beautypg.com

Brocade Fabric OS Encryption Administrator’s Guide Supporting NetApp Lifetime Key Manager (LKM) and KeySecure Storage Secure Key Manager (SSKM) Environments (Supporting Fabric OS v7.2.0) User Manual

Page 160

background image

142

Fabric OS Encryption Administrator’s Guide (LKM/SSKM)

53-1002925-01

CryptoTarget container configuration

3

Target:

20:0c:00:06:2b:0f:72:6d 20:00:00:06:2b:0f:72:6d

VT:

20:00:00:05:1e:41:4e:1d 20:01:00:05:1e:41:4e:1d

Number of host(s):

1

Configuration status: committed

Host:

10:00:00:00:c9:2b:c9:3a 20:00:00:00:c9:2b:c9:3a

VI:

20:02:00:05:1e:41:4e:1d 20:03:00:05:1e:41:4e:1d

Number of LUN(s):

0

Operation Succeeded

6. Display the redirection zone. It includes the host, the target, the virtual initiator, and the virtual

target.

FabricAdmin:switch> cfgshow

Defined configuration:

cfg: itcfg

itzone

cfg: r_e_d_i_r_c__fg

red_1109_brcd200c00062b0f726d200200051e414e1d;

red_______base

zone: itzone 10:00:00:00:c9:2b:c9:3a; 20:0c:00:06:2b:0f:72:6d

zone: red_1109_brcd200c00062b0f726d200200051e414e1d

10:00:00:00:c9:2b:c9:3a;

20:0c:00:06:2b:0f:72:6d;

20:02:00:05:1e:41:4e:1d;

20:00:00:05:1e:41:4e:1d

zone: red_______base

00:00:00:00:00:00:00:01;

00:00:00:00:00:00:00:02;

00:00:00:00:00:00:00:03;

00:00:00:00:00:00:00:04

Effective configuration:

cfg: itcfg

zone: itzone 10:00:00:00:c9:2b:c9:3a

20:0c:00:06:2b:0f:72:6d

NOTE

You may view the frame redirection zone with the cfgshow command, but you cannot use the zone
for any other applications that use frame redirection. Do not perform any further operations with this
zone, such as deleting the zone or adding the zone to a different configuration. Such operations may
result in disruptive behavior, including data corruption on the LUN.

Removing an initiator from a CryptoTarget container

You may remove one or more initiators from a given CryptoTarget container. This operation
removes the initiators’ access to the target port.

If the initiator has access to multiple targets and you wish to remove access to all targets, follow the
procedure described to remove the initiator from every CryptoTarget container that is configured
with this initiator.

NOTE

Stop all traffic between the initiator you intend to remove and its respective target ports. Failure to
do so results in I/O failure between the initiator and the target port.

1. Log in to the group leader as Admin or FabricAdmin.

2. Enter the cryptocfg

--

remove

-

initiator command. Specify the CryptoTarget container name

followed by one or more initiator port WWNs. The following example removes one initiator from
the CryptoTarget container “my_disk_tgt”.

FabricAdmin:switch> cryptocfg --rem -initiator my_disk_tgt

10:00:00:00:c9:2b:c9:3a