Brocade Secure Fabric OS Administrator's Guide (53-1000244-01, November 2006)

Secure Fabric OS Administrator’s Guide 3-5
Publication Number: 53-1000244-01
3
2. Ensure that any zoning configuration downloads have completed on all switches in the fabric.
For information specific to zoning, see the Advanced Zoning Users Guide for Fabric OS v2.6.x and
v3.2.x, the Fabric OS Procedures Guide for Fabric OS v4.4.x, or the Fabric OS Administrator’s
Guide for Fabric OS v5.0.1, v5.1.0, or v5.2.0.
3. Open a sectelnet or SSH connection to the switch that will be the primary FCS switch.
The login prompt is displayed.
4. Log in to the switch.
5. Terminate any other sectelnet or SSH connections to the fabric (when using the secModeEnable
command, no other sessions should be active) and ensure that any other commands entered in the
current session have completed.
6. Use the secModeEnable command to enable secure mode.
Several optional arguments are available. This step illustrates three forms of the command:
Type secmodeenable --quickmode.
Type secmodeenable.
This version invokes the command’s interactive mode; then, identify each FCS switch at the
prompts (as shown in the next example). Press Enter with no data to end the FCS list.
Type secmodeenable "fcsmember;...;fcsmember".
fcsmember is the domain ID, WWN, or switch name of the primary and backup FCS switches,
with the primary FCS switch listed first.
See the Fabric OS Command Reference for other forms of the secModeEnable command.
ote
Most Secure Fabric OS commands must be executed on the primary FCS switch. The
secModeEnable command must be entered from a sectelnet or SSH connection.
N
ote
The secModeEnable command might fail if a switch running Fabric OS v2.6.x is in
the fabric. Fabric OS v2.6.x supports a maximum security database size of 16 Kb. If
you use --lockdown=dcc or --quickmode, a security database greater than 16 Kb
can be created. Enable security successful using other secModeEnable operands.
See the Fabric OS Command Reference for detailed command and operand
information.
Do not use the secModeEnable --currentpwd command until the passwords are
changed from the factory defaults by answering the password prompts during the
login.
Do not use
secModeEnable --quickmode in Fabrics with a fibre channel router
connected.