07-11-2017 11:56 PM
I have to implement a secure authentication (FC-SP, with DH-Chap) between fc switch and hbas. The hbas are from Emulex and Qlogic. Do anyone now, how I can do this?
Thanks and kind regards
07-12-2017 12:19 AM
did you take a look in Admin Guide ?
here is a chapterfor Autonthication Policy and how to configure DH-Chap
07-13-2017 12:17 AM
thank you for your quick answer. The authentication between the swichtes is not the problem, this is implemented now. But how can I do the authentication between the host hbas (vSphere and Windows Server) and the switches. I do not find any information how to configure the hbas for this feature. Yes, Emulex and Qlogic are supporting this feature, but there are no infos, how I can do that.
08-21-2017 05:54 AM
per the below you need to set the device policy to passive:
For the Qlogic BR (former brocade you can use the GUI (HCM)) the following CLI to setup security (AdminGuide_BRSeriesAdapters)
Issue the following QLogic BCU CLI commands to view or configure security
authentication for the ports:
bcu auth - -algo <port_id> <md|sha1|ms|sm>
bcu auth - -policy <port_id> <on|off>
bcu auth - -secret <port_id> <secret string>
bcu auth - -show <port_id>
bcu auth - -stats <port_id>
bcu auth - -statsclr <port_id>
Now, for example, took a look at emulex LPE12000 and from the following (Emulex Drivers for Windows for LightPulse Adapters User Guide ) it looks like the authentication needs to be enabled in the drivers.
EnableAUTH enables fabric authentication. This parameter requires the authentication to be supported by the fabric. Authentication is enabled if this value is set to 1.
More configuration options in the Emulex One Command Manager CLI at (Emulex OneCommand Manager Command Line Interface for LightPulse Adapters User Guide )
These commands configure a DHCHAP connection between an FC port and a switch port. Authentication commands apply
only to LPe12000-series adapters.
I have provided some example on the HBA configurations, further depends on HBA, OS and drivers versions.