# A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Dell EMC SmartFabric OS10 and SmartFabric Services Security Best Practices Guide December 2021

Summary

Secure your critical network infrastructure with this comprehensive guide tailored for SmartFabric OS10 and SFS deployments. Designed for network engineers and IT security professionals, this manual establishes definitive best practices for securing multi-layered fabric environments. It provides detailed guidance on topics including strong user credential management, advanced cryptography, network zoning, secure boot enablement, physical hardening, and robust auditing to ensure autonomous and resilient operations across your Dell EMC network architecture.

📄 Preview 📖 Table of Contents Contents PAGE OF 40

Page 1 Text Content

Dell EMC Smart Fabric OS10 and Smart Fabric Services Security Best Practices Guide December 2021

12 2021 Rev. A06

Page Summary Contents For Dell EMC SmartFabric OS10 and SmartFabric Services Security Best Practices Guide December 2021

Page 1 Dell EMC Smart Fabric OS10 and Smart Fabric Services Security Best Practices Guide December 2021 12 2021 Rev. A06
Page 2 Notes, cautions, and warnings NOTE: A NOTE indicates important information that helps you make better use of your product. CAUTION: A CAUTION indicates either potential damage to hardware or loss of d...
Page 3 Contents Chapter 1: Preface........................................................................................................................ Certified cryptographic modules........................
Page 4 Preface This document provides a set of recommendations for securing switches that run Dell EMC Smart Fabric OS10 including the Smart Fabric Services (SFS) mode. For detailed configuration, see the De...
Page 5 NOTE: If you plan to use FIPS, Dell Technologies recommends enabling FIPS as one of the first steps of configuring your new switch. OS10# crypto fips enable OS10# write memory Check if FIPS is enabled...
Page 6 the switch. If the commands that are entered by the user are configured in the remote server for that user, the remote server authorizes the usage of the command. By default, the role you configure wi...
Page 7 default—Record all user authentication and logins or all user-entered commands in OS10 sessions on remote connections; for example, Telnet and SSH. start-stop—Send a start notice when a process begins...
Page 8 router—Accesses router-bgp and router-ospf modes. line—Accesses line-vty mode. priv-lvl privilege-level—Enter the number of a privilege level, from 2 to 14. command-string—Enter the commands supported...
Page 9 Configure remote authentication This section describes how to configure remote authentication on the system. Configure RADIUS authentication Traditional RADIUS-based user authentication runs over UDP ...
Page 10 Configure the global timeout used to wait for an authentication response from TACACS+ servers. To avoid long waiting, configure a lower value. OS10(config)# tacacs-server timeout seconds OS10(config)#...
Page 11 User and credential management This section describes how to manage user accounts and credentials. Preloaded accounts The following accounts are initialized during the installation of Dell EMC Smart F...
Page 12 If you do not want your users to access the Linux shell, disable the linuxadmin account. OS10(config)# system-user linuxadmin disable OS10(config)# exit OS10# write memory Disable access to Linux comm...
Page 13 numeric number—(Optional) Sets the minimum number of numeric characters that are required, from 0 to 31; default 0. special-char number—(Optional) Sets the minimum number of special characters that ar...
Page 14 Table 3. Services supported (continued) Application Management VRF Default VRF Non-default VRF SSH server Yes Yes Yes Syslog Yes Yes Yes TACACS+ server Yes Yes Yes Telnet server Yes Yes Yes TFTP clien...
Page 15 Proxy ARP is a technique that network devices use to acquire the MAC address of a device which is not present in the network on behalf of other devices. Do S attacks are possible with misconfigured ne...
Page 16 Firewall settings This sections provides various configuration procedures to harden the switch. Access rules Configure secure access rules. Enable only SSH for remote system access By default, in OS10...
Page 17 max-retry number—(Optional) Sets the maximum number of consecutive failed login attempts for a user before the user is locked out, from 0 to 16. lockout-period minutes—(Optional) Sets the amount of ti...
Page 18 Data plane rules The data plane is part of the network that carries user traffic. Data plane rules include services and settings that affect user data. Apply these rules on border-filtering devices th...
Page 19 OS10(config-if-eth1/1/1)# switchport port-security OS10(config-if-port-sec)# no disable OS10(config-if-port-sec)# mac-learn limit 100 OS10(config-if-port-sec)# end OS10# write memory Configure MAC add...
Page 20 disabled on the system. Secure dynamic MAC address movement is allowed between port-security-enabled and port-security- disabled interfaces. Use the following command in INTERFACE PORT SECURITY mode: ...
