12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 6: FC Security Best PracticesAs a best practice, assign only one host, or initiator, per zone. Singleinitiatorzoning (SIZ) serves two basic purposes. A SIZ restricts host-tohostcommunications and limits RSCNs to the zones requiring theinformation.HBA Best Practices Summary• Use single-initiator zones• Use secure management protocols when accessing the storagedevice management interface• For the most sensitive environments, use DH-CHAP to authenticatestorage devices joining a fabricProtecting the Storage DevicesDisk storage devices actually store the data, which is the most valuableasset in a SAN environment, and thus requires the most rigoroussecurity considerations.Storage device security features can include the following:• LUN masking is usually implemented at the storage device levelusing vendor-provided tools available through either a CLI or GUI.• DH-CHAP support, as defined in the ANSI T11 FC-SP standard, isused to authenticate a storage device joining a fabric. This is usuallydone to protect against WWN spoofing attacks.• Secure management interfaces and supported protocols such asSSH to secure the CLI interface and SSL to secure the GUIinterface.As a best practice, LUN masking should always be used to contain thevisibility of a LUN to a specific host and to prevent other hosts fromseeing LUNs not assigned to them. LUN masking combined withswitch-based zoning offers the best protection to a LUN within a fabric.Furthermore, it is advisable to create separate zones between the HBAand the disk or tape storage. Separating the disk and tape storage preventsRSCNs destined for disk devices from being propagated to tapedevices, which are more prone to disruption resulting from an RSCN.94 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!