.SAN design reference guide Vol. 1-5 785350-001
Table 36 Zoning enforcement for B-series Fibre Channel switches and MP Router LSANs
CommentsEnforcementConfigurationSwitches or routers
Hard zoning
Access authorization
at frame level in
hardware
Define zones using
domain number and
port number
Encryption SAN Switch
SN8000B 8-Slot SAN Backbone Director
SN8000B 4-Slot SAN Director
SN6000B 16Gb FC Switch
HP StoreFabric SN6500B 16Gb FC Switch
SN3000B 16Gb FC Switch
DC SAN Backbone Director
DC04 SAN Director
SAN Director 2/128, 4/256
SAN Switch 8/8, 8/24, 8/40, 8/80
EVA4400 Embedded Switch Module, 8 Gb Brocade
Brocade 16Gb SAN Switch for HP BladeSystem c-Class
Brocade 8Gb SAN Switch for HP BladeSystem c-Class
Brocade 4Gb SAN Switch for HP c-Class BladeSystem
SAN Switch 4/8, 4/16, 4/32B, 4/64
1606 Extension SAN Switch
DC Dir Switch MP Extension Blade
400 MP Router, MP Router Blade, MP Router
1
B-series FCoE CN switch
Define zones using
WWNs only
Soft zoning, Name
Servers discovery-based
authentication, and login
protection
Name Server
directory-based
authentication, login
authentication
Define zones using
combination of
domain/port numbers
and WWNs
1
400 MP Router, MP Router Blade, and MP Router LSAN zones support WWN-based zoning only.
Zoning guidelines for B-series Fibre Channel switches
To configure B-series Fibre Channel switch zoning, observe the following best practices:
• For 4 Gb/s and 2 Gb/s SAN fabric switches, avoid transitions to soft zoning in a
hardware-enforced zoning environment.
B-series Fibre Channel switches allow a maximum of 64 SID entries for each quad. If you
exceed this limit, the affected ports transition from hard to soft enforcement. Although the
switch logs display warning messages, data integrity is preserved during this transition.
• Maintain data access as defined in your SAN design, but avoid configuring hosts and targets
on the same quad.
• Configure each quad with members of the same zone. Avoid configuring members of different
zones on the same quad. For example, configure UNIX zone members on one quad and
Windows members on a different quad.
• Minimize zone entries by including only hosts and targets that communicate. For example,
rather than combine all hosts of the same OS type into one zone, make smaller zones with
only hosts and targets that need to communicate.
• Use the portzoneshow command to display and verify the zoning status of each port.
The portzoneshow command displays the status of each port:
◦ Hard—Hardware enforcement
◦ Soft—Name server and ASIC-assisted authentication
◦ All—No zoning enforcement
Zoning guidelines
The following messages indicate that a port has changed to soft zoning:
Fibre Channel switch fabric rules 121