Cisco Nexus 5000 Series Switch CLI Software Configuration Guide (OL-16597-01, July 2009)
Example:
switch# show fcsp dhchap database
DHCHAP Local Password:
Non-device specific password:*******
Other Devices' Passwords:
Password for device with WWN:20:00:00:05:30:00:38:5e is *******
Step 7
Display the DHCHAP configuration in the Fibre Channel interface.
Example:
switch# show fcsp interface fc2/4
fc2/4
fcsp authentication mode:SEC_MODE_ON
Status:Successfully authenticated
Step 8
Repeat these steps on the connecting MDS 9509 switch.
Example:
MDS-9509# show wwn switch
Switch WWN is 20:00:00:05:30:00:38:5e
MDS-9509(config)# fcsp enable
MDS-9509(config)# fcsp dhchap password rtp9509
MDS-9509(config)# fcsp dhchap devicename 20:00:00:05:30:00:54:de password rtp9216
MDS-9509(config)# interface fc 4/5
MDS-9509(config-if)# fcsp on
MDS-9509# show fcsp dhchap database
DHCHAP Local Password:
Non-device specific password:*******
Other Devices' Passwords:
Password for device with WWN:20:00:00:05:30:00:54:de is *******
MDS-9509# show fcsp interface fc2/4
Fc2/4
fcsp authentication mode:SEC_MODE_ON
Status:Successfully authenticated
You have now enabled and configured DHCHAP authentication for the sample setup in shown in the figure
above.
Default Fabric Security Settings
The following table lists the default settings for all fabric security features in any switch.
Table 90: Default Fabric Security Settings
DefaultParameters
DisabledDHCHAP feature
A priority list of MD5 followed by SHA-1 for
DHCHAP authentication
DHCHAP hash algorithm
Auto-passiveDHCHAP authentication mode
0, 4, 1, 2, and 3, respectivelyDHCHAP group default priority exchange order
30 secondsDHCHAP timeout value
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
634 OL-16597-01
Configuring FC-SP and DHCHAP
Default Fabric Security Settings