HP Virtual Connect for c-Class BladeSystem Version 3.
© Copyright 2010 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein. Microsoft is a U.S. registered trademark of Microsoft Corporation.
Contents Introduction .................................................................................................................................. 6 Virtual Connect documentation ...................................................................................................................... 6 Overview ..................................................................................................................................... 7 Virtual Connect overview ...................................
Trap categories and required administrative privileges ......................................................................... 44 Trap severities .................................................................................................................................. 44 SNMP Configuration (VC-Enet) .......................................................................................................... 45 SNMP Configuration (VC-FC) ................................................................
Bandwidth assignment ...................................................................................................................... 98 PXE settings ............................................................................................................................................... 99 Define Server Profile screen ....................................................................................................................... 100 Advanced Profile Settings...............................
Introduction Virtual Connect documentation The following Virtual Connect documentation is available on the HP website (http://www.hp.com/go/bladesystem/documentation): • HP Virtual Connect for c-Class BladeSystem User Guide This guide provides details for the Virtual Connect GUI, including descriptions of screen contents and steps to set up domains, profiles, networks, and storage.
Overview Virtual Connect overview Virtual Connect is a set of interconnect modules and embedded software for HP BladeSystem c-Class enclosures that simplifies the setup and administration of server connections.
By stacking (cabling) the Ethernet modules within the domain and connecting the FC modules to the same set of FC SANs, every server blade in the domain can be configured to access any external network connection. With this configuration, the administrator can use Virtual Connect Manager to deploy and migrate a server blade profile to any server in the Virtual Connect domain without changing external LAN or SAN configurations.
HP Virtual Connect Manager Configuring browser support Access to the application must be through HTTPS (HTTP exchanged over an SSL-encrypted session). For optimal viewing, HP recommends setting the screen resolution to 1280 x 1024. Requirements The HP Virtual Connect Manager Web interface requires an XSLT-enabled browser with support for JavaScript 1.3 or equivalent. The following browsers are supported: • Microsoft® Internet Explorer 7.x or higher • Mozilla Firefox 3.
Always apply relevant licenses that are dependent on MAC addresses after the server profiles are assigned so that the licenses are not lost due to a change in MAC address. IMPORTANT: If you plan to use RDP for RedHat Linux installation and also plan to use Useror HP-defined MAC addresses, you must import the enclosure before running RDP. RDP "rip and replace" is not supported in a Virtual Connect environment.
Command line overview The HP Virtual Connect Manager Command Line Interface can be used as an alternative method for managing the Virtual Connect Manager. Using the CLI can be useful in the following scenarios: • HP Management Applications (for example, Systems Insight Manager or Insight Control tools) can query the Virtual Connect Manager for information these tools need to present a complete management view of HP BladeSystem enclosures and devices.
• There is no connection to the Virtual Connect Ethernet module running the active Virtual Connect Manager. • The Virtual Connect Manager is in the middle of a failover or recovery. • The attempted IP sign-in address is not valid for the specified account. • The attempted IP sign-in address is for a Virtual Connect Ethernet module not running the active Virtual Connect Manager. • The browser settings are incorrect. See "Configuring browser support (on page 9).
Navigating the HP Virtual Connect Manager GUI Navigation overview The HP Virtual Connect Manager navigation system consists of a tree view on the left side of the page that lists all of the system devices and available actions. The tree view remains visible at all times. The right side of the page, which includes a pull-down menu at the top, displays details for the selected device or activity.
Menu item Links to information" on page 20) Reset Virtual Connect Manager Reset Virtual Connect Manager screen ("Reset Virtual Connect Manager" on page 21) Help Table of contents VC Manager help file table of contents Index VC Manager help file index For This Page Help topic specific to the current page Virtual Connect Documentation on hp.com The Virtual Connect Documentation page on the HP website (http://www.hp.com/go/bladesystem/ documentation).
To select the device and open the device detail page, click the link for an individual device. Individual device pages contain detailed information about the selected device and any other functions related to that device. Domain Status summary The Domain Status summary provides a count of Virtual Connect elements that are in an alert status other than OK. Virtual Connect elements summarized here include networks, shared uplink sets, server profiles, interconnect modules, and server blades.
To view a summary of systems that have an alert icon displayed, click the Domain Status link. See "Domain Status screen (on page 17).
Domain Status screen This screen provides an overall domain status and a detailed summary of systems that currently have an alert status other than OK. To view detailed information about a device, click that device name in the list. Additional information on the issue might be available as a tooltip for the severity icon. To see this information, mouse over the severity icon.
Enclosures View This graphical representation consists of an enclosure front view and rear view. To display a window with information about a particular device, mouse over that device in this graphical view. The Enclosures view provides status on each device in the enclosure and the option to select an individual device for more detailed information. To display the Enclosures View screen, click Hardware Overview in the left window.
Enclosures view (multiple enclosures) When more than one enclosure has been imported, each enclosure is displayed on the Enclosures View screen. Status icon definitions Icon Status Description Critical A device or system is indicating a potential outage. Incompatibl e/ Mismatch A profile is incompatible with assigned hardware. Missing A device or item is missing. Major A device or system is degraded. Minor A device or system is degraded. Disabled A device or item is disabled.
Icon Status Description Normal Status of this line item is okay. Information al — Other icon definitions Icon Description Mouse over to view specific help for the associated field. The UID/PID of this line item is not illuminated. The UID/PID for this line item is illuminated. The server blade is powered on. (green) The server blade is powered off. (amber) Click to view a printable report of the onscreen summary. This icon is not available if no report function is available for that screen.
Reset Virtual Connect Manager Users must have Administrative privileges to reset the Virtual Connect Manager. In a multi-enclosure environment, the Ethernet modules in bays 1 and 2 of the primary enclosure host the Virtual Connect Manager. To reset the Virtual Connect Manager application running on the primary Virtual Connect Ethernet module, select Reset Virtual Connect Manager from the Tools pull-down menu. The Reset Virtual Connect Manager screen is displayed.
Domain management Domain overview A basic Virtual Connect domain includes a single HP c-Class BladeSystem c7000 Enclosure for a total of 16 servers (or up to 32 servers if the double-dense option is enabled), or a single HP c-Class BladeSystem c3000 Enclosure for a total of 8 servers (or up to 16 servers if the double-dense option is enabled).
