HP Brocade 8/12c Fabric Watch Administrator's Guide v6.4.0 (53-1001770-01, Jun - Page 64

Security monitoring guidelines and default settings, Security class areas

Page 64 highlights

6 Security monitoring guidelines and default settings Security monitoring guidelines and default settings The Security class monitors all attempts to breach your SAN security, helping you fine-tune your security measures. Security class areas Table 5 lists Product Name areas in the security class and describes what each area indicates. Configure the Security class using the thConfig command. TABLE 5 Security class areas Area Indicates DCC violations HTTP violations Illegal command Incompatible security DB Invalid certificates Login violations No-FCS SCC violations SLAP failures (FCAP failures) Telnet violations TS Out of Sync An unauthorized device attempts to log in to a secure fabric. A browser access request reaches a secure switch from an unauthorized IP address. Commands permitted only to the primary Fibre Channel Switch (FCS) are executed on another switch. Secure switches with different version stamps have been detected. Monitors invalid certificates. Login violations which occur when a secure fabric detects a login failure. The switch has lost contact with the primary FCS. SCC violations which occur when an unauthorized switch tries to join a secure fabric. The WWN of the unauthorized switch appears in the ERRLOG. SLAP failures which occur when packets try to pass from a nonsecure switch to a secure fabric. Telnet violations which occur when a Telnet connection request reaches a secure switch from an unauthorized IP address. Time Server (TS) which occur when an out-of-synchronization error has been detected. Security monitoring setting guidelines Use the Security class default settings for area and notification configuration. There is no reason to alter the default settings. 44 Fabric Watch Administrator's Guide 53-1001770-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144

44
Fabric Watch Administrator’s Guide
53-1001770-01
Security monitoring guidelines and default settings
6
Security monitoring guidelines and default settings
The Security class monitors all attempts to breach your SAN security, helping you fine-tune your
security measures.
Security class areas
Table 5
lists Product Name areas in the security class and describes what each area indicates.
Configure the Security class using the
thConfig
command.
Security monitoring setting guidelines
Use the Security class default settings for area and notification configuration. There is no reason to
alter the default settings.
TABLE 5
Security class areas
Area
Indicates
DCC violations
An unauthorized device attempts to log in to a secure fabric.
HTTP violations
A browser access request reaches a secure switch from an unauthorized IP address.
Illegal command
Commands permitted only to the primary Fibre Channel Switch (FCS) are executed on
another switch.
Incompatible security
DB
Secure switches with different version stamps have been detected.
Invalid certificates
Monitors invalid certificates.
Login violations
Login violations which occur when a secure fabric detects a login failure.
No-FCS
The switch has lost contact with the primary FCS.
SCC violations
SCC violations which occur when an unauthorized switch tries to join a secure fabric.
The WWN of the unauthorized switch appears in the ERRLOG.
SLAP failures (FCAP
failures)
SLAP failures which occur when packets try to pass from a nonsecure switch to a
secure fabric.
Telnet violations
Telnet violations which occur when a Telnet connection request reaches a secure
switch from an unauthorized IP address.
TS Out of Sync
Time Server (TS) which occur when an out-of-synchronization error has been detected.