Linux Storage - MDS FC alias and zoning commands
Linux Storage Solution · Config document · referenced from FC aliases, zones and zonesets
ZONESET_V12, ZONESET_V11) and the switch warns about it. The old zonesets stay in the full zone database; the notes do not remove them. One of the author's comments names HV03 where the command creates HV04; the command is right, the comment is not.The command set that gave every logged-in port an FC alias, built one single-initiator zone per server, collected the zones into the zonesets PROD-DMZ (VSAN 12) and PROD-DC (VSAN 11), and activated them, with the show zoneset active output before and after each activation. The port WWNs come from the flogi and fcns databases. The show running-config zone listings taken at the end are their own Config documents: VSAN 11 and VSAN 12.
| Item | Value |
|---|---|
| Switch | FCSwitch1, Cisco MDS 9124e, NX-OS 5.2(8) |
| Run as | admin, configuration mode FCSwitch1(config)# and its sub-modes config-fcalias, config-zone, config-zoneset |
| Aliases | HV01, HV02, MGMT01, Storage1-C0P0 in VSAN 11; HV03, HV04, Storage1-C0P1 in VSAN 12 |
| Zones | HV01-Storage1, HV02-Storage1, MGMT01-Storage1 in VSAN 11; HV03-Storage1, HV04-Storage1 in VSAN 12 |
| Zonesets | PROD-DC activated in VSAN 11, PROD-DMZ activated in VSAN 12 |
| Replaced | ZONESET_V11 and ZONESET_V12, interface-based zones with the switch WWN 20:00:54:7f:ee:ab:cd:18 |
| Time | the running configuration carries Fri Dec 6 04:31:15 2013 for VSAN 12 and 05:28:58 for VSAN 11 |
The commands
Setting the FC aliases for the servers. Each fcalias name line opens the config-fcalias sub-mode for the member pwwn line after it; configuration mode on FCSwitch1. The author wrote one comment per alias: HV01 sits in BAY1 and belongs to VSAN 11 (DC); HV02 in BAY2, VSAN 11 (DC); HV03 in BAY3, VSAN 12 (DMZ); the fourth comment reads "the FC alias for server HV03, which sits in BAY4" although the alias created is HV04; MGMT01 in BAY5, VSAN 11 (DC).
$ fcalias name HV01 vsan 11 $ member pwwn 50:01:43:80:12:34:56:c0 $ fcalias name HV02 vsan 11 $ member pwwn 50:01:43:80:12:34:56:d4 $ fcalias name HV03 vsan 12 $ member pwwn 50:01:43:80:12:34:57:90 $ fcalias name HV04 vsan 12 $ member pwwn 50:01:43:80:12:34:57:92 $ fcalias name MGMT01 vsan 11 $ member pwwn 50:01:43:80:12:34:40:2c
Setting the FC aliases for the disk array: one for the storage port in VSAN DC (11), one for the storage port in VSAN DMZ (12). Same mode.
$ fcalias name Storage1-C0P0 vsan 11 $ member pwwn 21:12:00:02:ac:00:ab:cd $ fcalias name Storage1-C0P1 vsan 12 $ member pwwn 21:11:00:02:ac:00:ab:cd
Zoning (single-initiator zoning) for the DMZ (VSAN 12). The zone named HV03-Storage1 for the server HV03 and the disk array in the DMZ zone (VSAN 12), and the zone HV04-Storage1 for HV04 and the disk array. Each zone name opens the config-zone sub-mode, exit leaves it; configuration mode on FCSwitch1.
$ zone name HV03-Storage1 vsan 12 $ member fcalias Storage1-C0P1 $ member fcalias HV03 $ exit $ zone name HV04-Storage1 vsan 12 $ member fcalias Storage1-C0P1 $ member fcalias HV04 $ exit
Zoning (single-initiator zoning) for the DC (VSAN 11): the zones HV01-Storage1, HV02-Storage1 and MGMT01-Storage1, each for one server and the disk array in the DC zone (VSAN 11). Same mode.
