Data Center Fabric Manager Enterprise User Manual v10.3.X (53-1001357-01, November 2009)

DCFM Enterprise User Manual 545
53-1001357-01
Chapter
18
Zoning
In this chapter
Zoning overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 545
Zoning configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 549
LSAN zoning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 569
Traffic isolation zoning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 573
Zoning administration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 579
Zoning overview
Zoning defines the communication paths in a fabric. A zone is a collection of initiator and target
ports within the SAN. The ports in a zone can only communicate with other ports in that zone.
However, ports can be members of more than one zone.
Zoning is a fabric management service that can be used to create logical subsets of devices within
a SAN and enable partitioning of resources for management and access control purposes. Zoning
allows only members of a zone to communicate within that zone. All others attempting to access
from outside the zone are rejected, hence zoning also provides a security function.
Zoning provides software zoning controlled at the Node World Wide Name (nWWN) level assisted by
the name server of a switch. Depending on the vendor, it also supports Domain/Port zoning and
Fabric Address zoning in a fabric without any router. Domain/Port zoning is not supported when the
fabric is in McDATA Open Mode (Interop Mode 3).
Special zones
Fabric OS has the following types of zones:
Zones
Enable you to partition your fabric into logical groups of devices that can access each other.
These are “regular” or “normal” zones. Unless otherwise specified, all references to zones in
this chapter refer to these regular zones.
Frame redirection zones
Re-route frames between an initiator and target through a Virtual Initiator and Virtual Target for
special processing or functionality, such as for storage virtualization or encryption. See
“Redirection zones” on page 489 for more information.
LSAN zones
Provide device connectivity between fabrics without merging the fabrics. See “LSAN zoning” on
page 569 for more information.