Firmware updates To update firmware, use the HP BladeSystem c-Class Virtual Connect Support Utility. For more information on installing the firmware, see the HP BladeSystem c-Class Virtual Connect Support Utility documentation on the HP website (http://www.hp.com/go/bladesystem/documentation). When upgrading to v3.00, any SAN fabrics previously using the static login distribution method are redefined to use dynamic login distribution.
For additional information, see "Interconnect Bay summary screen (Ethernet module) (on page 128)" and "Administrative module removal (on page 142)." The following table describes the available actions in the Domain Settings (Domain Configuration) screen. Clicking another link in the pull-down menu or left navigation window causes current edits that have not been applied to be lost. Task Action Change the domain name Enter the revised domain name, and then click Apply.
4. Enter the name of the domain to be deleted. This should be the name of the domain you are currently logged into, displayed in the Virtual Connect Domain Name box on the Domain Settings (Domain Configuration) screen (on page 23). 5. Click OK. If deleting a domain that was using MAC addresses predefined by HP, the administrator should also update the "Teaming" driver configuration file on the host OS.
Task Action Clear unsaved changes on the screen Click Clear. Save changes and remain on this screen Click Apply. Cancel without saving changes Click Cancel. Domain Settings (Domain Enclosures) screen Use this screen to import, delete, or add enclosures in the domain. Multiple enclosures are supported only if a VC-Enet module is running in bay 1 and bay 2 of the primary enclosure.
Column Description Status Displays whether the enclosure has been imported Adding and importing a remote enclosure Adding and importing a remote enclosure requires full domain and server privileges. Virtual Connect Manager supports up to four c7000 enclosures in a single domain. To add a remote enclosure: 1. Click Find on the Domain Settings (Domain Enclosures) screen (on page 26). 2. Type in the following information: o OA IP Address o OA User Name o OA Password 3. Click OK. 4.
5. Click Import.
Virtual Connect Manager imports the enclosure and provides status information. Removing a remote enclosure To remove a remote enclosure, disassociate all profiles, networks, port sets, and port monitors from the enclosure. If the enclosure is currently in a No-COMM state, the remote enclosure remains in VC Mode. Take the enclosure out of VC mode manually with the OA command line for that enclosure. To remove a remote enclosure: 1. Go to the Domain Settings (Domain Enclosures) screen (on page 26). 2.
IMPORTANT: Virtual Connect Manager cannot use backup configurations created with previous versions of Virtual Connect Manager. For example, if you are currently using v2.01, you cannot use a backup configuration that was created using v1.20. To back up a domain configuration: 1. Click Backup Configuration. 2. Navigate to the hard drive location for the backup file. 3. Name the file (usually the domain name), and then click Save. To restore a domain configuration: 1.
Domain Settings (Local Users) screen The first time this screen appears, the only local user account is the Administrator account, which has domain privileges. The Administrator account cannot be deleted or have domain privileges removed. However, the Administrator password can be changed. The default Administrator password is identified on the Default Network Settings label on the Ethernet module in interconnect bay 1.
• To enable strong passwords or enable local users, click Advanced. To enable the use of strong passwords, select the Require Strong Passwords checkbox. Use the up and down arrows to select a password length between 3 and 40 characters.
Column Description Contact Contact information for the user account. The contact information can be the name of an individual, a telephone number, or other useful information. All users can modify their own contact information. Account Status Shows whether a user account is enabled or disabled. Delete Displays the Delete icon. Click the Delete icon, and then click Apply to delete that line item. The following table describes the available actions in the Domain Settings (Local Users) screen.
Add new user Observe the following user settings guidelines: • Username is a required field. • A username must contain an alpha-numeric value with 1 to 13 characters. • A password must contain an alpha-numeric value with 3 to 40 characters.
• • • o Administer SSL certificates o Delete the VC domain o Save configuration to disk o Restore the configuration from a backup o Configure SNMP settings Networking o Configure network default settings o Select the MAC address range to be used by the VC domain o Create, delete, and edit networks o Create, delete, and edit shared uplink sets o Configure Ethernet SNMP settings Server o Create, delete, and edit server Virtual Connect profiles o Assign and unassign profiles to device
Directory Settings (Directory Server) screen This screen enables Administrators to set up an LDAP server to authenticate users accessing the CLI or GUI based on user name, password, and role. Beginning with version 1.31 of Virtual Connect Manager, users can test an LDAP configuration before applying it. For more information, see "Test LDAP authentication (on page 39)." The following table describes the fields within the Directory Settings (Directory Server) screen.
Directory Settings (Directory Groups) screen Use this screen to manage the Directory Group settings for Virtual Connect Manager. The following table describes the fields within the Directory Settings (Directory Groups) screen. Field Description Group Name The Directory Server group name. Microsoft Active Directory servers have a reverse mapping from the user to the groups the user belongs to.
To remove a group from the configuration, click the Delete icon. To open the Add LDAP Group page, click New. Add LDAP Group Use this screen to add a Directory Group. The following table describes the fields within the Add LDAP Group screen. Field Description Group Name This is the Directory Server group name. Microsoft Active Directory servers have a reverse mapping from the user to the groups the user is a member of.
Directory Settings (Directory Certificate) screen Directory Certificates provide authentication of the Directory Server. There are two ways to verify the identity of the Directory Server: • Install certificates that complete a certificate chain to a root Certificate Authority. • Install a certificate that exactly matches the certificate provided by the Directory Server. To upload a certificate, select the certificate from the list, and then click Certificate Upload.
The status window displays any problems encountered during the test. When testing is complete, click Close. SNMP overview SNMP is used by network management systems to monitor network-attached devices for conditions that require administrative attention. SNMP consists of a set of standards for network management, including an Application Layer protocol, a database schema, and a set of data objects.
• For Flex-10 connections, threshold and link state change traps reflect the state of the entire physical port. These traps are not generated for individual FlexNICs. For more information on Flex-10 connections, see "Flex-10 overview (on page 94)." The following table provides a list of MIBs and where they are supported.
