12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 6: FC Security Best Practicesencryption software. Of course, any software-based implementationwould negatively impact performance. Performance-sensitive and mission-criticalapplications may not be well-suited to this type ofencryption. Furthermore, the cost of implementing application-basedencryption can be quite expensive, as it requires modifying productioncode. Although this may be justified for some applications, it is noteasily scalable to other multiple applications across a typical productionenvironment.Some backup applications offer an encryption module to encrypt thedata to the backup media. The encryption module is built into thebackup application software, but this method utilizes processingcycles on the backup server resulting in a negative performanceimpact, which increases the backup window.There are also specialized applications designed to encrypt data-atrestto disk or tape media. Several vendors such as RSA and PGP offersuch solutions. Again, the main issue with software-based solutions isperformance degradation and the impact on production server andapplication performance.Appliance-Based EncryptionAppliance-based encryption solutions do not become a part of the fabricand must be inserted in the data path between the host and the storageto encrypt the data. The process of inserting the appliance in the datapath may cause a disruption of the production environment.Fabric-Based EncryptionFabric-based encryption is accomplished using switches with encryptionand compression capabilities. These switches can be added to anexisting fabric using standard ISLs and assigned a domain ID, as withany other FC switch. One of the main advantages of the <strong>Brocade</strong> fabric-basedencryption solution over appliance-based solutions is theability to redirect or reroute frames from anywhere within the fabricthrough the encryption switch. <strong>Brocade</strong> FC switches use a technologyknown as frame or nameserver redirection, which was introduced inFabric OS 5.3. Frame redirection enables a transparent integration ofthe encryption solution into an existing fabric. Data can be writtenfrom servers to storage devices anywhere in the fabric without requiringdirect insertion of the switch into the data path.Another significant advantage of fabric-based encryption is the abilityto encrypt data in a heterogeneous environment. Some solutions, suchas the <strong>Brocade</strong> Encryption Solution, encrypt data directed to both tape112 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!