12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 6: FC Security Best PracticesAs mentioned previously, one of the most frequently observed oversightsin data centers is to physically install the switches in a dualfabricconfiguration in the same rack or cabinet. One particular customer'sdata center was located in a room on the floor underneath thecafeteria, and as Murphy’s law would have it, a water leak from the cafeteriamade its way into the computer room. Fortunately, this leak didnot damage the SAN equipment, but if it had, the entire SAN wouldhave failed, along with all of the application servers and storagedevices, resulting in a massive outage.Most of an organization's critical applications reside in the SAN and aloss of the SAN is disastrous. Simply installing fabric A equipment inone rack and fabric B equipment in another rack would address thisissue.In shared environments particularly, it is good practice to lock racks orcabinets containing switches and SAN equipment. In some sharedenvironments with isolated SANs, the entire SAN can be enclosedinside a locked wire cage structure to prevent unauthorized access.The final aspect of physical security considered during a SAN securityassessment are the environmental and utility factors.Power feeds and circuits should also be redundant to connect oneswitch power supply into one circuit and the other power supply into adifferent circuit. The equipment should be protected with an uninterruptablepower supply (UPS) system and the UPS system should betested and batteries replaced regularly.To protect against a loss of availability resulting from a power failure,data centers should also use power generators, exercised on a regularbasis to be certain they will function properly when a power failureoccurs. Contracts should be in place with a service level agreement(SLA), guaranteeing a pre-determined response time from identifieddiesel fuel providers in the event of a power failure. A massive powergrid failure similar to the one experienced in northeastern US and Canadaon August 13, 2003, could result in hundreds or thousands ofdata centers within a large area scrambling for available diesel fuel torefuel their power generators.The equipment in a computer room not only consumes enormousquantities of power but generates so much heat that a complete failureof the cooling system could result in a shutdown of the entirecomputer room within a few hours. It is important to ensure there isproper cooling in all areas of the computer room and to eliminate anyhot spots in an aisle or other area.114 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!