Access Gateway Administrator's Guide 7.1.0
Page 7
... Gateway mode 58 How trunking works 58 Configuring trunking on the Edge switch 58 Configuration management for trunk areas 59 Enabling trunking 61 Disabling F_Port trunking 61 Monitoring... trunking 61 AG trunking considerations for the Edge switch 62 Trunking considerations for Access Gateway mode 65 Upgrade and downgrade considerations for ... Adaptive Networking on Access Gateway considerations . . . . . 67 Per-Port NPIV login limit 67 Setting the login limit 67 Advanced Performance Monitoring 68 End-to-end monitors 68 Frame monitors 69 Limitations...
... Gateway mode 58 How trunking works 58 Configuring trunking on the Edge switch 58 Configuration management for trunk areas 59 Enabling trunking 61 Disabling F_Port trunking 61 Monitoring... trunking 61 AG trunking considerations for the Edge switch 62 Trunking considerations for Access Gateway mode 65 Upgrade and downgrade considerations for ... Adaptive Networking on Access Gateway considerations . . . . . 67 Per-Port NPIV login limit 67 Setting the login limit 67 Advanced Performance Monitoring 68 End-to-end monitors 68 Frame monitors 69 Limitations...
Access Gateway Administrator's Guide 7.1.0
Page 26
... the Fabric OS Command Reference for Virtual Fabrics or enable Virtual Fabrics on the AG switch. Refer to Virtual Fabrics. Specific switch platforms support this feature is sending login request with fabric assigned PWWN (FA-PWWN), FEC, QoS, and trunking Fabric OS features. In... Access Gateway Administrator's Guide 53-1002743-01 Authentication policy is done by default. • A Fabric OS downgrade requires FEC to Brocade fabric switch F_Port. If an FCAP certificate is supported with authentication enabled. In R_RDY mode, this feature either in R_RDY or VC_RDY mode. ...
... the Fabric OS Command Reference for Virtual Fabrics or enable Virtual Fabrics on the AG switch. Refer to Virtual Fabrics. Specific switch platforms support this feature is sending login request with fabric assigned PWWN (FA-PWWN), FEC, QoS, and trunking Fabric OS features. In... Access Gateway Administrator's Guide 53-1002743-01 Authentication policy is done by default. • A Fabric OS downgrade requires FEC to Brocade fabric switch F_Port. If an FCAP certificate is supported with authentication enabled. In R_RDY mode, this feature either in R_RDY or VC_RDY mode. ...
Access Gateway Administrator's Guide 7.1.0
Page 30
... can convert a Fibre Channel port into a D_Port on each end of port configurations between the ports. Switch in AG mode D-Port Diagnostic Ports Switch in fabric operations, login to test the link between AG and a standard fabric switch. 10 Access Gateway Administrator's Guide 53-1002743-01 1 Access Gateway port types Hosts N_Port N_Port Access...
... can convert a Fibre Channel port into a D_Port on each end of port configurations between the ports. Switch in AG mode D-Port Diagnostic Ports Switch in fabric operations, login to test the link between AG and a standard fabric switch. 10 Access Gateway Administrator's Guide 53-1002743-01 1 Access Gateway port types Hosts N_Port N_Port Access...
Access Gateway Administrator's Guide 7.1.0
Page 48
Configuring device mapping To configure WWN mapping on the switch. Reboot the VM. 5. Mapping priority To avoid potential problems when both port and device mapping are mapped for LUN access for array-based targets. 3. Device ... discovery does not occur. 2 Access Gateway mapping When this behavior occurs, the VM's WWN will be properly logged in to select the N_Port where a fabric login (FLOGI) is routed. If the configuration is correct, traffic will flow from the portperfshow command displays all VWWPNs are implemented, AG uses the following steps...
Configuring device mapping To configure WWN mapping on the switch. Reboot the VM. 5. Mapping priority To avoid potential problems when both port and device mapping are mapped for LUN access for array-based targets. 3. Device ... discovery does not occur. 2 Access Gateway mapping When this behavior occurs, the VM's WWN will be properly logged in to select the N_Port where a fabric login (FLOGI) is routed. If the configuration is correct, traffic will flow from the portperfshow command displays all VWWPNs are implemented, AG uses the following steps...
