HP StorageWorks 8/20q Fibre Channel Switch Command Line Interface Guide 83
7 Connection Security Configuration
The 8/20q Fibre Channel Switch supports secure connections with Telnet and switch management
applications. The Secure Shell protocol (SSH) secures Telnet connections to the switch. The Secure Sockets
Layer (SSL) protocol secures switch connections to the following management applications:
• Simple SAN Connection Manager
• QuickTools
• Enterprise Fabric Management Suite
• Storage Management Initiative-Specification (SMI-S)
Managing SSL and SSH services
Consider the following when enabling SSH and SSL services:
• Simple SAN Connection Manager version 1.0 does not support the SSL service. If SSL is enabled, you
will be unable to manage the switch using this version of Simple SAN Connection Manager.
• To establish a secure Telnet connection, your workstation must use an SSH client.
• To enable secure SSL connections, you must first synchronize the date and time on the switch and
workstation. See ”Managing the date and time” (page 47).
• The SSL service must be enabled to authenticate users through a Remote Authentication Dial-In Service
(RADIUS) server. See ”Configuring a RADIUS server on the switch” (page 86).
• To disable SSL when using a user authentication RADIUS server, the RADIUS server authentication order
must be local.
• Enabling SSL automatically creates a security certificate on the switch.
To manage both SSH and SSL services, enter the set setup services command, as shown in the
following example:
8/20q FC Switch #> admin start
8/20q FC Switch (admin) #> set setup services
A list of attributes with formatting and current values will follow.
Enter a new value or simply press the ENTER key to accept the current value.
If you wish to terminate this process before reaching the end of the list
press 'q' or 'Q' and the ENTER key to do so.
PLEASE NOTE:
-----------
* Further configuration may be required after enabling a service.
* If services are disabled, the connection to the switch may be lost.
* When enabling SSL, please verify that the date/time settings
on this switch and the workstation from where the SSL connection
will be started match, and then a new certificate may need to be
created to ensure a secure connection to this switch.
TelnetEnabled (True / False) [True ]
SSHEnabled (True / False) [False] True
GUIMgmtEnabled (True / False) [True ]
SSLEnabled (True / False) [False] True
EmbeddedGUIEnabled (True / False) [True ]
SNMPEnabled (True / False) [True ]
NTPEnabled (True / False) [False]
CIMEnabled (True / False) [False]
FTPEnabled (True / False) [True ]
MgmtServerEnabled (True / False) [True ]
Do you want to save and activate this services setup? (y/n): [n] y