12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Fabric-Based Encryptionthe <strong>Brocade</strong> audit log feature, introduced in FOS 5.2.0. Auditableevents using this feature are generated by the switch then sent to anexternal host through syslogd (the daemon that sends messages tothe syslog).Track Changes FeatureFrom a security perspective, it may also be important to keep a recordof specific changes that cannot be considered switch events but thatcan provide useful information, such as unsuccessful login attempts.The track changes feature introduced in FOS 4.0.0 tracks thesechanges and logs them into the syslog. The following list identifies thechanges tracked by this feature:• Successful login• Unsuccessful login• Logout• Configuration file change from task• Track changes on• Track changes offFabric-Based EncryptionEncryption ensures confidentiality of data, whether it is at rest or inflight. Encryption of data-at-rest in an FOS environment can be performedat the fabric level using the <strong>Brocade</strong> Encryption Solution. Thissolution is discussed in greater detail in “Chapter 11: <strong>Brocade</strong> DataEncryption Products” starting on page 173.Encrypting data-in-flight can be used to secure communicationsbetween two data centers connected through an FCIP tunnel, for example.This solution could be implemented in an FOS environment usingthe <strong>Brocade</strong> 7800 or FX8-24, also discussed at length in Chapter 11.FIPS ModeAs discussed in “Chapter 9: Compliance and Storage” starting onpage 155, FIPS 140-2 is a standard that was established to simplifythe procurement of security products by providing a simple method toensure that products meet certain security requirement levels. <strong>Brocade</strong>switches by default are not compliant with the FIPS standard, butthey can be placed into FIPS mode to immediately enhance the securitylevel of the switch. FIPS mode has been available since FOS 6.0.0.Securing Fibre Channel Fabrics 149

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!