DCFM Enterprise User Manual (53-1001775-01, June 2010)

DCFM Enterprise User Manual 603
53-1001775-01
Chapter
22
Zoning
In this chapter
Zoning overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 603
Zoning configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 607
LSAN zoning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 628
Traffic isolation zoning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 632
Zoning administration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 638
Zoning overview
Zoning defines the communication paths in a fabric. A zone is a collection of initiator and target
ports within the SAN. The ports in a zone can only communicate with other ports in that zone.
However, ports can be members of more than one zone.
Zoning is a fabric management service that can be used to create logical subsets of devices within
a SAN and enable partitioning of resources for management and access control purposes. Zoning
allows only members of a zone to communicate within that zone. All others attempting to access
from outside the zone are rejected, hence zoning also provides a security function.
Zoning provides software zoning controlled at the Node World Wide Name (nWWN) level assisted by
the name server of a switch. Depending on the vendor and interoperability mode, it also supports
Domain/Port zoning. Domain/Port zoning is not supported when the fabric is in McDATA Open
Mode (InteropMode 3).
Types of zones
Fabric OS has the following types of zones:
Regular zones
Enable you to partition your fabric into logical groups of devices that can access each other.
These are “regular” or “normal” zones. Unless otherwise specified, all references to zones in
this chapter refer to these regular zones.
Frame redirection zones
Re-route frames between an initiator and target through a Virtual Initiator and Virtual Target for
special processing or functionality, such as for storage virtualization or encryption. See
“Redirection zones” on page 572 for more information.
LSAN zones
Provide device connectivity between fabrics without merging the fabrics. See “LSAN zoning” on
page 628 for more information.