19-4
Cisco MDS 9000 Fabric Manager Switch Configuration Guide
OL-7753-01
Chapter 19 Configuring Fabric Security
Configuring the DHCHAP Hash Algorithm
•
Off—Does not support DHCHAP authentication. Authentication messages sent to such ports return
error messages to the initiating switch.
Whenever DHCHAP port mode is changed to a mode other than the Off
mode, reauthentication is
performed.
Table 19-1
identifies the switch-to-switch authentication behavior between two Cisco MDS switches in
various modes.
Configuring the DHCHAP Hash Algorithm
Cisco MDS switches support a default hash algorithm priority list of MD-5 followed by SHA-1 for
DHCHAP authentication.
If you change the hash algorithm configuration, ensure to change it globally for all switches in the fabric.
RADIUS and protocols always use MD-5 for CHAP authentication. Using SHA-1 as the hash
algorithm may prevent RADIUS and usage--even if these AAA protocols are enabled for
DHCHAP authentication.
Configuring DHCHAP Groups
All switches in the Cisco MDS Family support all DHCHAP groups specified in the standard: 0 (null
DH group which does not perform the Diffie-Hellman exchange), 1, 2, 3, or 4.
If you change the DH group configuration, ensure to change it globally for all switches in the fabric.
Configuring DHCHAP Passwords
DHCHAP authentication in each direction requires a shared secret password between the connected
devices. To do this, you can use one of three approaches to manage passwords for all switches in the
fabric which participate in DHCHAP:
•
Approach 1—Use the same password for all switches in the fabric--the simplest approach. When
you add a new switch, you will use the same password to authenticate that switch in this fabric. It is
also the most vulnerable approach if someone from outside maliciously attempts to access any one
switch in the fabric
Table 19-1
DHCHAP Authentication Status Between Two MDS Switches
Switch N
Switch 1
DHCHAP Modes
on
on
FC-SP authentication is performed
auto-Active
FC-SP authentication is not performed.
auto-Passive
FC-SP authentication is not performed.
off
Link is brought down
Содержание DS-C9216I-K9
Страница 26: ...Contents xxvi Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 ...
Страница 42: ...xlii Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 New and Changed Information ...
Страница 128: ...10 8 Cisco MDS 9000 Fabric Manager Switch Configuration Guide OL 7753 01 Chapter 10 Managing System Hardware ...