Brocade Network Advisor SAN User Manual v11.1x (53-1002167-01, May 2011)

Brocade Network Advisor SAN User Manual 579
53-1002167-01
Chapter
19
Zoning
In this chapter
Zoning overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 579
Zone database size . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 583
Zoning configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 583
LSAN zoning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 602
Traffic isolation zoning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 606
Zoning administration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 612
Zoning overview
Zoning defines the communication paths in a fabric. A zone is a collection of initiator and target
ports within the SAN. The ports in a zone can only communicate with other ports in that zone.
However, ports can be members of more than one zone.
Zoning is a fabric management service that can be used to create logical subsets of devices within
a SAN and enable partitioning of resources for management and access control purposes. Zoning
allows only members of a zone to communicate within that zone. All others attempting to access
from outside the zone are rejected, hence zoning also provides a security function.
Zoning provides software zoning controlled at the Node World Wide Name (nWWN) level assisted by
the name server of a switch. Depending on the vendor and interoperability mode, it also supports
Domain/Port zoning. Domain/Port zoning is not supported when the fabric is in McDATA Open
Mode (InteropMode 3).
Types of zones
Fabric OS has the following types of zones:
Regular zones
Enable you to partition your fabric into logical groups of devices that can access each other.
These are “regular” or “normal” zones. Unless otherwise specified, all references to zones in
this chapter refer to these regular zones.
Frame redirection zones
Re-route frames between an initiator and target through a Virtual Initiator and Virtual Target for
special processing or functionality, such as for storage virtualization or encryption. See
“Redirection zones” on page 552 for more information.
LSAN zones
Provide device connectivity between fabrics without merging the fabrics. See “LSAN zoning” on
page 602 for more information.