HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.X Procedures User Guide (AA- - Page 181

Zoning enforcement, Software-enforced zoning

Page 181 highlights

Zoning enforcement Software-enforced and hardware-enforced zoning are supported. Software-enforced zoning Zoning enables users to restrict access to devices in a fabric. Software-enforced zoning prevents hosts from discovering unauthorized target devices, while hardware-enforced zoning prevents a host from accessing a device it is not authorized to access. Software-enforced zoning: • Is also called soft zoning, Name Server zoning, fabric-based zoning, session-based zoning, or hardware-assisted zoning. • Is available on 1-Gbit/sec, 2-Gbit/sec, and 4-Gbit/sec platforms. • Prevents hosts from discovering unauthorized target devices. • Ensures that the Name Server does not return any information to an unauthorized initiator in response to a Name Server query. • Is always active whenever a zone configuration is in effect. • Does not prohibit access to the device. If an initiator has knowledge of the network address of a target device, it does not need to query the Name Server to access it, which could lead to undesired access to a target device by unauthorized hosts. • Is exclusively enforced through selective information presented to end nodes through the fabric SNS. When an initiator queries the Name Server for accessible devices in the fabric, the Name Server returns only those devices that are in the same zone as the initiator. Devices that are not part of the zone are not returned as accessible devices. Hardware-enforced zoning Hardware-enforced zoning is specified without using the mixed-zoning scheme (mixed zones contain domains, ports and WWNs as zone members). HP StorageWorks switches augment software-enforced zoning with hardware enforcement. The exact methodology varies on different switch models. Hardware-enforced zoning (also called hard zoning): • Prevents a host from accessing a device it is not authorized to access. • Checks each frame before it is delivered to a zone member and discards it if there is a zone mismatch. When hardware-enforced zoning is active, the switch monitors the communications and blocks any frames that do not comply with the effective zone configuration. The switch performs this blocking at the transmit side of the port on which the destination device is located. • Is enforced at the ASIC level. Each ASIC maintains a list of source port IDs that have permission to access any of the ports on that ASIC. Fabric OS uses hardware-enforced zoning (on a per-zone basis) whenever the fabric membership or zone configuration changes. Table 35 shows the various HP StorageWorks switch models, the hardware zoning methodology for each, and tips for best usage. Fabric OS 5.x administrator guide 181

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS 5.x administrator guide
181
Zoning enforcement
Software-enforced and hardware-enforced zoning are supported.
Software-enforced zoning
Zoning enables users to restrict access to devices in a fabric. Software-enforced zoning prevents hosts
from discovering unauthorized target devices, while hardware-enforced zoning prevents a host from
accessing a device it is not authorized to access.
Software-enforced zoning:
Is also called
soft zoning
,
Name Server zoning
,
fabric-based zoning
,
session-based zoning,
or
hardware-assisted zoning
.
Is available on 1-Gbit/sec, 2-Gbit/sec, and 4-Gbit/sec platforms.
Prevents hosts from discovering unauthorized target devices.
Ensures that the Name Server does not return any information to an unauthorized initiator in response
to a Name Server query.
Is always active whenever a zone configuration is in effect.
Does not prohibit access to the device. If an initiator has knowledge of the network address of a target
device, it does not need to query the Name Server to access it, which could lead to undesired access
to a target device by unauthorized hosts.
Is exclusively enforced through selective information presented to end nodes through the fabric SNS.
When an initiator queries the Name Server for accessible devices in the fabric, the Name Server
returns only those devices that are in the same zone as the initiator. Devices that are not part of the
zone are not returned as accessible devices.
Hardware-enforced zoning
Hardware-enforced zoning is specified without using the mixed-zoning scheme (mixed zones contain
domains, ports and WWNs as zone members). HP StorageWorks switches augment software-enforced
zoning with hardware enforcement. The exact methodology varies on different switch models.
Hardware-enforced zoning (also called
hard zoning
):
Prevents a host from accessing a device it is not authorized to access.
Checks each frame before it is delivered to a zone member and discards it if there is a zone
mismatch. When hardware-enforced zoning is active, the switch monitors the communications and
blocks any frames that do not comply with the effective zone configuration. The switch performs this
blocking at the transmit side of the port on which the destination device is located.
Is enforced at the ASIC level. Each ASIC maintains a list of source port IDs that have permission to
access any of the ports on that ASIC.
Fabric OS uses hardware-enforced zoning (on a per-zone basis) whenever the fabric membership or zone
configuration changes.
Table 35
shows the various HP StorageWorks switch models, the hardware zoning methodology for each,
and tips for best usage.