System Administrator Guide - Hitachi Vantara

Transcription

System Administrator GuideHitachi Virtual Storage Platform G200, G400, G600, G800Hitachi Virtual Storage Platform F400, F600, F800MK-94HM8016-05June 2016

2014, 2016 Hitachi, Ltd. All rights reserved.No part of this publication may be reproduced or transmitted in any form or by any means, electronicor mechanical, including copying and recording, or stored in a database or retrieval system forcommercial purposes without the express written permission of Hitachi, Ltd., or Hitachi Data SystemsCorporation (collectively “Hitachi”). Licensee may make copies of the Materials provided that any suchcopy is: (i) created as an essential step in utilization of the Software as licensed and is used in noother manner; or (ii) used for archival purposes. Licensee may not make any other copies of theMaterials. “Materials” mean text, data, photographs, graphics, audio, video and documents.Hitachi reserves the right to make changes to this Material at any time without notice and assumesno responsibility for its use. The Materials contain the most current information available at the timeof publication.Some of the features described in the Materials might not be currently available. Refer to the mostrecent product announcement for information about feature and product availability, or contactHitachi Data Systems Corporation at https://support.hds.com/en us/contact-us.html.Notice: Hitachi products and services can be ordered only under the terms and conditions of theapplicable Hitachi agreements. The use of Hitachi products is governed by the terms of youragreements with Hitachi Data Systems Corporation.By using this software, you agree that you are responsible for:1. Acquiring the relevant consents as may be required under local privacy laws or otherwise fromauthorized employees and other individuals to access relevant data; and2. Verifying that data continues to be held, retrieved, deleted, or otherwise processed inaccordance with relevant laws.Notice on Export Controls. The technical data and technology inherent in this Document may besubject to U.S. export control laws, including the U.S. Export Administration Act and its associatedregulations, and may be subject to export or import regulations in other countries. Reader agrees tocomply strictly with all such regulations and acknowledges that Reader has the responsibility to obtainlicenses to export, re-export, or import the Document and any Compliant Products.Hitachi is a registered trademark of Hitachi, Ltd., in the United States and other countries.AIX, AS/400e, DB2, Domino, DS6000, DS8000, Enterprise Storage Server, eServer, FICON,FlashCopy, IBM, Lotus, MVS, OS/390, PowerPC, RS/6000, S/390, System z9, System z10, Tivoli,z/OS, z9, z10, z13, z/VM, and z/VSE are registered trademarks or trademarks of InternationalBusiness Machines Corporation.Active Directory, ActiveX, Bing, Excel, Hyper-V, Internet Explorer, the Internet Explorer logo,Microsoft, the Microsoft Corporate Logo, MS-DOS, Outlook, PowerPoint, SharePoint, Silverlight,SmartScreen, SQL Server, Visual Basic, Visual C , Visual Studio, Windows, the Windows logo,Windows Azure, Windows PowerShell, Windows Server, the Windows start button, and Windows Vistaare registered trademarks or trademarks of Microsoft Corporation. Microsoft product screen shots arereprinted with permission from Microsoft Corporation.All other trademarks, service marks, and company names in this document or website are propertiesof their respective owners.2System Administrator Guide for Hitachi Virtual Storage Platform Gx00 and Fx00 Models

ContentsPreface. 9Intended audience. 10Product version. 10Release notes. 10Changes in this revision. 10Related documents.10Document conventions. 11Conventions for storage capacity values.12Accessing product documentation. 13Getting help.13Comments. 141 System administration overview. 15System management architecture. 16Administration tasks and tools.16Maintenance utility. 18Device Manager - Storage Navigator.19NAS Manager.20Accessing a storage system without the management software. 212 System configuration.23Setting up a management client.25Requirements for management clients.25General requirements. 25Requirements for Windows-based computers. 25Requirements for UNIX/Linux-based computers. 26Setting up TCP/IP for a firewall.27Configuring the web browser.27Configuring Internet Explorer for Device Manager - Storage Navigator. 28Configuring Firefox for Device Manager - Storage Navigator. 28Installing Adobe Flash Player. 29Logging in to Device Manager - Storage Navigator.303System Administrator Guide for Hitachi Virtual Storage Platform Gx00 and Fx00 Models

