Dhchap Compatibility With Fibre Channel Features; About Enabling Dhchap; Enabling Dhchap - Cisco Nexus 5000 Series Configuration Manual

Nx-os san
Hide thumbs Also See for Nexus 5000 Series:
Table of Contents

Advertisement

Configuring FC-SP and DHCHAP
Before You Begin
You must explicitly enable the DHCHAP feature to access the configuration and verification commands for
fabric authentication. When you disable this feature, all related configurations are automatically discarded.
Step 1
Enable DHCHAP.
Step 2
Identify and configure the DHCHAP authentication modes.
Step 3
Configure the hash algorithm and DH group.
Step 4
Configure the DHCHAP password for the local switch and other switches in the fabric.
Step 5
Configure the DHCHAP timeout value for reauthentication.
Step 6
Verify the DHCHAP configuration.

DHCHAP Compatibility with Fibre Channel Features

When configuring the DHCHAP feature along with existing Cisco NX-OS features, consider these compatibility
issues:
• SAN port channel interfaces—If DHCHAP is enabled for ports belonging to a SAN port channel,
• Port security or fabric binding—Fabric-binding policies are enforced based on identities authenticated
• VSANs—DHCHAP authentication is not done on a per-VSAN basis.
By default, the DHCHAP feature is disabled in all Cisco SAN switches.

About Enabling DHCHAP

By default, the DHCHAP feature is disabled in all Cisco SAN switches.
You must explicitly enable the DHCHAP feature to access the configuration and verification commands for
fabric authentication. When you disable this feature, all related configurations are automatically discarded.

Enabling DHCHAP

You can enable DHCHAP for a Cisco Nexus device.
OL-27583-01
DHCHAP authentication is performed at the physical interface level, not at the port channel level.
by DHCHAP.
Cisco Nexus 5000 Series NX-OS SAN Switching Configuration Guide, Release 5.2(1)N1(1)
Configuring DHCHAP Authentication
241

Advertisement

Table of Contents
loading

Table of Contents