Trap Category Severity MIB authenticationFailure VC-Enet Other CRITICAL SNMPv2-MIB Domain status change VCM Domain Status Corresponds to the name of the new state VCD-MIB StackingLinkRedundant status change VCM Domain Status Corresponds to the name of the new state VCD-MIB Module role change VCM Domain Status INFO VCM-MIB Stale checkpoint VCM Domain Status WARNING VCD-MIB Valid checkpoint VCM Domain Status NORMAL VCD-MIB Enclosure status change VCM Domain Status Corresponds to
The VC-FC module generates connUnitPortStatusChange traps based on changes to the connUnitPortStatus element of the FA-MIB. The following table shows the mapping of connUnitPortStatusChange trap severities to the VC Domain MIB's trap severity definitions.
Trap categories and required administrative privileges In general, users with Domain privileges can manage any SNMP operations. Users with Network privileges can manage Ethernet operations, and users with Storage privileges can manage FC operations. The following table provides a summary of trap categories and the required administrative privileges.
SNMP Configuration (VC-Enet) By enabling SNMP for VC-Enet modules, network management systems can monitor VC-Enet modules in the domain for events, such as warnings and errors, that might require corrective actions. The user must have network or domain administrator privileges to administer SNMP Enet settings. The VC-Enet SNMP settings apply to all VC-Enet modules in the Virtual Connect domain. The following table describes the fields within the SNMP Configuration screen.
Field name Description Community String The Community String acts like a password for a given trap destination. The trap receiving application can use the community string to filter the incoming traps. Default: public Format Format of the new trap. Select SNMPv1 or SNMPv2. To add a trap destination, right-click on the header row of the destination table, and then select Add Destination. See "Adding an SNMP trap destination (on page 46).
For VC-Enet modules, the maximum trap community string length is 39. For VC-FC modules, the maximum trap community string length is 24. 5. Click OK to save the information and return to the main SNMP configuration screen, or continue and select trap categories or trap severities. If you enter information that is invalid (for example, if you use a space in the Destination name), a red box appears around that field. Mouse over the box to see information regarding the error.
The VC-FC SNMP settings apply to all VC-FC modules in the VC domain. The following table describes the fields within the SNMP Configuration screen. Field name Description Enable SNMP Select to enable SNMP System Contact Specify a contact name for this system when SNMP is enabled Read Community Controls SNMP read access when SNMP is enabled. The default value for read community string is "public". The read community string must always be set when SNMP is enabled. The maximum length is 39 characters.
To edit or delete a trap destination, right-click on that trap destination row, and then select Edit Destination or Delete Destination. To apply changes made on this screen, click Apply. SMI-S overview The ability to enable or disable SMI-S is not available on the HP VC 8Gb 24-Port FC module. The SMI-S was created by SNIA to standardize storage management solutions.
Domain management 50
System Log Configuration Use this screen to view or set remote log destination settings. Column Description Log host The IP address or the DNS of the configured remote log destination Log severity Severity of the log messages that should be sent to the specified destination. Valid values include "Critical", "Error", "Warning", and "Informational". Transport The transport protocol to be used for sending the log messages to the destination. Valid values include "TCP" and "UDP".
To send a test message to all enabled remote log destinations, click Test. To delete a remote log destination, select the checkbox next the preferred destination, and then click Delete.
Network management Networks overview The Virtual Connect Ethernet module uses standard Ethernet bridge circuitry with special firmware so that it functions as a configurable Ethernet port aggregator. For a specific external data center connection, only the selected server Ethernet NIC ports are visible on what appears to be an isolated, private, loopfree network.
Define Ethernet Network screen The Define Ethernet Network screen is accessible to all users with network privileges from the Define a Network link on the Virtual Connect Manager homepage or the Define pull-down menu. The following table describes the fields within the Define Ethernet Network screen. Field name Description Network Network Name Name of the network Smart Link (on page 53) To enable Smart Link, edit the network settings after the network is created.
Field name Description address and switch port appear. A link is provided to obtain more information about the far-end switch port. PID When selected, sets/clears the port identifier color as blue on the VCEnet module to aid in the location of the specific uplink. The PID status for the overall network also appears. Speed/Duplex Pull-down menu to specify the speed and duplex (where applicable) of the uplink port. Half-duplex operations are not supported by the VCEnet module.
3. Select whether to designate (checked) or not designate (unchecked) this network as a private network ("Private Networks" on page 53). 4. Select whether to enable (checked) or disable (unchecked) VLAN tunneling ("Server VLAN Tagging Support" on page 69). This option is only available if the 'Tunnel VLAN Tags' radio button was previously selected on the Advanced Settings tab of the Ethernet Settings screen. 5.
Advanced Network Settings These settings affect only newly created profiles. Changing these settings does not affect any assigned profiles. To set the speed, click the selection box, select a setting (100Mb to 10Gb), and then click OK. • Set a Custom value for the Preferred Link Connection Speed. This value is the default speed for server profile connections mapped to this network. The server administrator can override this setting on an individual profile connection.
This screen has similar fields to the Define Ethernet Network screen (on page 54). This screen can only be edited by users with network privileges, but it is viewable by all authorized users. The following table describes the fields within the Edit Network screen.
Field name Description PID When selected, this option sets/clears the port identifier color as blue on the VC E-net module to aid in the location of the specific uplink. The PID status for the overall network also appears. Speed/Duplex Pull-down menu to specify the speed and duplex (where applicable) of the uplink port The following table describes the available actions in the Edit Network Screen.
This summary screen displays the external connections for each network and is available to all authorized users. The following table describes the columns within the summary table on the Ethernet Networks (Summary) screen.
Task Action Define a new network Right-click in the table to display a menu, and then click Add. Delete a network Left-click on the network row, right-click to display a menu, and then select Delete. Type in the network name, and then click OK. Illuminate the PID for all uplink ports associated with a network Click on the circle next to the network in the list.
The following table describes the available actions in the Ethernet Networks (Server Connections) screen. Clicking another link in the pull-down menu or left navigation window causes current edits that have not been applied to be lost. Task Action Sort list view Click the down arrow next to the Show box to display All Networks, or one specific network. Edit a network Click on the name of the network in the table listing. Edit a server profile Click on the name of the profile in the table listing.
For additional information, see "MAC address settings (on page 63)." MAC Address Settings IMPORTANT: Configuring Virtual Connect to assign server blade MAC addresses requires careful planning to ensure that the configured range of MAC addresses is used once within the environment. Duplicate MAC addresses on an Ethernet network can result in a server network outage. Each server blade Ethernet NIC ships with a factory default MAC address.