Page 21 Sticky MAC Addresses : 10 Secure Dynamic MAC addresses : 0 Cryptography This section provides information about cryptography. X.509v3 certificates OS10 supports X.509v3 certificates to secure communic...
Page 22 altname altname—Enter an alternate name for the organization; for example, using the IP address such as altname IP:192.168.1.100. Copy CSR to the CA server. OS10# copy home://Dell Host.pem scp:///file...
Page 23 00:e7:81:4b:4a:12:8d:ce:88:e6:73:3f:da:19:03: c6:56:01:19:b2:02:61:3f:5b:1e:33:28:a1:ed:e3: 85:bc:56:fb:18:d5:16:2e:a0:e7:3a:f9:34:b4:df: 37:97:93:a9:b9:94:b2:9f:69:af:fa:31:77:68:06: 89:7b:6d:fc:91:1...
Page 24 2. Install a self-signed certificate and key file in EXEC mode. crypto cert install cert-file home://cert-filename key-file {key-path | private} [password passphrase] [fips] cert-file cert-path specif...
Page 25 X509v3 Subject Key Identifier: DA:39:A3:EE:5E:6B:4B:0D:32:55:BF:EF:95:60:18:90:AF:D8:07:09 X509v3 Subject Alternative Name: DNS:dell.domain.com Signature Algorithm: sha256With RSAEncryption b8:83:ae:3...
Page 26 | Downloaded CRLs | View revoked certificates The following displays a list of revoked certificates: OS10# show crypto crl COMODO_Certification_Authority.0.crl.pem Certificate Revocation List (CRL): V...
Page 27 (Optional) Enable CRL checking for certificates received from external devices in SECURITY-PROFILE mode. CRL checking verifies the validity of a certificate using the CRLs installed on the switch. OS1...
Page 28 When you configure the switch for X.509v3 SSH authentication and remote authentication of users using RADIUS or TACACS+, and when connecting using SSH, the following sequence occurs: 1. Insert a CAC o...
Page 29 6. The SSH client application sends an authentication request with the X.509v3 certificate. 7. The OS10 SSH server validates the public certificate, including validating the trust chain, valid date ra...
Page 30 Configure the user X.509v3 certificate details to allow the SSH server to match the user certificate to the account. username username certificate subject “x509v3-subject-string” or username username ...
Page 31 Version : 2.3 Local System MAC address : 20:04:0f:20:86:00 Role priority : 32768 VLT MAC address : 20:04:0f:21:9a:00 IP address : fda5:74c8:b79e:1::1 Delay-Restore timer : 90 seconds Peer-Routing : Di...
Page 32 5. Verify if the newly created certificates are present in the home directory. Switch-A: Switch-A# dir home Directory contents for folder: home Date (modified) Size (bytes) Name --------------------- ...
Page 33 Switch-A: Switch-A(config)# cluster security-profile DELL123 Switch-B: Switch-A(config)# cluster security-profile DELL123 13. (Only if you are running release 10.4.3.x) Create the store folder under t...
Page 34 1 20:04:0f:20:86:00 up fda5:74c8:b79e:1::1 2.3 Physical security This section provides information about physical security o the switch. Physical interfaces Disable unused interfaces To prevent unauth...
Page 35 For more information about configuring X.509v3 PKI certificates, see the Dell EMC Smart Fabric OS10 User Guide. Enable audit logging To monitor user activity and configuration changes on the switch, e...
Page 36 OS10(config)# snmp-server community public ro acl snmp-read-only-acl OS10(config)# exit OS10# write memory Configure SNMP v3 SNMP v2 does not support encryption or authentication. Dell EMC Networking ...
Page 37 localized—Generate an SNMPv3 authentication and/or privacy key in localized key format. Configure SNMP traps Use the following configuration to enable SNMP traps: Enable SNMP traps on the system. OS10...
Page 38 Check what SNMP rules are running OS10# show running-configuration snmp snmp-server community public ro acl snmp-read-only-acl Serviceability This section provides information about serviceability Dat...
Page 39 Protecting the startup configuration file saves a protected copy of the current startup config file internally. During switch boot up, the protected version of the startup configuration is loaded. Pro...
Page 40 Check if bootloader protection is enabled Use the following command to view the status of bootloader protection on the system: OS10# show boot protect Boot protection enabled Authorized users: root li...

Manual Details

Brand Best
Pages 40
File Size 327.08 KB
Published May 16, 2026
108 views

Enter the captcha to get the download link:

captcha

Frequently Asked Questions

What are required for upgrading an ES10 image?

Secure boot must be enabled, requiring the use of the image secure-install command to validate the SHA256, GPG, or PKI signature before installation.

How can I check if Secure Boot is active on the device?

Use the command 'OS10# show secure-boot status' to verify the secure boot and file integrity status.

What protocol should be used for setting system time zone?

To minimize cross-time zone troubleshooting issues, set the clock timezone to Coordinated Universal Time (UTC).

How can I prevent unauthorized access to the switch firmware?

Protect the bootloader using a GRUB password with the command 'OS10# boot protect enable username username password'.