12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Securing Management Interfacesadmin lockout policy can be disabled to prevent a DoS attack on thataccount; however, it is then vulnerable to a brute-force guessingattack. The admin account lockout policy is enabled or disabled usingthe passwdCfg command (passwdCfg [- - enableadminlockout][- - disableadminlockout]).When a switch authenticates a user, by default it consults the localpassword database. However, the <strong>Brocade</strong> user authentication modelallows for two other methods to authenticate users: RADIUS and LDAP.SAN administrators can manage both passwords and usernames oneach switch locally or through a centralized access control administrationmethod, such as the RADIUS authentication protocol or the LDAP.These protocols allow a SAN administrator to change a password ordisable a user's account from one central location and that change isapplied immediately across all switches to which the user has access.The authentication method to be used is defined using the aaaConfigcommand (aaaConfig - - authspec ["radius" | "ldap" |"radius;local" | "ldap;local" - - backup]).For redundancy, more than one authentication server can be addedusing the aaaConfig - - add command.Role-Based Access ControlRBAC can be used to restrict which commands a user can use. Forexample, a SAN administrator may want to allow summer interns to gettheir feet wet in SAN management by viewing and monitoring the SANconfiguration and status, but does not want to them to be able tochange any configuration parameters. A user account can be createdwith the User role to allow view but not modify permission. Table 11lists the roles available in Fabric OS and when these roles became available.As of FOS 7.0, users can create their own customized roles withthe roleConfig command.Table 2. <strong>Brocade</strong> RBACRole NameFirst inFOSDutiesDescriptionAdmin All All administration All administrativecommands excludingchassis-specificcommandsBasicSwitchAdmin5.2.0 Restricted switchadministrationMostly monitoring withlimited switch (local)commandsSecuring Fibre Channel Fabrics 141

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!