12.07.2015 Views

BROCADE IP PRIMER

BROCADE IP PRIMER

BROCADE IP PRIMER

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

User Access ControlIf you were to copy this config to a TFTP server, you would not see the five periods,but you would see the encrypted hash. It would look something like this:enable super-user-password 8 $1$eqT62$3cKeWJKxb3ISFOenable port-config-password 7 $4jl,sL%alsEN&enable read-only-password 7 $1$eqjajidfio1KLjs.$Why not show this information in the show run output? Well, as safe andsound as this appears, it is possible, though time-intensive, to reverse-engineerthe hash. For example, if an attacker obtains access to this information,given enough time, he could use the hash to discover the actual passwords.Brocade makes it harder for attackers by hiding the hash and the passwordsfrom anyone with read-only access to the switch.You can actually show the passwords in plain text, by adding this command tothe Global config:Switch#conf tSwitch(config)#no service password-encryptionYour passwords will still show as five periods (“.....”) when you view either thestartup or running config on the switch. This time, if you were to copy the configto a TFTP server, the passwords would be shown in plain text. There are veryfew scenarios in which turning off password-encryption is a good idea. The safestthing is to leave this setting at its default.If you absolutely must show the password hash in the startup and running config,you may enter this command:Switch#conf tSwitch(config)#enable password-displayBrocade recommends against this (and so does the author). Default settingswill provide the greatest security.Recovering PasswordsThe feared day has come. You've forgotten your Super-User password, and youneed to make an important change to the switch's config. You do have one lasthope, but to perform this procedure, you must have serial access to the switch.This procedure cannot be performed remotely.1. Reload the switchThe switch must be reloaded. If you cannot log in to issue the “reload”command, you must power off the switch, and power it back on.2. Enter Boot-Monitor mode by pressing the “b” key when prompted. Youmust press the “b” key within two seconds of the switch receiving power.You should see a prompt that looks like this:BOOT MONITOR>Brocade <strong>IP</strong> Primer 143

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!