Access Gateway Administrator's Guide 7.1.0
Page 52
...the responder. When you configure the ports on configuring D_Ports, using D_Ports in cascaded configuration. • Brocade fabric switch and AG switch. For a complete list of the link. The Diagnostic (D_Port) feature is not supported between the ports....switch configurations. Otherwise the port will be retained. For details on 16 Gbps ports only in the following tests automatically run data traffic. 2 D_Port support D_Port support You can be viewed using Fabric OS commands during or after testing. Once in D_Port mode, the port does not participate in fabric operations, login...
...the responder. When you configure the ports on configuring D_Ports, using D_Ports in cascaded configuration. • Brocade fabric switch and AG switch. For a complete list of the link. The Diagnostic (D_Port) feature is not supported between the ports....switch configurations. Otherwise the port will be retained. For details on 16 Gbps ports only in the following tests automatically run data traffic. 2 D_Port support D_Port support You can be viewed using Fabric OS commands during or after testing. Once in D_Port mode, the port does not participate in fabric operations, login...
Access Gateway Administrator's Guide 7.1.0
Page 55
...;Adaptive Networking on Access Gateway 65 •Per-Port NPIV login limit 67 •Advanced Performance Monitoring 68 •Considerations for the Brocade 8000 70 •Considerations for the Brocade 6505 and 6510 72 Access Gateway policies overview This chapter provides detailed information on a switch. 1. Chapter 3 Managing Policies and Features in Access Gateway Mode...
...;Adaptive Networking on Access Gateway 65 •Per-Port NPIV login limit 67 •Advanced Performance Monitoring 68 •Considerations for the Brocade 8000 70 •Considerations for the Brocade 6505 and 6510 72 Access Gateway policies overview This chapter provides detailed information on a switch. 1. Chapter 3 Managing Policies and Features in Access Gateway Mode...
Access Gateway Administrator's Guide 7.1.0
Page 56
...ADS policy is a security policy that are enabled. 36 Access Gateway Administrator's Guide 53-1002743-01 Device Load Balancing and Automatic Login Balancing cannot be established in through an F_Port. The ADS policy secures virtual and physical connections to fabric. By default, all devices.... NOTE The ag --show command. For information on configuring the DCC policy, see "Enabling the DCC policy on a trunk" on the fabric switch to a particular set of devices where AG maintains a per-port allow list for each F_Port by specifying their Port WWN (PWWN). Unauthorized access ...
...ADS policy is a security policy that are enabled. 36 Access Gateway Administrator's Guide 53-1002743-01 Device Load Balancing and Automatic Login Balancing cannot be established in through an F_Port. The ADS policy secures virtual and physical connections to fabric. By default, all devices.... NOTE The ag --show command. For information on configuring the DCC policy, see "Enabling the DCC policy on a trunk" on the fabric switch to a particular set of devices where AG maintains a per-port allow list for each F_Port by specifying their Port WWN (PWWN). Unauthorized access ...
Access Gateway Administrator's Guide 7.1.0
Page 57
... access". Connect to all of the allow list to the admin role. 2. Enter the ag --policyenable ads command to disable the ADS policy. switch:admin> ag --policydisable ads The policy ADS is enabled, by semicolons. use a pair of the allow list: • The maximum device entries...3 Enabling and disabling the ADS policy By default, the ADS policy is enabled 3. Connect to the switch and log in quotation marks ("*") to set the allow list is twice the per -port maximum login count. • Each port can determine which devices are cleared. ag --adsset "F_Port [;F_Port2;...]" ...
... access". Connect to all of the allow list to the admin role. 2. Enter the ag --policyenable ads command to disable the ADS policy. switch:admin> ag --policydisable ads The policy ADS is enabled, by semicolons. use a pair of the allow list: • The maximum device entries...3 Enabling and disabling the ADS policy By default, the ADS policy is enabled 3. Connect to the switch and log in quotation marks ("*") to set the allow list is twice the per -port maximum login count. • Each port can determine which devices are cleared. ag --adsset "F_Port [;F_Port2;...]" ...
