Dhchap Compatibility With Fibre Channel Features; About Enabling Dhchap - Cisco AP775A - Nexus Converged Network Switch 5010 Configuration Manual

Cli software configuration guide
Hide thumbs Also See for AP775A - Nexus Converged Network Switch 5010:
Table of Contents

Advertisement

Configuring FC-SP and DHCHAP
DHCHAP is a mandatory password-based, key-exchange authentication protocol that supports both
switch-to-switch and host-to-switch authentication. DHCHAP negotiates hash algorithms and DH groups
before performing authentication. It supports MD5 and SHA-1 algorithm-based authentication.
To configure DHCHAP authentication using the local password database, perform this task:
Procedure
Step 1
Enable DHCHAP.
Step 2
Identify and configure the DHCHAP authentication modes.
Step 3
Configure the hash algorithm and DH group.
Step 4
Configure the DHCHAP password for the local switch and other switches in the fabric.
Step 5
Configure the DHCHAP timeout value for reauthentication.
Step 6
Verify the DHCHAP configuration.

DHCHAP Compatibility with Fibre Channel Features

This section identifies the impact of configuring the DHCHAP feature along with existing Cisco NX-OS
features:
• SAN port channel interfaces—If DHCHAP is enabled for ports belonging to a SAN port channel,
• Port security or fabric binding—Fabric-binding policies are enforced based on identities authenticated
• VSANs—DHCHAP authentication is not done on a per-VSAN basis.

About Enabling DHCHAP

By default, the DHCHAP feature is disabled in all Cisco Nexus 5000 Series switches.
You must explicitly enable the DHCHAP feature to access the configuration and verification commands for
fabric authentication. When you disable this feature, all related configurations are automatically discarded.
Enabling DHCHAP
To enable DHCHAP for a Cisco Nexus 5000 Series switch, perform this task:
Procedure
Step 1
Step 2
Step 3
OL-16597-01
DHCHAP authentication is performed at the physical interface level, not at the port channel level.
by DHCHAP.
Command or Action
switch# configuration terminal
switch(config)# fcsp enable
switch(config)# no fcsp enable
DHCHAP Compatibility with Fibre Channel Features
Purpose
Enters configuration mode.
Enables the DHCHAP in this switch.
Disables (default) the DHCHAP in this
switch.
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
627

Advertisement

Table of Contents
loading

Table of Contents