[ Applies to ] StorageGuard / Broadcom Brocade FC switches / Storage Network
This article lists the recommended baseline checks for Broadcom Brocade FC switches. It is also applicable for Dell Connectrix, HPE Storage Networking, IBM Storage Networking and Lenovo ThinkSystem Fibre Channel Switches. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Broadcom Brocade Fibre Channel directors and switches (including OEM models) connect servers and storage in a Storage Area Network (SAN), running Brocade Fabric OS (FOS).
Why hardening Broadcom Brocade FC switches matters
The SAN fabric controls which hosts can reach which storage. Securing management access, authentication, zoning, fabric policies and port settings prevents unauthorized access to storage and disruption of the fabric.
Recommended baseline checks
The baseline below contains 155 checks, listed alphabetically.
| ID | Configuration check | Component |
|---|---|---|
| SG-M2054T031V01 | Access restriction by IP | Fabric OS |
| SG-C0393T031V01 | Account lockout threshold | Fabric OS |
| SG-M7278T031V01 | Active MAPS policy | Fabric OS |
| SG-M7096T031V01 | Allow username in passwords | Fabric OS |
| SG-M4115T031V01 | Approved AAA servers | Fabric OS |
| SG-C0163T031V01 | Approved AD domain | Fabric OS |
| SG-C0838T031V01 | Approved audit severity level | Fabric OS |
| SG-C0436T031V01 | Approved authentication (aaa) servers | Fabric OS |
| SG-C0449T031V01 | Approved DNS servers | Fabric OS |
| SG-C0435T031V01 | Approved LDAP servers | Fabric OS |
| SG-C0013T031V01 | Approved NTP servers | Fabric OS |
| SG-C0839T031V01 | Approved routing policy | Fabric OS |
| SG-C0492T031V01 | Approved rte external policy | Fabric OS |
| SG-C0841T031V01 | Approved syslog facility | Fabric OS |
| SG-C0015T031V01 | Approved Syslog servers | Fabric OS |
| SG-M5657T031V01 | Audit log content | Fabric OS |
| SG-C0001T031V01 | Audit logging status | Fabric OS |
| SG-M8760T031V01 | Authentication hash algorithm | Fabric OS |
| SG-C0479T031V01 | Authentication policy configuration | Fabric OS |
| SG-C0031T031V01 | Authentication server configuration | Fabric OS |
| SG-C0024T031V01 | Authentication server redundancy | Fabric OS |
| SG-C0480T031V01 | Buffer optimized mode status | Fabric OS |
| SG-C0029T031V01 | Centralized log server | Fabric OS |
| SG-C0233T031V01 | Centralized log server redundancy | Fabric OS |
| SG-M8783T031V01 | Certificate validation mode | Fabric OS |
| SG-M7556T031V01 | Cipher strength | Fabric OS |
| SG-C0381T031V01 | Cleartext HTTP IP Filter | Fabric OS |
| SG-M2950T031V01 | Correct timezone | Fabric OS |
| SG-C0487T031V01 | Credit recovery mode | Fabric OS |
| SG-C0080T031V01 | Data in-transit encryption | Fabric OS |
| SG-C0056T031V01 | Default passwords | Fabric OS |
| SG-M9131T031V01 | Default passwords (disabled account) | Fabric OS |
| SG-M7794T031V01 | Default users used | Fabric OS |
| SG-M3492T031V01 | Default zone | Fabric OS |
| SG-C0176T031V01 | Default zone policy | Fabric OS |
| SG-M2908T031V01 | Device Authentication Policy | Fabric OS |
| SG-C0489T031V01 | DLS and two-hop lossless | Fabric OS |
| SG-C0243T031V01 | DNS server configuration | Fabric OS |
| SG-C0060T031V01 | DNS server redundancy | Fabric OS |
| SG-M6522T031V01 | DNS service status | Fabric OS |
| SG-C0484T031V01 | Domain ID and insistent domain id status | Fabric OS |
| SG-F8147T031V01 | Domain Name Configuration | Fabric OS |
| SG-M6526T031V01 | Email notification | Fabric OS |
