Connection Security; Device Security - HP StorageWorks SN6000 Installation And Reference Manual

Fibre channel switch
Hide thumbs Also See for StorageWorks SN6000:
Table of Contents

Advertisement

Connection security

Connection security provides an encrypted data path for switch management methods. The switch supports
the Secure Shell (SSH) protocol for the command line interface and the Secure Socket Layer (SSL) protocol
for management applications such as QuickTools, Enterprise Fabric Management Suite, and SMI-S. Use
the CLI to configure SSH and SSL. For more information about SSH and SSL configuration, see the HP
StorageWorks SN6000 Fibre Channel Switch Command Line Interface Guide.
The SSL handshake process between the workstation and the switch involves the exchanging of certificates.
These certificates contain the public and private keys that define the encryption. When the SSL service is
enabled, a certificate is automatically created on the switch. The workstation validates the switch certificate
by comparing the workstation date and time to the switch certificate creation date and time. For this
reason, it is important to synchronize the workstation and switch with the same date, time, and time zone.
The switch certificate is valid 24 hours before its creation date and 365 days after its creation date. If the
certificate should become invalid, create a new certificate using the create certificate CLI
command. For information about the create certificate CLI command, see the HP StorageWorks
SN6000 Fibre Channel Switch Command Line Interface Guide.
Consider your requirements for connection security: for the command line interface (SSH), management
applications (SSL), or both. If an SSL connection security is required, also consider using the Network Time
Protocol (NTP) to synchronize workstations and switches.

Device security

Device security provides for the authorization and authentication of devices that you attach to a switch. You
can configure a switch with a group of devices against which the switch authorizes new attachments by
devices, other switches, or devices issuing management server commands. Device security is configured
through the use of security sets and groups. Use the CLI to configure device security. For more information
about device security configuration, see the HP StorageWorks SN6000 Fibre Channel Switch Command
Line Interface Guide.
A group is a list of device worldwide names that are authorized to attach to a switch. There are three types
of groups: one for other switches (ISL), another for devices (port), and a third for devices issuing
management server commands (MS).
A security set is a set of up to three groups with no more than one of each group type. The security
configuration is made up of all security sets on the switch. The security database has the following limits:
Maximum number of security sets is 4.
Maximum number of groups is 16.
Maximum number of members in a group is 1,000.
Maximum total number of group members is 1,000.
In addition to authorization, the switch can be configured to require authentication to validate the identity
of the connecting switch, device, or host. Authentication can be performed locally using the switch's
security database, or remotely using a RADIUS server such as Microsoft RADIUS. With a RADIUS server,
the security database for the entire fabric resides on the server. In this way, the security database can be
managed centrally, rather than on each switch. You can configure up to five RADIUS servers to provide
failover.
You can configure the RADIUS server to authenticate just the switch or both the switch and the initiator
device if the device supports authentication. When using a RADIUS server, every switch in the fabric must
have a network connection. A RADIUS server can also be configured to authenticate user accounts as
described in
"User account
with a RADIUS server. For more information, see
Consider the devices, switches, and management agents and evaluate the need for authorization and
authentication. Also consider whether the security database is to be distributed on the switches or
centralized on a RADIUS server and how many servers to configure. Use the CLI to configure RADIUS
servers. For more information about RADIUS server configuration, see the HP StorageWorks SN6000 Fibre
Channel Switch Command Line Interface Guide.
30
security" (page 29). A secure connection is required to authenticate user logins
"Connection
security" (page 30).

Advertisement

Table of Contents
loading

Table of Contents