Data Center Fabric Manager Professional Plus User Manual - Supporting DCFM 10.3.x (53-1001356-01, October 2009)

DCFM Professional Plus User Manual 505
53-1001356-01
Chapter
17
Zoning
In this chapter
Zoning overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 505
Zoning configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 509
LSAN zoning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 529
Traffic isolation zoning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 533
Zoning administration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 539
Zoning overview
Zoning defines the communication paths in a fabric. A zone is a collection of initiator and target
ports within the SAN. The ports in a zone can only communicate with other ports in that zone.
However, ports can be members of more than one zone.
Zoning is a fabric management service that can be used to create logical subsets of devices within
a SAN and enable partitioning of resources for management and access control purposes. Zoning
allows only members of a zone to communicate within that zone. All others attempting to access
from outside the zone are rejected, hence zoning also provides a security function.
Zoning provides software zoning controlled at the Node World Wide Name (nWWN) level assisted by
the name server of a switch. Depending on the vendor, it also supports Domain/Port zoning and
Fabric Address zoning in a fabric without any router. Domain/Port zoning is not supported when the
fabric is in McDATA Open Mode (Interop Mode 3).
Special zones
Fabric OS has the following types of zones:
Zones
Enable you to partition your fabric into logical groups of devices that can access each other.
These are “regular” or “normal” zones. Unless otherwise specified, all references to zones in
this chapter refer to these regular zones.
Frame redirection zones
Re-route frames between an initiator and target through a Virtual Initiator and Virtual Target for
special processing or functionality, such as for storage virtualization or encryption. See
“Redirection zones” on page 449 for more information.
LSAN zones
Provide device connectivity between fabrics without merging the fabrics. See “LSAN zoning” on
page 529 for more information.