| SG-C0600T031V01 | End of support | Fabric OS |
| SG-C0600T032V01 | End of support | SANnav |
| SG-C0175T031V01 | Event types enabled for audit logging | Fabric OS |
| SG-C0162T031V01 | Expired SSL certificate | Fabric OS |
| SG-C0476T031V01 | Fabric naming convention | Fabric OS |
| SG-M3697T031V01 | Fabric wide consistency policy | Fabric OS |
| SG-C0183T031V01 | FC security policies | Fabric OS |
| SG-M4572T031V01 | FIPS mode | Fabric OS |
| SG-C0178T031V01 | FIPS verification | Fabric OS |
| SG-M9809T031V01 | Firmware integrity check | Fabric OS |
| SG-C0842T031V01 | FTP service status | Fabric OS |
| SG-M6272T031V01 | FTP status | Fabric OS |
| SG-C0600T031V02 | Future end of support | Fabric OS |
| SG-C0600T032V02 | Future end of support | SANnav |
| SG-M6343T031V01 | G_port locking status | Fabric OS |
| SG-C0814T031V01 | HA operational status | Fabric OS |
| SG-M4654T031V01 | HTTP service status | Fabric OS |
| SG-C0382T031V01 | HTTPS certificate | Fabric OS |
| SG-C0257T031V01 | HTTPS cipher strength | Fabric OS |
| SG-C0827T031V01 | HTTPS Status | Fabric OS |
| SG-C0209T031V01 | Idle session timeout | Fabric OS |
| SG-C0494T031V01 | Insistent domain ID mode | Fabric OS |
| SG-C0892T031V01 | IPFilter per-rule permit check | Fabric OS |
| SG-C0206T031V01 | IPFilter status | Fabric OS |
| SG-M7711T031V01 | Last password change | Fabric OS |
| SG-M1743T031V01 | LDAP mapping to role | Fabric OS |
| SG-M8639T031V01 | LDAP SSL | Fabric OS |
| SG-C0169T031V01 | Lockout enforcement for admin | Fabric OS |
| SG-C0427T031V01 | Login banner message | Fabric OS |
| SG-C0426T031V01 | Login banner status | Fabric OS |
| SG-C0268T031V01 | Maximum length of sequential character sequences | Fabric OS |
| SG-C0269T031V01 | Maximum number of repeated password characters | Fabric OS |
| SG-C0234T031V01 | Maximum password age | Fabric OS |
| SG-C0392T031V01 | Minimum account lockout duration | Fabric OS |
| SG-C0262T031V01 | Minimum password age | Fabric OS |
| SG-C0270T031V01 | Minimum password digits | Fabric OS |
| SG-C0264T031V01 | Minimum password length | Fabric OS |
| SG-C0271T031V01 | Minimum password lowercase characters | Fabric OS |
| SG-C0812T031V01 | Minimum password position changes | Fabric OS |
| SG-C0272T031V01 | Minimum password special characters | Fabric OS |
| SG-C0273T031V01 | Minimum password uppercase characters | Fabric OS |
| SG-F1577T031V01 | Non-default local admin | Fabric OS |
| SG-C0231T031V01 | Non-default local users | Fabric OS |
| SG-M1498T031V01 | NTP configuration | Fabric OS |
| SG-C0171T031V01 | NTP server configuration | Fabric OS |
| SG-C0432T031V01 | NTP server redundancy | Fabric OS |
| SG-M1373T031V01 | Number of disallowed past passwords | Fabric OS |
| SG-C0281T031V01 | Password expiration warning message | Fabric OS |
| SG-C0417T031V01 | Password hash strength | Fabric OS |
| SG-C0284T031V01 | Password history | Fabric OS |
| SG-C0284T031V02 | Password history - root user | Fabric OS |
| SG-C0276T031V01 | Password reverse check | Fabric OS |
| SG-M3916T031V01 | Past passwords check is enabled | Fabric OS |
| SG-C0142T031V01 | Persistent ports state | Fabric OS |
| SG-C0143T031V01 | Prevent ports from becoming E_Ports | Fabric OS |
| SG-C0319T031V01 | PWD policy status | Fabric OS |
| SG-M2529T031V01 | Remote support status | Fabric OS |
| SG-M3788T031V01 | Required AAA servers | Fabric OS |
| SG-C0440T031V01 | Required authentication (aaa) servers | Fabric OS |
