19-2
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
OL-7753-01
Chapter 19 Configuring Fabric Security
About DHCHAP
Figure 19-1
Authentication between Switches and Hosts
Fibre Channel (FC) host bus adapters (HBAs) with appropriate firmware and drivers are required for
host-switch authentication.
About DHCHAP
DHCHAP is an authentication protocol that authenticates the devices connecting to a switch. Fibre
Channel authentication allows only trusted devices to be added to a fabric, thus preventing unauthorized
devices from accessing the switch.
The terms FC-SP and DHCHAP are used interchangeably in this chapter.
DHCHAP is a mandatory password-based, key-exchange authentication protocol that supports both
switch-to-switch and host-to-switch authentication. DHCHAP negotiates hash algorithms and DH
groups before performing authentication. It supports MD-5 and SHA-1 algorithm-based authentication.
Configuring the DHCHAP feature requires the ENTERPRISE_PKG license.
DHCHAP Compatibility with Existing MDS Features
This sections identifies the impact of configuring the DHCHAP feature along with existing MDS
features:
Storage
Subsytems
Unauthorized
hosts and switches
FC-SP
(DH-CHAP)
FC-SP
(DH-CHAP)
Trusted hosts
RADIUS server
2
09
Содержание DS-C9216I-K9
Страница 26: ...Contents xxvi Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 ...
Страница 42: ...xlii Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 New and Changed Information ...
Страница 128: ...10 8 Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 Chapter 10 Managing System Hardware ...