12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 6: FC Security Best PracticesSecond, HBA drivers can have difficulty discovering an entire SAN. TheDefault Zoning feature ensures that devices not already assigned to anactive zone will be assigned to the Default Zone and will not be seen byother devices when an administrator disables a zoning configuration.RSCNs are required for a SAN to function properly, but RSCNs can bepotentially disruptive if not managed properly by the SAN switch. <strong>Brocade</strong>switches forward RSCNs only to zones with devices affected bythe addition or removal of a device. Also, <strong>Brocade</strong> switches forward onlyone RSCN if identical RSCNs occur within a half-second window, anapproach that limits the impact of a device sending hundreds or thousandsof RSCNs per second. Furthermore, organizations can entirelysuppress RSCNs on specific ports. Some applications, particularly inthe video imaging and multimedia industries and tape backups, actuallyrequire this capability.Finally, it is possible for a switch to obtain a new domain ID after areboot, particularly when a switch is added to a new fabric or after amassive power failure. To prevent this from occurring, it is a best practiceto assign a domain ID to a switch using an insistent domain ID(IDID). An IDID will survive reboots or power failures and will neverchange once assigned. Table9 explains the domain ID behavior ininsistent and non-insistent domain IDs.Table 1. Domain ID behaviorDID Assigned? Non-Insistent Domain ID Insistent Domain IDDID not in use DID is assigned DID is assignedDID already assigned New DID is assigned Switch won't join fabricVirtual Fabrics and Administrative Domains. Virtual Fabrics (VF)allows a physical switch to be partitioned into multiple LogicalSwitches, each with its own unique fabric ID (FID). Logical Switchescan be connected to physical or Logical Switches, similar to a physicalswitch using ISLs, to form Logical Fabrics. This feature is very usefulfor multi-tenant environments and for environments that can benefitfrom a logical separation of data and management on a commonphysical fabric.The Administrative Domain (AD) feature was introduced in <strong>Brocade</strong>FOS 5.2.0 and provides another method of partitioning a fabric intoseparately managed domains. An AD is a logical grouping of devicesthat can be managed separately either by the same or different sys-100 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!