Initial super-user login. 30Normal login.30Changing your password. 32Adding your SVP to the trusted sites zone for Windows server. 32Changing the date and time.33Changing the controller clock settings. 33Changing the SVP clock settings. 34Changing the system date and time of the NAS modules. 34Changing network settings.35Setting up TCP/IP for a firewall.36Enabling IPv6 communication. 36Changing network communication settings.36Changing network permissions. 36Changing the administrator password. 37Creating a login message.37Setting up security. 38Selecting a cipher suite. 38Configuring SMU security - (Unified NAS module only).39Updating the certificate files. 40Forcing the system lock to release.42Setting storage system information.43Registering the primary SVP host name. 43Report configuration tool. 44Prerequisites for the report configuration tool. 44Installing the report configuration tool.45Using the report configuration tool.45Modifying SVP port numbers. 45Viewing the port number used in SVP.46Effects of changing SVP port numbers.47Changing the SVP port number.48Initializing the SVP port number.49Reassigning an automatically assigned port number. 50Initializing and reassigning an automatically assigned port number . 51Changing the range of an automatically assigned port number.52Initializing the range of an automatically assigned port number. 53Managing SSL certificates. 53Flow of SSL communication settings.53Creating a keypair.54Creating a private key.54Creating a public key. 55Obtaining a signed certificate. 56Obtaining a self-signed certificate .56Obtaining a signed and trusted certificate. 56Verifying and releasing an SSL certificate passphrase. 57Converting SSL certificates to PKCS#12 format. 58Updating a signed certificate. 58Notes on updating a signed certificate for the service processor.59Returning the certificate to default. 59Problems with website security certificates. 60Managing HCS certificates.60Registering HCS certificates. 61Deleting HCS certificates. 614System Administrator Guide for Hitachi Virtual Storage Platform Gx00 and Fx00 Models

Blocking HTTP communication to the SVP . 62Releasing HTTP communication blocking.62Backing up HDvM - SN configuration files.63Restoring HDvM - SN configuration files .643 User Administration. 67User administration for maintenance utility.68Required roles for operating Maintenance Utility.68Setting up user accounts. 69Disabling user accounts.71Removing user accounts.75Backing up user accounts.78Restoring user account information. 78User administration for Device Manager - Storage Navigator. 80User administration overview.80Workflow for creating and managing user accounts.80Administrator tasks.81User tasks. 81Managing user accounts.81Creating user accounts. 82Character restrictions for user names and passwords. 83Changing user passwords. 85Changing user permissions. 86Enabling or Disabling user accounts.87Deleting user accounts. 88Releasing a user lockout. 88Managing user groups.89Roles.89Built-in groups, roles, and resource groups.90Verifying the roles available to a user group. 92Checking if a role is available to a user group. 92Creating a new user group.93Changing a user group name. 94Changing user group permissions. 94Changing assigned resource groups.95Deleting a user group. 95Using an authentication server and authorization server. 96Authentication server protocols. 97Authorization server requirements. 98Connecting two authentication servers.98Connecting authentication and authorization servers.99Naming a user group in Device Manager - Storage Navigator. 99Creating configuration files. 100Creating an LDAP configuration file.100Creating a RADIUS configuration file. 103Creating a Kerberos configuration file.106User Administration for NAS Manager. 110Administrator types and responsibilities. 110Adding an SMU user (an administrator). 111Changing the password for a currently logged in user.114Changing your own password.1155System Administrator Guide for Hitachi Virtual Storage Platform Gx00 and Fx00 Models

Changing another user's password.116Changing an SMU user profile. 118SMU user authentication.121Active Directory user authentication.122Using Transport Layer Security (TLS) with Active Directory authentication. 122Configuring Active Directory servers.123Configuring Active Directory groups. 126User authentication through RADIUS servers. 130Displaying list of RADIUS servers. 131Adding a RADIUS server. 132Displaying details of RADIUS server. 1344 Alert notifications. 137Viewing alert notifications. 138Configuring alert notifications.138General settings.139Email settings. 140Syslog settings.140SNMP settings. 142Sending test messages. 142Sending a test email message.143Example of a test email message.143Sending a test Syslog message. 143Sending a test SNMP trap.

System Administrator Guide Hitachi Virtual Storage Platform G200, G400, G600, G800 Hitachi