McDATA StorageWorks 2/140 - Director Switch Planning Manual page 222

Products in a san environment
Hide thumbs Also See for StorageWorks 2/140 - Director Switch:
Table of Contents

Advertisement

Physical Planning Considerations
5
McDATA Products in a SAN Environment - Planning Manual
5-18
• RADIUS server support - Remote authentication dial-in user
service (RADIUS) is a client-server, UDP-based protocol that
supports storage and authentication of passwords and CHAP
secrets. Directors, fabric switches, and SAN routers support a
RADIUS client (LAN-connected to a primary or secondary
RADIUS server) that authenticates CHAP responses and login
passwords. The RADIUS server stores:
— Management server-to-fabric element (director or fabric
switch) CHAP secrets.
— E_Port and N_Port DHCHAP secrets.
— Hypertext transfer protocol (HTTP) user passwords for the
EFCM Basic Edition interface.
— Telnet user passwords for the CLI.
— RADIUS server interface encryption keys.
• Inband access control list - The management server interface
supports an access control list (ACL) that provides attached port
worldwide names (WWNs) or switch node names for which
director or fabric switch communication is allowed. The CLI and
EFCM Basic Edition interface do not support configuration of an
inband access control list.
• Out-of-band access control list - Directors and fabric switches
support an IP-based ACL that defines the node IP addresses that
are permitted to log in to the fabric element through an
out-of-band management interface. Each director or fabric switch
is individually configured with a list of IP address ranges.
• Encrypted SSH protocol - Secure shell (SSH) protocol is a
software-enforced security encryption feature that controls CLI
access to a director or fabric switch. The SSH protocol suite
supports secure shell communication, remote file copy, file
transfer, and port forwarding through a telnet interface.
• Security log - The security log records security-related events
(including but not limited to SANtegrity features). The log is a
default feature of the Enterprise Operating System, classic
(E/OSc) firmware and does not require enablement through a
product feature enablement (PFE) key. Log entries record the
following events:

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents