HP 8/20q HP StorageWorks 8/20q Fibre Channel Switch installation and reference - Page 25

Port binding, Device security

Page 25 highlights

Port binding Port binding provides authorization for a list of up to 32 switch and device WWNs that are permitted to log in to a particular switch port. Switches or devices that are not among the 32 are refused access to the port. Consider what ports to secure and the set of switches and devices that are permitted to log in to those ports. Use the CLI to configure port binding. For more informaton about port binding configuration, see the HP StorageWorks 8/20q Fibre Channel Switch command line interface guide. Device security Device security provides for the authorization and authentication of devices that you attach to a switch. You can configure a switch with a group of devices against which the switch authorizes new attachments by devices, other switches, or devices issuing management server commands. Device security is configured through the use of security sets and groups. Use the CLI to configure device security. For more information about device security configuration, see the HP StorageWorks 8/20q Fibre Channel Switch command line interface guide. A group is a list of device worldwide names that are authorized to attach to a switch. There are three types of groups: one for other switches (ISL), another for devices (port), and a third for devices issuing management server commands (MS). A security set is a set of up to three groups with no more than one of each group type. The security configuration is made up of all security sets on the switch. The security database has the following limits: • Maximum number of security sets is 4. • Maximum number of groups is 16. • Maximum number of members in a group is 1,000. • Maximum total number of group members is 1,000. In addition to authorization, the switch can be configured to require authentication to validate the identity of the connecting switch, device, or host. Authentication can be performed locally using the switch's security database, or remotely using a RADIUS server such as Microsoft RADIUS. With a RADIUS server, the security database for the entire fabric resides on the server. In this way, the security database can be managed centrally, rather than on each switch. You can configure up to five RADIUS servers to provide failover. You can configure the RADIUS server to authenticate just the switch or both the switch and the initiator device if the device supports authentication. When using a RADIUS server, every switch in the fabric must have a network connection. A RADIUS server can also be configured to authenticate user accounts as described in "User account security" on page 24. A secure connection is required to authenticate user logins with a RADIUS server. For more information, see "Connection security" on page 24. Consider the devices, switches, and management agents and evaluate the need for authorization and authentication. Also consider whether the security database is to be distributed on the switches or centralized on a RADIUS server and how many servers to configure. Use the CLI to configure RADIUS servers. For more information about RADIUS server configuration, see the HP StorageWorks 8/20q Fibre Channel Switch command line interface guide. 8/20q Fibre Channel Switch installation and reference guide 25

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72

8/20q Fibre Channel Switch installation and reference guide
25
Port binding
Port binding provides authorization for a list of up to 32 switch and device WWNs that are permitted to
log in to a particular switch port. Switches or devices that are not among the 32 are refused access to the
port. Consider what ports to secure and the set of switches and devices that are permitted to log in to those
ports. Use the CLI to configure port binding. For more informaton about port binding configuration, see the
HP StorageWorks 8/20q Fibre Channel Switch command line interface guide
.
Device security
Device security provides for the authorization and authentication of devices that you attach to a switch. You
can configure a switch with a group of devices against which the switch authorizes new attachments by
devices, other switches, or devices issuing management server commands. Device security is configured
through the use of security sets and groups. Use the CLI to configure device security. For more information
about device security configuration, see the
HP StorageWorks 8/20q Fibre Channel Switch command line
interface guide
.
A group is a list of device worldwide names that are authorized to attach to a switch. There are three types
of groups: one for other switches (ISL), another for devices (port), and a third for devices issuing
management server commands (MS).
A security set is a set of up to three groups with no more than one of each group type. The security
configuration is made up of all security sets on the switch. The security database has the following limits:
Maximum number of security sets is 4.
Maximum number of groups is 16.
Maximum number of members in a group is 1,000.
Maximum total number of group members is 1,000.
In addition to authorization, the switch can be configured to require authentication to validate the identity
of the connecting switch, device, or host. Authentication can be performed locally using the switch’s
security database, or remotely using a RADIUS server such as Microsoft RADIUS. With a RADIUS server,
the security database for the entire fabric resides on the server. In this way, the security database can be
managed centrally, rather than on each switch. You can configure up to five RADIUS servers to provide
failover.
You can configure the RADIUS server to authenticate just the switch or both the switch and the initiator
device if the device supports authentication. When using a RADIUS server, every switch in the fabric must
have a network connection. A RADIUS server can also be configured to authenticate user accounts as
described in ”
User account security
” on page 24. A secure connection is required to authenticate user
logins with a RADIUS server. For more information, see ”
Connection security
” on page 24.
Consider the devices, switches, and management agents and evaluate the need for authorization and
authentication. Also consider whether the security database is to be distributed on the switches or
centralized on a RADIUS server and how many servers to configure. Use the CLI to configure RADIUS
servers. For more information about RADIUS server configuration, see the
HP StorageWorks 8/20q Fibre
Channel Switch command line interface guide
.