Configuring lun security – HP StorageWorks XP Remote Web Console Software User Manual

Page 9

Advertising
background image

You can add, change, and delete LU paths when the system is in operation. For example, if new
disks or server hosts are added to your storage system, you can add new LU paths. If an existing
server host is to be replaced, you delete the LU paths that correspond to the host before replacing
the host. You do not need to restart the system when you add, change, or delete LU paths with
LUN Manager.

If a hardware failure (such as a CHA failure) occurs, there is a chance that some LU paths will be
disabled and some I/O operations stopped. To avoid such a situation, the system administrator
can define alternate LU paths; if one LU path fails, the alternate path takes over the host I/O.

For instructions on how to define LU paths, see

“Defining Fibre Channel LU Paths” (page 29)

. For

instructions on how to change LU path settings, see

“Changing the Fibre Channel LU Path Settings”

(page 59)

. For instructions on how to define alternate paths, see

“Defining and Viewing Alternate

Paths” (page 81)

.

NOTE:

In a Fibre Channel environment, up to 2,048 LU paths can be defined for one host group.
Up to 2,048 LU paths can be defined for one port.

You cannot define an LU path to volumes reserved by HP StorageWorks XP Auto LUN Software.
For more information about XP Auto LUN, See the HP StorageWorks XP24000/XP20000
Auto LUN Software User Guide
.

Up to 255 host groups can be created for one Fibre Channel port.

You cannot define an LU path to journal volumes.

You cannot define an LU path to pool volumes.

You cannot define an LU path to system disk volumes.

You cannot define an LU path to quorum disk volumes

Configuring LUN Security

To protect mission-critical data in your storage system from illegal access, you must apply security
policies to logical volumes. Use LUN Manager to enable LUN security on ports to safeguard LUs
from illegal access.

If a port has the External attribute, you cannot apply LUN security to the port.

If LUN security is enabled, host groups affect which host can access which LUs. Hosts can only
access LUs associated with the host group to which the hosts belong. The hosts cannot access LUs
associated with the other host groups. For example, hosts in the hp-ux host group cannot access
LUs associated with the windows host group. Also, hosts in the windows host group cannot access
LUs associated with the hp-ux host group.

In

“Enabling LUN Security” (page 10)

, LUN security is enabled on port CL1-A. The two hosts in

the hg-lnx host group can only access the three LUs 00:00:00, 00:00:01, and 00:00:02. The two
hosts in the hg-hpux host group can only access the two LUs 00:02:01 and 00:02:02. The two
hosts in the hg-solar host group can only access the two LUs 00:01:05 and 00:01:06.

Configuring LUN Security

9

Advertising
This manual is related to the following products: