12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 6: FC Security Best PracticesSAN AvailabilitySAN availability is an important consideration when designing a SANsecurity program to protect against a targeted denial-of-service attack,natural disaster, hardware failure, or human error.The key to maintaining high availability is to eliminate or reduce thenumber of single points of failure (SPOF). SPOFs can be found throughoutthe FC fabric, including:• Hardware devices• Paths between devices• Data centersSwitch hardware availability. The hardware itself may have redundantcomponents such as power supplies and fan modules. Some of thesecomponents may be “hot swappable” to allow replacement of fieldreplaceable units (FRUs) in the field without bringing down the switch.Another solution for hardware redundancy is to use enterprise-classdirectors instead of switches. Directors offer greater hardware redundancyand overall robustness for maximum production uptime. The<strong>Brocade</strong> 48000 Director or <strong>Brocade</strong> DCX or DCX-4S Backbone, forexample, can offer “six nines” (99.9999%) availability or better.One of the simplest and best ways to eliminate a hardware SPOF isthrough the use of redundant dual--fabric architectures. In a dual-fabricdesign any single hardware component could fail without undueimpact on the production environment (see “Dual Fabrics” onpage 35). All hardware is duplicated in this architecture and there aretwo or more paths between any host and its associated storage. Ofcourse, a dual-fabric architecture applies only to disk-based SANs,since backup applications cannot handle dual-attached tape devices.One common availability error observed in many data centers usingdual-fabric architectures is to co-locate both fabric A and fabric B inthe same physical rack or cabinet in the computer room. Often this isthe result of a procurement issue when the switches are initially purchasedalong with one single rack. Once a fabric has been racked andinstalled, it most likely wil never move again. Realistically, this shouldbe planned before installing the FC equipment and a technologyrefresh or move to a new data center provides an excellent opportunityto fully separate the fabrics right from the start.104 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!