HP 316095-B21 FW 08.01.00 McDATA EFCM Basic User Manual (620-000240-000, Novem - Page 117

Defining the CHAP Secret of the Product, Defining Port Authentication Sequences

Page 117 highlights

Defining the CHAP Secret of the Product Defining Port Authentication Sequences Configuring Device Authentication 5 • Dialog for adding devices to the list of Authenticated Devices. These devices are allowed to make connections to the product, which is described in Configuring Authentication Devices on page 5-12. The top left of the Device Authentication page contains a dialog for defining the CHAP secret of the product. The WWN of the product displays in the Local Node Name field. To specify a CHAP secret for the product, enter a 16-character CHAP secret in the CHAP Secret field. Enter the same sequence of characters in the Confirm CHAP field. Select the OK button to save and activate the CHAP secret. You can configure the port authentication sequences to be used by the product's E_Ports and N_Ports. The user has the option of selecting authentication parameters for E Ports and N Ports at the top right of the page. It allows the user to configure the Authentication Sequence (RADIUS, then Local; RADIUS only; or Local only) that specifies the way of authenticating the E/N port devices. Selecting the OK button sends the contents to the switch, while selecting the Cancel button reloads the dialog with current switch settings. • Enable authentication-select the Enabled E_Port Authentication check box to enable authentication on E_Ports. Select the Enabled N_Port Authentication check box to enable authentication on N_Ports. Clear the appropriate check box to disable port authentication. • Authentication Sequence-Use the drop-down menu to specify the authentication sequence used for out-of-band software. The following options are available for authenticating a software ID and its CHAP secret: - Local Only-Only local authentication is performed. That is to say, authentication is performed by the product (local device) only. - RADIUS Only-Only the RADIUS server is used for authentication. - RADIUS then Local-First the RADIUS server is used for authentication, then the local device. Configuring Security 5-11

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312

5
Configuring Security
5-11
Configuring Device Authentication
Dialog for adding devices to the list of Authenticated Devices.
These devices are allowed to make connections to the product,
which is described in
Configuring Authentication Devices
on
page 5-12.
Defining the CHAP
Secret of the
Product
The top left of the
Device Authentication
page contains a dialog for
defining the CHAP secret of the product. The WWN of the product
displays in the
Local Node Name
field.
To specify a CHAP secret for the product, enter a 16-character CHAP
secret in the
CHAP Secret
field. Enter the same sequence of characters
in the
Confirm CHAP
field.
Select the
OK
button to save and activate the CHAP secret.
Defining Port
Authentication
Sequences
You can configure the port authentication sequences to be used by
the product’s E_Ports and N_Ports. The user has the option of
selecting authentication parameters for E Ports and N Ports at the top
right of the page. It allows the user to configure the Authentication
Sequence (RADIUS, then Local; RADIUS only; or Local only) that
specifies the way of authenticating the E/N port devices.
Selecting
the
OK
button sends the contents to the switch, while selecting the
Cancel
button reloads the dialog with current switch settings.
Enable authentication—select the
Enabled E_Port Authentication
check box to enable authentication on E_Ports. Select the
Enabled
N_Port Authentication
check box to enable authentication on
N_Ports. Clear the appropriate check box to disable port
authentication.
Authentication Sequence—Use the drop-down menu to specify
the authentication sequence used for out-of-band software. The
following options are available for authenticating a software ID
and its CHAP secret:
Local Only
—Only local authentication is performed. That is to
say, authentication is performed by the product (local device)
only.
RADIUS Only
—Only the RADIUS server is used for
authentication.
RADIUS then Local
—First the RADIUS server is used for
authentication, then the local device.