$ zone name HV01-Storage1 vsan 11 $ member fcalias Storage1-C0P0 $ member fcalias HV01 $ exit $ zone name HV02-Storage1 vsan 11 $ member fcalias Storage1-C0P0 $ member fcalias HV02 $ exit $ zone name MGMT01-Storage1 vsan 11 $ member fcalias Storage1-C0P0 $ member fcalias MGMT01 $ exit
Create the zoneset named PROD-DMZ for VSAN 12 and fill it with the zones defined above. zoneset name opens the config-zoneset sub-mode; configuration mode on FCSwitch1.
$ zoneset name PROD-DMZ vsan 12 $ member HV03-Storage1 $ member HV04-Storage1 $ exit
Create the zoneset named PROD-DC for VSAN 11 and fill it with the zones defined above. Same mode.
$ zoneset name PROD-DC vsan 11 $ member HV01-Storage1 $ member HV02-Storage1 $ member MGMT01-Storage1 $ exit
Activating PROD-DMZ for the DMZ (VSAN 12)
Look at which zoning is currently active for VSAN 12. The show ran from configuration mode on FCSwitch1.
$ show zoneset active vsan 12
output 5 lines
zoneset name ZONESET_V12 vsan 12 zone name Z_FC1_b3_FC1_e2_V12 vsan 12 * fcid 0x660000 [interface bay3 swwn 20:00:54:7f:ee:ab:cd:18] * fcid 0x660200 [interface bay4 swwn 20:00:54:7f:ee:ab:cd:18] * fcid 0x660300 [interface ext2 swwn 20:00:54:7f:ee:ab:cd:18]
Activate the zoneset named PROD-DMZ. Configuration mode; the switch warns that a different zoneset is active and the y after [n] is the answer typed.
$ zoneset activate name PROD-DMZ vsan 12
output 2 lines
WARNING: You are trying to activate zoneset PROD-DMZ, which is different from current active zoneset ZONESET_V12. Do you want to continue? (y/n) [n] y Zoneset activation initiated. check zone status
Check that the zoneset for VSAN 12 activated successfully: show the zoning currently active for VSAN 12. The author marked the result as OK.
$ show zoneset active vsan 12
output 5 lines
zoneset name PROD-DMZ vsan 12 zone name HV03-Storage1 vsan 12 * fcid 0x660000 [pwwn 50:01:43:80:12:34:57:90] * fcid 0x660200 [pwwn 50:01:43:80:12:34:57:92] * fcid 0x660300 [pwwn 21:11:00:02:ac:00:ab:cd]
The next step in the notes, showing every zoning setting active and inactive for VSAN 12 with sh run zone vsan 12, is the Config document running configuration of the zoning, VSAN 12.
Activating PROD-DC for the DC (VSAN 11)
Look at which zoning is currently active for VSAN 11. Configuration mode on FCSwitch1.
$ show zoneset active vsan 11
output 12 lines
zoneset name ZONESET_V11 vsan 11 zone name Z_FC1_b1_FC1_e1_V11 vsan 11 * fcid 0x2a0000 [interface bay1 swwn 20:00:54:7f:ee:ab:cd:18] * fcid 0x2a0300 [interface ext1 swwn 20:00:54:7f:ee:ab:cd:18] zone name Z_FC1_b2_FC1_e1_V11 vsan 11 * fcid 0x2a0100 [interface bay2 swwn 20:00:54:7f:ee:ab:cd:18] * fcid 0x2a0300 [interface ext1 swwn 20:00:54:7f:ee:ab:cd:18] zone name Z_FC1_b5_FC1_e1_V11 vsan 11 * fcid 0x2a0200 [interface bay5 swwn 20:00:54:7f:ee:ab:cd:18] * fcid 0x2a0300 [interface ext1 swwn 20:00:54:7f:ee:ab:cd:18]
Activate the zoneset named PROD-DC. Configuration mode; same warning, same answer.
$ zoneset activate name PROD-DC vsan 11
output 2 lines
WARNING: You are trying to activate zoneset PROD-DC, which is different from current active zoneset ZONESET_V11. Do you want to continue? (y/n) [n] y Zoneset activation initiated. check zone status
Check that the zoneset for VSAN 11 activated successfully: show the zoning currently active for VSAN 11. The author marked the result as OK.
