Dell Brocade G620 Brocade 8.0.1 Fabric OS Troubleshooting and Diagnostics Guid - Page 64

Device authentication, Protocol and certificate management, Password recovery options continued

Page 64 highlights

Security TABLE 11 Password recovery options (continued) Topic If a user has only the root password, what is the password recovery mechanism? How to recover boot PROM password? How to recover a user, or admin password? Solution Use the passwd command to set other passwords. Use the passwdDefault command to set all passwords to default. Contact your switch service provider and provide the recovery string. Refer to Passwords on page 63 for more information on recovering these passwords. Symptom Probable cause and recommended action Device authentication Symptom Probable cause and recommended action User is unable to modify switch settings. The most common error when managing user accounts is not setting up Role-Based Access Control (RBAC). Errors such as a user not being able to run a command or modify switch settings are usually related to what role the user has been assigned. Switch is unable to authenticate device. When the device authentication policy is set to ON, the switch expects a FLOGI with the FC-SP bit set. If this bit is not set, the switch rejects the FLOGI with reason LS_LOGICAL_ERROR (0x03), in the switch log with the explanation of "Authentication Required"(0x48), and disables the port. Set the device authentication policy mode on the switch to ON. Symptom Probable cause and recommended action Switch is unable to form an F_Port. Regardless of the device authentication policy mode on the switch, the F_Port is disabled if the DH-CHAP protocol fails to authenticate. If the HBA sets the FC-SP bit during FLOGI and the switch sends a FLOGI accept with FC-SP bit set, then the switch expects the HBA to start the AUTH_NEGOTIATE. From this point on until the AUTH_NEGOTIATE is completed, all ELS and CT frames, except the AUTH_NEGOTIATE ELS frame, are blocked by the switch. During this time, the Fibre Channel driver rejects all other ELS frames. The F_Port does not form until the AUTH_NEGOTIATE is completed. It is the HBA's responsibility to send an Authentication Negotiation ELS frame after receiving the FLOGI accept frame with the FC-SP bit set. Protocol and certificate management This section provides information and procedures for troubleshooting standard Fabric OS security features such as protocol and certificate management. Symptom Probable cause and recommended action Troubleshooting certificates. If you receive messages in the browser or in a pop-up window when logging in to the target switch using HTTPS, refer to Table 12 for recommended actions you can take to correct the problem Brocade Fabric OS Troubleshooting and Diagnostics Guide 64 53-1004126-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107

TABLE 11
Password recovery options (continued)
Topic
Solution
If a user has only the root password, what is the password recovery
mechanism?
Use the
passwd
command to set other passwords.
Use the
passwdDefault
command to set all passwords to default.
How to recover boot PROM password?
Contact your switch service provider and provide the recovery string.
How to recover a user, or admin password?
Refer to
Passwords
on page 63 for more information on recovering these
passwords.
Symptom
User is unable to modify switch settings.
Probable cause and recommended action
The most common error when managing user accounts is not setting up
Role-Based Access Control (RBAC).
Errors such as a user not being able to run a command or modify switch
settings are usually related to what role the user has been assigned.
Device authentication
Symptom
Switch is unable to authenticate device.
Probable cause and recommended action
When the device authentication policy is set to ON, the switch expects a
FLOGI with the FC-SP bit set. If this bit is not set, the switch rejects the
FLOGI with reason LS_LOGICAL_ERROR (0x03), in the switch log with
the explanation of "Authentication Required"(0x48), and disables the port.
Set the device authentication policy mode on the switch to ON.
Symptom
Switch is unable to form an F_Port.
Probable cause and recommended action
Regardless of the device authentication policy mode on the switch, the
F_Port is disabled if the DH-CHAP protocol fails to authenticate. If the
HBA sets the FC-SP bit during FLOGI and the switch sends a FLOGI
accept with FC-SP bit set, then the switch expects the HBA to start the
AUTH_NEGOTIATE. From this point on until the AUTH_NEGOTIATE is
completed, all ELS and CT frames, except the AUTH_NEGOTIATE ELS
frame, are blocked by the switch. During this time, the Fibre Channel
driver rejects all other ELS frames. The F_Port does not form until the
AUTH_NEGOTIATE is completed. It is the HBA's responsibility to send
an Authentication Negotiation ELS frame after receiving the FLOGI
accept frame with the FC-SP bit set.
Protocol and certificate management
This section provides information and procedures for troubleshooting standard Fabric OS security features such as protocol and
certificate management.
Symptom
Troubleshooting certificates.
Probable cause and recommended action
If you receive messages in the browser or in a pop-up window when
logging in to the target switch using HTTPS, refer to
Table 12
for
recommended actions you can take to correct the problem
Security
Brocade Fabric OS Troubleshooting and Diagnostics Guide
64
53-1004126-01