HP StorageWorks MSA 2/8 HP StorageWorks Secure Fabric OS V1.0 User Guide (AA-R - Page 109

Management Access, command. Turning Secure Mode

Page 109 highlights

Managing Secure Fabric OS ■ Fabric Manager ■ Web Tools ■ Fabric Access (API) Does Secure Fabric OS prevent all unauthorized access? There is no 100% protection in any network. However, the Secure Fabric OS product makes it possible for the administrator to create a significantly increased level of security that is customized to the fabric. Once Secure Fabric is turned on, can it be turned off again? Yes, by using the secmodedisable command. Turning Secure Mode on or off does not disrupt traffic. What happens if I create a policy with no members in it? You cannot create an empty FCS policy, but you can create other types of policies with no members. However, creating a policy with no members closes all access to that aspect of the fabric, which can result in preventing administrative access to the fabric. Before setting a policy, read all the information provided about that policy under "Creating Secure Fabric OS Policies Other Than the FCS Policy" on page 58. How do I prevent someone from adding a computer to the fabric and mounting a LUN? The following approaches can be used in conjunction, although no guarantees can be made of absolute security: ■ Store all the FCS switches in a physically secure area. ■ Use hardware-based zoning. ■ Create a DCC policy for each switch in the fabric. ■ Create an Options policy. Management Access What version of SSH and the SSH clients does Fabric OS v4.1.x support? Fabric OS v4.1.x supports version 2 of the SSH protocol. Any SSH client that supports version 2 of the protocol is supported. For example, PuTTy or F-Secure. Secure Fabric OS Version 1.0 User Guide 109

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129

Managing Secure Fabric OS
109
Secure Fabric OS Version 1.0 User Guide
Fabric Manager
Web Tools
Fabric Access (API)
Does Secure Fabric OS prevent all unauthorized access?
There is no 100% protection in any network. However, the Secure Fabric OS
product makes it possible for the administrator to create a significantly
increased level of security that is customized to the fabric.
Once Secure Fabric is turned on, can it be turned off again?
Yes, by using the
secmodedisable
command. Turning Secure Mode on
or off does not disrupt traffic.
What happens if I create a policy with no members in it?
You cannot create an empty FCS policy, but you can create other types of
policies with no members. However, creating a policy with no members closes
all access to that aspect of the fabric, which can result in preventing
administrative access to the fabric. Before setting a policy, read all the
information provided about that policy under “
Creating Secure Fabric OS
Policies Other Than the FCS Policy
” on
page 58
.
How do I prevent someone from adding a computer to the fabric and mounting a
LUN?
The following approaches can be used in conjunction, although no guarantees
can be made of absolute security:
Store all the FCS switches in a physically secure area.
Use hardware-based zoning.
Create a DCC policy for each switch in the fabric.
Create an Options policy.
Management Access
What version of SSH and the SSH clients does Fabric OS v4.1.x support?
Fabric OS v4.1.x supports version 2 of the SSH protocol. Any SSH client that
supports version 2 of the protocol is supported. For example, PuTTy or
F-Secure.