[ Applies to ] StorageGuard / Brocade FC switches and directors, Brocade SANnav / SSH and HTTPS
Before StorageGuard can scan your Brocade SAN, it needs network access and a read-only account on each device it connects to. This article covers both supported sources: Brocade FC switches and directors, scanned over SSH, and Brocade SANnav, scanned over HTTPS.
In this article
Brocade FC switches
StorageGuard collects configuration data from Brocade FC switches and directors by running read-only Fabric OS (FOS) commands over SSH.
Requirements
| Requirement | Details |
|---|---|
| Seed director | The network name or IP address of one Brocade SAN director. StorageGuard scans this director to discover the names and IP addresses of the other Brocade switches in the fabric. |
| Credentials | A user name and password for each Brocade director and switch. |
| Role and permissions | The account needs an unlimited read-only role that can run all show commands and other read-only FOS commands, such as userconfig --show -a, snmpconfig --show snmpv3, and auditcfg --show. In a Virtual Fabric environment, the account also needs chassis permission. |
| Network access | SSH connectivity (port 22 by default) from the StorageGuard server to each Brocade director and switch. |
Create a scan account on the switch
The following procedure is a suggested way to create a custom role with Observe (read-only) permission on every RBAC class, and a user assigned to that role.
- Log in to the director or switch over SSH with an account that can manage roles and users.
-
Create the role:
roleconfig --add sguardrole -
Grant Observe permission (
-perm O) on each RBAC class:roleconfig --change sguardrole -class ADSelect -perm O roleconfig --change sguardrole -class AG -perm O roleconfig --change sguardrole -class APM -perm O roleconfig --change sguardrole -class AdminDomains -perm O roleconfig --change sguardrole -class Audit -perm O roleconfig --change sguardrole -class Authentication -perm O roleconfig --change sguardrole -class Blade -perm O roleconfig --change sguardrole -class ChassisConfiguration -perm O roleconfig --change sguardrole -class ChassisManagement -perm O roleconfig --change sguardrole -class ConfigManagement -perm O roleconfig --change sguardrole -class Configure -perm O roleconfig --change sguardrole -class DCE -perm O roleconfig --change sguardrole -class DMM -perm O roleconfig --change sguardrole -class Debug -perm O roleconfig --change sguardrole -class Diagnostics -perm O roleconfig --change sguardrole -class EncryptionConfiguration -perm O roleconfig --change sguardrole -class EncryptionManagement -perm O roleconfig --change sguardrole -class EthernetConfig -perm O roleconfig --change sguardrole -class FCoE -perm O roleconfig --change sguardrole -class FICON -perm O roleconfig --change sguardrole -class FIPSBootprom -perm O roleconfig --change sguardrole -class FIPSCfg -perm O roleconfig --change sguardrole -class FRUManagement -perm O roleconfig --change sguardrole -class Fabric -perm O roleconfig --change sguardrole -class FabricDistribution -perm O roleconfig --change sguardrole -class FabricRouting -perm O roleconfig --change sguardrole -class FabricWatch -perm O roleconfig --change sguardrole -class Factory -perm O roleconfig --change sguardrole -class FirmwareKeyManagement -perm O roleconfig --change sguardrole -class FirmwareManagement -perm O roleconfig --change sguardrole -class HA -perm O roleconfig --change sguardrole -class IPSec -perm O roleconfig --change sguardrole -class IPfilter -perm O roleconfig --change sguardrole -class ISCSI -perm O roleconfig --change sguardrole -class LayerTwo -perm O roleconfig --change sguardrole -class License -perm O roleconfig --change sguardrole -class LocalUserEnvironment -perm O roleconfig --change sguardrole -class LogSupportsave -perm O roleconfig --change sguardrole -class Logging -perm O roleconfig --change sguardrole -class MAPS -perm O roleconfig --change sguardrole -class ManagementAccessConfiguration -perm O roleconfig --change sguardrole -class ManagementServer -perm O roleconfig --change sguardrole -class NameServer -perm O roleconfig --change sguardrole -class Nocheck -perm O roleconfig --change sguardrole -class NxPortManagement -perm O roleconfig --change sguardrole -class PKI -perm O roleconfig --change sguardrole -class PhysicalComputerSystem -perm O roleconfig --change sguardrole -class PortMirror -perm O roleconfig --change sguardrole -class RADIUS -perm O roleconfig --change sguardrole -class Reboot -perm O roleconfig --change sguardrole -class Restricted -perm O roleconfig --change sguardrole -class RoleConfig -perm O roleconfig --change sguardrole -class RoutingAdvanced -perm O roleconfig --change sguardrole -class RoutingBasic -perm O roleconfig --change sguardrole -class SNMP -perm O roleconfig --change sguardrole -class SRM -perm O roleconfig --change sguardrole -class Security -perm O roleconfig --change sguardrole -class Service -perm O roleconfig --change sguardrole -class SessionManagement -perm O roleconfig --change sguardrole -class Statistics -perm O roleconfig --change sguardrole -class StatisticsDevice -perm O roleconfig --change sguardrole -class StatisticsPort -perm O roleconfig --change sguardrole -class SwitchConfiguration -perm O roleconfig --change sguardrole -class SwitchManagement -perm O roleconfig --change sguardrole -class SwitchManagementIPConfiguration -perm O roleconfig --change sguardrole -class SwitchPortConfiguration -perm O roleconfig --change sguardrole -class SwitchPortManagement -perm O roleconfig --change sguardrole -class SwitchPortSecurityConfiguration -perm O roleconfig --change sguardrole -class Topology -perm O roleconfig --change sguardrole -class USBManagement -perm O roleconfig --change sguardrole -class UserManagement -perm O roleconfig --change sguardrole -class WWNCard -perm O roleconfig --change sguardrole -class WWNCardZoning -perm O roleconfig --change sguardrole -class Zoning -perm O -
Create the user and assign the role as both its switch role (
-r) and chassis role (-c). Replace<password>with the account password, and<LF IDs>with all logical fabric IDs, for example1-128:userconfig --add sguarduser -r sguardrole -c sguardrole -p <password> -l <LF IDs> - Repeat these steps on each director and switch that StorageGuard scans.
Note: Some roleconfig --change commands can fail because not every RBAC class exists in every FOS version. These failures are expected and you can ignore them. Classes that may be missing include SwitchPortSecurityConfiguration, SRM, MAPS, LayerTwo, IPSec, Factory, FabricWatch, FIPSBootprom, Debug, and APM.
Tip: In a Virtual Fabric environment, also allow the account to run fosexec with read-only show commands.
Brocade SANnav
StorageGuard collects configuration data from SANnav by running read-only API calls over HTTPS.
Requirements
| Requirement | Details |
|---|---|
| Server address | The network name or IP address of each SANnav server. |
| Credentials | A read-only user name and password for each SANnav server. |
| Network access | HTTPS connectivity (port 443) from the StorageGuard server to each SANnav server. |
Create a scan account in SANnav
- In the SANnav navigation bar, click SANnav, and then select Security > SANnav User Management.
- Click Users, and then click + in the subnavigation bar.
- Enter the user name and password.
- In the Roles section, select AllPrivileges_ReadOnly.
- In the AORs section, select All Fabrics.
- Click Save.
Related articles
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.