Fabric OS 5.2.x administrator guide
77
Enabling and disabling local authentication as backup
It is useful to enable local authentication so that the switch can take over authentication locally if the
RADIUS servers fail to respond because of power outage or network problems. To enable or disable local
authentication, enter the appropriate command:
For details about this command and how it is different from
aaaConfig –radiuslocal
, see
Table 12
on page 58.
When local authentication is enabled and RADIUS servers fail to respond, you can log in to the default
switch accounts (
admin
and
user
) or any user-defined account. You must know the passwords of these
accounts.
When the command succeeds, the event log indicates that local database authentication is disabled or
enabled.
Setting the boot PROM password
The boot PROM password provides an additional layer of security by protecting the boot PROM from
unauthorized use. Setting a recovery string for the boot PROM password enables you to recover a lost boot
PROM password by contacting your switch service provider. Without the recovery string, a lost boot PROM
password cannot be recovered.
You should set the boot PROM password and the recovery string on all switches, as described next. If your
site procedures dictate that you set the boot PROM password without the recovery string, see ”
Without a
Recovery String
” on page 114.
SS
Setting the boot PROM password with a recovery String
To set the boot PROM password with a recovery string, refer to the section that applies to your switch
model.
NOTE:
Setting the boot PROM password requires accessing the boot prompt, which stops traffic flow
through the switch until the switch is rebooted. You should perform this procedure during a planned down
time.
4/8 and 4/16 SAN Switch, SAN Switch 2/8V, SAN Switch 2/16V, SAN Switch 2/32, SAN
Switch 4/32, 4/64 SAN Switch, and 400 MP Router
How to set the boot PROM password for a switch with a recovery string
1.
Connect to the serial port interface as described in ”
How to connect via the serial port
” on page 24.
2.
Reboot the switch.
3.
Press
ESC
within four seconds after the message “Press escape within 4 seconds...” displays.
The following options are available:
4.
Enter
2.
If no password was previously set, the following message displays:
switch:admin>
aaaConfig –radiuslocalbackup
Option
Description
1 Start system.
Continues the system boot process.
2 Recovery password.
Lets you set the recovery string and the boot PROM
password.
3 Enter command shell. Provides access to boot parameters.
Recovery password is NOT set. Please set it now.
Summary of Contents for AE370A - Brocade 4Gb SAN Switch 4/12
Page 18: ...18 ...
Page 82: ...82 Managing user accounts ...
Page 102: ...102 Configuring standard security features ...
Page 126: ...126 Maintaining configurations ...
Page 198: ...198 Routing traffic ...
Page 238: ...238 Using the FC FC routing service ...
Page 260: ...260 Administering FICON fabrics ...
Page 280: ...280 Working with diagnostic features ...
Page 332: ...332 Administering Extended Fabrics ...
Page 414: ...398 Configuring the PID format ...
Page 420: ...404 Configuring interoperability mode ...
Page 426: ...410 Understanding legacy password behaviour ...
Page 442: ...426 ...
Page 444: ......
Page 447: ......