12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Securing Management InterfacesThe traffic exchanged on the Ethernet management interfacesbetween two FC switches or enterprise-class platforms (directors orbackbones) can also be encrypted by creating a tunnel using IPSec(configured with the ipSecConfig command).Finally, several FOS commands are used to copy information to andfrom the switches that use unsecure services such as FTP to exchangedata in cleartext format. The FTP service can be replaced in somecases with the SCP service, which is based on SSH. The following commandscan be secured using SCP instead of FTP:• configUpload and configDownload (since FOS 4.4.0)• firmwareDownload (since FOS 5.3.0)• supportSave (since FOS 5.3.0)In order to use SCP instead of FTP for the configuration upload anddownload operations, the configure command must be used. To useSCP with the firmwareDownload and supportSave commands, aparameter must be entered at the command line to indicate that theSCP protocol will be used.SNMP is a commonly used protocol to monitor and manage <strong>Brocade</strong>switches. The earlier versions of this protocol, SNMPv1/2, had somesecurity vulnerabilities that could be exploited. It is safer to use the latestversion, SNMPv3, since it supports encrypted community stringsalong with several other capabilities.If you are using SNMPv1/2, make sure to change the default communitystrings predefined in FOS, since they are well known and can beused in an attack. Additionally, the security level can be changed andset to:• No security• Authentication only• Authentication and privacyThese settings can be configured using the snmpConfig command.Protecting Login SessionsOne of the first things a hacker may do when planning an attack is tocollect information about the targeted device. One of the simplestmethods to collect SAN information is to simply type the IP address ofa switch in a Web browser using HTTP to immediately display the WebTools interface. The Web Tools interface would conveniently display afair amount of useful information that could be used for an eventualSecuring Fibre Channel Fabrics 135

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!