Cisco MDS 9000 Series Configuration Manual page 231

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring FC-SP and DHCHAP
DHCHAP is a mandatory password-based, key-exchange authentication protocol that supports both
switch-to-switch and host-to-switch authentication. DHCHAP negotiates hash algorithms and DH groups
before performing authentication. It supports MD5 and SHA-1 algorithm-based authentication.
Configuring the DHCHAP feature requires the ENTERPRISE_PKG license (see the Cisco MDS 9000 Family
NX-OS Licensing Guide).
To configure DHCHAP authentication using the local password database, follow these steps:
Procedure
Step 1
Enable DHCHAP.
Step 2
Identify and configure the DHCHAP authentication modes.
Step 3
Configure the hash algorithm and DH group.
Step 4
Configure the DHCHAP password for the local switch and other switches in the fabric.
Step 5
Configure the DHCHAP timeout value for reauthentication.
Step 6
Verify the DHCHAP configuration.
Example
This section includes the following topics:
DHCHAP Compatibility with Existing Cisco MDS Features
This section identifies the impact of configuring the DHCHAP feature along with existing Cisco MDS features:
• PortChannel interfaces—If DHCHAP is enabled for ports belonging to a PortChannel, DHCHAP
• FCIP interfaces—The DHCHAP protocol works with the FCIP interface just as it would with a physical
• Port security or fabric binding—Fabric binding policies are enforced based on identities authenticated
• VSANs—DHCHAP authentication is not done on a per-VSAN basis.
• High availability—DHCHAP authentication works transparently with existing HA features.
About Enabling DHCHAP
By default, the DHCHAP feature is disabled in all switches in the Cisco MDS 9000 Family.
You must explicitly enable the DHCHAP feature to access the configuration and verification commands for
fabric authentication. When you disable this feature, all related configurations are automatically discarded.
Enabling DHCHAP
To enable DHCHAP for a Cisco MDS switch, follow these steps:
authentication is performed at the physical interface level, not at the PortChannel level.
interface.
by DHCHAP.
DHCHAP Compatibility with Existing Cisco MDS Features
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
213

Advertisement

Table of Contents
loading

Table of Contents