StorageGuard collects configuration data from Hitachi VSP storage systems through read-only REST API calls, either through the Ops Center server or directly on each array's SVP when Ops Center is not used. We also recommend enabling OS-level access to the management host for complementary configuration collection.
This article explains how to choose a connection option, prepare the account and network access it needs, and verify access before you scan.
Note: Running StorageGuard 10.1 or later? StorageGuard 10.1 replaces the legacy Hitachi VSP probe with new Hitachi REST data sources. See Hitachi VSP and Ops Center | Scan Requirements (StorageGuard 10.1 and later).
In this article
- Choose a connection option
- Option 1: Scan through Ops Center
- Option 2: Scan directly on the SVP
- Verify access before you scan
- Troubleshooting
Choose a connection option
| Option | StorageGuard connects to | Use when |
|---|---|---|
| 1 – Through Ops Center | Ops Center Common Services (portal) and Configuration Manager on the Ops Center server | Ops Center, with Configuration Manager, manages your arrays |
| 2 – Directly on the SVP | The Configuration Manager REST API embedded on each array's SVP | Ops Center is not used |
Option 1: Scan through Ops Center
The following table lists the requirements for scanning Hitachi VSP storage systems through Ops Center.
| # | Requirement |
|---|---|
| 1 | Ops Center API Configuration Manager is installed, and the storage arrays are registered to it. |
| 2 | The host name or IP address of the Ops Center server. |
| 3 | An Ops Center application user assigned to the opscenter-security-administrator role. See Create the user account for Option 1. |
| 4 | The same user account defined on each storage system and assigned to the Security Administrator (View Only) group. Configuration Manager authenticates REST API requests with accounts registered on the storage system, or managed by an external authentication server connected to it. |
| 5 | The user can access https://[Server]:443/portal and https://[Server]:23451/ConfigurationManager. See Verify access before you scan. |
| 6 | HTTPS connectivity from the StorageGuard server to each Ops Center server on ports 443, 23451, and 23450. |
| 7 | Optional: an OS user account on the Ops Center host, as described in Preparation for scanning storage management hosts. |
Create the user account for Option 1
Use the following suggested method to create an account with the required privileges. Create the account in Ops Center, and then define the same account on each storage system.
In the Ops Center portal:
- Log in to the Ops Center portal with an administrative account.
- In the navigation bar, click Manage users, and then select Users from the Asset type list.
- In the Users window, click +.
- Enter the account information, and then click Submit.
- Enter and confirm a password, and then click Submit.
- Assign the user the built-in opscenter-security-administrator role.
On each storage system:
- Log in to the SVP user interface with an administrative account.
- On the Administration tab, click Users and Permissions, and then click New User.
- Enter the same user name and password as the Ops Center account.
- Assign the user the Security Administrator (View Only) group.
Note: If your storage systems authenticate users through an external authentication server (for example, LDAP), you do not need to create a local account on the storage system. Make sure the external account is mapped to the Security Administrator (View Only) group.
Option 2: Scan directly on the SVP
The following table lists the requirements for scanning Hitachi VSP storage systems directly.
| # | Requirement |
|---|---|
| 1 | The SVP IP address of each array. |
| 2 | A user account on the storage system, assigned to the Security Administrator (View Only) group. See Create the user account for Option 2. |
| 3 | The user can access https://[SVP IP]:443/ConfigurationManager. See Verify access before you scan. |
| 4 | HTTPS connectivity from the StorageGuard server to each SVP on port 443. |
| 5 | Optional: an SVP OS user account, as described in Preparation for scanning storage management hosts. |
Note: Direct REST API access is not available on older Hitachi VSP models. For those arrays, use Option 1.
Create the user account for Option 2
Use the following suggested method on each storage system:
- Log in to the SVP user interface with an administrative account.
- On the Administration tab, click Users and Permissions, and then click New User.
- Enter the account details.
- Assign the user the built-in Security Administrator (View Only) group. This group includes the Security Administrator (View Only), Audit Log Administrator (View Only), and Storage Administrator (View Only) roles.
Verify access before you scan
Run these checks from the StorageGuard server, or from a host with the same network path, using curl. Replace the values in square brackets.
Note: The -k option skips certificate validation. Use it for these connectivity tests only.
Verify Ops Center access (Option 1)
Request a token from the Ops Center portal:
curl -k -u "[user]:[password]" -X POST \
https://[Server]:443/portal/auth/v1/providers/builtin/token
A JSON response containing a token confirms that the account and role are valid.
Verify Configuration Manager access (Options 1 and 2)
Use [Server]:23451 for Option 1, or [SVP IP]:443 for Option 2.
-
List the storage systems that Configuration Manager can reach, and note the storageDeviceId of each:
curl -k -H "Accept: application/json" \ https://[host]:[port]/ConfigurationManager/v1/objects/storagesFor Option 1, confirm that every array you expect appears in the list.
-
Confirm that the account can open a session on an array:
curl -k -u "[user]:[password]" -X POST \ -H "Accept: application/json" -H "Content-Type: application/json" \ https://[host]:[port]/ConfigurationManager/v1/objects/storages/[storageDeviceId]/sessionsA JSON response containing a token and a sessionId confirms that the account is defined on the storage system with the correct group. Repeat for each array.
-
Close the test session:
curl -k -X DELETE -H "Authorization: Session [token]" \ https://[host]:[port]/ConfigurationManager/v1/objects/storages/[storageDeviceId]/sessions/[sessionId]
Troubleshooting
| Symptom | Likely cause | Resolution |
|---|---|---|
| curl or the scan times out, or the connection is refused | A port is blocked between the StorageGuard server and the target | Open 443, 23451, and 23450 to the Ops Center server (Option 1), or 443 to each SVP (Option 2). |
| Ops Center token request returns HTTP 401 | Wrong credentials, or the role is missing | Confirm the password, and that the user has the opscenter-security-administrator role. |
| Ops Center succeeds, but Configuration Manager sessions fail with 401 or 403 | The account is not defined on the storage system, or not in the correct group | Create the same account on each storage system and assign it the Security Administrator (View Only) group. |
| Fewer arrays than expected are listed | Arrays are not registered to Configuration Manager | Register the storage systems to Configuration Manager. |
| Direct connection fails on an older model | The model does not support direct REST API access | Use Option 1. |
Related articles
- Hitachi VSP and Ops Center | Scan Requirements (StorageGuard 10.1 and later)
- Preparation for scanning storage management hosts
Hitachi references
- Registering a local storage system to an Ops Center API Configuration Manager connection
- Registering storage systems to an Ops Center API Configuration Manager REST API connection
- How to access Hitachi Configuration Manager to register storage devices
Still need help?
Submit a request and the Core6 Support team will get back to you.
Comments
0 comments
Please sign in to leave a comment.