Thursday 1 September 2011

What is Fabric Security – Zoning ?


Zoning is a switch function that allows devices within the fabric to be logically segmented into groups that can communicate with each other. When a device logs into a fabric, it is registered by the name server. When a port logs into the fabric, it goes through a device discovery process with other devices registered as SCSI FCP in the name server. The zoning function controls this process by only letting ports in the same zone establish these link level services. A collection of zones is called a zone set. The zone set can be active or inactive. An active zone set is the collection of zones currently being used by the switched fabric to manage data traffic.

Single HBA zoning consists of a single HBA port and one or more storage ports. A port can reside in multiple zones. This provides the ability to map a single Storage port to multiple host ports. For example, a Symmetrix FA port or a CLARiiON SP port can be mapped to multiple single HBA zones. This allows multiple hosts to share a single storage port.

The type of zoning to be used depends on the type of devices in the zone and site policies :-

1) In port zoning, only the ports listed in the zone are allowed to send Fibre Channel frames to each other. The switch software examines each frame of data for the Domain ID of the switch, and the port number of the node, to ensure it is allowed to pass to another node connected to the switch. Moving a node that is zoned by a port zoning policy to a different switch port may effectively isolate it. On the other hand, if a node is inadvertently plugged into a port that is zoned by a port zoning policy, that port will gain access to the other ports in the zone.

2) WWN zoning creates zones by using the WWNs of the attached nodes (HBA and storage ports). WWN zoning provides the capability to restrict devices, as specified by their WWPNs, into zones. This is more flexible, as moving the device to another physical port with the fabric cannot cause it to lose access to other zone members.

2 comments:

  1. Hi There,
    Thank you for sharing knowledgeable blog with us i hope that you will post many more blog with us :
    The most comprehensive guide on choosing the best blogging platform we have the good detailed comparison guide on all major blogging sites in whole USA like as shutdown unix command, brocade zoning commands, types of zoning in san, cisco zoning commands, vmax3 provisioning steps, snapvx, san zoning, unix flavors, timefinder snapvx, san storage explained, storage provisioning steps, emc snapvx, san zoning, symsg commands, how to backup brocade switch config, snapvx step by step, vmax snapvx, san zoning steps, gatekeeper device, zoning explained, emc vmax3, vsan vs zoning, dell emc vmax3, difference between vmax and vmax3, thin provisioning explained, data sovereignty requirements.
    Click here for more information:- types of zoning in san

    ReplyDelete
  2. Hi There,
    Thank you so much for the post you do and also I like your post,we have a well-detailed comparison guide on all major blogging sites and the most comprehensive guide on choosing the best blogging platform, here you can see VMware vSAN 6.6 Technical Overview.
    Click here for Read more

    ReplyDelete