Brocade Secure Fabric OS Administrator's Guide - Supporting Fabric OS v3.2.0, v4.4.0, v5.0.1, v5.1.0, 5.2.0, and 5.3.0 (53-1000244-02, June 2007)

42 Secure Fabric OS Administrator’s Guide
53-1000244-02
3
The FCS policy of Active and Defined Policy sets have been changed.
Review them before you issue secpolicyactivate again.
fcsswitchc:admin> secpolicyshow "active","FCS_POLICY"
____________________________________________________
ACTIVE POLICY SET
FCS_POLICY
PosPrimaryWWN DId swName
__________________________________________________
1Yes 10:00:00:00:00:00:33:3c3 fcsswitchc
2No 10:00:00:00:00:00:11:1c1 fcsswitcha
3No 10:00:00:00:00:00:22:2c2 fcsswitchb
The backup FCS switch becomes the new primary FCS switch, and the FCS policy is modified
so that the new and previous primary FCS switches have exchanged places.
Creating Secure Fabric OS Policies Other Than the FCS Policy
The FCS policy is automatically created when secure mode is enabled; other Secure Fabric OS
policies can be created after secure mode is enabled. (Using the quickmode or lockdown options to
the secModeEnable command also creates an SCC policy and a DCC policy.) The member list of
each policy determines the devices or switches to which the policy applies.
If a policy does not exist, then no Secure Fabric OS controls are in effect for that aspect of the
fabric. If a policy exists but has no members, that functionality is disabled for all switches in the
fabric. As soon as a policy has been created, that functionality becomes disabled for all switches
except the members listed in the policy.
NOTE
Save policy changes frequently; changes are lost if the switch is rebooted before the changes are
saved.
Each supported policy is identified by a specific name, and only one policy of each type can exist
(except for DCC policies). The policy names are case sensitive and must be entered in all
uppercase. Multiple DCC policies can be created using the naming convention DCC_POLICY_nnn,
with nnn representing a unique string.
NOTE
Uploading and saving a copy of the Secure Fabric OS database after creating the desired Secure
Fabric OS policies is strongly recommended. The configUpload command can be used to upload a
copy of the configuration file, which contains all the Secure Fabric OS information. For more
information about this command, see the Fabric OS Command Reference.