Send documentation comments to mdsfeedback-doc@cisco.com
45-3
Cisco MDS 9000 Family Fabric Manager Configuration Guide
OL-17256-03, Cisco MDS NX-OS Release 4.x
Chapter 45 Configuring FC-SP and DHCHAP
DHCHAP
Step 3 Configure the hash algorithm and DH group.
Step 4 Configure the DHCHAP password for the local switch and other switches in the fabric.
Step 5 Configure the DHCHAP timeout value for reauthentication.
Step 6 Verify the DHCHAP configuration.
This section includes the following topics:
• DHCHAP Compatibility with Existing Cisco MDS Features, page 45-3
• About Enabling DHCHAP, page 45-4
• Enabling DHCHAP, page 45-4
• About DHCHAP Authentication Modes, page 45-5
• Configuring the DHCHAP Mode, page 45-5
• About the DHCHAP Hash Algorithm, page 45-6
• Configuring the DHCHAP Hash Algorithm, page 45-6
• About the DHCHAP Group Settings, page 45-7
• Configuring the DHCHAP Group Settings, page 45-7
• About the DHCHAP Password, page 45-7
• Configuring DHCHAP Passwords for the Local Switch, page 45-8
• About Password Configuration for Remote Devices, page 45-8
• Configuring DHCHAP Passwords for Remote Devices, page 45-8
• About the DHCHAP Timeout Value, page 45-9
• Configuring the DHCHAP Timeout Value, page 45-9
• Configuring DHCHAP AAA Authentication, page 45-10
• Enabling FC-SP on ISLs, page 45-10
DHCHAP Compatibility with Existing Cisco MDS Features
This sections identifies the impact of configuring the DHCHAP feature along with existing Cisco MDS
features:
• PortChannel interfaces—If DHCHAP is enabled for ports belonging to a PortChannel, DHCHAP
authentication is performed at the physical interface level, not at the PortChannel level.
• FCIP interfaces—The DHCHAP protocol works with the FCIP interface just as it would with a
physical interface.
• Port security or fabric binding—Fabric binding policies are enforced based on identities
authenticated by DHCHAP.
• VSANs—DHCHAP authentication is not done on a per-VSAN basis.
• High availability—DHCHAP authentication works transparently with existing HA features.