12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 8: Securing FOS-Based FabricsThe following is an important distinction: placing a switch in FIPS modeis not the same as making the switch FIPS-compliant. Placing a switchin FIPS mode enhances the security level of the switch according tothe compliance requirements specified by FIPS 140-2 Level 2.Enabling FIPS mode is a disruptive action, since it requires a reboot ofthe switch to take effect.FIPS mode is enabled and configured using the fipsCfg command.CAUTION: FIPS mode is disruptive and may have unexpected implicationsif you are not familiar with this mode of operation. For example, ifyou lose the admin password on a switch running in FIPS mode, therewill be no way to regain management control of that switch. FIPS modeshould be used only if there is a mandatory operational requirement todo so. Again, operating a switch in FIP mode does not imply that theswitch is FIPS 140-2 compliant.When a <strong>Brocade</strong> switch is in FIPS mode, the following occur:• Root account disabled• Telnet disabled, only SSH can be used• HTTP disabled, only HTTPS can be used• RPC disabled, only secure RPC can be used• Only TLS-AES128 cipher suite used with secure RPC• SNMP read-only operations exclusively, SNMP write operationsdisabled• DH-CHAP/FCAP hashing performed only using SHA-256• Mandatory firmware signature validation• SCP used exclusively (no FTP) for configUpload, configDownload,supportSave, and firmwareDownload commands• IPSec usage of AES-XCBC, MD5, and DH group 1 blocked• RADIUS uses only PEAP or MSCHAPv2, CHAP and PAP disallowed• Only the following encryption algorithms functional: HMAC-SHA1,3DES-CBC, AES128-CBC, AES192-CBC, and AES256-CBCStarting in FOS 6.2.0, the following steps are required to prepare aswitch to run in FIPS mode:1. (Optional) Configure RADIUS or LDAP server.2. (Optional) Configure authentication protocols.150 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!