$ show zoneset active vsan 11
output 12 lines
zoneset name PROD-DC vsan 11 zone name HV01-Storage1 vsan 11 * fcid 0x2a0000 [pwwn 50:01:43:80:12:34:56:c0] * fcid 0x2a0300 [pwwn 21:12:00:02:ac:00:ab:cd] zone name HV02-Storage1 vsan 11 * fcid 0x2a0100 [pwwn 50:01:43:80:12:34:56:d4] * fcid 0x2a0300 [pwwn 21:12:00:02:ac:00:ab:cd] zone name MGMT01-Storage1 vsan 11 * fcid 0x2a0200 [pwwn 50:01:43:80:12:34:40:2c] * fcid 0x2a0300 [pwwn 21:12:00:02:ac:00:ab:cd]
The sh run zone vsan 11 that follows in the notes is the Config document running configuration of the zoning, VSAN 11.
What the lines mean
| Line | Meaning |
|---|---|
fcalias name X vsan N | a named list of members, valid in one VSAN only; the same alias name would have to be created again in another VSAN |
member pwwn | an alias member by port WWN; the only member type used here |
zone name X vsan N | a zone, the unit of access: members of one zone may talk to each other |
member fcalias | a zone member by alias; the switch resolves it to the WWN when the zoneset is activated |
zoneset name X vsan N, member <zone> | a set of zones; only one zoneset per VSAN can be active |
zoneset activate name X vsan N | makes that zoneset the active one, replacing whatever was active |
* fcid … [pwwn …] | in the active zoneset output, a member that is logged in (*) with the FCID it has now |
[interface bayN swwn …] | a member defined by switch port: the WWN of the switch (swwn) and the interface on it, as the old zonesets did it |
Each zone pairs one server alias with one storage alias, so a server sees only the storage port and never another server's HBA: this is what single-initiator zoning means. The old zones Z_FC1_b3_FC1_e2_V12 and Z_FC1_bN_FC1_e1_V11 did the same pairing by switch port instead of by WWN. The notes do not say who created them or whether they came with the enclosure; the names read as "FC switch 1, bay N, to FC switch 1, ext N, VSAN 11", which is my reading of them. What the full zone database looked like after all of this, with the old and the new side by side, is in the two running-configuration documents.
Checked against Cisco MDS NX-OS 9.4(5a)
| As built | Today |
|---|---|
fcalias name X vsan N, member pwwn | Unchanged; the member types are pwwn, fwwn, fcid, domain-id and port, IP address and interface fc with swwn or domain-id. Cisco's best practice now reads "Device aliases should be used to simplify the management of world wide names (WWNs) whenever possible" and "Operate device aliases in Enhanced mode whenever possible", which I read as device aliases instead of FC aliases |
zone name X vsan N, member fcalias | Unchanged; zone members may also be device-alias, fcid, fwwn, pwwn, interface fc slot/port with domain-id or swwn, IP address or symbolic node name |
zoneset name, zoneset activate name X vsan N and the warning "You are trying to activate zoneset X, which is different from current active zoneset Y" | Unchanged, warning text included. New since then: zoneset overwrite-control vsan N refuses to activate a zoneset with a different name unless force is given, which would have stopped the replacement done here without an explicit decision |
| Single-initiator zones, one server and one storage alias each | Still Cisco's recommendation: "a single initiator with a single target is the most efficient approach to zoning" and "Configuring multiple initiators to multiple targets is not recommended." Smart zoning, off by default, "eliminates the need to create a single initiator to single target zones"; how it does so is my general understanding, not a sentence of the guide |
| Basic zoning, default zone denied, full zone set not distributed (nothing in the notes changes these) | Still the defaults: enhanced zoning disabled, smart zoning disabled, default zone policy "Denied to all members", full zone set not distributed |
Interface-based zone members, as in the old Z_FC1_… zones | Still a valid member type; the guide's only advice is to anchor interface members on the switch with the highest port count in the fabric. No sentence preferring pwwn over interface members was found |
The commands typed in 2013 are the commands of today. What changed is the advice around them: device aliases instead of FC aliases, as I read Cisco's sentences, and the option of smart zoning instead of one zone per initiator.