Cisco MDS 9000 Series Configuration Manual page 235

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring FC-SP and DHCHAP
Refer to the fcsp dhchap dhgroup command in the Cisco MDS 9000 Series NX-OS Command Reference
Guide for details about the groups.
Tip
If you change the DH group configuration, change it globally for all switches in the fabric.
Configuring the DHCHAP Group Settings
To change the DH group settings, follow these steps:
Procedure
Step 1
switch# configure terminal
Enters configuration mode.
Step 2
switch(config)# fcsp dhchap dhgroup 2 3 4
Specifies the list of DH groups to be use. The list is specified in order of descending priority. Unspecified
groups are excluded from use by DHCHAP.
Step 3
switch(config)# no fcsp dhchap dhgroup 2 3 4
(Optional) Reverts to the DHCHAP default order.
About DHCHAP Password
DHCHAP authentication in each direction requires a shared secret password between the connected devices.
To do this, you can use one of three approaches to manage passwords for all switches in the fabric that
participate in DHCHAP.
• Approach 1—Use the same password for all switches in the fabric. This is the simplest approach. When
• Approach 2—Use a different password for each switch and maintain that password list in each switch
• Approach 3—Use different passwords for different switches in the fabric. When you add a new switch,
Note
All passwords are restricted to 64 alphanumeric characters and can be changed, but not deleted.
you add a new switch, you use the same password to authenticate that switch in this fabric. It is also the
most vulnerable approach if someone from the outside maliciously attempts to access any one switch in
the fabric.
in the fabric. When you add a new switch, you create a new password list and update all switches with
the new list. Accessing one switch yields the password list for all switches in that fabric.
multiple new passwords corresponding to each switch in the fabric must be generated and configured in
each switch. Even if one switch is compromised, the password of other switches are still protected. This
approach requires considerable password maintenance by the user.
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
Configuring the DHCHAP Group Settings
217

Advertisement

Table of Contents
loading

Table of Contents