HP 8/20q HP StorageWorks 8/20q and SN6000 Fibre Channel Switch Enterprise Fabr - Page 65

Managing Fabric Security

Page 65 highlights

4 Managing Fabric Security This chapter describes connection security and user account security concepts. It also describes the tasks to configure port security, device security, and RADIUS servers. Connection security Connection security provides an encrypted data path for switch management methods. The switch supports the Secure Shell (SSH) protocol for the command line interface and the Secure Socket Layer (SSL) protocol for management applications such as Enterprise Fabric Management Suite and Common Information Module (CIM). For information about enabling SSH, SSL, and CIM services, see "Managing system services" (page 97). The SSL handshake process between the workstation and the switch involves the exchanging of certificates, which contain the public and private keys that define the encryption. The switch certificate is valid for one year beginning with its creation date and time. The workstation validates the switch certificate by comparing the workstation date and time to the switch certificate creation date and time. For this reason, it is important to synchronize the workstation and switch with the same date, time, and time zone. If you do not create a certificate, the switch automatically creates one. Consider your requirements for connection security: for the command line interface (SSH), management applications such as Enterprise Fabric Management Suite (SSL), or both. If SSL connection security is required, also consider using the Network Time Protocol (NTP) to synchronize workstations and switches. User account security User account security is the process by which your user account and password are authenticated with the list of valid user accounts and passwords. The switch validates your account and password when you attempt to add a fabric using Enterprise Fabric Management Suite or log in to a switch through Telnet. Your system administrator defines accounts, passwords, and authority levels that are stored on the switch. For information about creating user accounts, see "Managing user accounts" (page 79). The Admin account has Admin authority, which grants full access to all tasks of the Enterprise Fabric Management Suite menu system. The switch validates your user account, and Enterprise Fabric Management Suite grants access to its menus. If you do not have Admin authority, you are limited to monitoring tasks. NOTE: If an administrator changes user access rights and passwords, existing Enterprise Fabric Management Suite, QuickTools, and CLI logins are not affected by the new settings. Login access and privileges are only checked for a new login request. HP StorageWorks 8/20q and SN6000 Fibre Channel Switch Enterprise Fabric Management Suite User Guide 65

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

HP StorageWorks 8/20q and SN6000 Fibre Channel Switch Enterprise Fabric Management Suite User Guide
65
4
Managing Fabric Security
This chapter describes connection security and user account security concepts. It also describes the tasks to
configure port security, device security, and RADIUS servers.
Connection security
Connection security provides an encrypted data path for switch management methods. The switch supports
the Secure Shell (SSH) protocol for the command line interface and the Secure Socket Layer (SSL) protocol
for management applications such as Enterprise Fabric Management Suite and Common Information
Module (CIM). For information about enabling SSH, SSL, and CIM services, see ”
Managing system
services
” (page 97).
The SSL handshake process between the workstation and the switch involves the exchanging of certificates,
which contain the public and private keys that define the encryption. The switch certificate is valid for one
year beginning with its creation date and time. The workstation validates the switch certificate by
comparing the workstation date and time to the switch certificate creation date and time. For this reason, it
is important to synchronize the workstation and switch with the same date, time, and time zone. If you do
not create a certificate, the switch automatically creates one.
Consider your requirements for connection security: for the command line interface (SSH), management
applications such as Enterprise Fabric Management Suite (SSL), or both. If SSL connection security is
required, also consider using the Network Time Protocol (NTP) to synchronize workstations and switches.
User account security
User account security is the process by which your user account and password are authenticated with the
list of valid user accounts and passwords. The switch validates your account and password when you
attempt to add a fabric using Enterprise Fabric Management Suite or log in to a switch through Telnet. Your
system administrator defines accounts, passwords, and authority levels that are stored on the switch. For
information about creating user accounts, see ”
Managing user accounts
” (page 79).
The Admin account has Admin authority, which grants full access to all tasks of the Enterprise Fabric
Management Suite menu system. The switch validates your user account, and Enterprise Fabric
Management Suite grants access to its menus. If you do not have Admin authority, you are limited to
monitoring tasks.
NOTE:
If an administrator changes user access rights and passwords, existing Enterprise Fabric
Management Suite, QuickTools, and CLI logins are not affected by the new settings. Login access and
privileges are only checked for a new login request.