Chapter 38 Configuring Fc-Sp And Dhchap; Dhchap Compatibility With Existing Cisco Mds Features - Cisco AP776A - Nexus Converged Network Switch 5020 Configuration Manual

Cisco mds 9000 family cli configuration guide - release 4.x (ol-18084-01, february 2009)
Hide thumbs Also See for AP776A - Nexus Converged Network Switch 5020:
Table of Contents

Advertisement

Chapter 38
Configuring FC-SP and DHCHAP
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Enable DHCHAP.
Step 1
Identify and configure the DHCHAP authentication modes.
Step 2
Configure the hash algorithm and DH group.
Step 3
Configure the DHCHAP password for the local switch and other switches in the fabric.
Step 4
Step 5
Configure the DHCHAP timeout value for reauthentication.
Verify the DHCHAP configuration.
Step 6
This section includes the following topics:

DHCHAP Compatibility with Existing Cisco MDS Features

This sections identifies the impact of configuring the DHCHAP feature along with existing Cisco MDS
features:
OL-18084-01, Cisco MDS NX-OS Release 4.x
DHCHAP Compatibility with Existing Cisco MDS Features, page 38-3
About Enabling DHCHAP, page 38-4
Enabling DHCHAP, page 38-4
About DHCHAP Authentication Modes, page 38-5
Configuring the DHCHAP Mode, page 38-5
About the DHCHAP Hash Algorithm, page 38-6
Configuring the DHCHAP Hash Algorithm, page 38-6
About the DHCHAP Group Settings, page 38-7
Configuring the DHCHAP Group Settings, page 38-7
About the DHCHAP Password, page 38-7
Configuring DHCHAP Passwords for the Local Switch, page 38-8
About Password Configuration for Remote Devices, page 38-8
Configuring DHCHAP Passwords for Remote Devices, page 38-9
About the DHCHAP Timeout Value, page 38-9
Configuring the DHCHAP Timeout Value, page 38-9
Configuring DHCHAP AAA Authentication, page 38-9
Displaying Protocol Security Information, page 38-10
PortChannel interfaces—If DHCHAP is enabled for ports belonging to a PortChannel, DHCHAP
authentication is performed at the physical interface level, not at the PortChannel level.
FCIP interfaces—The DHCHAP protocol works with the FCIP interface just as it would with a
physical interface.
Port security or fabric binding—Fabric binding policies are enforced based on identities
authenticated by DHCHAP.
VSANs—DHCHAP authentication is not done on a per-VSAN basis.
High availability—DHCHAP authentication works transparently with existing HA features.
Cisco MDS 9000 Family CLI Configuration Guide
DHCHAP
38-3

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents