HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.3.x administrator guide (569 - Page 87

Configuring standard security features, Secure protocols, Table 16 Secure protocol support

Page 87 highlights

4 Configuring standard security features This chapter provides information and procedures for configuring standard Fabric OS security features such as account and password management. Additional security features are available when secure mode is enabled. For information about licensed security features available in Secure Fabric OS, refer to the Secure Fabric OS administrator's guide. Secure protocols Fabric OS supports the secure protocols shown in Table 16. T, able 16 Secure protocol support Protocol Description SSL Supports SSLv3, 128-bit encryption by default. Fabric OS uses SSL to support HTTPS. A certificate must be generated and installed on each switch to enable SSL. HTTPS Web Tools supports the use of HTTPS. Secure File Copy (scp) Configuration upload and download support the use of scp. SNMPv3 SNMPv1 is also supported. Simple Network Management Protocol (SNMP) is a standard method for monitoring and managing network devices. Using SNMP components, you can program tools to view, browse, and manipulate switch variables and set up enterprise-level management processes. Every HP switch carries an SNMP agent and management information b ase (MIB). The agent accesses MIB information about a device and makes it available to a network manager station. You can manipulate information of your choice by trapping MIB elements using the Fabric OS CLI, Web Tools, or Fabric Manager. The SNMP Access Control List (ACL) provides a way for the administrator to restrict SNMP get/set operations to certain hosts/IP addresses. This is used for enhanced management security in the storage area network. For details on MIB files, naming conventions, loading instructions, and information about using the SNMP agent, refer to the Fabric OS MIB reference manual. Table 17 describes additional software or certificates that you must obtain to deploy secure protocols. Table 17 Items needed to deploy secure protocols Protocol Host side Switch side Secure telnet (sectelnet) Sectelnet client License not required, but a switch certificate issued by HP is required SSH SSH client None HTTPS No requirement on host Switch IP certificate for SSL side except a browser that supports HTTPS Secure File Copy (scp) SSH daemon, scp server None SNMPv3, SNMPv1 None None Fabric OS 5.3.0 administrator guide 89

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465

Fabric OS 5.3.0 administrator guide
89
4
Configuring standard security features
This chapter provides information and procedures for configuring standard Fabric OS security features such
as account and password management.
Additional security features are available when secure mode is enabled. For information about licensed
security features available in Secure Fabric OS, refer to the
Secure Fabric OS administrator’s guide
.
Secure protocols
Fabric OS supports the secure protocols shown in
Table 16
.
,
Simple Network Management Protocol (SNMP) is a standard method for monitoring and managing
network devices. Using SNMP components, you can program tools to view, browse, and manipulate switch
variables and set up enterprise-level management processes.
Every HP switch carries an SNMP agent and management information b ase (MIB). The agent accesses
MIB information about a device and makes it available to a network manager station. You can manipulate
information of your choice by
trapping
MIB elements using the Fabric OS CLI, Web Tools, or Fabric
Manager.
The SNMP Access Control List (ACL) provides a way for the administrator to restrict SNMP get/set
operations to certain hosts/IP addresses. This is used for enhanced management security in the storage
area network.
For details on MIB files, naming conventions, loading instructions, and information about using the SNMP
agent, refer to the
Fabric OS MIB reference manual
.
Table 17
describes additional software or certificates that you must obtain to deploy secure protocols.
Table 16
Secure protocol support
Protocol
Description
SSL
Supports SSLv3, 128-bit encryption by default. Fabric OS uses SSL to
support HTTPS. A certificate must be generated and installed on each
switch to enable SSL.
HTTPS
Web Tools supports the use of HTTPS.
Secure File Copy (scp)
Configuration upload and download support the use of scp.
SNMPv3
SNMPv1 is also supported.
Table 17
Items needed to deploy secure protocols
Protocol
Host side
Switch side
Secure telnet
(sectelnet)
Sectelnet client
License not required, but a switch
certificate issued by HP is required
SSH
SSH client
None
HTTPS
No requirement on host
side except a browser
that supports HTTPS
Switch IP certificate for SSL
Secure File Copy (scp)
SSH daemon, scp
server
None
SNMPv3, SNMPv1
None
None