements
All connections are outbound HTTPS from the StorageGuard collector: the Local Scan Server in the StorageGuard appliance, or a remote mediator. Open the following ports for the components your option uses.
| From | To | Port | Used by |
|---|---|---|---|
| StorageGuard collector | Array SVP, GUM, or controller | 443/TCP |
Option A |
| StorageGuard collector | Configuration Manager server | 23451/TCP |
Options B and C |
| StorageGuard collector | Common Services server | 443/TCP |
Option C |
| StorageGuard collector | Ops Center Administrator server | 443/TCP |
Option C |
- HTTPS only. The Configuration Manager HTTP port (23450) is not used.
- Ops Center ships with a self-signed certificate by default.
- StorageGuard authenticates again for each scan. Configuration Manager sessions are opened per array and closed when the scan ends, and Common Services and Administrator tokens are short-lived, so no standing sessions are left behind.
Non-default ports
If an Ops Center component or array listens on a non-default port, change the port globally in StorageGuard using Scan > Advanced settings or edit it specifically for this data source by modifying the port of its associated connectivity policy.
Note: A data source that Common Services discovery creates, and that has no connectivity policy of its own, uses its component's default port.
Option A: Direct to a single array
Use this option when neither Ops Center nor a centralized Configuration Manager is installed. StorageGuard connects directly to each array's REST API through a Hitachi VSP One Block data source. Add one data source per array.
| # | Requirement |
|---|---|
| 1 | The IP address of each array's SVP, GUM, or controller. |
| 2 | A storage system account on each array, assigned to the Security Administrator (View Only) group. See Storage system account. |
| 3 | HTTPS connectivity from the StorageGuard collector to each array on port 443. |
| 4 | The account can access https://[array]:443/ConfigurationManager/simple. See Verify Hitachi VSP One Block access. |
| 5 | Optional: an SVP OS user account for complementary OS-level collection, as described in Preparation for scanning storage management hosts. |
Note: Direct REST API access is not available on older Hitachi VSP models. For those arrays, use Option B or Option C.
Option B: Centralized Configuration Manager
StorageGuard connects to a Configuration Manager server that manages multiple arrays. Discovery adds every VSP registered on it, so you add a single data source.
| # | Requirement |
|---|---|
| 1 | Ops Center API Configuration Manager is installed, and the storage arrays are registered to it. |
| 2 | The host name or IP address of the Configuration Manager server. |
| 3 | A Configuration Manager account, created in Configuration Manager and also defined on each storage system with the same user name and password, assigned to the Security Administrator (View Only) group. See Configuration Manager account. |
| 4 | HTTPS connectivity from the StorageGuard collector to the Configuration Manager server on port 23451. |
| 5 | The account can access https://[Server]:23451/ConfigurationManager. See Verify Configuration Manager access. |
| 6 | Optional: an OS user account on the Configuration Manager host, as described in Preparation for scanning storage management hosts. |
Option C: Ops Center Common Services
You add one OpsCenter Common Services data source. This does two things:
- Scans Common Services itself. StorageGuard collects its security and IAM configuration and evaluates a dedicated set of security checks against it.
- Onboards everything registered with it. Discovery reads the application services linked to Common Services, such as Configuration Manager, Administrator, and VSP One Block, and adds a data source for each automatically. The Configuration Manager data source then discovers and collects the VSP arrays, exactly as in Option B.
Note: Discovery also adds other linked Ops Center services, such as Automator, Analyzer, and Protector, to the StorageGuard inventory. These services are not scanned individually, so they need no account, role, or port of their own.
Note: Option C builds on Option B. Complete the Option B requirements first, and then the requirements below.
| # | Requirement |
|---|---|
| 1 | All Option B requirements are met: Configuration Manager is installed with the arrays registered, the Configuration Manager account exists in Configuration Manager and on each storage system, and port 23451 is open. |
| 2 | The host name or IP address of the Common Services server. |
| 3 | A Common Services account with the opscenter-security-administrator role. See Common Services account. |
| 4 | An Ops Center Administrator account with the Viewer role, scoped to all resource groups. See Ops Center Administrator account. |
| 5 | Configuration Manager and Ops Center Administrator are registered with Common Services, so that discovery can find them. |
| 6 | HTTPS connectivity from the StorageGuard collector to the Common Services and Ops Center Administrator servers on port 443. |
| 7 | Optional: an OS user account on the Ops Center host, as described in Preparation for scanning storage management hosts. |
Caution: The data sources that discovery creates inherit their credentials and connectivity policy from the Common Services data source. If the same account is configured in Common Services, Administrator, Configuration Manager, and on each storage system, no further setup is needed before scanning. If you use separate accounts, override the credentials on each discovered Configuration Manager and Administrator data source with that component's account before you scan. Otherwise, collection fails.
