Setup Guide

HBA, authentication enabled Authorization negotiation - accept
DH-CHAP
Success - F_Port
Failure - disable
Authorization negotiation - accept
DH-CHAP
Success - F_Port
Failure - disable
Authorization negotiation - reject
F_Port without authentication
HBA, authentication disabled No negotiation
No light
No negotiation
F_Port without authentication
No negotiation
F_Port without authentication
Supported Fabric OS commands
The following Fabric OS commands for authentication policy apply to AG mode:
authutil --policy
authutil --show
authutil --set
secauthsecret --set
secauthsecret --show
NOTE
Although authutil --authinit is not supported in AG mode, it is supported in Native mode.
For more information, refer to the
Fabric OS Command Reference
.
Limitations and considerations
Be aware of the following limitations and considerations when configuring authentication policy on an AG device:
Authentication policy is not supported on cascaded AG device configurations.
Authentication is not supported between an AG device running Fabric OS 7.1.0 (or subsequent release) and a fabric switch
running a version prior to Fabric OS 7.1.0. If the AG device is connected to a fabric switch running a version prior to Fabric OS
7.1.0, the AG device N_Ports will be disabled if authentication is enabled on both switches. Devices mapped to N_Ports
connected to fabric switches running any version prior to Fabric OS 7.1.0 will also be disabled.
If authentication is disabled on the fabric switch, the AG device N_Port will come online without authentication policy.
Device and switch policies must be disabled on the AG device before converting it to Native mode.
Device and switch policies must be disabled on the fabric switch in Native mode before converting it to AG mode.
Authentication policy is disabled by default on all ports in AG mode.
High availability (HA) reboots are supported.
AG mode without all Ports on Demand licenses
Prior to Fabric OS 7.3.0, the Brocade non-embedded switches (Brocade 300, 5100, 6505, and 6510) require all Ports on Demand
(PoD) licenses to run in Access Gateway mode. However, starting with Ports on Demand (PoD) release 7.3.0, all PoD licenses are not
required to run these switches in AG mode.
Consider the following points while running the switches in AG mode without Ports on Demand (PoD) licenses:
Access Gateway Basic Concepts
Brocade Fabric OS Access GatewayAdministration Guide
20 53-1004110-01