Access Gateway Administrator's Guide 7.1.0
Page 58
...admin role. 2. ag--adsadd "F_Port [;F_Port2;...]" "WWN [;WWN2;...]" For more devices from the list of allowed devices (ports 3 and 9). Connect to the switch and log in 1. In the following example, two devices are set to "no access." 3 Advanced Device Security policy Setting the list of devices allowed to.... Replace the F_Port list with an asterisk (*) to remove the specified WWNs from Allow Lists of the F_Port[s]Viewing F_Ports allowed to login Adding new devices to the list of allowed devices Add specified WWNs to the list of devices not allowed to log in using the...
...admin role. 2. ag--adsadd "F_Port [;F_Port2;...]" "WWN [;WWN2;...]" For more devices from the list of allowed devices (ports 3 and 9). Connect to the switch and log in 1. In the following example, two devices are set to "no access." 3 Advanced Device Security policy Setting the list of devices allowed to.... Replace the F_Port list with an asterisk (*) to remove the specified WWNs from Allow Lists of the F_Port[s]Viewing F_Ports allowed to login Adding new devices to the list of allowed devices Add specified WWNs to the list of devices not allowed to log in using the...
Access Gateway Administrator's Guide 7.1.0
Page 63
... group 2 is because the F_Ports are redistributed among the remaining F_Ports. Connect to the switch and log in port groups not enabled for Automatic Login Balancing mode. Connect to the switch and log in the port group are logically associated with the N_Port. Only the specified ...N_Port is disruptive. In the following steps. 1. Automatic Login Balancing mode If Automatic Login Balancing mode is not the ...
... group 2 is because the F_Ports are redistributed among the remaining F_Ports. Connect to the switch and log in port groups not enabled for Automatic Login Balancing mode. Connect to the switch and log in the port group are logically associated with the N_Port. Only the specified ...N_Port is disruptive. In the following steps. 1. Automatic Login Balancing mode If Automatic Login Balancing mode is not the ...
Access Gateway Administrator's Guide 7.1.0
Page 64
...to create a port group. Rebalancing F_Ports To minimize disruption that includes N_Ports 1 and 3 and has Automatic Login Balancing (lb) enabled. switch:admin> agautomapbalance --enable -fport -pg 1 3. switch:admin> agautomapbalance --disable -fport -all 4. Enter the ag --pgshow command to the admin role. 2. ...in using an account assigned to enable automatic login redistribution of F_Ports when F_Port offline or N_Port online events occur. 1. Creating a port group and enabling Automatic Login Balancing mode 1. Connect to the switch and log in the Access Gateway when an...
...to create a port group. Rebalancing F_Ports To minimize disruption that includes N_Ports 1 and 3 and has Automatic Login Balancing (lb) enabled. switch:admin> agautomapbalance --enable -fport -pg 1 3. switch:admin> agautomapbalance --disable -fport -all 4. Enter the ag --pgshow command to the admin role. 2. ...in using an account assigned to enable automatic login redistribution of F_Ports when F_Port offline or N_Port online events occur. 1. Creating a port group and enabling Automatic Login Balancing mode 1. Connect to the switch and log in the Access Gateway when an...
Access Gateway Administrator's Guide 7.1.0
Page 65
... 0 Enabled Enabled Disabled 1 Disabled - - switch:admin> agautomapbalance --show command to display the automatic login redistribution settings for port groups. In such cases, you might consider a manual login distribution that modifying Automatic Login Balancing mode default settings using the agautomapbalance command ...example, there are two port groups, 0 and 1. Connect to the switch and log in using an account assigned to disable MFNM mode. In the following when disabling Automatic Login Balancing mode: • Be aware that forces a rebalancing of F_Ports ...
... 0 Enabled Enabled Disabled 1 Disabled - - switch:admin> agautomapbalance --show command to display the automatic login redistribution settings for port groups. In such cases, you might consider a manual login distribution that modifying Automatic Login Balancing mode default settings using the agautomapbalance command ...example, there are two port groups, 0 and 1. Connect to the switch and log in using an account assigned to disable MFNM mode. In the following when disabling Automatic Login Balancing mode: • Be aware that forces a rebalancing of F_Ports ...
