HP 8/20q HP StorageWorks 8/20q Fibre Channel Switch Command Line Interface Gui - Page 83

Connection Security Configuration, Managing SSL and SSH services

Page 83 highlights

7 Connection Security Configuration The 8/20q Fibre Channel Switch supports secure connections with Telnet and switch management applications. The Secure Shell protocol (SSH) secures Telnet connections to the switch. The Secure Sockets Layer (SSL) protocol secures switch connections to the following management applications: • Simple SAN Connection Manager • QuickTools • Enterprise Fabric Management Suite • Storage Management Initiative-Specification (SMI-S) Managing SSL and SSH services Consider the following when enabling SSH and SSL services: • Simple SAN Connection Manager version 1.0 does not support the SSL service. If SSL is enabled, you will be unable to manage the switch using this version of Simple SAN Connection Manager. • To establish a secure Telnet connection, your workstation must use an SSH client. • To enable secure SSL connections, you must first synchronize the date and time on the switch and workstation. See "Managing the date and time" (page 47). • The SSL service must be enabled to authenticate users through a Remote Authentication Dial-In Service (RADIUS) server. See "Configuring a RADIUS server on the switch" (page 86). • To disable SSL when using a user authentication RADIUS server, the RADIUS server authentication order must be local. • Enabling SSL automatically creates a security certificate on the switch. To manage both SSH and SSL services, enter the set setup services command, as shown in the following example: 8/20q FC Switch #> admin start 8/20q FC Switch (admin) #> set setup services A list of attributes with formatting and current values will follow. Enter a new value or simply press the ENTER key to accept the current value. If you wish to terminate this process before reaching the end of the list press 'q' or 'Q' and the ENTER key to do so. PLEASE NOTE Further configuration may be required after enabling a service. * If services are disabled, the connection to the switch may be lost. * When enabling SSL, please verify that the date/time settings on this switch and the workstation from where the SSL connection will be started match, and then a new certificate may need to be created to ensure a secure connection to this switch. TelnetEnabled SSHEnabled GUIMgmtEnabled SSLEnabled EmbeddedGUIEnabled SNMPEnabled NTPEnabled CIMEnabled FTPEnabled MgmtServerEnabled (True / False) (True / False) (True / False) (True / False) (True / False) (True / False) (True / False) (True / False) (True / False) (True / False) [True ] [False] True [True ] [False] True [True ] [True ] [False] [False] [True ] [True ] Do you want to save and activate this services setup? (y/n): [n] y HP StorageWorks 8/20q Fibre Channel Switch Command Line Interface Guide 83

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330

HP StorageWorks 8/20q Fibre Channel Switch Command Line Interface Guide
83
7
Connection Security Configuration
The 8/20q Fibre Channel Switch supports secure connections with Telnet and switch management
applications. The Secure Shell protocol (SSH) secures Telnet connections to the switch. The Secure Sockets
Layer (SSL) protocol secures switch connections to the following management applications:
Simple SAN Connection Manager
QuickTools
Enterprise Fabric Management Suite
Storage Management Initiative-Specification (SMI-S)
Managing SSL and SSH services
Consider the following when enabling SSH and SSL services:
Simple SAN Connection Manager version 1.0 does not support the SSL service. If SSL is enabled, you
will be unable to manage the switch using this version of Simple SAN Connection Manager.
To establish a secure Telnet connection, your workstation must use an SSH client.
To enable secure SSL connections, you must first synchronize the date and time on the switch and
workstation. See ”
Managing the date and time
” (page 47).
The SSL service must be enabled to authenticate users through a Remote Authentication Dial-In Service
(RADIUS) server. See ”
Configuring a RADIUS server on the switch
” (page 86).
To disable SSL when using a user authentication RADIUS server, the RADIUS server authentication order
must be local.
Enabling SSL automatically creates a security certificate on the switch.
To manage both SSH and SSL services, enter the
set setup services
command, as shown in the
following example:
8/20q FC Switch #> admin start
8/20q FC Switch (admin) #> set setup services
A list of attributes with formatting and current values will follow.
Enter a new value or simply press the ENTER key to accept the current value.
If you wish to terminate this process before reaching the end of the list
press 'q' or 'Q' and the ENTER key to do so.
PLEASE NOTE:
-----------
* Further configuration may be required after enabling a service.
* If services are disabled, the connection to the switch may be lost.
* When enabling SSL, please verify that the date/time settings
on this switch and the workstation from where the SSL connection
will be started match, and then a new certificate may need to be
created to ensure a secure connection to this switch.
TelnetEnabled
(True / False)
[True ]
SSHEnabled
(True / False)
[False]
True
GUIMgmtEnabled
(True / False)
[True ]
SSLEnabled
(True / False)
[False]
True
EmbeddedGUIEnabled
(True / False)
[True ]
SNMPEnabled
(True / False)
[True ]
NTPEnabled
(True / False)
[False]
CIMEnabled
(True / False)
[False]
FTPEnabled
(True / False)
[True ]
MgmtServerEnabled
(True / False)
[True ]
Do you want to save and activate this services setup? (y/n): [n]
y