EMC VMAX – Access Control Logix (ACLX) Gatekeeper Mapping

Access Control Logix (ACLX) gatekeeper mapping is required for initial device masking configuration on the VMAX via the Administration host and also required for the Control Station when using a NAS VG Gateway with the VMAX.
The Symmetrix configuration recommendation is to assign only the ACLX (Access Control Logix) gatekeeper volume to the Administration Host or Control Station.

In this example the ACLX volume is already mapped as LUN ff to the Director FA ports: 2g1,3g1 which are zoned to the Administration Host.
We need to MAP the ACLX Volume(003C) to the FA Ports 1f1,2f1,3f1,4f1 which will be used for the NAS Control Station. The ACLX device must be at LUN address 00E when mapping to the Control Station.

Mapping ACLX (volume 003C) Via UNISPHERE:

Firstly we navigate to the ACLX Volume 003C, choosing the MAP option and then proceed to select FA Ports 1f1,2f1,3f1,4f1
UNI1

Configure ACLX as target and LUN 0E – this must be done for each FA Port
UNI2

UNI3

Next we choose the option to ‘Set Volume Status’ and configure as Write Disable
UNI4

UNI5

ACLX is now mapped to both our Administration Host and Control Station as Lun 0FF and 00E respectfully:
UNI6

You can review the task of Mapping the LUN to the FA Ports by navigating to System->Job List:
UNI7

Mapping ACLX (volume 003C) Via SYMCLI:
You can also use symcli to Map the ACLX volume as follows

symdev -sid 1151 list -aclx -v provides the symdev number and other detailed information for the ACLX volume
CLI1
CLI2

Map the ACLX volume to the specified director and port, with the specified FA LUN number:
symconfigure -sid xxx -cmd “map dev 003C to dir 1f:1 lun=00E;” commit
symconfigure -sid xxx -cmd “map dev 003C to dir 2f:1 lun=00E;” commit
symconfigure -sid xxx -cmd “map dev 003C to dir 3f:1 lun=00E;” commit
symconfigure -sid xxx -cmd “map dev 003C to dir 4f:1 lun=00E;” commit
symdev -sid xxx write_disable 003C -FA ALL

List all details for dev 003C including FA and DA mappings as well as disk group used:
symdev -sid xxx list -dev 003C -v

List the details for each FA port and ensure the ACLX is mapped to each:
symcfg -sid xxx -dir 1f -p 1 list -addr -avail
symcfg -sid xxx -dir 2f -p 1 list -addr -avail
symcfg -sid xxx -dir 3f -p 1 list -addr -avail
symcfg -sid xxx -dir 4f -p 1 list -addr -avail

List Connections via ACLX:
CLI3

If you require to UNMAP the ACLX Volume from FA ports 1F1-4F1:
symconfigure -sid xxx -cmd “unmap dev 003C from dir 1f:1;” commit
symconfigure -sid xxx -cmd “unmap dev 003C from dir 2f:1;” commit
symconfigure -sid xxx -cmd “unmap dev 003C from dir 3f:1;” commit
symconfigure -sid xxx -cmd “unmap dev 003C from dir 4f:1;” commit

Unmap dev from all Directors:
symconfigure -sid xxx -cmd “unmap dev 003C from dir ALL:ALL;” commit

3 thoughts on “EMC VMAX – Access Control Logix (ACLX) Gatekeeper Mapping

  1. Hi Dave, thanks for explaining about ACLX.

    On my VMAX, ACLX device is mapped to all FA ports and hence any new Solaris or Windows host connected to it is seeing a small device of ~3MB. VMWare hosts are not seeing it. All the online reading I did doesn’t say if it’s ok to unmap it and will the hosts behave well by doing so. Would you know?

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s