MSA Storage
1752806 Members
6775 Online
108789 Solutions
New Discussion юеВ

Re: MSA1500cs acl configuration

 
Thierry W
Occasional Contributor

MSA1500cs acl configuration

Hello,
We have a msa1500 cs with A/A firmware.
Already some LUN accessed by 2 cluster nodes with multipath on Novell SLES. No acl setup.
We want to add a single path server to a new configure LUN. The HBA differ from the cluster nodes one. We want to prevent access to this new server to view existing LUN so i want to setup acl but :
If i make a first acl rule (for new server) it will enable acl (as mentionned in doc) but what about existing servers (which are in production)?
How does it affect existing servers (dirupting connections ?) ? do i have to create acl rules for these servers ?
Thanks for replies
4 REPLIES 4
Uwe Zessin
Honored Contributor

Re: MSA1500cs acl configuration

If you want to start using ACLs you must set them up for all servers.
.
Thierry W
Occasional Contributor

Re: MSA1500cs acl configuration

What do you mean ?
I want to configure acl via MSA CLI.
I know i can setup SSP via ACU too but is it the same ? and again how does it affect my production servers ?
Thanks
Uwe Zessin
Honored Contributor

Re: MSA1500cs acl configuration

If you set the ACLs up properly (for ALL servers: new + existing ones), it will not affect your servers, but I thought that is self-explanatory so I did not mention it.

Now, things can go wrong (I know from experience how easy it is to mess something up), so I recommend to do it with downtime.

- shutdown the operating systems

- set up the ACL
-- as a plus, verify the operating system profile on each connection

- go into the management interface of each Fibre Channel adapter and check if all paths are still available

- boot one server and check the paths from the operating system, too

- proceed with the next server and so on...
.
Thierry W
Occasional Contributor

Re: MSA1500cs acl configuration

It worked thanks for replies