[ Applies to ] StorageGuard / Cisco MDS and Nexus FC switches, Cisco NDFC / SSH and HTTPS
Before StorageGuard can scan your Cisco SAN, it needs network access and a read-only account on each source it connects to. This article covers both sources: Cisco MDS and Nexus FC switches, scanned over SSH, and Cisco Nexus Dashboard Fabric Controller (NDFC), scanned through its REST API.
Tip: Scan NDFC in addition to your switches. NDFC provides configuration data that complements what StorageGuard collects from the switches directly.
In this article
Cisco FC switches
StorageGuard collects configuration data from Cisco FC switches and directors by running read-only NX-OS and SAN-OS commands over SSH.
Requirements
| Requirement | Details |
|---|---|
| Seed director | The network name or IP address of one Cisco FC SAN director. StorageGuard scans this director to discover the names and IP addresses of the other Cisco FC switches in the fabric. |
| Credentials | A user name and password for each Cisco FC director and switch. |
| Role and permissions | The account needs an unlimited read-only role that can run all show commands, including show running-config and show startup-config. |
| Network access | SSH connectivity (port 22 by default) from the StorageGuard server to each Cisco FC director and switch. |
Create a scan account on the switch
The following procedure is a suggested way to create a custom read-only role and a user assigned to it. The role rules differ between MDS and Nexus platforms.
- Log in to the director or switch over SSH with an account that can manage roles and users.
- Run the commands for your platform. Replace
<password>with the account password. - Repeat these steps on each director and switch that StorageGuard scans.
Cisco MDS
configure terminal
role name sguardrole
rule 1 permit show
rule 2 permit show feature running-config
rule 3 permit show feature role
rule 4 permit show feature startup-config
exit
username sguard password <password> role sguardrole
Cisco Nexus
configure terminal
role name sguardrole
rule 1 permit command show *
rule 2 permit command show running-config *
rule 3 permit command show role *
rule 4 permit command show startup-config *
rule 5 permit read
exit
username sguard password <password> role sguardrole
The following optional commands apply to both platforms:
| Command | When to use it |
|---|---|
description storageguard scan user |
Labels the role. Run it in role configuration mode, before exit. |
role commit |
Commits pending role changes to the fabric. Run it after exit if role distribution is enabled. |
copy running-config startup-config |
Saves the configuration so the role and user persist after a reload. Run it last. |
Cisco NDFC
StorageGuard scans NDFC with its NDFC REST API scanner, which collects configuration data through read-only REST API calls over HTTPS.
Requirements
| Requirement | Details |
|---|---|
| Host address | The network name or IP address of the Cisco NDFC host. |
| Credentials | A user name and password for the NDFC application. |
| Role and permissions | The account needs a read-only role that can make read (GET) REST API calls. The NDFC Network Operator role meets this requirement. |
| Network access | HTTPS connectivity (port 443 by default) from the StorageGuard server to each NDFC host. |
Create a scan account in NDFC
- Log in to the Nexus Dashboard admin console.
- Assign the scan user account the Network Operator role, or a higher role.
Related articles
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.