12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The <strong>Brocade</strong> SAN Security ModelPassword policies can be defined to enforce basic rules on how passwordsare created and managed. Passwords should be strong in thesense that they would be difficult to guess or break using a dictionaryor brute force attack. The use of common words, or common numbersequences, do not make good passwords; random combinations of atleast eight numbers and alphabetic characters is typically a minimum.Passwords should not be reused on a regular basis and this can beenforced using the password history feature. Accounts should also belocked out after several (usually three) unsuccessful login attempts.Finally, passwords should be forced to expire after a period of time,even though this is always a sensitive subject. Over time, a passwordwill have a higher probability of being discovered and compromised,therefore it is important to change passwords on a regular basis. Howoften the password should be changed depends on the organization’sspecific requirements. If the password is changed too often, itbecomes more difficult for users to remember the password and notconfuse it with previous passwords. When forced to change their passwordstoo frequently, some users may simply resort to writing theirpassword down and keeping it somewhere near the computer, andpossibly accessible to others.Since most system administrators are responsible for more than onesystem, a unique account administrator must be created on eachmanaged device. The same goes for password changes, which mustalso be changed on each device the administrator is responsible for.To simplify this, a single sign-on method such as RADIUS or LDAP isrecommended. These methods allow a SAN administrator to change auser’s password for all servers in one centralized location.User and Password Best Practices Summary• Use secure channels• Change default passwords on ALL default accounts• Use unique user accounts with proper roles and privileges• Create and enforce password policies (strength, history, expiration,and lockout)• Use an account and password management method such asRADIUS or LDAPSecuring Fibre Channel Fabrics 103

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!