HP StorageWorks 2/140 FW 08.01.00 McDATA Products in a SAN Environment Plannin - Page 57

Security Features, Port binding, Password protection, Remote user restrictions

Page 57 highlights

Security Features Introduction to McDATA Multi-Protocol Products 1 • Port binding - Directors and fabric switches support an optional feature that binds an attached Fibre Channel device to a specified product port through the device's WWN. NOTE: SAN routers support port binding only for R_Ports. SAN management and Element Manager applications offer the following security features for McDATA switching products. Products or product classes that do not support a security feature are noted. • Password protection - Users must provide a user name and password to log in to the management server and access all managed products. Administrators can configure user names and passwords for up to 16 users, and can authorize or prohibit specific management permissions for each user. • Remote user restrictions - Remote user access to all managed products is either disabled or restricted to configured IP addresses. • SNMP workstation restrictions - Remote users on SNMP workstations can only access management information base (MIB) variables managed by the product SNMP agent. SNMP workstations must belong to SNMP communities configured through the Element Manager application. If configured, the agent can send authorization failure traps when unauthorized SNMP workstations attempt to access a managed product. • Port blocking - System administrators can restrict device access by blocking or unblocking any director or fabric switch port through the associated Element Manager application. NOTE: SAN routers do not support port blocking. • Audit log tracking - Configuration changes to a director or fabric switch are recorded in an audit log stored on the management server. Users can display the audit log through the Element Manager application. Log entries include the date and time of the configuration change, a description of the change, and the source of the change. NOTE: SAN routers do not support audit log tracking. Introduction to McDATA Multi-Protocol Products 1-31

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318

1
Introduction to McDATA Multi-Protocol Products
1-31
Introduction to McDATA Multi-Protocol Products
Port binding -
Directors and fabric switches support an optional
feature that binds an attached Fibre Channel device to a specified
product port through the device’s WWN.
NOTE:
SAN routers support port binding only for R_Ports.
Security Features
SAN management and Element Manager applications offer the
following security features for McDATA switching products.
Products or product classes that do not support a security feature
are noted.
Password protection -
Users must provide a user name and
password to log in to the management server and access all
managed products. Administrators can configure user names
and passwords for up to 16 users, and can authorize or prohibit
specific management permissions for each user.
Remote user restrictions -
Remote user access to all managed
products is either disabled or restricted to configured IP
addresses.
SNMP workstation restrictions -
Remote users on SNMP
workstations can only access management information base
(MIB) variables managed by the product SNMP agent. SNMP
workstations must belong to SNMP communities configured
through the Element Manager application. If configured, the
agent can send authorization failure traps when unauthorized
SNMP workstations attempt to access a managed product.
Port blocking -
System administrators can restrict device access
by blocking or unblocking any director or fabric switch port
through the associated Element Manager application.
NOTE:
SAN routers do not support port blocking.
Audit log tracking -
Configuration changes to a director or fabric
switch are recorded in an audit log stored on the management
server. Users can display the audit log through the Element
Manager application. Log entries include the date and time of the
configuration change, a description of the change, and the source
of the change.
NOTE:
SAN routers do not support audit log tracking.