12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 6: FC Security Best PracticesSeparation of Duties Best Practices Summary• In sensitive environments, separate fabrics fully• Create LSANs to isolate fabrics but share resources such astape backup systems• Use pWWN when defining zoning members• Use single-initiator zones• Use default zones• Use Virtual Fabrics to logically separate sensitive environmentsfrom less-sensitive environments• Use traffic isolation to separate traffic to avoid contentionUser and Password ManagementPasswords and accounts are the gatekeepers to the managementinterfaces and must be protected to ensure they are not acquired byunauthorized individuals. The simplest method to prevent unauthorizedpersons from obtaining a password by sniffing traffic is to use asecure protocol, such as SSH or SSL or both, to access the managementinterface.One of the most common ways to break into a SAN is by attempting tolog in using the default passwords. One of the first items verified duringa SAN security assessment is whether the default passwords havebeen changed for the standard accounts (user, admin, root, and factory).In recent <strong>Brocade</strong> SAN security assessments, one out of everyfour companies assessed had at least two switches still using thedefault password for at least one account. This is the simplest way tobreak into a corporate SAN and can be easily prevented by changingthe default passwords during initial installation.As a best practice, all individual users should have their own uniqueuser account. The default accounts, such as root, factory, and admin,should never be used. Instead, individual SAN administrators shouldbe assigned unique user accounts with the appropriate roles to allowthem to carry out their daily management responsibilities.102 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!