HP StorageWorks MSA 2/8 HP StorageWorks Fabric OS Procedures V3.1.x/4.1.x User - Page 95

Disabling the Telnet Interface, Listeners, Removal of Unused Listeners

Page 95 highlights

Basic Security in FOS Disabling the Telnet Interface From a security standpoint, with the addition of SSH, the telnet interface is no longer necessary to manage the switch. Some customers may wish to disable telnet to prevent a user from passing cleartext passwords over the network when logging in to the switch. The configure [telnetd] command is provided to allow customers to disable the telnet interface. The default configuration of the switch will ship with telnet enabled. For more information on the configure command, refer to the HP StorageWorks Fabric OS Version 3.1.x/4.1.x Reference Guide. 1. Log in to the switch as Admin. 2. Enter configure [telnetd] at the command line. This configure command can be run with the switch enabled. 3. Press Enter. The Telnet interface is disabled. SNMP, HTTP, API, RSNMP, WSNMP, SES, and MS are managed through their respective policies when security is enabled. Refer to the HP StorageWorks Secure Fabric OS Version 1.0 User Guide for information. Listeners In order to make the Fabric OS more secure, the principal has been adopted that the Linux subsystem should provide only the minimal necessary functionality required to implement supported features and capabilities. Removal of Unused Listeners Changing the principal to provide the minimum Linux subsystem functionality required that a number of listeners be removed from this version of the Fabric OS. Some listeners are required for CP to CP communications on the internal network of the Core Switch 2/64. These listeners are blocked on the Core Switch 2/64, and are not started on the SAN Switch 2/32. Table 5: Removed Listeners for the Core Switch 2/64 and SAN Switch 2/32 Listener Name chargen echo daytime Core Switch 2/64 Do not start Do not start Do not start SAN Switch 2/32 Do not start Do not start Do not start Fabric OS Procedures Version 3.1.x/4.1.x User Guide 95

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270

Basic Security in FOS
95
Fabric OS Procedures Version 3.1.x/4.1.x User Guide
Disabling the Telnet Interface
From a security standpoint, with the addition of SSH, the telnet interface is no
longer necessary to manage the switch. Some customers may wish to disable
telnet to prevent a user from passing cleartext passwords over the network when
logging in to the switch. The
configure
[telnetd]
command is provided
to allow customers to disable the telnet interface. The default configuration of the
switch will ship with telnet enabled.
For more information on the
configure
command, refer to the
HP
StorageWorks Fabric OS Version 3.1.x/4.1.x Reference Guide
.
1.
Log in to the switch as Admin.
2.
Enter
configure
[telnetd]
at the command line.
This configure command can be run with the switch enabled.
3.
Press
Enter
.
The Telnet interface is disabled.
SNMP, HTTP, API, RSNMP, WSNMP, SES, and MS are managed through their
respective policies when security is enabled. Refer to the
HP StorageWorks Secure
Fabric OS Version 1.0 User Guide
for information.
Listeners
In order to make the Fabric OS more secure, the principal has been adopted that
the Linux subsystem should provide only the minimal necessary functionality
required to implement supported features and capabilities.
Removal of Unused Listeners
Changing the principal to provide the minimum Linux subsystem functionality
required that a number of listeners be removed from this version of the Fabric OS.
Some listeners are required for CP to CP communications on the internal network
of the Core Switch 2/64. These listeners are blocked on the Core Switch 2/64, and
are not started on the SAN Switch 2/32.
Table 5:
Removed Listeners for the Core Switch 2/64 and SAN Switch 2/32
Listener Name
Core Switch 2/64
SAN Switch 2/32
chargen
Do not start
Do not start
echo
Do not start
Do not start
daytime
Do not start
Do not start