About Fabric Authentication; Dhchap - HP Cisco MDS 9020 - Fabric Switch Configuration Manual

Cisco mds 9000 family cli configuration guide, release 3.x (ol-16184-01, april 2008)
Hide thumbs Also See for Cisco MDS 9020 - Fabric Switch:
Table of Contents

Advertisement

S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Configuring FC-SP and DHCHAP
Fibre Channel Security Protocol (FC-SP) capabilities provide switch-switch and host-switch
authentication to overcome security challenges for enterprise-wide fabrics. Diffie-Hellman Challenge
Handshake Authentication Protocol (DHCHAP) is an FC-SP protocol that provides authentication
between Cisco MDS 9000 Family switches and other devices. DHCHAP consists of the CHAP protocol
combined with the Diffie-Hellman exchange.
This chapter includes the following sections:

About Fabric Authentication

All switches in the Cisco MDS 9000 Family enable fabric-wide authentication from one switch to
another switch, or from a switch to a host. These switch and host authentications are performed locally
or remotely in each fabric. As storage islands are consolidated and migrated to enterprise-wide fabrics
new security challenges arise. The approach of securing storage islands cannot always be guaranteed in
enterprise-wide fabrics. For example, in a campus environment with geographically distributed switches
someone could maliciously interconnect incompatible switches or you could accidentally do so,
resulting in Inter-Switch Link (ISL) isolation and link disruption. This need for physical security is
addressed by switches in the Cisco MDS 9000 Family (see
Figure 36-1
Fibre Channel (FC) host bus adapters (HBAs) with appropriate firmware and drivers are required for
Note
host-switch authentication.

DHCHAP

DHCHAP is an authentication protocol that authenticates the devices connecting to a switch. Fibre
Channel authentication allows only trusted devices to be added to a fabric, thus preventing unauthorized
devices from accessing the switch.
OL-16184-01, Cisco MDS SAN-OS Release 3.x
About Fabric Authentication, page 36-1
DHCHAP, page 36-1
Sample Configuration, page 36-10
Default Settings, page 36-12
Switch and Host Authentication
36
C H A P T E R
Figure
36-1).
Cisco MDS 9000 Family CLI Configuration Guide
36-1

Advertisement

Table of Contents
loading

Table of Contents