McDATA Sphereon 4300 Specifications Page 234

  • Download
  • Add to my manuals
  • Print
  • Page
    / 318
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 233
5
5-30
McDATA Products in a SAN Environment - Planning Manual
Physical Planning Considerations
Each server HBA is explicitly bound to a storage volume or LUN,
and access is explicitly authorized (access is blocked by default).
The process is compatible with OSI standards. The following are
transparently supported:
Different operating systems and applications.
Different storage volume managers and file systems.
Different fabric devices, including disk drives, tape drives,
and tape libraries.
If the server is rebooted, the server-to-storage connection is
automatically re-established.
The connection is bound to a storage port WWN. If the fiber-optic
cable is disconnected from the storage port, the server-to-storage
connection is automatically re-established when the port cable is
reconnected. The connection is automatically re-established if the
storage port is cabled through a different director or switch port.
Access control can also be implemented at the storage device as an
addition or enhancement to redundant array of independent disks
(RAID) controller software. Data access is controlled within the
storage device, and server HBA access to each LUN is explicitly
limited (access is blocked by default). Storage-level access control:
Provides control at the storage port and LUN level and does not
require configuration at the server.
Supports a heterogeneous server environment and multiple
server paths to the storage device.
Is typically proprietary and protects only a specific vendor’s
storage devices. Storage-level access control may not be available
for many legacy devices.
Security Best
Practices
When implementing a enterprise data security policy, establish a set
of best practice conventions using methods described in this section
in the following order of precedence (most restrictive listed first):
1. SANtegrity Authentication - The SANtegrity Authentication
feature is recommended for high-security SANs to provide
user-configurable, software-enforced password protection and
encrypted authentication for the management server, directors,
and fabric switches. These features significantly restrict access to
Fibre Channel fabric elements.
Page view 233
1 2 ... 229 230 231 232 233 234 235 236 237 238 239 ... 317 318

Comments to this Manuals

No comments