McDATA 4416 manual Device Security

Page 30

Fabric Security

Device Security

NOTE: Device security is available only with the SANtegrity Enhanced PFE key. Refer to McDATA Switch Module Management Guide for information about installing a PFE key. For additional McDATA PFE keys, please contact your McDATA representative or visit the web site at www.mcdata.com.

Device security provides for the authorization and authentication of devices that you attach to a switch. You can configure a switch with a group of devices against which the switch authorizes new attachments by devices, other switches, or devices issuing management server commands. Device security is configured through the use of security sets and groups. A group is a list of device worldwide names that are authorized to attach to a switch. There are three types of groups: one for other switches (ISL), another for devices (port), and a third for devices issuing management server commands (MS). A security set is a set of up to three groups with no more than one of each group type. The security configuration is made up of all security sets on the switch. The security database has the following limits:

Maximum number of security sets is 4.

Maximum number of groups is 16.

Maximum number of members in a group is 1000.

Maximum total number of group members is 1000.

In addition to authorization, the switch can be configured to require authentication to validate the identity of the connecting switch, device, or host. Authentication can be performed locally using the switch’s security database, or remotely using a Remote Dial-In User Service (RADIUS) server such as Microsoft® RADIUS. With a RADIUS server, the security database for the entire fabric resides on the server. In this way, the security database can be managed centrally, rather than on each switch module. You can configure up to five RADIUS servers to provide failover.

You can configure the RADIUS server to authenticate just the switch module or both the switch module and the initiator device if the device supports authentication. When using a RADIUS server, every switch in the fabric must have a network connection. A RADIUS server can also be configured to authenticate user accounts as described in “User Account Security” on page 2-11. A secure connection is required to authenticate user logins with a RADIUS server. Refer to “Connection Security” on page 2-9for more information.

Consider the devices, switches, and management agents and evaluate the need for authorization and authentication. Also consider whether the security database is to distributed on the switches or centralized on a RADIUS server and how many servers to configure.

2-10

McDATA 4416 Fibre Channel Switch Module Installation Guide

Image 30
Contents McDATA Fibre Channel Switch Module Installation Guide Record of Revisions and Updates Contents Chapter Installation Chapter TroubleshootingAppendix a Specifications Contents McDATA 4416 Fibre Channel Switch Module Installation Guide Figures Figures Viii Tables Tables How to Use this Manual PrefaceWho Should Use this Manual Related Documentation McDATA 4416 Switch Module General DescriptionSwitch Module Controls and LEDs Maintenance ButtonInput Power LED Green Switch Module LEDsIdentifier LED Green System Fault LED Amber Input Power LED System Fault LED AmberFibre Channel Ports 10 11 12Port Logged-In LED Green External Port LEDsLogged-In LED Green Port Activity LED GreenTransceivers Port TypesEthernet Port Activity LEDGreen RJ-45 Ethernet Port Switch Module Management Planning DevicesDevice Access Limit DescriptionAccess Control List Hard Zones Soft ZonesPerformance DistanceBandwidth LatencyMultiple Chassis Fabrics Optimizing Device PerformanceDomain ID, Principal Priority, and Domain ID Lock Switch Module Services McDATA 4416 Fibre Channel Switch Module Installation Guide Fabric Security Connection SecurityDevice Security Fabric Management User Account SecurityMcDATA 4416 Fibre Channel Switch Module Installation Guide Installation Site RequirementsFabric Management Workstation Installing a Switch Install SFP TransceiversEnvironmental Conditions Mount the Switch Module in the Server Chassis Switch Module in I/OModule Slot Connect the Management Workstation to the Switch Module Indirect Ethernet Direct Ethernet RJ-45 ConnectionStart McDATA Embedded Web Server or McDATA Element Manager Configure the Switch Module Install Firmware Cable Devices to the SwitchMcDATA 4416 Fibre Channel Switch Module Installation Guide Using the CLI to Install Firmware McDATA 4416 Command Line Interface GuideMcDATA 4416 Fibre Channel Switch Module Installation Guide Troubleshooting Input Power LED Is ExtinguishedSystem Fault LED is Illuminated Logged-In LED Indications EPort IsolationLogged-In LED Troubleshooting Excessive Port Errors Recovering a Switch Module Maintenance Exit Maintenance Image UnpackMaintenance Copy Log Files Maintenance Reset Network ConfigMaintenance Reset User Accounts to Default Maintenance Remove Switch ConfigMcDATA 4416 Fibre Channel Switch Module Installation Guide Specifications Fabric SpecificationsMaintainability Specifications LED indicatorsFabric Management Specifications Dimensional SpecificationsElectrical Specifications Environmental Specifications Regulatory Certifications Certification DescriptionMcDATA 4416 Fibre Channel Switch Module Installation Guide Glossary Server Switch InterfaceInformation Base Protocol Interference EMI Index NumericsLED Reset 1-2,4-7services 2-7specifications A-1 McDATA 4416 Fibre Channel Switch Module Installation Guide