<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Isolate a lun to one machine in Disk Enclosures</title>
    <link>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166145#M42972</link>
    <description>Landscape is as follows&lt;BR /&gt;1 Va7110 with luns 0 - 5&lt;BR /&gt;6 HPUX servers&lt;BR /&gt;&lt;BR /&gt;Lun 0 all servers see it&lt;BR /&gt;Lun 1&amp;amp;2 server H see (mirror of vg00 &amp;amp; vg01)&lt;BR /&gt;Lun 3 server TW sees it&lt;BR /&gt;Lun 4 server H sees it.&lt;BR /&gt;Lun 5 I am trying to isolate to server TH&lt;BR /&gt;&lt;BR /&gt;Except for Lun 0 and 5 (just created and configured in secure manager in the VA to go to TH).  Problem is that all servers can see it when you do an ioscan -fnCdisk.  &lt;BR /&gt;&lt;BR /&gt;It has been suggested that I do port isolation on the switches somehow to say Lun 5 is ONLY viewable by server TH and none others.&lt;BR /&gt;&lt;BR /&gt;Do I need to user any of the arm commands also?  It has only been 5 years since we last touched this and all memory is long gone.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;BR /&gt;Chuck</description>
    <pubDate>Wed, 25 Mar 2009 13:58:27 GMT</pubDate>
    <dc:creator>Charles Holland</dc:creator>
    <dc:date>2009-03-25T13:58:27Z</dc:date>
    <item>
      <title>Isolate a lun to one machine</title>
      <link>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166145#M42972</link>
      <description>Landscape is as follows&lt;BR /&gt;1 Va7110 with luns 0 - 5&lt;BR /&gt;6 HPUX servers&lt;BR /&gt;&lt;BR /&gt;Lun 0 all servers see it&lt;BR /&gt;Lun 1&amp;amp;2 server H see (mirror of vg00 &amp;amp; vg01)&lt;BR /&gt;Lun 3 server TW sees it&lt;BR /&gt;Lun 4 server H sees it.&lt;BR /&gt;Lun 5 I am trying to isolate to server TH&lt;BR /&gt;&lt;BR /&gt;Except for Lun 0 and 5 (just created and configured in secure manager in the VA to go to TH).  Problem is that all servers can see it when you do an ioscan -fnCdisk.  &lt;BR /&gt;&lt;BR /&gt;It has been suggested that I do port isolation on the switches somehow to say Lun 5 is ONLY viewable by server TH and none others.&lt;BR /&gt;&lt;BR /&gt;Do I need to user any of the arm commands also?  It has only been 5 years since we last touched this and all memory is long gone.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;BR /&gt;Chuck</description>
      <pubDate>Wed, 25 Mar 2009 13:58:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166145#M42972</guid>
      <dc:creator>Charles Holland</dc:creator>
      <dc:date>2009-03-25T13:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Isolate a lun to one machine</title>
      <link>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166146#M42973</link>
      <description>You need to configure the secure manager access table - most easy from the GUI of commandview sdm AFAIR.</description>
      <pubDate>Wed, 25 Mar 2009 14:10:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166146#M42973</guid>
      <dc:creator>Torsten.</dc:creator>
      <dc:date>2009-03-25T14:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Isolate a lun to one machine</title>
      <link>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166147#M42974</link>
      <description>Examples from the manual:&lt;BR /&gt;&lt;BR /&gt;Read the current contents of the security table into file secure.txt on host with &lt;BR /&gt;alias green. The password is the default value, AUTORAID.&lt;BR /&gt;&lt;BR /&gt;armsecure -r -f secure.txt -p AUTORAID green&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Write the security table stored in file secure.txt to array alias green. The &lt;BR /&gt;password is s33k3r. Clear the exisitng table before writing the new one, and &lt;BR /&gt;re-enable Secure Manager.&lt;BR /&gt;&lt;BR /&gt;armsecure â  w -c â  f secure.txt -p s33k3r green&lt;BR /&gt;&lt;BR /&gt;armsecure â  e -p s33k3r green&lt;BR /&gt;</description>
      <pubDate>Wed, 25 Mar 2009 14:13:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166147#M42974</guid>
      <dc:creator>Torsten.</dc:creator>
      <dc:date>2009-03-25T14:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Isolate a lun to one machine</title>
      <link>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166148#M42975</link>
      <description>Sorry bad format. again:&lt;BR /&gt;&lt;BR /&gt;Write the security table stored in file secure.txt to array alias green. The &lt;BR /&gt;password is s33k3r. Clear the exisitng table before writing the new one, and &lt;BR /&gt;re-enable Secure Manager.&lt;BR /&gt;&lt;BR /&gt;armsecure -w -c -f secure.txt -p s33k3r green&lt;BR /&gt;&lt;BR /&gt;armsecure -e -p s33k3r green</description>
      <pubDate>Wed, 25 Mar 2009 14:15:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166148#M42975</guid>
      <dc:creator>Torsten.</dc:creator>
      <dc:date>2009-03-25T14:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Isolate a lun to one machine</title>
      <link>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166149#M42976</link>
