Brocade Fabric Watch Administrator's Guide (53-1000243-01, November 2006)

Fabric Watch Administrator’s Guide 1-9
Publication Number: 53-1000243-01
Fabric Watch Components
1
Resource Class Area
Table 1-7 describes the Fabric Watch resource class area.
Security Class Areas
Table 1-8 lists Fabric Watch areas in the security class and describes what each area indicates. For details
on each area, see the Secure Fabric OS Administrator’s Guide.
Table 1-7 Resource Class Area
Area Description
Flash Monitor Monitors the compact flash space available by calculating the percentage of flash
space consumed and comparing it with the configured high threshold value.
Table 1-8 Security Class Areas
Area Indicates
API Violation An API access request reaches a secure switch from an unauthorized IP
address.
DCC Violation An unauthorized device attempts to log in to a secure fabric.
Front Panel Violation A secure switch detects unauthorized front panel access.
HTTP Violation A browser access request reaches a secure switch from an unauthorized IP
address.
Illegal Command Commands permitted only to the primary Fibre Channel Switch (FCS) are
executed on another switch.
Incompatible DB Secure switches with different version stamps have been detected.
Invalid Certificates The primary FCS sends a certificate to all switches in the secure fabric before
it sends configuration data. Receiving switches accept only packets with the
correct certificate; any other certificates are invalid and represent an
attempted security breach.
Invalid Signatures If a switch cannot verify the signature of a packet, the switch rejects the
packet and the signature becomes invalid.
Invalid Timestamps If a time interval becomes too great from the time a packet is sent to the time
it is received, the timestamp of the packet becomes invalid and the switch
rejects it.
Login Violation A login violation occurs when a secure fabric detects a login failure.
MS Violation An MS (Management Server) violation occurs when an access request
reaches a secure switch from an unauthorized WWN (World Wide Name).
The WWN appears in the ERRLOG.
No FCS The switch has lost contact with the primary FCS.
RSNMP Violation An RSNMP (Remote Simple Network Management Protocol) violation
occurs when an SNMP (simple network management protocol) get operation
reaches a secure switch from an unauthorized IP address.