Multifunction Gigabit server adapter. Only the primary MAC address is used by standard (not multifunction) Ethernet devices. • If a server blade is moved from a Virtual Connect managed enclosure to a non-Virtual Connect enclosure, the local MAC addresses on that server blade are automatically returned to the original factory defaults.
Whenever port monitoring is enabled, a warning icon appears in the banner at the top of the page. If port monitoring is configured and enabled within the Virtual Connect domain, Ethernet data from the monitored ports is replicated on the network analyzer port, which poses a security risk and could result in network loops if not connected properly. The following table describes the fields within the Ethernet Settings (Port Monitoring) screen.
Field name Description MAC MAC address of monitored port Server Bay Assignment Enclosure and server device bay the monitored port is associated with Network Network associated with the downlink port, if one exists Delete Displays Delete icon. Click to remove the port from the monitored list. The following table describes the available actions in the Ethernet Settings (Port Monitoring) screen.
Select Monitored Ports screen The Select Monitored Ports screen is displayed when the Select Ports button is clicked on the Ethernet Settings (Port Monitoring) screen. You can select up to 16 server ports to monitor. The list of ports can be filtered by selecting one or more of the drop-down boxes at the top of the screen. The following table describes the available actions in the Select Monitored Ports screen. Task Action Select a port to be monitored Select the checkbox corresponding to the port.
Task Action Clear newly selected ports without saving and return to the Port Monitoring screen Click Cancel.
Server VLAN Tagging Support This option provides explicit VLAN tagging support for server links, enabling each server link to be shared among multiple networks. Users can map server VLAN-tagged Ethernet packets to specific networks, which is essential in deploying server virtualization applications such as a virtual operating system solution.
The following figure shows tunneled VLAN tags. On the dedicated, green network, both uplink and server VLAN tags are tunneled through Virtual Connect unchanged. On the shared, red and blue networks, uplink VLAN tags are mapped to networks. Untagged frames are mapped to the native VLAN, if present, otherwise they are dropped. Server frames are untagged only, and tagged frames are dropped. Each server port is connected to a single network.
possibility of configurations where server VLANs might not match external VLANs used on uplinks. To avoid this scenario, you can select the 'Force server connections to use the same VLAN mappings as shared uplink sets' option. Server port connections to networks are defined on the Define Server Profile screen (on page 100). Restrictions and limitations • • Maximum number of networks per shared uplink set: o For Virtual Connect v2.30 and later – 128 networks o For Virtual Connect v1.
o No server profile connections are assigned to multiple networks not linked to a Shared Uplink Set. This action forces all server connections mapped to multiple networks to be linked to a shared uplink set. Server administrators cannot override this selection when creating or editing a profile. Multiple Networks Link Speed Settings When using mapped VLAN tags (multiple networks over a single link), these settings are used for the overall link speed control.
Stacking Links screen To access this screen, click the Stacking Links link under Fibre Channel Settings in the left VC Manager navigation window. Be sure to connect any Ethernet module stacking cables before running the network setup wizard. IMPORTANT: For a Virtual Connect environment to operate properly, all Virtual Connect Ethernet modules within the Virtual Connect domain must be interconnected with stacking links.
Port X0 indicates the 10Gb port connected through the midplane of horizontally-adjacent VC-Enet modules. Ports X7 and X8 connect to the internal link between horizontally-adjacent Flex-10 enabled VC-Enet modules. NOTE: Virtual Connect does not support stacking for FC modules, so each VC-FC module requires uplink connections to the external FC SAN environment.
For Virtual Connect v1.34 and Virtual Connect v2.10, a maximum of 64 associated networks is supported in each shared uplink set. All other versions support a maximum of 32 networks per shared uplink set. The following table describes the fields within the Define Shared Uplink Set screen. Field name Description Ethernet Shared External Uplink Set Uplink Set Name Descriptive name for the shared uplink set. Do not use spaces.
Field name Description Network Name Displays the name of the associated networks VLAN ID Displays the VLAN ID number Native Select whether native VLAN is enabled (checked) or disabled (unchecked). Smart Link Select whether Smart Link is enabled (checked) or disabled (unchecked). Private Network Select to designate (checked) or not to designate (unchecked) this network as a private network. The following table describes the available actions in the Define Shared Uplink Set screen.
1. Enter the shared uplink set name. The uplink set name can be up to 64 characters in length (no spaces). 2. Add one or more external ports using the Add Port pull-down menu. Only available ports are listed, and they display the current port link status. Select two or more ports to ensure a high availability connection. 3. Select the speed and duplex (where applicable) of the uplink ports. Click the drop-down box under Speed/Duplex, and then select a setting.
Use this screen to edit the properties of an existing shared uplink set, add/delete an associated network, or delete a shared uplink set. This screen has the same fields as the Define Shared Uplink screen. The screen can be edited only by users with network privileges, but it is viewable by all authorized users. The following table describes the fields within the Edit Shared Uplink Set screen.
Field name Description Network Name Displays the name of the associated networks VLAN ID Displays the VLAN ID number Native Select whether native VLAN is enabled (checked) or disabled (unchecked). Smart Link Select whether Smart Link is enabled (checked) or disabled (unchecked). Private Network Select whether to designate (checked) or not designate (unchecked) the network as a private network. The following table describes the available actions in the Edit Shared Uplink Set screen.
This summary screen provides an overview of external shared uplink connections. This screen is only applicable if multiple networks are being connected over a single external uplink set by the use of VLAN tagging. The following table describes the fields within the Shared Uplink Sets screen.
Shared Uplink Sets (Associated Networks) screen To access this screen, click the Shared Uplink Sets link in the left VC Manager navigation window, and then click the Associated Networks tab. This summary screen displays the mapping of networks to external shared uplink connections. This screen is only applicable if multiple networks are being connected over a single external uplink set by the use of VLAN tagging.
Storage management Storage overview The Virtual Connect Fibre Channel modules enable the c-Class administrator to reduce FC cabling by making use of N_Port_ID virtualization (NPIV). The HP VC-FC acts as an HBA aggregator where each NPIV-enabled N-port uplink can carry the FC traffic for multiple HBAs. Because it uses an N-port uplink, it can be connected to data center Brocade, McData, Cisco, and Qlogic FC switches that support the NPIV protocol.
