HP StorageWorks 2/24 FW 07.00.00/HAFM SW 08.06.00 McDATA Products in a SAN Env - Page 54

Security Features, Eclipse-series SAN routers, Port binding, Password protection

Page 54 highlights

Introduction to McDATA Multi-Protocol Products 1 - Eclipse-series SAN routers - Intelligent ports that support IP network connectivity are not assigned BB_Credits. However, the ports provide approximately 96 megabytes (MB) of Transmission Control Protocol (TCP) packet buffering per transmission direction. TCP output buffering absorbs fabric data to ensure Fibre Channel BB_Credits are not exhausted. Up to eight MB of buffering can be allocated to any single iFCP or iSCSI session. • Port binding - Directors and fabric switches support an optional feature that binds an attached Fibre Channel device to a specified product port through the device's WWN. NOTE: SAN routers support port binding only for R_Ports. Security Features SAN management and Element Manager applications offer the following security features for McDATA switching products. Products or product classes that do not support a security feature are noted. • Password protection - Users must provide a user name and password to log in to the management server and access all managed products. Administrators can configure user names and passwords for up to 16 users, and can authorize or prohibit specific management permissions for each user. • Remote user restrictions - Remote user access to all managed products is either disabled or restricted to configured IP addresses. • SNMP workstation restrictions - Remote users on SNMP workstations can only access management information base (MIB) variables managed by the product SNMP agent. SNMP workstations must belong to SNMP communities configured through the Element Manager application. If configured, the agent can send authorization failure traps when unauthorized SNMP workstations attempt to access a managed product. • Port blocking - System administrators can restrict device access by blocking or unblocking any director or fabric switch port through the associated Element Manager application. NOTE: SAN routers do not support port blocking. 1-28 McDATA Products in a SAN Environment - Planning Manual

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322

1
1-28
McDATA Products in a SAN Environment - Planning Manual
Introduction to McDATA Multi-Protocol Products
Eclipse-series SAN routers -
Intelligent ports that support IP
network connectivity are not assigned BB_Credits. However,
the ports provide approximately 96 megabytes (MB) of
Transmission Control Protocol (TCP) packet buffering per
transmission direction. TCP output buffering absorbs fabric
data to ensure Fibre Channel BB_Credits are not exhausted.
Up to eight MB of buffering can be allocated to any single
iFCP or iSCSI session.
Port binding -
Directors and fabric switches support an optional
feature that binds an attached Fibre Channel device to a specified
product port through the device’s WWN.
NOTE:
SAN routers support port binding only for R_Ports.
Security Features
SAN management and Element Manager applications offer the
following security features for McDATA switching products.
Products or product classes that do not support a security feature
are noted.
Password protection -
Users must provide a user name and
password to log in to the management server and access all
managed products. Administrators can configure user names
and passwords for up to 16 users, and can authorize or prohibit
specific management permissions for each user.
Remote user restrictions -
Remote user access to all managed
products is either disabled or restricted to configured IP
addresses.
SNMP workstation restrictions -
Remote users on SNMP
workstations can only access management information base
(MIB) variables managed by the product SNMP agent. SNMP
workstations must belong to SNMP communities configured
through the Element Manager application. If configured, the
agent can send authorization failure traps when unauthorized
SNMP workstations attempt to access a managed product.
Port blocking -
System administrators can restrict device access
by blocking or unblocking any director or fabric switch port
through the associated Element Manager application.
NOTE:
SAN routers do not support port blocking.