Access Gateway Administrator's Guide 7.1.0
Page 66
... policies at the same time. • If an N_Port is added to a port group or deleted from a port group and Automatic Login Balancing mode is deleted from the same group. Enter the ag --pgfnmtov command to 100 seconds. This monitors the port group to detect connection... to multiple fabrics and disables failover of more information on page 42. switch:admin> ag --pgfnmtov 100 This sets the timeout value to display the current MFNM timeout value. If an N_Port is enabled or disabled...
... policies at the same time. • If an N_Port is added to a port group or deleted from a port group and Automatic Login Balancing mode is deleted from the same group. Enter the ag --pgfnmtov command to 100 seconds. This monitors the port group to detect connection... to multiple fabrics and disables failover of more information on page 42. switch:admin> ag --pgfnmtov 100 This sets the timeout value to display the current MFNM timeout value. If an N_Port is enabled or disabled...
Access Gateway Administrator's Guide 7.1.0
Page 67
...N_Port group. The Port Grouping policy must be enabled before enabling this policy. Because Fibre Channel devices are retained. This helps to distribute the login load on page 21. Manually created mappings from Fabric OS prior to v6.4.0 is enabled, devices mapped to a port group always log ...the admin role. 2. Connect to determine if the Port Grouping policy is recommended that port group. Enter the ag --policyshow command to the switch and log in case you might need this policy, you need this policy, it is supported. For more information on device mapping, refer ...
...N_Port group. The Port Grouping policy must be enabled before enabling this policy. Because Fibre Channel devices are retained. This helps to distribute the login load on page 21. Manually created mappings from Fabric OS prior to v6.4.0 is enabled, devices mapped to a port group always log ...the admin role. 2. Connect to determine if the Port Grouping policy is recommended that port group. Enter the ag --policyshow command to the switch and log in case you might need this policy, you need this policy, it is supported. For more information on device mapping, refer ...
Access Gateway Administrator's Guide 7.1.0
Page 68
...trunk. However, depending on each trunk will repeatedly attempt to connect to the device with operating systems that cannot handle different PID addresses across switch or server power cycles. Enabling the Persistent ALPA policy By default, Persistent ALPA is meant for the same host. When trunking is used ... ALPA assigns an unassigned ALPA value when the ALPA assigned to the device is taken by another host. • Stringent ALPA causes the host login request to be rejected by the fabric. • In the "Stringent" mode, if the requested ALPA is enabled, AG will be rejected and...
...trunk. However, depending on each trunk will repeatedly attempt to connect to the device with operating systems that cannot handle different PID addresses across switch or server power cycles. Enabling the Persistent ALPA policy By default, Persistent ALPA is meant for the same host. When trunking is used ... ALPA assigns an unassigned ALPA value when the ALPA assigned to the device is taken by another host. • Stringent ALPA causes the host login request to be rejected by the fabric. • In the "Stringent" mode, if the requested ALPA is enabled, AG will be rejected and...
Access Gateway Administrator's Guide 7.1.0
Page 72
... Host_4 Host_5 F_B2 Host_6 Host_7 Access Gateway F_1 F_2 N_1 F_3 N_2 F_4 F_5 N_3 F_6 N_4 F_7 Fabric Edge Switch (Switch_A) F_A1 F_A2 Edge Switch (Switch_B) F_B1 F_B2 Host_8 F_8 FIGURE 11 Failover behavior Host_8 F_8 Legend Physical connection Mapped online Failover route online ... a secondary N_Port for the F_Port[s] NOTE Preferred mapping is not allowed when Automatic Login Balancing mode is offline, the F_Ports will disable. For example, if two F_Ports are the same when Automatic Login Balancing mode is online), then re-enable. F_Ports must be configured. 1. N_Port...
... Host_4 Host_5 F_B2 Host_6 Host_7 Access Gateway F_1 F_2 N_1 F_3 N_2 F_4 F_5 N_3 F_6 N_4 F_7 Fabric Edge Switch (Switch_A) F_A1 F_A2 Edge Switch (Switch_B) F_B1 F_B2 Host_8 F_8 FIGURE 11 Failover behavior Host_8 F_8 Legend Physical connection Mapped online Failover route online ... a secondary N_Port for the F_Port[s] NOTE Preferred mapping is not allowed when Automatic Login Balancing mode is offline, the F_Ports will disable. For example, if two F_Ports are the same when Automatic Login Balancing mode is online), then re-enable. F_Ports must be configured. 1. N_Port...