Define SAN Fabric screen To define a SAN fabric, select the Define SAN Fabric link on the Home page, or click Define SAN Fabric on the SAN Fabrics screen. Only connect HP VC 4Gb FC module, HP VC 8Gb 24-Port FC module, or HP VC 8Gb 20-Port FC module uplinks to Fibre Channel switch ports that are NPIV-enabled. If using a Brocade FC switch, verify that NPIV is enabled properly by using the portshow command.
• Multi-enclosure domain The following table describes the columns and fields within the Define SAN Fabric screen. Column Description Fabric Name Descriptive name for the virtual fabric. Do not use spaces. Login Re-Distribution Login Re-distribution setting for the fabric Configured Speed Speed of the uplink ports, available after a port has been added Uplink Port Number of the enclosure uplink port Bay Enclosure bay selected for the SAN fabric.
Task Description Set the uplink port speed After an uplink port has been added, click the drop-down arrow in the Configured Speed field, and then select a speed. Delete an uplink port Left-click an uplink port row to select it, right-click to display a menu, and then select Delete Port. Save changes and remain on this screen Click Apply. Clear the current, unsaved changes and return to the home page Click Cancel.
Maximum logins per port: (1..255) [255] 126 . . switch:admin> switchenable Cisco switch Cisco Fibre Channel switches running SAN-OS 3.0 or later will support NPIV. To enable NPIV on Cisco Fibre Channel Switches running the Cisco Device Manager, use the following procedure: 1. From the Cisco Device Manager, click Admin, and then select FeatureControl. The Feature Control window appears. 2. Click the row titled NPIV. 3. In the Action column select enable, and then click Apply. 4.
SAN Fabrics (External Connections) To access this screen, click SAN Fabrics in the left VC Manager navigation window. This screen lists all of the SAN fabrics that have been created and displays the external connection information. • To edit a fabric, left-click to select the SAN Fabric row, right-click to display a menu, and then select Edit. • To add a fabric, left-click to select the SAN Fabric row, right-click to display a menu, and then select Add.
To delete a fabric, select the checkbox of that line item, and then click Delete. To create a new fabric, click Define SAN Fabric. To redistribute logins on a SAN fabric, click Redistribute Logins.
Edit SAN Fabric Use this screen to edit a SAN fabric configuration. The following table describes the fields within the Edit SAN Fabric screen. Field Description Fabric Name Descriptive name for the fabric. Do not use spaces.
The following table describes the available actions in the Edit SAN Fabric screen. Clicking another link in the pull-down menu or left navigation window causes the current edits that have not been applied to be lost. Task Description Modify a fabric name Type a name in the Fabric Name field. Do not use spaces. Set the uplink port speed Click the drop-down arrow in the Configured Speed field and select a speed. Add an uplink port Click Add Port.
• Select Fibre Channel Settings from the Configure pull-down menu.
Server management Server profile overview A Virtual Connect server profile is a logical grouping of attributes related to server connectivity that can be assigned to a server blade. The server profile can include MAC address, PXE, and network connection settings for each server NIC port and WWN, SAN fabric connection, and SAN boot parameter settings for each Fibre Channel HBA port. After being defined, the server profile can be assigned to any server blade within the Virtual Connect domain.
Virtual Connect domain that has existing profiles, an option to add FC connections appears in the existing profiles during editing. • Some server profile SAN boot settings (controller boot order) are applied by Virtual Connect only after the server blade has been booted at least once with the final mezzanine card configuration.
“Bays 1-4 (HP Integrity BL890c i2)”. This is true in the left navigation tree, in the Server Bays summary screen, in the list of bays that a profile can be assigned to in the Edit Server Profile screen, and so on. A profile is assigned to an entire multi-blade server, not to the individual blades in the server.
Although these four FlexNICs share a single 10Gb physical interface, Virtual Connect is able to keep traffic for the FlexNICs isolated, and each FlexNIC is assigned to a different Virtual Connect network. Each FlexNIC can be assigned a different bandwidth (from 100Mb to 10Gb), which is enforced by hardware mechanisms.
Flex-10 configuration Network administrator For each Virtual Connect network, the network administrator can set a "Preferred" and "Maximum" speed for FlexNICs that connect to that network. FlexNICs cannot connect to a network at a speed higher than the maximum speed set by the network administrator for that network. The "preferred" speed setting is the speed recommended by the network administrator for any FlexNIC that attaches to that network.
The Allocated Bandwidth column displays "not allocated" until the profile is assigned to a device bay that contains a server. At that time, bandwidth is allocated to each connection and the result is reported in this column. See "Bandwidth assignment (on page 98)." The Mapping column describes how each connection of a profile is assigned to physical devices in a server, and to which interconnect bay that device is connected.
8. Assign profile connection 8 to LOM port 2 because it is Flex-10 capable and can support up to four connections. For information about multi-blade server port assignments, see "Multi-blade servers (on page 93)." Bandwidth assignment In Flex-10 environments, four FlexNICs must share a single 10Gb link. Each FlexNIC is allocated a portion of that 10Gb link's bandwidth.
Requested Calculation Allocation + remainder FlexNIC a 1Gb (1/12)*10Gb = 800Mb 900Mb FlexNIC b 2Gb (2/12)*10Gb = 1600Mb 1700Mb FlexNIC c 4Gb (4/12)*10Gb = 3300Mb 3300Mb FlexNIC d 5Gb (5/12)*10Gb = 4100Mb 4100Mb 2. Every FlexNIC that is linked must be allocated at least 100Mb. For example, if four FlexNICs on a given port have requested bandwidth settings of 2Gb, 8Gb, Auto, and Auto, their allocated bandwidth is as shown in the table below.
Only the first FlexNIC on each physical port of a Flex-10 device can be used for PXE boot. Virtual Connect cannot enable PXE boot on the remaining FlexNICs of a physical port. Redundancy for PXE operations can be achieved using multiple PXE enabled NICs. However, the Virtual Connect Manager is limited to enabling only one NIC for PXE booting.
