Brocade Fabric OS Message Reference - Supporting Fabric OS v7.0.1 (53-1002448-01, March 2012)

620 Fabric OS Message Reference
53-1002448-01
SEC-1188
94
SEC-1188
Message <timestamp>, [SEC-1188], <sequence-number>,, INFO, <system-name>, Security
violation: Unauthorized device <device node name> tries to FLOGI to index/area
<port number> of switch <switch WWN>.
Probable Cause Indicates a device connection control (DCC) security violation was reported. The specified device
attempted to login using fabric login (FLOGI) to an unauthorized port. The DCC policy correlates
specific devices to specific port locations. If the device changes connected port, the device will not
be allowed to login.
Recommended
Action
Check the DCC policy and verify the specified device is allowed in the fabric and is included in the
DCC policy. If the specified device is not included in the policy, add it to the policy. If the host is not
allowed access to the fabric, this is a valid violation message and an unauthorized entity is trying to
access your fabric. Take appropriate action, as defined by your enterprise security policy.
Severity INFO
SEC-1189
Message <timestamp>, [SEC-1189], <sequence-number>,, INFO, <system-name>, Security
violation: Unauthorized host with IP address
<IP address> tries to do SNMP write
operation.
Probable Cause Indicates an SNMP security violation was reported. The specified unauthorized host attempted to
perform a write SNMP operation.
Recommended
Action
Check the WSNMP policy and verify which hosts are allowed access to the fabric through SNMP. If
the host is allowed access to the fabric but is not included in the policy, add the host to the policy. If
the host is not allowed access to the fabric, this is a valid violation message and an unauthorized
entity is trying to access your fabric. Take appropriate action, as defined by your enterprise security
policy.
Severity INFO
SEC-1190
Message <timestamp>, [SEC-1190], <sequence-number>,, INFO, <system-name>, Security
violation: Unauthorized host with IP address <IP address> tries to do SNMP read
operation.
Probable Cause Indicates an SNMP security violation was reported. The specified unauthorized host attempted to
perform a read SNMP operation.
Recommended
Action
Check the RSNMP policy to verify the hosts allowed access to the fabric through SNMP read
operations are included in the RSNMP policy. If the host is allowed access but is not included in the
RSNMP policy, add the host to the policy. If the host is not allowed access to the fabric, this is a
valid violation message and an unauthorized entity is trying to access your fabric. Take appropriate
action, as defined by your enterprise security policy.
Severity INFO