Create the scan service accounts
Create a read-only service account for each component your option uses. No write, provisioning, firmware, or maintenance permissions are required.
For Option C, you can use either separate accounts per component, or one account with the same user name and password configured in every component, each with that component's role. With one shared account, the data sources that discovery creates work without any credential changes.
| Account | Minimum role (read/view only) | Where to create it | Needed for |
|---|---|---|---|
| Common Services | opscenter-security-administrator | Ops Center portal | Option C |
| Ops Center Administrator | Viewer, scoped to all resource groups | Ops Center Administrator | Option C |
| Configuration Manager | The Security Administrator (View Only) group on each storage system | Configuration Manager (in Ops Center or on an external server), and each storage system | Options B and C |
| Storage system | The Security Administrator (View Only) group | Each storage system | Option A |
Note: Role names and scoping can vary slightly between Ops Center versions. Confirm the exact view-only role assignments with your storage or Ops Center administrator when you create the accounts.
Common Services account (Option C)
- Log in to the Ops Center portal with an administrative account.
- In the navigation bar, click Manage users, and then select Users from the Asset type list.
- In the Users window, click +.
- Enter the account information, and then click Submit.
- Enter and confirm a password, and then click Submit.
- Add the user to a user group that has the built-in opscenter-security-administrator role.
Note: Common Services has no dedicated read-only IAM role. The opscenter-security-administrator role is the least-privileged role that can read the security and IAM configuration. StorageGuard still issues only read requests.
Ops Center Administrator account (Option C)
- Log in to Ops Center Administrator with an administrative account.
- Create a user for StorageGuard.
- Assign the user the read-only Viewer role, scoped to all resource groups.
Configuration Manager account (Options B and C)
- Create the account in Configuration Manager, either in Ops Center or on the external Configuration Manager server.
- Define the same account, with the same user name and password, on each storage system managed by Configuration Manager. Follow the steps in Storage system account.
Storage system account (Option A, and for the Configuration Manager account)
Repeat on each storage system:
- Log in to the SVP user interface with an administrative account.
- On the Administration tab, click Users and Permissions, and then click New User.
- Enter the account details. For Options B and C, use the same user name and password as the Configuration Manager account.
- Assign the user the built-in Security Administrator (View Only) group. This group includes the three view-only roles StorageGuard needs:
- Storage Administrator (View Only) – Hitachi's documented minimum for reading storage configuration.
- Security Administrator (View Only) – to read user accounts, external authentication settings, and certificates.
- Audit Log Administrator (View Only) – to read audit log and syslog settings.
Note: If your storage systems authenticate users through an external authentication server (for example, LDAP), you do not need to create a local account. Make sure the external account is mapped to the Security Administrator (View Only) group.
Verify access before you scan
Run these checks from the StorageGuard collector host, or from a host with the same network path, using curl. Replace the values in square brackets.
Note: The -k option skips certificate validation, which is needed for the default self-signed Ops Center certificate. Use it for these connectivity tests only.
Verify Configuration Manager access (Options B and C)
Use the Configuration Manager account, and [Server]:23451 as the host and port.
-
List the storage systems that Configuration Manager can reach, and note the storageDeviceId of each:
curl -k -H "Accept: application/json" \ https://[host]:[port]/ConfigurationManager/v1/objects/storagesConfirm that every array you expect appears in the list.
-
Confirm that the account can open a session on an array:
curl -k -u "[user]:[password]" -X POST \ -H "Accept: application/json" -H "Content-Type: application/json" \ https://[host]:[port]/ConfigurationManager/v1/objects/storages/[storageDeviceId]/sessionsA JSON response containing a token and a sessionId confirms that the account is defined on the storage system with the correct group. Repeat for each array.
-
Close the test session:
curl -k -X DELETE -H "Authorization: Session [token]" \ https://[host]:[port]/ConfigurationManager/v1/objects/storages/[storageDeviceId]/sessions/[sessionId]
Verify Hitachi VSP One Block access (Option A)
Open a session with the storage system account:
curl -k -u "[user]:[password]" -X POST \
-H "Accept: application/json" \
https://[array]:443/ConfigurationManager/simple/v1/objects/sessions
A JSON response containing a session token confirms that the account is valid.