Column name Description Profile Profile Name Descriptive name for the server profile. The specified text is used as the base (prefix) for the name of the created Virtual Connect server profiles. The text can be up to 48 alpha-numeric characters, dashes, and underscores. Do not use spaces. Advanced Profile Settings (on page 103) Select to show if server factory defaults are being used for Ethernet MAC Addresses, Fibre Channel WWNs, and Serial Numbers (Logical).
Column name Description Model Model name of the server blade in the device bay Status Status of the server blade in the device bay UID Icon indicates if the server blade UID is on or off If VC-assigned MAC addresses, WWNs, or non-default Fibre Channel boot parameters are being used, always power off the affected server blades before assigning a profile. When assigning a VC-assigned serial number (logical), power off the server.
b. Click the down arrow under Port Speed to select Auto, 2Gb, 4Gb, 8Gb, or Disabled for that port. Auto is the default. 6. To modify the Fibre Channel boot parameters, select the Show Fibre Channel Boot Parameters checkbox. See "Fibre Channel boot parameters (on page 107)." 7. To assign the server profile to a device bay, click the down arrow next to Select Location to select an enclosure and bay number. This step can be deferred.
CAUTION: To avoid storage networking issues and potential loss of data associated with duplicate WWNs on a FC SAN fabric, plan carefully when allowing Virtual Connect to assign server blade WWNs so that the configured range of WWNs is used only once within the environment. Multiple network connections for a server port Server port connections to virtual networks are defined on the Define Server Profile screen (on page 100). Previous to Virtual Connect Manager v1.
With this 'forced' option selected, the server connection VLAN mappings are linked to the chosen shared uplink set. Any change to the uplink VLAN mappings is reflected automatically on the server connection using those shared uplink set VLAN mappings. Therefore, to minimize network outage time, any VLAN mapping changes to the uplinks requires immediate changes being made to the VLAN tagging on the servers.
the server side. Finally, to simplify configuration, a "Copy From…" button is available to copy existing network mappings from a shared uplink set or from other server ports. VLAN ID mapping guidelines • For each server port, all VLAN mappings must be unique. When the 'Force same VLAN mappings as Shared Uplink Sets' option is selected, this setting is handled automatically because all networks within a shared uplink set must have unique VLAN IDs.
Server network mapping is similar to the set of networks defined under a shared uplink set. The only difference is that when defining a shared uplink set, the networks are created in the Virtual Connect Domain along with options such as "Native VLAN", "Smart Link", and so on, while defining server network mappings does not result in creation of any networks in the VC Domain.
Define a Server Profile screen ("Define Server Profile screen" on page 100). To access the Fibre Channel boot parameters, select the Show Fibre Channel Boot Parameters checkbox. There are four SAN Boot options: • Use BIOS/EFI (default)—SAN boot settings are not configured by Virtual Connect Manager. BIOS settings are used. • Primary—Port is enabled for SAN boot, and is first in the boot order. • Secondary—Port is enabled for SAN boot, and is second in the boot order.
Server Profiles screen This screen lists all server profiles that have been defined within the domain, including assigned and unassigned profiles. From this screen, users can see the assigned device bays, NIC MAC addresses, FC HBA WWNs, network connections, and Fibre Channel Fabric and Boot Parameters for all server profiles as well as generate a printable report of this information.
Task Action Show all profiles, only assigned profiles, or only unassigned profiles Click the down arrow in the Show: box. Define a new profile Left-click in the table, right-click to display a menu, and then click Add, or select Server Profile from the Define menu at the top of the screen. Edit a server profile Left-click on the profile row, right-click to display a menu, and then click Edit.
Column name Description Ethernet Network Connections (Physical ports) Port Relative order of the Ethernet port on the server receiving the profile. System board NICs are first in the order, followed by NICs on mezzanine cards Network Name Name of the network associated with this port, selected from a list of defined networks Status Status of the network Port Speed Setting The requested operational speed for the server port. Valid values include "Auto", "Preferred", and "Custom".
Task Action Assign a Network Name Click the drop-down arrow in the Network Name field, and then select a network. Change the port speed setting Click the drop-down arrow in the Port Speed Setting column, and then select Preferred, Auto, or Custom. If Custom is selected, set the port speed, and then click OK. Enable or disable PXE, or use the Use BIOS setting Click the drop-down arrow in the PXE column and select enabled, disabled, or Use BIOS.
Server profile troubleshooting In some cases, server profiles can be assigned to server blades when certain mismatches exist between the server profile definition and the server blade. The following list summarizes Virtual Connect behavior under these circumstances: • If the number of Network connections in the profile is more than the number of physical Ethernet ports, the profile is assigned, but a warning message appears.
• Making modifications to a profile that affect settings on the server blade; for example, PXE enable/disable, changing the number of connections, or changing Fibre Channel boot parameters • When assigning a VC-Assigned serial number (logical) The following operations do not require the server blade to be powered off: • Changing the network connected to an already defined Ethernet port • Changing the Fabric connected to a Fibre Channel port • Changing the speed of a Fibre Channel port • Assignin
• Changing the requested bandwidth Restart after OA credential recovery For VC v1.21 and higher, the VC Manager behavior has changed for powered-up servers when restarting after a recovery of OA credentials. In previous versions, the servers entered a "profile pending" state and required a power cycle to recover. For VC v1.21 and higher, a new state, "profile recovered," is applied to servers that are powered on when VC Manager restarts after an OA credential recovery.
Server management 116
Certificate Administration Certificates/Authentications (SSL Certificate) screen This page displays the detailed information of the Secure Socket Layer (SSL) Certificate currently in use by the Virtual Connect Manager. An SSL certificate is used to certify the identity of the Virtual Connect Manager and is required by the underlying HTTP server to establish a secure (encrypted) communications channel with the client Web browser.
The following table describes the tables within the Certificate/Authentications (SSL Certificate) screen. Row Description Issued to The subject, or "Common Name," to which this SSL Certificate is issued. By default, this is the dynamic DNS name of the HP 1/10Gb VC-Enet Module. If a Virtual Connect domain IP address is configured, a new certificate request is issued to the domain IP address.
Note that a new certificate request is generated each time this web page is visited, so the content may not be the same each time. Certificate Upload There are two methods for uploading certificates for use in the Virtual Connect Ethernet module: • Paste the certificate contents into the text field, and then click Upload. • Paste the URL of the certificate into the URL field, and then click Apply.