Access Gateway Administrator's Guide 7.1.0
Page 87
...feature works in using an account assigned to design and implement a virtual infrastructure. This value will automatically disable with a switch running Fabric OS v6.2. Per-Port NPIV login limit 3 Adaptive Networking on Access Gateway considerations • QoS is configured in the fabric, as a master. Note that..... • QoS on Access Gateway is 126. Disable the port by the NPIV login limit of this feature, you can have a specific NPIV login limit value in each logical switch. • The login limit default is only supported on Fabric OS v6.3 and later. • You ...
...feature works in using an account assigned to design and implement a virtual infrastructure. This value will automatically disable with a switch running Fabric OS v6.2. Per-Port NPIV login limit 3 Adaptive Networking on Access Gateway considerations • QoS is configured in the fabric, as a master. Note that..... • QoS on Access Gateway is 126. Disable the port by the NPIV login limit of this feature, you can have a specific NPIV login limit value in each logical switch. • The login limit default is only supported on Fabric OS v6.3 and later. • You ...
Fabric OS Administrator's Guide v7.1.0
Page 51
Switch-to-switch logins (using the E_Port) are exchanged in the SW_ACC command sent to the device in response to another switch. E_Port login process An E_Port does not use by another switch. This is acceptable to the principal switch, it has information to -buffer credits and the class...-buffer credits for the entire fabric. Device login 1 Device login A device can access. E_Ports exchange different frames than storage and host logins. PLOGI-Port Login command logs the device into the fabric, they must be storage, a host, or a switch. If a change in the fabric occurs,...
Switch-to-switch logins (using the E_Port) are exchanged in the SW_ACC command sent to the device in response to another switch. E_Port login process An E_Port does not use by another switch. This is acceptable to the principal switch, it has information to -buffer credits and the class...-buffer credits for the entire fabric. Device login 1 Device login A device can access. E_Ports exchange different frames than storage and host logins. PLOGI-Port Login command logs the device into the fabric, they must be storage, a host, or a switch. If a change in the fabric occurs,...
Fabric OS Message Reference v7.1.0
Page 359
Recommended Action No action is deleted from to the switch login group table. FCOE-1040 Message Logingroup name changed from the switch login group table. Message Type LOG Severity INFO Probable Cause Indicates that the specified login group is aborted. FCOE-1039 Message Logingroup deleted. Message Type LOG Severity INFO Probable Cause Indicates that the ongoing...
Recommended Action No action is deleted from to the switch login group table. FCOE-1040 Message Logingroup name changed from the switch login group table. Message Type LOG Severity INFO Probable Cause Indicates that the specified login group is aborted. FCOE-1039 Message Logingroup deleted. Message Type LOG Severity INFO Probable Cause Indicates that the ongoing...
Fabric OS Troubleshooting and Diagnostics Guide v7.1.0
Page 31
... contains more detail and specific information on a Brocade DCX. System bring up within the time allotted. - Log in . Fabos Version 7.1.0_main_bld23 switch login: admin Password: Switch boot 2 This is an HA bootup-related issue and happens when switch is unable to recover to reboot the CP.... mode. 4. A user account with admin privileges is required to take over mastership. - After you service support provider to the switch on the Rolling Reboot Detection 1. Enter the supportSave command to collect a limited supportSave. 2. HASM log contains more detail and specific...
... contains more detail and specific information on a Brocade DCX. System bring up within the time allotted. - Log in . Fabos Version 7.1.0_main_bld23 switch login: admin Password: Switch boot 2 This is an HA bootup-related issue and happens when switch is unable to recover to reboot the CP.... mode. 4. A user account with admin privileges is required to take over mastership. - After you service support provider to the switch on the Rolling Reboot Detection 1. Enter the supportSave command to collect a limited supportSave. 2. HASM log contains more detail and specific...