Verify Common Services access (Option C)
-
Request a token with the Common Services account:
curl -k -u "[user]:[password]" -X POST \ https://[Server]:443/portal/auth/v1/providers/builtin/tokenThe response contains a bearer token, valid for 300 seconds.
-
Confirm that the role can read the security configuration:
curl -k -H "Authorization: Bearer [token]" \ https://[Server]:443/portal/security/v1/password-policyA JSON response confirms the role. An HTTP 403 means the role is insufficient; see Troubleshooting.
Verify Ops Center Administrator access (Option C)
Request a token with the Ops Center Administrator account:
curl -k -i -u "[user]:[password]" -X POST \
https://[admin-server]:443/v1/security/tokens
An X-Auth-Token header in the response confirms that the account is valid.
Add the data source and run the first scan
- In StorageGuard, add a new Hitachi data source of the type for your option:
- Option A: Hitachi VSP One Block, with the array's SVP, GUM, or controller address. Repeat for each array.
- Option B: Configuration Manager, with the Configuration Manager server.
- Option C: OpsCenter Common Services, with the Common Services server.
- Enter the credentials: the storage system account for Option A, the Configuration Manager account for Option B, or the Common Services account for Option C.
- Run Discovery on the new data source. For Option B, every VSP registered on the server is added. For Option C, data sources are created for the services linked to Common Services, and the arrays are then discovered through Configuration Manager.
- For Option C with separate accounts only: open each discovered Configuration Manager and Administrator data source, and override its credentials with that component's account. Skip this step if the same account is configured across all components.
- Confirm that the discovered VSP systems fall within the scope of a security policy.
- Run a scan.
- Run Security Analysis to evaluate checks against the collected data.
Verify it worked
- Every expected VSP array appears after Discovery.
- The scan completes without collection or authentication errors on any data source.
- Security Analysis returns check results for the arrays and, for Option C, for Common Services and Administrator.
Upgrading from an earlier version
If you scanned Hitachi VSP arrays with StorageGuard 10.0.x or earlier, migrate from the legacy HiCommand probes to the new data sources after upgrading to 10.1.
Caution: Disable the legacy probes, but do not delete them until you have verified the results from the new data sources.
- Disable the existing Hitachi VSP (legacy HiCommand) probes.
- Add a new Hitachi data source using one of the connection options.
- Run Discovery on the new data source.
- Confirm that the VSP systems fall within the scope of a security policy.
- Run a scan.
- Run Security Analysis to evaluate checks against the new data.
- Verify the results against the legacy data: confirm that the same arrays appear, and review any check results that differ.
- Remove the disabled legacy HiCommand probes.
Note: Some differences from the legacy results are expected where the new data sources collect data the legacy probe did not, such as the Common Services and Administrator checks added by Option C.
Troubleshooting
| Symptom | Likely cause | Resolution |
|---|---|---|
| curl or the scan times out, or the connection is refused | A port is blocked between the StorageGuard collector and the target | Open the ports listed in Network and security requirements. If the component uses a non-default port, change the port in StorageGuard. |
| Common Services token request returns HTTP 401 | Wrong credentials | Confirm the user name and password of the Common Services account. |
| Some Common Services requests return HTTP 403 | The opscenter-security-administrator role cannot read every endpoint in your Ops Center version | Also add the account to the opscenter-administrators group. |
| Common Services succeeds, but Configuration Manager collection fails with 401 or 403 | The Configuration Manager data source still uses the inherited Common Services credentials, or the Configuration Manager account is not defined on the storage system in the correct group | Override the credentials on the Configuration Manager data source, and confirm the Configuration Manager account exists on each VSP in the Security Administrator (View Only) group. |
| The Administrator data source fails authentication | It still uses the inherited Common Services credentials | Override the credentials with the Ops Center Administrator account. |
| Administrator data is missing for some storage systems | The Viewer role is not scoped to all resource groups | Scope the Ops Center Administrator account's Viewer role to all resource groups. |
| Discovery finds fewer arrays than expected | Arrays are not registered to Configuration Manager | Register the storage systems to Configuration Manager, then run Discovery again. |
| Common Services discovery creates no Configuration Manager or Administrator data source | The service is not registered with Common Services | Register it with Common Services, or add a Configuration Manager data source manually (Option B). |
| Direct connection to an array fails on an older model | The model does not support direct REST API access | Use Option B or Option C. |
Related articles
Hitachi references
- Registering a local storage system to an Ops Center API Configuration Manager connection
- Configuring a REST API environment (Ops Center API Configuration Manager REST API Reference Guide)
Still need help?
Submit a request and the Core6 Support team will get back to you.
Comments
0 comments
Please sign in to leave a comment.