| SG-C0450T031V01 | Required DNS servers | Fabric OS |
| SG-C0014T031V01 | Required NTP servers | Fabric OS |
| SG-F4081T031V01 | Required SAN zone member identification | Fabric OS |
| SG-C0016T031V01 | Required Syslog servers | Fabric OS |
| SG-M3069T031V01 | REST API status | Fabric OS |
| SG-M7296T031V01 | Root access | Fabric OS |
| SG-M9337T031V01 | Routing Table Entry policy | Fabric OS |
| SG-C0387T031V01 | SAN Fabric - Zone member identification | Fabric OS |
| SG-C0893T031V01 | Secondary authentication service configuration | Fabric OS |
| SG-M1205T031V01 | Secure upload/download | Fabric OS |
| SG-M2879T031V01 | Security monitoring rules | Fabric OS |
| SG-C0447T031V01 | Self-signed certificate | Fabric OS |
| SG-M3830T031V01 | Session timeout | Fabric OS |
| SG-M7288T031V01 | Single HBA zoning | Fabric OS |
| SG-M4589T031V01 | SNMP Access Control List | Fabric OS |
| SG-C0058T031V01 | SNMP community default string | Fabric OS |
| SG-C0491T031V01 | SNMP MIB configuration | Fabric OS |
| SG-C0403T031V01 | SNMP minimum storage alerts level | Fabric OS |
| SG-C0345T031V01 | SNMP request access control list | Fabric OS |
| SG-M8223T031V01 | SNMP security level | Fabric OS |
| SG-C0155T031V01 | SNMP service disabled | Fabric OS |
| SG-M3352T031V01 | SNMP user authentication | Fabric OS |
| SG-C0840T031V01 | SNMP v3 informs state | Fabric OS |
| SG-C0123T031V01 | SNMP versions enabled | Fabric OS |
| SG-C0422T031V01 | SNMPv3 privacy encryption algorithm | Fabric OS |
| SG-C0419T031V01 | SNMPv3 user authentication protocol | Fabric OS |
| SG-C0346T031V01 | SNMPv3 user security | Fabric OS |
| SG-C0258T031V01 | SSH cipher strength | Fabric OS |
| SG-M4676T031V01 | SSH KEX strength | Fabric OS |
| SG-M5931T031V01 | SSH MAC strength | Fabric OS |
| SG-C0890T031V01 | SSH session idle timeout | Fabric OS |
| SG-C0822T031V01 | SSH Status | Fabric OS |
| SG-M5624T031V01 | Switch authentication policy | Fabric OS |
| SG-C0493T031V01 | System timezone | Fabric OS |
| SG-M4735T031V01 | Tape and disk separate zones | Fabric OS |
| SG-M1713T031V01 | Target Fabric OS (FOS) release | Fabric OS |
| SG-C0019T031V01 | Target OS version | Fabric OS |
| SG-M2199T031V01 | TCP timestamps | Fabric OS |
| SG-C0385T031V01 | Telnet service status | Fabric OS |
| SG-C0390T031V01 | TLS level | Fabric OS |
| SG-M3867T031V01 | TLS security level | Fabric OS |
| SG-C0448T031V01 | Trusted certificate-authority (CA) | Fabric OS |
| SG-C0116T031V01 | Unapproved admin users | Fabric OS |
| SG-C0119T031V01 | Unapproved user groups | Fabric OS |
| SG-F6785T031V01 | Unused active ports disabled | Fabric OS |
| SG-M5029T031V01 | Unused port status | Fabric OS |
| SG-M4314T031V01 | Unused ports not disabled (persistently) | Fabric OS |
| SG-C0213T031V01 | Use of secure LDAP | Fabric OS |
| SG-C0341T031V01 | User role configuration | Fabric OS |
| SG-C0837T031V01 | Username not allowed in password | Fabric OS |
| SG-C0342T031V01 | Users are not assigned with roles | Fabric OS |
| SG-C0485T031V01 | Virtual fabrics | Fabric OS |
| SG-M3789T031V01 | Zone member identification type | Fabric OS |
Related components
A complete baseline also covers the components that manage, connect to or protect Broadcom Brocade FC switches. Review the configuration of:
- Brocade SANnav
- Brocade Network Advisor (legacy)
- Management workstations and automation
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.