Cisco MDS 9000 Series Configuration Manual page 24

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Port Security
Port Security
The port security feature prevents unauthorized access to a switch port by binding specific world-wide names
(WWNs) that have access to one or more given switch ports.
When port security is enabled on a switch port, all devices connecting to that port must be in the port security
database and must be listed in the database as bound to a given port. If both of these criteria are not met, the
port will not achieve an operationally active state and the devices connected to the port will be denied access
to the SAN.
For information on configuring port security, see
Fibre Channel Common Transport Management Server Query
With the FC-CT query management feature, an administrator can configure the network in such a manner
that only a storage administrator or a network administrator can send queries to a switch and access information
such as devices that are logged in devices in the fabric, switches in the fabric, how they are connected, how
many ports each switch has and where each port is connected, configured zone information and privilege to
add or delete zone and zone sets, and Host Bus Adapter (HBA) details of all the hosts connected in the fabric
and so on.
For information on configuring fabric binding, see
Fabric Binding
The fabric binding feature ensures Inter-Switch Links (ISLs) are enabled only between specified switches in
the fabric binding configuration. This feature helps prevent unauthorized switches from joining the fabric or
disrupting the current fabric operations. This feature uses the Exchange Fabric Membership Data (EEMD)
protocol to ensure that the list of authorized switches is identical in all of the switches in a fabric.
For information on configuring fabric binding, see
TrustSec Fibre Channel Link Encryption
Cisco TrustSec Fibre Channel Link Encryption is an extension of the Fibre Channel-Security Protocol (FC-SP)
feature and uses the existing FC-SP architecture to provide integrity and confidentiality of transactions.
Encryption is added to the peer authentication capability to provide security and prevent unwanted traffic
interception. Peer authentication is implemented according to the FC-SP standard using the Diffie-Hellman
Challenge Handshake Authentication Protocol (DHCHAP) protocol.
For information on configuring TrustSec Fibre Channel Link Encryption, see
Transport , on page
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
6
247.
About Port Security, on page
About Fibre Channel Common Transport , on page
About Fabric Binding , on page
Security Overview
225.
247.
251.
About Fibre Channel Common

Advertisement

Table of Contents
loading

Table of Contents