      <description>Torsten,&lt;BR /&gt;&lt;BR /&gt;The commands you suggest appear that your are going to unload the access table, wipe it out and then load it back.  What kind of change can that cause?&lt;BR /&gt;&lt;BR /&gt;from the command:&lt;BR /&gt;armsecure -r -f /tmp/stuff -p passw0rd va7110&lt;BR /&gt; I get&lt;BR /&gt;# more /tmp/stuff&lt;BR /&gt;DEFAULT                      0 WC&lt;BR /&gt;NODEWWN 50060b0000236bc7     1 W&lt;BR /&gt;NODEWWN 50060b0000236bc7     2 W&lt;BR /&gt;NODEWWN 50060b0000236bc7     4 W&lt;BR /&gt;NODEWWN 50060b0000236c6b     3 W&lt;BR /&gt;NODEWWN 50060b000023b999     1 W&lt;BR /&gt;NODEWWN 50060b000023b999     2 W&lt;BR /&gt;NODEWWN 50060b000023b999     4 W&lt;BR /&gt;NODEWWN 50060b000023b9a5     5 W&lt;BR /&gt;NODEWWN 50060b000023b9e5     5 W&lt;BR /&gt;NODEWWN 50060b0000242599     3 W&lt;BR /&gt;DEFAULT                      1 0&lt;BR /&gt;DEFAULT                      2 0&lt;BR /&gt;DEFAULT                      3 0&lt;BR /&gt;DEFAULT                      4 0&lt;BR /&gt;DEFAULT                      5 W&lt;BR /&gt;&lt;BR /&gt;which pretty well matches what is in the attatched screen shot from the VA itself.&lt;BR /&gt;Item 5 to each of the two san swithches is how I have it.  That part I feel I have right.  &lt;BR /&gt;&lt;BR /&gt;How do I set things up after that so that ONLY server TH can see the lun?&lt;BR /&gt;</description>
      <pubDate>Wed, 25 Mar 2009 15:34:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166149#M42976</guid>
      <dc:creator>Charles Holland</dc:creator>
      <dc:date>2009-03-25T15:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Isolate a lun to one machine</title>
      <link>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166150#M42977</link>
      <description>If you download the file, modify it and load it back, it would be extend the existing entries if you don't clear the table first.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Can you see what is wrong?&lt;BR /&gt;&lt;BR /&gt;DEFAULT 1 0&lt;BR /&gt;DEFAULT 2 0&lt;BR /&gt;DEFAULT 3 0&lt;BR /&gt;DEFAULT 4 0&lt;BR /&gt;DEFAULT 5 W&lt;BR /&gt;&lt;BR /&gt;The default for LUN 5 is write access for all servers:&lt;BR /&gt;&lt;BR /&gt;...Permissions&lt;BR /&gt;&lt;BR /&gt;0 - No access. Denies all access to the LUN. By default each LUN (except &lt;BR /&gt;LUN 0) is assigned this permission when it is created. LUN 0 is assigned â  CWâ   &lt;BR /&gt;permission. If a host is denied access to a LUN, the host operating system will &lt;BR /&gt;not â  seeâ   the LUN. This value is represented as â  Noneâ   in the GUI Secure &lt;BR /&gt;Manager table.&lt;BR /&gt;On versions of firmware prior to HP14, the default LUN table entries grant Write &lt;BR /&gt;access to all hosts. &lt;BR /&gt;&lt;BR /&gt;W - Write access. Grants a host full access to all data on the LUN. With write &lt;BR /&gt;permission, a host can write data to the LUN, and read all data on the LUN. A table &lt;BR /&gt;entry granting a host write permission to a LUN overrides the No Access security &lt;BR /&gt;imposed by default on all other hosts.</description>
      <pubDate>Wed, 25 Mar 2009 15:46:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166150#M42977</guid>
      <dc:creator>Torsten.</dc:creator>
      <dc:date>2009-03-25T15:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Isolate a lun to one machine</title>
      <link>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166151#M42978</link>
      <description>I see my mistake (I remember changing this to write) and have corrected it.  But still on server H, that shouldn't see LUN 5 I have the following output from an IO scan:&lt;BR /&gt;&lt;BR /&gt;disk       20  1/0/2/0/0.2.0.0.0.0.5    sdisk     NO_HW       DEVICE       HP  A6189B&lt;BR /&gt;&lt;BR /&gt;From server M I have the following:&lt;BR /&gt;disk       26  0/2/0/0.1.0.0.0.0.5     sdisk     NO_HW       DEVICE       HP  A6189B&lt;BR /&gt;                             /dev/dsk/c6t0d5   /dev/rdsk/c6t0d5&lt;BR /&gt;&lt;BR /&gt;Again I am trying to get only one server to see this Lun.</description>
      <pubDate>Wed, 25 Mar 2009 16:17:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166151#M42978</guid>
      <dc:creator>Charles Holland</dc:creator>
      <dc:date>2009-03-25T16:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Isolate a lun to one machine</title>
      <link>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166152#M42979</link>
      <description>Looks good now:&lt;BR /&gt;&lt;BR /&gt;NO_HW indicates the server cannot access it any longer. This will disappear after a reboot (or use rmsf).</description>
      <pubDate>Wed, 25 Mar 2009 16:34:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166152#M42979</guid>
      <dc:creator>Torsten.</dc:creator>
      <dc:date>2009-03-25T16:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Isolate a lun to one machine</title>
      <link>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166153#M42980</link>
      <description>Torsten, thanks for the help, won't make that mistake on the next LUN creation.&lt;BR /&gt;Chuck</description>
      <pubDate>Thu, 26 Mar 2009 11:31:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/disk-enclosures/isolate-a-lun-to-one-machine/m-p/5166153#M42980</guid>
      <dc:creator>Charles Holland</dc:creator>
      <dc:date>2009-03-26T11:31:09Z</dc:date>
    </item>
  </channel>
</rss>