If the new certificate is successfully accepted and installed by the Virtual Connect Manager, you are automatically logged out. The HTTP server must be restarted for the new certificate to take effect. Certificates/Authentications (SSH Administration) This screen lists the current user (assuming administrator privileges) of each authorized SSH key and enables the user to add new keys. Only local users can have authorized SSH keys.
When a user has authorized one or more SSH keys, the user can delete all of them by clicking Clear SSH Keys. Removing the authorized SSH keys does not affect current SSH sessions. Web SSL Configuration This screen enables you to change the currently configured SSL encryption strength. This screen is only available to users with Domain Administration privileges.
When the web SSL encryption strength is changed, logged in users are notified that they must reconnect.
Hardware information screens Enclosure Information screen The following table describes the rows within the Enclosure Information screen.
Removing an enclosure To remove a remote enclosure, disassociate all profiles, networks, port sets, and port monitors from the enclosure. If the enclosure is currently in a No-COMM state, the remote enclosure remains in VC Mode. Take the enclosure out of VC mode manually with the OA command line for that enclosure.
Enclosure Status screen When a VC domain loses connectivity with a remote enclosure OA, the Enter OA Credential button appears on this screen. For additional information, see "Recovering remote enclosures. ("Recovering remote enclosures" on page 21)" The following table describes the rows within the Enclosure Status screen.
Interconnect Bays Status and Summary screen The following table describes the rows within the Interconnect Bays Status table in the Interconnect Bays Status and Summary screen.
Causes for INCOMPATIBLE status When a module status is INCOMPATIBLE, details can be viewed in the System log ("System Log screen" on page 49). The system log provides information about why a module is marked incompatible so that proper corrective action can be taken. Following is a list of reasons why a module might be INCOMPATIBLE and the suggested corrective action. • Module adjacency Typically, a module can only be in a bay next to a module of the same type.
Interconnect Bay Summary screen (Ethernet module) This screen provides a summary of the interconnect module status and port information. To remove a module, see "Module removal and replacement (on page 141)" and "Administrative module removal (on page 142)." The following table describes the rows within the Interconnect Bay Status (VC-Enet Module) table in the Bay Summary screen.
The following table describes the rows within the Interconnect Bay Information table in the Bay Summary screen.
Column Description Label Uplink port number Network(s) Network name or the name of the shared uplink associated with this port Status Displays whether the port is linked or unlinked Connector Type Displays the physical type of the faceplate connector, type of pluggable module if one is present, or "Internal" to indicate the inter-switch link is active on the VC-Enet module. LAG ID Identifies the group of ports that have been aggregated together to form an 802.3ad Link Aggregation Group.
To refresh the statistics, click Refresh Statistics. The following tables describe the rows within the Port Detailed Statistics screen.
Port Statistic Description IfInUcastPkts The number of subnetwork-unicast packets delivered to a higher-layer protocol. IfInNUcastPkts The number of non-unicast (subnetwork-broadcast or subnetworkmulticast) packets delivered to a higher-layer protocol. IfInDiscards The number of inbound packets that were chosen to be discarded even though no errors had been detected to prevent their being delivered to a higher-layer protocol.
Port Statistic Description Dot1dBasePortMtuExceededDiscar ds The number of frames discarded by this port due to an excessive size. It is incremented by both transparent and source route bridges. Dot1dBasePortInFrames The number of frames that have been received by this port from its segment.
Port Statistic Description EtherStatsPkts1024to1518Octets The total number of packets (including bad packets) received that were between 1024 and 1518 octets in length inclusive (excluding framing bits, but including FCS octets). EtherStatsOversizePkts The total number of packets received that were longer than 1518 octets (excluding framing bits, but including FCS octets) and were otherwise well-formed.
Port Statistic Description EtherStatsCRCAlignErrors The total number of packets received that had a length (excluding framing bits, but including FCS octets) of between 64 and 1518 octets, inclusive, but had either a bad FCS with an integral number of octets (FCS Error) or a bad FCS with a non-integral number of octets (Alignment Error). TXNoErrors All packets transmitted without errors, less oversized packets. RXNoErrors All packets received without errors, less oversized and undersized packets.
Port Statistic Description Dot3StatsDeferredTransmissions A count of frames for which the first transmission attempt on a particular interface is delayed because the medium is busy. The count represented by an instance of this object does not include frames involved in collisions. This counter does not increment when the interface is operating in full-duplex mode.
Port Statistic Description Dot3StatsSymbolErrors For an interface operating at 100 Mb/s, the number of times an invalid data symbol occurred when a valid carrier was present.
Port Statistic Description IfHCOutBroadcastPckts The total number of packets that higher-level protocols requested be transmitted, and which were addressed to a broadcast address at this sublayer, including those that were discarded or not sent. This object is a 64-bit version of ifOutBroadcastPkts. Remote Device Information Description remote_type Type of remote device. Virtual Connect uses this information to configure the link as an uplink, a stacking link, or to disable.
Interconnect Bay Summary screen (VC-FC Module) This screen provides a summary of the interconnect module status and port information. To remove a module from the domain, see "Administrative module removal (on page 142)." The following table describes the rows within the Interconnect Bay Status (VC-FC Module) table in the Bay Summary screen.
The following table describes the rows within the Interconnect Bay Information table in the Bay Summary screen.
Column Description SAN Fabric Name of the SAN Fabric connected to the uplink port Port Speed Speed setting of the uplink port Connector Status Status of the uplink port Connected To MAC address of the device that this port is connected to on the other end. The device must support LLDP to display this information. The following table describes the rows within the Server Port Information table in the Bay Summary Screen.
2. Remove all uplinks and downlinks. 3. Replace the module. Administrative module removal The Remove from Domain feature enables users to remove an interconnect module from the Virtual Connect domain without having to delete the entire domain, or having the bay permanently configured for a specific interconnect module type. Removing a VC-Enet module and installing it in another enclosure causes the configuration information on that module to be cleared.
Interconnect Bay Overall Status icon definitions Icon Operational state Meaning Corrective action OK Device is fully operational. None Unknown Device operational state cannot be determined. Check Onboard Administrator communication. Initializing Device is initializing. Wait until initialization is complete. (This icon should only be seen at startup.) Degraded Device is partially operational, but capability is lost. Check and correct the Onboard Administrator error condition.
