Cisco Nexus 5000 Series Switch Fabric Manager Software Configuration Guide, NX-OS 4.0 (OL-16598-01, June 2008)

Send comments to nx5000-docfeedback@cisco.com
16-16
Nexus 5000 Series Switch Fabric Manager Software Configuration Guide
OL-16598-01
Chapter 16 Configuring and Managing Zones
Zone Sets
Note The default zone members are explicitly listed only when the default zone policy is configured
as permit. When the default zone policy is configured as deny, the members of this zone are not
shown. See the “Verifying Zone Information” section on page 16-28.
About the Default Zone
Each member of a fabric (in effect a device attached to an Nx port) can belong to any zone. If a member
is not part of any active zone, it is considered to be part of the default zone. Therefore, if no zone set is
active in the fabric, all devices are considered to be in the default zone. Even though a member can
belong to multiple zones, a member that is part of the default zone cannot be part of any other zone. The
switch determines whether a port is a member of the default zone when the attached port comes up.
Note Unlike configured zones, default zone information is not distributed to the other switches in the fabric.
Traffic can either be permitted or denied among members of the default zone. This information is not
distributed to all switches; it must be configured in each switch.
Note When the switch is initialized for the first time, no zones are configured and all members are considered
to be part of the default zone. Members are not permitted to communicate with each other.
Configure the default zone policy on each switch in the fabric. If you change the default zone policy on
one switch in a fabric, be sure to change it on all the other switches in the fabric.
Note The default settings for default zone configurations can be changed.
The default zone members are explicitly listed when the default policy is configured as permit or when
a zone set is active. When the default policy is configured as deny, the members of this zone are not
explicitly enumerated when you view the active zone set.
You can change the default zone policy for any VSAN by choosing VSANxx > Default Zone from the
Logical Domains pane and clicking the Policies tab. It is recommended that you establish connectivity
among devices by assigning them to a nondefault zone.
Configuring the Default Zone
To permit or deny traffic to members in the default zone using Fabric Manager, perform this task:
Step 1 Expand a VSAN, and then choose Default Zone in the Fabric Manager Logical Domains pane.
Step 2 Click the Policies tab in the Information pane.
You see the zone policies information in the Information pane (see Figure 16-18).