12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 11: <strong>Brocade</strong> Data Encryption Productsused for cross-site backups, where data stored at one site is backedup to a tape library located at another site. Figure 50 demonstrateshow the data-in-flight for a cross-site backup can be encrypted using adata-at-rest encryption solution.asSite ACiphertextSite B<strong>Brocade</strong>EncryptionSwitchEncryptedframe payloadServersTape libraryFigure 10. Encrypted cross-site backupSimilarly, this same strategy could be used for data replicationbetween two sites.Figure 51 illustrates how a data-at-rest encryption solution can be usedto encrypt data on the dark fiber during data replication. In this case, thedata stored on the primary data center is encrypted using the encryptiondevice. The disk-to-disk replication application (such as EMC SRDF orIBM PPRC) will simply copy the data which is already in ciphertext formatto the alternate site where it will be stored as is in ciphertext.The latest <strong>Brocade</strong> FC products are based on the 16 Gbps Condor-3ASIC. This new ASIC has built-in encryption and compression capabilitiesthat allow SAN administrators to configure up to two ISL ports (E_Ports)per ASIC for data-in-flight encryption. This feature may also be used toencrypt replicated disk data between two sites or for cross-site backupswhen both sites are connected via ISLs using dark fiber. A new 16 Gbpsswitch at one data center will encrypt outbound frames on the ISL andget decrypted at the other end by another 16 Gbps FC switch. The Condor-3ASIC is also capable of compressing data. As seen previously, it isnot possible to compress encrypted data, so the compression is the firstoperation to take place when used in conjunction with encryption.196 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!