18-8
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
OL-7753-01
Chapter 18 Configuring Switch Security
Configuring
•
Maintains simultaneous connections to multiple servers
•
Adapts to growing, as well as congested networks
Enabling
By default, the feature is disabled in all switches in the Cisco MDS 9000 Family. You must
explicitly enable the feature to access the configuration and verification commands for fabric
authentication. When you disable this feature, all related configurations are automatically discarded.
Setting the Server Address
If a secret key is not configured for a configured server, a warning message is issued and the global secret
encryption key is automatically used.
Setting the Secret Key
From Fabric Manager, choose
Switches > Security > > Defaults
to configure global values
for the key for all servers.
Secret keys configured for individual servers override the globally configured values.
Setting the Timeout Value
From Fabric Manager, choose
Switches > Security > > Defaults
to configure global timeout
values for all servers.
Timeout values configured for individual servers override the globally configured values.
Defining Custom Attributes for Roles
MDS uses custom attribute for service shell to configure the roles to which a user belongs.
attributes are specified as name=value format. The attribute name for this custom attribute is
cisco-av-pair. The following example illustrates how to specify roles using this attribute:
cisco-av-pair=shell:roles=”network-admin vsan-admin”
custom attributes can be defined on an ACS server for various services (for example, shell).
MDS requires the custom attribute for service shell to be used for defining roles.
Содержание DS-C9216I-K9
Страница 26: ...Contents xxvi Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 ...
Страница 42: ...xlii Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 New and Changed Information ...
Страница 128: ...10 8 Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 Chapter 10 Managing System Hardware ...