HP StorageWorks 64 FW 07.00.00/HAFM SW 08.06.00 McDATA Products in a SAN Envir - Page 225

SANtegrity Binding, Fabric binding, Switch binding

Page 225 highlights

Physical Planning Considerations 5 - Authorization errors. - Authentication errors. - Management application user connections. Use of the SANtegrity Authentication feature in conjunction with other security provisions must be carefully planned and coordinated. For additional information, refer to Security Best Practices. Obtain planning assistance from McDATA's professional services organization before implementing the feature. SANtegrity Binding Enterprise Fabric Mode SANtegrity Binding is a feature that enhances data security in large and complex SANs comprised of numerous fabrics and devices provided by multiple OEMs, SANs that intermix FCP and FICON protocols, and FICON-cascaded high-integrity SANs. The feature allows or prohibits director or switch attachment to fabrics (fabric binding) and Fibre Channel device attachment to directors or switches (switch binding). The SANtegrity Binding feature includes: • Fabric binding - Using fabric binding, administrators allow only specified directors or fabric switches to attach to specified fabrics in a SAN. This provides security from accidental fabric merges or disruption, particularly in environments that use patch panels for centralizing fibers and physical connections. This feature is enabled through the SAN management application. • Switch binding - Using switch binding, administrators allow only specified devices and fabric elements to connect to specified director or fabric switch ports. This provides security in environments that include a large number of devices by ensuring only the intended set of devices attach to a director or switch. This feature is enabled through the Element Manager application. Although Enterprise Fabric Mode is not a keyed feature, it is integral to SANtegrity Binding operation. Enterprise Fabric Mode must be enabled through the SAN management application before fabric binding and switch binding can operate. Enterprise Fabric Mode also enables the following parameters: Physical Planning Considerations 5-19

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322

5
Physical Planning Considerations
5-19
Physical Planning Considerations
Authorization errors.
Authentication errors.
Management application user connections.
Use of the SANtegrity Authentication feature in conjunction with
other security provisions must be carefully planned and coordinated.
For additional information, refer to
Security Best Practices
. Obtain
planning assistance from McDATA’s professional services
organization before implementing the feature.
SANtegrity Binding
SANtegrity Binding is a feature that enhances data security in large
and complex SANs comprised of numerous fabrics and devices
provided by multiple OEMs, SANs that intermix FCP and FICON
protocols, and FICON-cascaded high-integrity SANs. The feature
allows or prohibits director or switch attachment to fabrics (fabric
binding) and Fibre Channel device attachment to directors or
switches (switch binding). The SANtegrity Binding feature includes:
Fabric binding -
Using fabric binding, administrators allow only
specified directors or fabric switches to attach to specified fabrics
in a SAN. This provides security from accidental fabric merges or
disruption, particularly in environments that use patch panels for
centralizing fibers and physical connections. This feature is
enabled through the SAN management application.
Switch binding -
Using switch binding, administrators allow
only specified devices and fabric elements to connect to specified
director or fabric switch ports. This provides security in
environments that include a large number of devices by ensuring
only the intended set of devices attach to a director or switch. This
feature is enabled through the
Element Manager application.
Enterprise Fabric
Mode
Although
Enterprise Fabric Mode
is not a keyed feature, it is integral to
SANtegrity Binding operation.
Enterprise Fabric Mode
must be
enabled through the SAN management application before fabric
binding and switch binding can operate.
Enterprise Fabric Mode
also
enables the following parameters: