12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 8: Securing FOS-Based FabricsFC RoutingFibre Channel Routing (FCR) is a means of isolating two fabrics fromeach other, while allowing specific devices in separate fabrics to communicatewith each other according to a set of pre-defined rules. FCRcan be implemented in one of two ways in an FOS-based fabric:• <strong>Brocade</strong> 7800 Extension Switch or FX8-24 Extension Blade• Integrated Routing (IR) feature, available in FOS 6.2.0 and laterThe <strong>Brocade</strong> 7800 and FX8-24 are specialized routing hardware platforms;IR is a licensed feature available on standard Condor 2-basedproducts (“Condor 2" identifies the ASIC type), which include the <strong>Brocade</strong>DCX/DCX-4S Backbone and <strong>Brocade</strong> 5100/5300 Switch. Withthe IR feature, a specific port in a supported switch can be configuredto perform FC-FC routing.ZoningZoning provides a logical means to group devices together and to isolatethem from other devices. Zoning has been discussed at length in“Chapter 3: SAN Basics for Security Professionals” starting onpage 19, as well as “Chapter 6: FC Security Best Practices” starting onpage 91. This section discusses zoning in greater detail and how it isimplemented and managed in an FOS environment.As a best practice, it is preferable to implement zones on FOS-basedfabrics using the pWWN instead of the domain ID/port ID, since bothare hardware-enforced and the pWWN provides more flexibility from amanagement perspective. However, do not use a combination of thetwo (mixed zone) within the same zone, as this will result in zoneenforcement by the name server, which is less secure.A set of zones make up a zone configuration, and it is possible to havemore than one zone configuration in a fabric. For example, there couldbe one zone configuration for the day shift, during which most productiontakes place, and another for the night shift, during whichmaintenance and backups are usually performed. When a configurationis changed, the effective configuration is disabled and the newconfiguration is enabled and then becomes the effective configuration.During this transition period, particularly with large fabrics, thename server must indicate to all the servers that there is a change inthe devices with which they are allowed to communicate. During thistransition, when the effective configuration is temporarily disabled, itis possible for all servers in the fabric to see all devices, since no zoneconfiguration is effectively defined.146 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!