Configuring Standard Security Features; Secure Protocols - HP AE370A - Brocade 4Gb SAN Switch 4/12 Administrator's Manual

Hp storageworks fabric os 5.2.x administrator guide (5697-0014, may 2009)
Hide thumbs Also See for AE370A - Brocade 4Gb SAN Switch 4/12:
Table of Contents

Advertisement

4

Configuring standard security features

This chapter provides information and procedures for configuring standard Fabric OS security features such
as account and password management.
Additional security features are available by purchasing the optional Secure Fabric OS feature. For
information about licensed security features available in Secure Fabric OS, refer to the Secure Fabric OS
Administrator's Guide.

Secure protocols

Fabric OS supports the secure protocols shown in
Table 16
Secure protocol support
,
Protocol
SSL
HTTPS
Secure File Copy (scp)
SNMPv3
Simple Network Management Protocol (SNMP) is a standard method for monitoring and managing
network devices. Using SNMP components, you can program tools to view, browse, and manipulate switch
variables and set up enterprise-level management processes.
Every HP switch carries an SNMP agent and management information b ase (MIB). The agent accesses
MIB information about a device and makes it available to a network manager station. You can manipulate
information of your choice by
Manager.
The SNMP Access Control List (ACL) provides a way for the administrator to restrict SNMP get/set
operations to certain hosts/IP addresses. This is used for enhanced management security in the storage
area network.
For details on MIB files, naming conventions, loading instructions, and information about using the SNMP
agent, refer to the Fabric OS MIB Reference Manual.
Table 17
describes additional software or certificates that you must obtain to deploy secure protocols.
Table 17
Items needed to deploy secure protocols
Protocol
Secure telnet
(sectelnet)
SSH
HTTPS
Secure File Copy (scp)
SNMPv3, SNMPv1
Description
Supports SSLv3, 128-bit encryption by default. Fabric OS uses SSL to
support HTTPS. A certificate must be generated and installed on each
switch to enable SSL.
Web Tools supports the use of HTTPS.
Configuration upload and download support the use of scp.
SNMPv1 is also supported.
trapping
MIB elements using the Fabric OS CLI, Web Tools, or Fabric
Host side
Sectelnet client
SSH client
No requirement on host
side except a browser
that supports HTTPS
SSH daemon, scp
server
None
Table
16.
Switch side
License not required, but a switch
certificate issued by HP is required
None
Switch IP certificate for SSL
None
None
Fabric OS 5.2.x administrator guide
83

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents