Escolar Documentos
Profissional Documentos
Cultura Documentos
Module 8
Objectives
This module prepares students to:
Describe zoning concept advantages and
limitations
Define the different types of zoning for Brocade
switches
Configure a multiple zone fabric
Perform merging of two fabrics with zoning
configurations
Security Comparisons
Comparisons of different security models
Host Level
(OV-SAM Allocater)
Infrastructure level
(Switch zoning)
Advantages
Disadvantages
Zoning Example
The server in the red zone sees one loop of disks and one tape
The server in the blue zone sees two storage arrays
The server in the green zone sees one loop, one array, and one
tape
No server sees loop 2
Zoning
Components
Fabric
A Hierarchical Structure
Cfg_I
Fabric may have more than one Cfg
Only one Cfg can be active
Cfg is a container for zones
Zones may overlap
Zone is a container for members
Members may be Defined with
Aliases
Member can be
A fabric physical port number
A node or port WWN
An AL_PA
An Alias
Zone_ABC
Member#1
Member#2
Member#n
Zone_XYZ
Cfg _N
Zoning enforcement
mechanisms
Soft Zoning: Name-Server assisted
Name Server restricts visibility
Always available when zoning enabled
elies o `good itize s for se urit No WWN
probing)
No reduction in performance
Hard Zoning: Hardware enforced
Available when certain rule conditions are met
through hardware logic checking
Provides additional security in addition to Soft
zoning
I hi its illegal a ess fro ` ad itize s
2x00 zoning
Mechanisms
Granularity
(domain, port), WWNs, AL-PA (QuickLoop)
Security
Hardware enforcement is very secure
Probing possible when soft zoning
: f:
3x00 zoning
Mechanism
Port-level zoning is Hardware Enforced
WWN zoning is Hardware Enforced
Mixed zones, Fabric Assist zones and Quick Loop zones remain enforced
through Name Server (Soft zoning)
Granularity
Same as in v2.x
Security
Hardware enforced zoning is very secure
Probing is still possible for ports with no hardware enforcement
a; torage a
,
: : : f:
: : : : f:
; torage
: : : : f: ;
: f:
zo eCreate )o e
, ; WWN
Soft Porting
If a device is defined by port (D,P) in one zone and by WWN in another, the
hardware enforcement at the port will be turned OFF and the zoning control will
e o trolled Na e er er. This is alled soft porti g .
Example:
aliCreate Host a , ,
aliCreate torage a , ,
zo eCreate p)o e , Host a; torage a
zo eCreate p)o e , , ; ,
aliCreate Host a ,
: : : : : f:
aliCreate torage ,
: : : : : f:
zo eCreate p)o e , Host ; torage
zo eCreate p)o e ,
: : : : : f: ; : : : : : f:
Zoning Rules(3x00)
ERROR/WARNING CODES
Port Zoning
Orange Zone: Host
1,1;2,11;
O 2,11
1,1
1,8;
1,5;2,15;
1
11
1,4;2,14
8 Switch 1
1,8
Bridge
15 4
2,1
11
Switch 2
14
Green Zone:
2,1;1,11;
2,8;
2,5;1,15;
2,4; 1,14
Host
G 1,11
2,8
Bridge
5 15
14 4
DLT
DLT DLT
1,4
1,5
2,15
XP
2,14
HSG
1,14
2,4
HSG
2,5
1,15
XP
DLT
World-Wide
Name
Zoning
Green Zone:
Orange Zone:
Host O
O-L0/6;O-L0/7
O-DLTS;
O-XP1;O-XP2
O-FC1, O-FC2
B-L0/6
B-L0/7
1
8
B-DLTS
Bridge
Host
G
G-L0/6
G-L0/7
11
11
Switch 1
15 4
Switch 2
14
14 4
G-L0/6;G-L0/7
G-DLTS;
G-XP1; G-XP2
G-FC1; G-FC2
G-DLTS
Bridge
5 15
DLT
DLT DLT
B-FC1
B-XP1
B-XP2
B-FC2
HSG
XP
B-L0/6: 50:06:0b:00:00:e6:e8
G-FC1
G-FC2
HSG
G-XP1
G-XP2
XP
DLT
Zoning commands (1 of 4)
Zoning commands are issued from any switch in a
fabric (you must be logged-in to the admin
account) to manage zones, zone aliases, and zone
configurations.
This is also true when working from the zoning GUI.
Zoning
commands
(2
of
4)
Configuration commands allow you to manipulate fabric
configurations:
Zoning commands (3 of 4)
Zone commands allow you to manipulate zones.
Zoning
commands
(4
of
4)
Management commands allow you to manipulate
preexisting configurations.
cfgEnable Enables a zone configuration.
cfgDisable Disables a zone configuration (caution).
Note: You should disable the effective configuration by
enabling another configuration (for example, cfgEnable
e _ o figuratio .
cfgSave Saves all zoning information into flash memory.
(to all switches in the fabric)
cfgShow Shows all zoning information.
cfgClear Clears all zone configurations.
Must be followed by a cfgSave.
If it is your intention to get rid of all zoning fabric-wide, with
switch FW v2.6.0c, this command must be preceded by a
cfgDisable command.
Create
Configurations
aliCreate
zoneCreate
cfgCreate
Enabled
Configuration
cfgEngMkt
ZoneEng
ZoneMkt
SDRAM
Switch
Domain
1
Flash
Memory
cfgEngMkt
Brocade SilkWorm
Configuration
Definitions
cfgEngMkt
ZoneEng
ZoneMkt
Enabled
Configuration
cfgEngMkt
ZoneEng
ZoneMkt
SDRAM
Switch
Domain
1
Flash
Memory
Enabled
Configuration
cfgEngMkt
ZoneEng
ZoneMkt
SDRAM
Switch
Domain
1
Flash
Memory
Configuration
Definitions
cfgEngMkt
ZoneEng
ZoneMkt
SDRAM
Switch
Domain
1
Flash
Memory
Enabled
Configuration
cfgEngMkt
ZoneEng
ZoneMkt
SDRAM
Switch
Domain
1
Flash
Memory
Writes name
Only to
flash
Splitting fabric
If an ISL goes down, causing a fabric to split into two separate fabrics, then each
new fabric retains the same zone configuration
Fabric will re-merge when ISL is back up and no zone changes have been made
Zoning Example #1
ZoneG is enabled. Which devices can Host A see?
Which devices can Host B see?
Host A
0/2/0/0
0/4/0/0
Host B
0/2/0/0
0/4/0/0
Switch
6
15
3
8
Switch
7
15 0
DLT
DLT
FC10
XP
FC10
XP
Host A
Host B
3
7
Switch
6
15
Switch
7
15 0
DLT
DLT
FC10
XP
FC10
XP
Host A
Host B
3
7
Switch
6
15
Switch
7
15 0
DLT
DLT
FC10
XP
FC10
XP
Host A
Host B
3
7
Switch
6
15
Switch
7
15 0
DLT
DLT
FC10
XP
FC10
XP
Host A
Host B
3
7
Switch
6
15
Switch
7
15 0
DLT
DLT
FC10
XP
FC10
XP
Learning check
Lab title
Lab #