FC SAN VM Migration Automation via WWGN Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for configuring fibre channel (FC) storage area networks (SANs) are inefficient and inflexible during virtual machine (VM) migration, requiring manual re-configuration of zones and updates to storage devices, which hampers migration efficiency and flexibility.
Innovation Solution
A method where a first server sends a login request message to a switch with a VM's identifier and world-wide group name (WWGN), enabling the switch to establish a correspondence between the identifier and WWGN, and the storage device to configure accordingly, allowing the VM to access storage without re-configuring zones or updating LUN correspondences during migration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual configuration of zones and LUN correspondences is performed for each VM migration, then storage access security is maintained, but migration efficiency deteriorates
Solution Approach 1:
The system enables self-service automation where the management server automatically discovers VM migration events, retrieves updated WWPN information, and reconfigures zone and LUN correspondences without manual intervention. The storage device and switch autonomously receive and process configuration updates, eliminating the need for administrators to manually reconfigure each migration while maintaining security through automated validation of WWPN-LUN bindings.
Solution Approach 2:
The system implements feedback mechanisms where the management server continuously monitors VM migration status, receives notifications of WWPN changes from the switch, and automatically triggers reconfiguration of zone and LUN correspondences. This closed-loop feedback ensures that storage access security is maintained by dynamically updating configurations in response to migration events, while eliminating manual intervention overhead.
2Reliability
If manual re-configuration is performed for each VM migration, then correct storage access is ensured, but operation complexity increases
Solution Approach 1:
The management server and storage system autonomously handle the complexity of zone and LUN reconfiguration by automatically discovering VM migration events, retrieving correct WWPN information from the switch, and updating configurations without administrator intervention. This self-service approach ensures storage access correctness through automated validation while dramatically simplifying operations by eliminating manual reconfiguration tasks.
Solution Approach 2:
The system performs preliminary actions by pre-establishing the automated configuration workflow before migrations occur. The management server is pre-configured to monitor migration events, and the system pre-defines the reconfiguration logic for zones and LUN correspondences. When migrations occur, these pre-prepared automation mechanisms immediately execute, ensuring correct storage access without requiring administrators to understand or perform complex configuration procedures.
3Reliability
If traditional zone technology and LUN masking are used with server granularity, then security isolation is achieved, but adaptability to virtualization scenarios deteriorates
Solution Approach 1:
The system segments the security isolation mechanism from the server level to the VM level by introducing WWPN-based identification and binding. Each VM receives a unique WWPN that can be independently bound to specific LUNs through automated zone configuration. This segmentation enables fine-grained security isolation at the VM level while maintaining the overall security architecture, allowing different VMs on the same server to have different storage access permissions.
Solution Approach 2:
The system enhances universality by making the zone and LUN masking mechanisms adaptable to both traditional server-level and modern virtualization scenarios. The automated management server can handle multiple WWPNs per server and dynamically reconfigure zones and LUN correspondences based on VM migration events. This multi-functionality allows the same security infrastructure to serve both physical server access and virtualized VM access with appropriate granularity control.
Data Source
Figure 1~3
Figure 4
Figure 5
AI summary
Embodiments of the present invention provide a method for configuring an FC SAN, and an apparatus, where the method includes: sending, by a first server, a login request message to a switch, where the login request message includes a first identifier of the first VM and a WWGN of a port group of the first VM, an N_port used on any server by the first VM belongs to the port group of the first VM, and the login request message enables the switch to establish a correspondence between the first identifier and the WWGN, and enables a storage device to establish the correspondence between the first identifier and the WWGN. A configuration of a first zone configured in the switch and a correspondence, configured in the storage device, of an LUN are both based on the WWGN; therefore, in a migration process of the first VM, a network administrator does not need to re-configure a zone, and the storage device does not need to re-configure a correspondence between the first VM and an accessible LUN either, so that migration efficiency and flexibility of the VM are improved.