12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Auditing and Assessing the SANAuditing and Assessing the SANNetwork security has become more public and is at the top of the prioritylist for many IT managers. Most companies perform securityaudits of their networks on a regular basis but SANs are often overlooked.It is important to audit the SAN as well to ensure the protectionof centralized data. SAN security audits should go beyond the technologicalcomponents and include a review of SAN security policies andphysical security.<strong>Brocade</strong> SAN Health Pro is a free SAN analysis tool that helps documentand analyze a SAN to document its topology and uncovermisconfigurations. For more information visit:http://www.brocade.com/services-support/drivers-downloads/sanhealth-diagnostics/index.page.Best Practices Summary for DMZ• Use a separate network, subnet, VLAN, or VPN for managementinterfaces• Use secure protocols to communicate using managementinterfaces and disable unused protocols• Use strong password management policies and implementRADIUS or LDAP• Persistently disable unused ports, disable E_port connectivityon all unused and node ports, and implement port ACLs• Use hardware-enforced pWWN zoning• Use LUN masking• For more sensitive environments, use DH-CHAP to authenticateservers• Perform a SAN security assessment to understand the currentstate of security of the SANSecuring Fibre Channel Fabrics 129

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!