Q-Logic SANBOX2-16 Switch User Manual


 
3 – Planning
Device Access
3-10 59021-07 A
D
3.4.3
Virtual Private Fabric Hard Zones
Virtual Private Fabric (VPF) zoning divides the fabric for purposes of controlling
discovery and both inbound and outbound traffic. This type of zoning is useful for
providing security and reserving paths between devices to guarantee bandwidth.
VPF zoning is a type of hard zoning that is hardware enforced. Members can only
transmit to and receive from members of the same VPF zone. The VPF zone
boundary is secure against both inbound and outbound traffic. The following rules
apply to VPF zones:
VPF zones that include members from multiple switches must include the
ports of the inter-switch links.
VPF zones cannot overlap; that is, a port can be a member of only one VPF
zone.
VPF zone boundaries supersede both soft and ACL zone boundaries.
Membership can be defined only by domain ID and port ID.
VPF zoning supports all port modes.
Fabric Security
An effective security profile begins with a security policy that states the
requirements. A threat analysis is needed to define the plan of action followed by
an implementation that meets the security policy requirements. Internet portals,
such as remote access and email, usually present the greatest threats. Fabric
security should also be considered in defining the IT infrastructure security policy.
Most fabrics are located at a single site and are protected by physical security,
such as key-code locked computer rooms. For these cases, security methods
such as user passwords for equipment and zoning for controlling device access,
are satisfactory.
Fabric security is needed when security policy requirements are more demanding:
for example, when fabrics span multiple locations and traditional physical
protection is insufficient to protect the IT infrastructure. Another benefit of fabric
security is that it creates a structure that helps prevent unintended changes to the
fabric.
Fabric security consists of the following:
User account security
Device security
Fabric services