Configuring The Dhchap Hash Algorithm; Configuring Dhchap Groups; Configuring Dhchap Passwords - Cisco DS-C9216I-K9 Configuration Manual

Switch guide
Table of Contents

Advertisement

Configuring the DHCHAP Hash Algorithm

Whenever DHCHAP port mode is changed to a mode other than the Off mode, reauthentication is
performed.
Table 19-1
various modes.
Table 19-1
Switch N
DHCHAP Modes
on
auto-Active
auto-Passive
off
Configuring the DHCHAP Hash Algorithm
Cisco MDS switches support a default hash algorithm priority list of MD-5 followed by SHA-1 for
DHCHAP authentication.
If you change the hash algorithm configuration, ensure to change it globally for all switches in the fabric.
RADIUS and TACACS+ protocols always use MD-5 for CHAP authentication. Using SHA-1 as the hash
algorithm may prevent RADIUS and TACACS+ usage--even if these AAA protocols are enabled for
DHCHAP authentication.

Configuring DHCHAP Groups

All switches in the Cisco MDS Family support all DHCHAP groups specified in the standard: 0 (null
DH group which does not perform the Diffie-Hellman exchange), 1, 2, 3, or 4.
If you change the DH group configuration, ensure to change it globally for all switches in the fabric.

Configuring DHCHAP Passwords

DHCHAP authentication in each direction requires a shared secret password between the connected
devices. To do this, you can use one of three approaches to manage passwords for all switches in the
fabric which participate in DHCHAP:
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
19-4
Off—Does not support DHCHAP authentication. Authentication messages sent to such ports return
error messages to the initiating switch.
identifies the switch-to-switch authentication behavior between two Cisco MDS switches in
DHCHAP Authentication Status Between Two MDS Switches
Approach 1—Use the same password for all switches in the fabric--the simplest approach. When
you add a new switch, you will use the same password to authenticate that switch in this fabric. It is
also the most vulnerable approach if someone from outside maliciously attempts to access any one
switch in the fabric
Chapter 19
Switch 1
on
FC-SP authentication is performed
FC-SP authentication is not performed.
FC-SP authentication is not performed.
Link is brought down
Configuring Fabric Security
OL-7753-01

Advertisement

Table of Contents
loading

Table of Contents