HBA and WWN

Source: Internet
Author: User

1. First introduce what is HBA.

The HBA mentioned here is the full name of fc hba, that is, the Fiber Channel Host Bus Adapter. In an FC network, a host, such as a server, needs to use an interface card to connect to an FC network or a FC storage device, such as a SAN, just as an Ethernet Card is required to connect to an Ethernet network. This type of interface card is called fc hba, or HBA for short.

Like the MAC address of the Ethernet Card, the HBA also has a unique identifier, which is the WWNWorld Wide Name ). There are two types of WWN on the HBA:

Node WWNWWNN): Each HBA has its own Node WWN.

Port WWNWWPN): Each port on the HBA has its unique Port WWN. Because the communication is implemented through port, in most cases, WWPN instead of WWNN is used.

WWN is 8 bytes in length, expressed in hexadecimal notation and separated by colons. Example: 50: 06: 04: 81: D6: F3: 45: 42


2. SAN data security methods

Two basic security mechanisms to ensure SAN data security are the partition system zoning and the Logical Unit value Logical Unit Number) mask.

Partitioning is a partitioning method. By using this method, certain storage resources are only visible to authorized users and departments. A partition can be composed of multiple servers, storage devices, subsystems, switches, hbas, and other computers. Only members in the same partition can communicate with each other.

Partition systems are usually implemented at the exchange level. There are two implementation modes: hard partition and soft partition. Hard partitioning refers to the partitioning policy based on the switching port. All communication attempts through an unauthorized port are forbidden. Since hard partitions are implemented in the system circuit and executed in the system route table, it is more secure than soft partitions.

In a fiber channel network, soft partitions are based on the wide area naming mechanism (WWN. WWN is the unique identifier assigned to optical fiber devices in the network. Since the software is used to ensure that the same WWNs does not appear in different partitions, the soft partition technology is more flexible than the hard partition technology, especially for applications with frequent changes in network configurations, this feature provides good manageability.

Some vswitches have the port binding function, so that network devices can only communicate with a predefined switch port. This technology can be used to restrict access to the storage pool, thus protecting the SAN from access by unauthorized users.

Another widely used technology is the LUN mask. A lun is the SCSI identifier of the logical unit in the target device, such as a tape or disk array. In the fiber channel field, LUN is implemented based on the system's WWN.

The lun mask technology is to assign the LUN to the host server. These servers can only see the Luns allocated to them. If many servers attempt to access specific devices, the network administrator can set a specific LUN or LUN group to Deny Access From other servers to protect data security. Not only on the host, but also on the HBA, storage controller, disk array, and switch can also implement various forms of LUN shielding technology.

If the partitioning and LUN technology can be used together with other security mechanisms on the network and its devices, it will be very effective for network security data security.


3. Can WWN be associated with a LUN?

Associating WWN with a logical unit serial number in a disk array is a method for implementing data security in SAN. Each HBA connected to a SAN on your server has a WWN.

In a disk array, you can allocate the WWN to a specific LUN so that only a specific HBA can access a specific LUN even if no partition is implemented in the SAN organization, this is usually called "LUN shielding ".


Oracle video tutorial follow: http://u.youku.com/user_video/id_UMzAzMjkxMjE2.html

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.