Icon Operational state Meaning Corrective action Unavailable Device is active but unable to provide service. Attempt to re-establish connection. Degraded Device is partially operational, but capacity is lost. Check and correct the Onboard Administrator error condition. Misconfigured Device has a configuration error. Correct the Virtual Connect Manager configuration attributes. Incompatible Device does not match the configuration. Remove the incorrect hardware. Insert the correct module.
Server Bays Summary screen Device bay numbering is affected by whether the 'Allow the double density device bays' option was selected while using the Domain Setup Wizard. Bays might appear as 'Covered' or 'Unknown.' For more information, see "Double-dense server bay option (on page 146)." If a multi-blade server is installed, the bay numbering shows a span of bays, for example, Bays 1-4, in the Bay column. For more information, see "Multi-blade servers (on page 93).
Double-dense server bay option If the 'Allow the double density device bays' option was selected while using the Domain Setup Wizard, VC Manager displays the server bays as double-dense, regardless of the actual hardware installed. For example, if a full-height server blade is installed in physical Bay 1 of a double-dense enabled enclosure, Bay 1A and Bay 1B in VC Manager are displayed as 'Covered.
Use of the double-dense server bay option requires OA version 2.20 or higher. If the OA is downgraded to a lower version, subsequent recovery of the double-dense enabled enclosure results in bays A and B being marked 'Unknown.
Server Bay Overall Status icon definitions Icon Operational state Meaning Corrective action OK Device is fully operational. None Unknown Device operational state cannot be determined. Check Onboard Administrator communication. Initializing Device is initializing. Wait until initialization is complete. (This icon should only be seen at startup.) Profile pending Device has a pending profile assignment. Turn server power off and apply the new profile.
Icon Operational state Meaning Corrective action Unknown Device operational state cannot be determined. Check Onboard Administrator communication. Disabled User has administratively disabled the device. Enable the component in Virtual Connect Manager. Initializing Device is initializing. Wait until initialization is complete. (This icon should only be seen at startup.) Profile pending Device has a pending profile assignment. Turn server power off and apply the new profile.
Server Bay Status screen To change the power state of the server blade, click Momentary Press. To power the server blade on or off, click Press and Hold. The following table describes the rows within the Server Bay Status table in the Server Bay Status screen.
Row Description Power Status/Control Icon indicates whether the server blade in that bay is powered on or off. The following table describes the rows within the Server Blade Information table in the Server Bay Status screen.
The following table describes the columns within the Server Ethernet Adapter Information table in the Server Bay Status screen.
Server Bay Status screen - multi-blade servers To change the power state of the server blade, click Momentary Press. To power the server blade on or off, click Press and Hold. The following table describes the rows within the Server Bay Status table in the Server Bay Status screen.
Row Description Enclosure Name Name of the enclosure where this server blade is installed UID Icon indicates whether the UID is illuminated or not illuminated. Power Status/Control Icon indicates whether the server blade in that bay is powered on or off. The following table describes the rows within the Server Blade Information table in the Server Bay Status screen.
Column Description Port Number Relative Fibre Channel Port number Adapter Mezzanine number where the HBA is connected Model Type of mezzanine installed WWN VC-Assigned WWN or "Server Factory Default" if not assigning WWNs Connected to Bay number Hardware information screens 155
Acronyms and abbreviations CFG constant frequency generator CHAP Challenge Handshake Authentication Protocol DNS domain name system DO data object FC Fibre Channel FCS Frame Check Sequence GMII Gigabit media independent interface HBA host bus adapter LACP Link Aggregation Control Protocol LAG link aggregation group LAG ID link aggregation group ID LDAP Lightweight Directory Access Protocol Acronyms and abbreviations 156
LLDP Link Layer Discovery Protocol MAC Media Access Control NPIV N_Port ID Virtualization OA Onboard Administrator PHY physical layer device PLS physical signaling POST Power-On Self Test RBSU ROM-Based Setup Utility RD receive data RDP Rapid Deployment Pack RMON remote monitoring SIM Systems Insight Manager SMI-S Storage Management Initiative Specification SNIA Storage Networking Industry Association Acronyms and abbreviations 157
SSL Secure Sockets Layer TCN Spanning Tree Topology Change Notification VID VLAN ID VLAN virtual local-area network WWN World Wide Name Acronyms and abbreviations 158
Glossary external port The Ethernet connectors (10GBASE-CX4 and RJ45) on the faceplate of the VC-Enet module labeled as ports 1-8, X1, and X2. shared server links A feature that enables each server link to be shared among multiple networks with the use of VLAN tagging. shared uplink port An Ethernet uplink port that carries the traffic for multiple Virtual Connect networks.
Index A About menu 12 accessing HP Virtual Connect Manager 10 ActiveX 9 adding a user 31 adding an LDAP group 38 adding enclosures 27 adding new users 34 administrative module removal 142 Advanced Network Settings 57 Advanced Profile Settings 103 B backup domain 29 bandwidth assignment 98 boot paramaters, Fibre Channel 107 Brocade switch 83, 85 browser requirements 9, 10 C certificate administration 117 certificate upload 119 certificate, requesting 118 Cisco switch 86 CLI (Command Line Interface) 11 comm
FC connections 100, 109, 113 Fibre Channel boot parameters 107 Fibre Channel settings (WWN) 90, 103 firmware, Onboard Administrator requirements 10 firmware, updating 23 Flex-10 configuration 96 Flex-10 overview 94 G graphical view 18 H homepage, Virtual Connect Manager 12 I multiple multiple multiple multiple enclosures, adding and importing 27 enclosures, using 8 networks link speed settings 68, 72 networks option 104 N native VLAN 74 navigating 13 network analyzer port 64 network, creating internal
required administrative privileges, trap categories 44 requirements, web interface 10 resetting the system 21 restore domain 29 rip and replace 9 S SAN Fabrics (External Connections) 87 SAN Fabrics (Server Connections) 87 select monitored ports 67 serial number (logical) settings 115 serial number, enclosure 22 server bay status information, multi-blade servers 153 server bay, information 145 server bay, status information 150 server blade, powering down 113 server connections, viewing 61 server profile ov