12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Securing Management InterfacesThe following is a list of the Secure Fabric OS features:• FCS (Fabric Configuration Server) policy• SCC (Switch Connection Control) policy• DCC (Device Connection Control) policy• MAC (Management Access Control) policy• PKI Switch-Switch AuthenticationSecuring Management InterfacesAs mentioned throughout this book, management interfaces are probablythe most vulnerable points in a SAN from a security perspective.The physical interfaces on an FC switch include management Ethernet,USB, and serial ports. With the older Silkworm 2800 switch, therewas also a front LCD panel that could be used to manage the switch.The USB port is used exclusively for downloading firmware to a switch,and as such, is not used for other management purposes. The USB isoften considered a security risk and it can be disabled from the activeCP using the usbStorage -d command. The USB port is disabled bydefault and must be explicitly enabled each time a USB storage deviceis inserted in the port using the usbStorage -e command. A USB storagedevice must also be present to enable the port.The serial interface can be used only to access the CLI and cannot bedisabled. (SFOS had a MAC policy to disable access to the serial port butno such policy exists in base FOS today.)With an Ethernet interface, the following tools can be used to managea <strong>Brocade</strong> FC switch:• CLI: telnet or secure shell (SSH)• GUI: <strong>Brocade</strong> Web Tools or <strong>Brocade</strong> DCFM• FTP (File Transfer Protocol) or SCP (Secure Copy Protocol)• SNMP (Simple Network Management Protocol)To protect the Ethernet interface, organizations should employ reliableIP network security best practices to isolate management interfacesand ensure that they are accessible only to the appropriate staff. Typically,the Ethernet interface is connected to a dedicated LAN or a VLANused exclusively for management purposes and is not connected to theproduction LAN, which provides proper isolation between the two LANs.Securing Fibre Channel Fabrics 133

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!