12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 6: FC Security Best PracticesThe primary confidentiality issue with switch-to-switch communicationsis not over the ISLs used to connect switches in a data center,but between switches that connect two data centers over distance. Adark fiber strand that is owned or leased by the organization is used toconnect two data centers.Securing Dark FiberSecuring a dark fiber connection is similar to the techniques describedearlier. Intercepting communications on a dark fiber, as was discussedearlier, does not require expensive equipment or physically cutting thecable. To prevent an attacker tapping into the fiber, dark fiber cablescan be protected in pressurized tubes. Changes in gas pressure in thetube indicate physical tampering. However, this type of attack isextremely rare and this solution is usually implemented only in governmentalsecurity organizations and some financial institutions.With the latest Condor-3 ASIC, the <strong>Brocade</strong> 16 Gbps FC products arecapable of encrypting up to two ISLs per ASIC at full 16 Gbps line rate.Furthermore, the Condor-3 ASIC can also first compress data, thenencrypt if both features are required.Securing WAN ConnectionsSecuring a SAN connection across a TCP/IP transport requires extraconsideration, since IP is much easier to access than dark fiber. Protocolssuch as iSCSI and FCIP are based on TCP/IP, and security in thesetypes of networks should include standard security mechanisms normallyused with a conventional LAN. To maintain confidentiality ofdata-in-flight, encryption protocols such as IPSec are commonly usedto encrypt data travelling across TCP/IP networks. IPSec can use differentencryption algorithms to perform the actual encryption.Most FCIP solutions on the market offer high-performance, hardwarebasedencryption using IPSec, including the <strong>Brocade</strong> 7500 ExtensionSwitch and FR4-18i Extension Blade.Fabric-to-Storage EncryptionThere are no data-in-flight encryption solutions available today toencrypt the data between a fabric and a storage device other than aspecialized encryption appliance, which can be installed in the datapath. However, a data-at-rest encryption solution may accomplish thisby encrypting the data prior to sending it from the fabric to the storagedevice, thus ensuring data confidentiality.110 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!