HP StorageWorks Fabric OS 5.2.x administrator guide (5697-0014, November 2009)
Fabric OS 5.2.x administrator guide 77
Enabling and disabling local authentication as backup
It is useful to enable local authentication so that the switch can take over authentication locally if the
RADIUS servers fail to respond because of power outage or network problems. To enable or disable local
authentication, enter the appropriate command:
For details about this command and how it is different from aaaConfig –radiuslocal, see Table 12
on page 58.
When local authentication is enabled and RADIUS servers fail to respond, you can log in to the default
switch accounts (admin and user) or any user-defined account. You must know the passwords of these
accounts.
When the command succeeds, the event log indicates that local database authentication is disabled or
enabled.
Setting the boot PROM password
The boot PROM password provides an additional layer of security by protecting the boot PROM from
unauthorized use. Setting a recovery string for the boot PROM password enables you to recover a lost boot
PROM password by contacting your switch service provider. Without the recovery string, a lost boot PROM
password cannot be recovered.
You should set the boot PROM password and the recovery string on all switches, as described next. If your
site procedures dictate that you set the boot PROM password without the recovery string, see ”Without a
Recovery String” on page 114.
SSSetting the boot PROM password with a recovery String
To set the boot PROM password with a recovery string, refer to the section that applies to your switch
model.
NOTE: Setting the boot PROM password requires accessing the boot prompt, which stops traffic flow
through the switch until the switch is rebooted. You should perform this procedure during a planned down
time.
4/8 and 4/16 SAN Switch, SAN Switch 2/8V, SAN Switch 2/16V, SAN Switch 2/32, SAN
Switch 4/32, 4/64 SAN Switch, and 400 MP Router
How to set the boot PROM password for a switch with a recovery string
1. Connect to the serial port interface as described in ”How to connect via the serial port” on page 24.
2. Reboot the switch.
3. Press ESC within four seconds after the message “Press escape within 4 seconds...” displays.
The following options are available:
4. Enter 2.
If no password was previously set, the following message displays:
switch:admin> aaaConfig –radiuslocalbackup
Option Description
1 Start system. Continues the system boot process.
2 Recovery password. Lets you set the recovery string and the boot PROM
password.
3 Enter command shell. Provides access to boot parameters.
Recovery password is NOT set. Please set it now.