12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

FC-Specific Security<strong>Brocade</strong>-supported SLAP (Switch Link Authentication Protocol) isbased on digital certificates in SFOS. Today, SLAP is no longer supportedon FC switches. FCAP (Fibre Channel Authentication Protocol),based on digital certificates, and DH-CHAP, based on exchange ofshared secrets, are the principle authentication protocols used in FC.DH-CHAP is more frequently used, since it is part of the FC-SP standardand does not require obtaining third-party digital certificates.<strong>Brocade</strong> introduced the AUTH policy in FOS 5.3.0 to allow SAN administratorsto enforce device authentication. The AUTH policy can be setto either of the following:• OFF: No authentication required (default)• ON: Strict enforcement of authentication on devices joiningF_Ports• PASSIVE: Authentication is optional and only authenticatesdevices configured for and capable of authenticationThe ON mode of the AUTH policy was introduced recently in FOS 5.2.0.Prior to this, device authentication could not be configured to requireauthentication.Isolation and SeparationSome environments or devices require special protection from otherenvironments or devices. SAN administrators may want to prevent asensitive system from being accessed by the general production environment,for example. Perhaps a test environment needs to beisolated from the production environment, to prevent changes in thetest environment from affecting the production systems. Environmentsand devices can be separated from each other in an FOS environmenteither physically or logically as follows:• Physically• Physically isolate critical or sensitive systems where appropriateusing separate fabrics• FC routing can provide isolation and controlled sharing• Logically• Zoning (hardware-enforced pWWN)• Virtual Fabrics/Administrative Domains• Traffic isolation zonesSecuring Fibre Channel Fabrics 145

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!