McDATA 4416 manual Fabric Management, User Account Security

Page 31

Fabric Management

User Account Security

User account security consists of the administration of account names, passwords, expiration date, and authority level. If an account has Admin authority, all management tasks can be performed by that account in McDATA Embedded Web Server, McDATA Element Manager, and the Telnet command line interface. Otherwise only monitoring tasks are available. The default account name, Admin, is the only account that can create or change account names and passwords. Account names and passwords are always required when connecting to a switch.

Authentication of the user account and password can be performed locally using the switch’s user account database or it can be done remotely using a RADIUS server such as Microsoft® RADIUS. Authenticating user logins on a RADIUS server requires a secure management connection to the switch. Refer to “Connection Security” on page 2-9for information about securing the management connection. A RADIUS server can also be used to authenticate devices and other switches as described in “Device Security” on page 2-10.

Consider your management needs and determine the number of user accounts, their authority needs, and expiration dates. Also consider the advantages of centralizing user administration and authentication on a RADIUS server.

NOTE: If the same user account exists on a switch and its RADIUS server, that user can login with either password, but the authority and account expiration will always come from the switch database.

Fabric Management

The McDATA Embedded Web Server application, McDATA Element Manager application, and CLI reside on the switch. These applications provide for the configuration, control, and maintenance of one fabric using McDATA Embedded Web Server, or one switch using McDATA Element Manager or the CLI. McDATA Element Manager requires the Element Manager PFE key and must be launched from EFCM. Supported workstation platforms include Windows and Linux.

Consider how many fabrics will be managed, how many management workstations are needed, and whether the fabrics will be managed with the McDATA Embedded Web Server, McDATA Element Manager, or the CLI.

A switch supports a combined maximum of 19 logins reserved as follows:

4 logins or sessions for internal applications such as management server and SNMP

9 high priority Telnet sessions

6 logins or sessions for McDATA Embedded Web Server, McDATA Element Manager, Telnet. Additional logins will be refused.

Planning

2-11

Image 31
Contents McDATA Fibre Channel Switch Module Installation Guide Record of Revisions and Updates Contents Chapter Troubleshooting Chapter InstallationAppendix a Specifications Contents McDATA 4416 Fibre Channel Switch Module Installation Guide Figures Figures Viii Tables Tables Preface How to Use this ManualWho Should Use this Manual Related Documentation General Description McDATA 4416 Switch ModuleMaintenance Button Switch Module Controls and LEDsSystem Fault LED Amber Switch Module LEDsIdentifier LED Green System Fault LED Amber Input Power LED Input Power LED Green10 11 12 Fibre Channel PortsPort Activity LED Green External Port LEDsLogged-In LED Green Port Logged-In LED GreenPort Types TransceiversActivity LED Ethernet PortGreen RJ-45 Ethernet Port Switch Module Management Devices PlanningLimit Description Device AccessSoft Zones Access Control List Hard ZonesDistance PerformanceLatency BandwidthOptimizing Device Performance Multiple Chassis FabricsDomain ID, Principal Priority, and Domain ID Lock Switch Module Services McDATA 4416 Fibre Channel Switch Module Installation Guide Connection Security Fabric SecurityDevice Security User Account Security Fabric ManagementMcDATA 4416 Fibre Channel Switch Module Installation Guide Site Requirements InstallationFabric Management Workstation Install SFP Transceivers Installing a SwitchEnvironmental Conditions Switch Module in I/O Mount the Switch Module in the Server ChassisModule Slot Indirect Ethernet Direct Ethernet RJ-45 Connection Connect the Management Workstation to the Switch ModuleStart McDATA Embedded Web Server or McDATA Element Manager Configure the Switch Module Cable Devices to the Switch Install FirmwareMcDATA 4416 Fibre Channel Switch Module Installation Guide McDATA 4416 Command Line Interface Guide Using the CLI to Install FirmwareMcDATA 4416 Fibre Channel Switch Module Installation Guide Input Power LED Is Extinguished TroubleshootingSystem Fault LED is Illuminated EPort Isolation Logged-In LED IndicationsLogged-In LED Troubleshooting Excessive Port Errors Recovering a Switch Module Maintenance Image Unpack Maintenance ExitMaintenance Remove Switch Config Maintenance Reset Network ConfigMaintenance Reset User Accounts to Default Maintenance Copy Log FilesMcDATA 4416 Fibre Channel Switch Module Installation Guide Fabric Specifications SpecificationsLED indicators Maintainability SpecificationsDimensional Specifications Fabric Management SpecificationsElectrical Specifications Environmental Specifications Certification Description Regulatory CertificationsMcDATA 4416 Fibre Channel Switch Module Installation Guide Glossary Server Interface SwitchInformation Base Protocol Interference EMI Numerics IndexLED Reset 1-2,4-7services 2-7specifications A-1 McDATA 4416 Fibre Channel Switch Module Installation Guide