beautypg.com

Dell POWEREDGE M1000E User Manual

Page 413

background image

Fabric OS Administrator’s Guide

413

53-1002745-02

Working with EX_Ports

14

This command is used to set up secret keys for the DH-CHAP authentication.
The minimum length of a secret key is 8 characters and maximum 40 characters.
Setting up secret keys does not initiate DH-CHAP authentication. If switch is
configured to do DH-CHAP, it is performed whenever a port or a switch is enabled.

Warning: Please use a secure channel for setting secrets. Using an insecure
channel is not safe and may compromise secrets.

Following inputs should be specified for each entry.

1. WWN for which secret is being set up.
2. Peer secret: The secret of the peer that authenticates to peer.
3. Local secret: The local secret that authenticates peer.

Press enter to start setting up secrets >

Enter peer WWN, Domain, or switch name (Leave blank when done):
10:00:00:05:33:13:70:3e
Enter peer secret:
Re-enter peer secret:
Enter local secret:
Re-enter local secret:
Enter peer WWN, Domain, or switch name (Leave blank when done):
Are you done? (yes, y, no, n): [no] y
Saving data to key store... Done.

myswitch:admin> secauthsecret --show
WWN

DId

Name

-----------------------------------------------
10:00:00:05:33:13:70:3e

8

sw0

Example Enabling encryption on port 1 of ‘myswitch’

There are two things to notice here— the first is that the initial attempt fails because the port is
currently enabled. The second is that the output from the second attempt shows encryption to be
enabled on the port, as shown by the portCfgShow command.

myswitch:admin> portcfgencrypt --enable 1
Please disable port to configure Encryption/Compression.
myswitch:admin> portdisable 1
myswitch:admin> portcfgencrypt --enable 1
myswitch:admin> portenable 1
myswitch:admin> portcfgshow 1
Area Number:

1

Octet Speed Combo:

1(16G|8G|4G|2G)

Speed Level:

AUTO(SW)

AL_PA Offset 13:

OFF

Trunk Port

OFF

Long Distance

OFF

VC Link Init

OFF

Locked L_Port

OFF

Locked G_Port

OFF

Disabled E_Port

OFF

Locked E_Port

OFF

ISL R_RDY Mode

OFF

RSCN Suppressed

OFF

Persistent Disable

OFF

LOS TOV enable

OFF

NPIV capability

ON