iSCSI Ether Zoning via VLAN and ACL Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The iSCSI protocol lacks effective zoning capabilities in Ethernet fabrics, which compromises security and efficiency, especially in enterprise-level data center configurations, where complete zoning solutions are absent.
Innovation Solution
The introduction of 'Ether Zoning' enables zoning at the frame level by configuring VLANs and ACLs between iSCSI initiators and targets, using in-band commands and automated zone group creation, allowing for secure and efficient segregation of devices within the Ethernet fabric.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If iSCSI protocol is used in Ethernet fabric without zoning, then ease of operation is improved, but security is compromised
Solution Approach 1:
The patent implements frame-level zoning by segmenting the Ethernet fabric into distinct zones using VLANs and ACLs. Each zone isolates specific iSCSI initiators and targets, allowing security policies to be applied at the frame level rather than requiring complete protocol redesign. This segmentation enables security enforcement while preserving iSCSI operation.
Solution Approach 2:
The patent introduces an intermediary zoning mechanism between iSCSI initiators and targets at the Ethernet switch level. This intermediary layer uses VLANs and ACLs to control frame forwarding decisions, acting as a mediator that enforces security policies without requiring changes to the iSCSI protocol itself or significant infrastructure modifications.
2Reliability
If frame-level zoning is implemented in iSCSI fabric, then security is improved, but device complexity increases
Solution Approach 1:
The patent leverages existing multi-functional capabilities of Ethernet switches by utilizing their built-in VLAN and ACL features for iSCSI zoning. Rather than introducing dedicated zoning hardware or protocol modifications, the solution repurposes universal Ethernet switching functions to provide frame-level security, thereby avoiding additional device complexity.
Solution Approach 2:
The patent enables the existing Ethernet infrastructure to serve the zoning function through self-configuration using standard VLAN and ACL mechanisms. The Ethernet switches use their own native security features to enforce iSCSI zoning policies, allowing the system to self-manage security without requiring external specialized devices or complex additional infrastructure.
3Reliability
If complete zoning solution is implemented, then security is improved, but infrastructure changes are required
Solution Approach 1:
The patent introduces an intermediary zoning mechanism between iSCSI initiators and targets at the Ethernet switch level. This intermediary layer uses VLANs and ACLs to control frame forwarding decisions, acting as a mediator that enforces security policies without requiring changes to the iSCSI protocol itself or significant infrastructure modifications.
Solution Approach 2:
The patent implements zoning by changing parameters of existing Ethernet frames (VLAN tags, ACL rules) rather than requiring fundamental infrastructure changes. By modifying frame-level parameters and utilizing existing switch configurations, the solution achieves complete zoning functionality while minimizing changes to the overall infrastructure.
Data Source
AI summary
Example implementations relate to hard zoning capabilities for devices using Internet small computer system interface (iSCSI) protocol. For example, a method includes creating a virtual local area network (VLAN) at an Ethernet switch between an initiator and target adapter. The method includes assigning an access control list (ACL) to the VLAN, The method includes segregating a device of a plurality of devices connected to the SAN into a zone group. The method also includes controlling access of a zone group based on the ACL and frame filtering.


