Home » Seguridad en una SAN Brocade I – Políticas SCC, DCC y AUTH

Seguridad en una SAN Brocade I – Políticas SCC, DCC y AUTH

En la administración de una red de fibra para almacenamiento más que medidas de seguridad de caracter preventivo son una práctica habitual el zoneado del switch ( o fabric) y el enmascaramiento de lunes (lun masking) desde la cabina en la provisión rutinaria de almacenamiento. Adiccionalmente, se puede añadir niveles de seguridad en la SAN con funcionalidades que proporcionan los fabricantes de switches de fibra. Ejemplos para tecnología Brocade son las políticas de control de las conexiones entre switches ( Switch Connection Control  – SCC)  y de control de dispositivos ( Device Connection Control – DCC). Lo que nos permiten hacer estas los políticas es restringir que switches y dispositivos se conectarán a la fabric.

SCC – Proteje las conexiónes inesperadas entre switches, se trata de verificar cada vez que se intenta realizar una conexión entre switches (ISL)  contra un listado de switches definido por la política.

DCC –   Proteje la conexiónes inesperadas entre dispositivos (HBAs de servidores, librerías, drives, VTLs, cabinas) con switches, se trata de verificar cada vez que se intenta realizar una conexión de un dispositivo de fibre  contra un listado de dispositivos definido por la política.

La aplicación de estas políticas pueden considerarse interesante en muchos casos, por ejemplo, si el parcheo de fibra y sus cambios es ajeno al personal de administración de la SAN, si se quiere minimizar el fallo humano, o evitar un intento de acceso no deseado de un equipo o un analizador de tráfico, …

La  SAN, al estar aislada sin acceso externo por otras redes es considerada segura, no necesitando medidas de protección especiales en apariencia. Pero si alguien consigue la contraseña de administración de alguno de los servidores conectado a la SAN, puede introducir driver de la HBAs modificados (o ni eso) para una  práctica de hack que es "wwn spoofing", es decir, modificar la HBA de un servidor con el wwn de otra que le permita tener acceso al recurso de almacenamiento  … y a sus datos. Recordemos que el sentido del hackering puede ser robar, corromper o destrozar el núcleo de información de la compañía. y … ¿ ésto lo evitaría DCC ? Si, ya que es una aplicación de "port locking" ( o "port binding") que es la asociación de un puerto a un wwn.

Para añadir un nivel mayor de seguridad se pueden usar protocolos de autenticación como DH-CHAP que pertenece a los protocolos FC-SP (Fibre Channel Security Protocols) definidos por la T11 y asegura mediante par de claves asociadas a wwn la negociación entre conexiones de forma segura. Aparte del "wwn spoofing" existen otras técnicas de hack en la fabric tales como "S_ID spoofing", " M-I-T-M attack" donde la aplicación de protocolos FC-SP  son eficaces para evitar cualquier riesgo de intrusión.

Para la tecnología Brocade está la política AUTH que implementa la autenticación entre switches y dispositivos a través de DH-CHAP / FCAP.

Otros puntos a revisar son las políticas de administración de contraseñas en los servidores de acceso a la SAN, en grandes compañías suelen haber muchos servidores que no son de produción con acceso a la SAN cuyas políticas de claves de administrador no suelen ser seguras y además son servidores que pueden estar fuera de las políticas restrictivas de la seguridad perimetral impuesta en el entorno de producción, y como podemos suponer ponen en grave compromiso el almacenamiento.
También es interesante para controlar este tipo de ataques la monitorización de las conexiones y desconexiones en la fabric, reinicios de servidores inesperados y wwn duplicados, además de tener procedimentados las acciones correspondientes para identificar lo más rápidamente la intrusión y aislarla. Hay muchos temas referentes a la seguridad como las virtual fabric, NPIV, interfaces de administración, políticas de distribución en la fabric,  que son muy interesantes su revisión. 

¿ Es vuestra SAN segura ? y … ¿ estás preparado para una intrusión?

734 Responses to “Seguridad en una SAN Brocade I – Políticas SCC, DCC y AUTH”

  1. Sports betting. Bonus to the first deposit up to 500 euros.
    Online Casino.
    online casino

  2. Hey there would you mind letting me know which webhost you’re working with? I’ve loaded your blog in 3 different internet browsers and I must say this blog loads a lot quicker then most. Can you suggest a good hosting provider at a fair price? Many thanks, I appreciate it!

  3. Why people still make use of to read news papers when in this technological world all is available on web?

  4. The other day, whille I was at work, my sister stole my
    apple ipad and testted to see if it ccan survive a thirty foot
    drop, just so she can be a youtube sensation. My iPad iss now destroyed
    andd she has 83 views. I know this is entirely off topic but I had
    to share itt with someone!

    Here is my webpage :: kiralık yazlık villa

  5. I like the helpful information you supply to your articles. I’ll bookmark your weblog and test again here frequently. I am quite certain I’ll be informed lots of new stuff right here! Good luck for the next!

  6. I’m curious to find out what blog platform you have been working with? I’m having some small security issues with my latest site and I’d like to find something more safe. Do you have any suggestions?

  7. Lan De Chair dice:

    Have you tried this hidden All-In-One toolbox that makes it fast & super easy to build an IMMEDIATELY profitable business online? this powerful All In One digital business can help you see sales in around 48 hours, in just a few clicks… It gets even better: You can accomplish all this Without Ever having to create Your Own Product, or Websites, and Even if if you don’t have a budget to invest​​.

    Go Here For Immediate Access: brilliantmoneyhacks.com

    Regards

  8. I’m really enjoying the design and layout of your website. It’s a very easy on the eyes which makes it much more pleasant for me to come here and visit more often. Did you hire out a designer to create your theme? Excellent work!

  9. Please let me know if you’re looking for a author for your site. You have some really great posts and I believe I would be a good asset. If you ever want to take some of the load off, I’d love to write some articles for your blog in exchange for a link back to mine. Please send me an e-mail if interested. Thank you!

  10. This post is actually a nice one it assists new the web
    viewers, who are wishing for blogging.

    Feel free to surf to my site :: Kiralık yazlıK Villa

  11. hello there and thank you for your information – I have certainly picked up anything new from right here. I did however expertise some technical points using this website, as I experienced to reload the site lots of times previous to I could get it to load properly. I had been wondering if your web hosting is OK? Not that I am complaining, but slow loading instances times will very frequently affect your placement in google and could damage your quality score if ads and marketing with Adwords. Anyway I am adding this RSS to my e-mail and can look out for much more of your respective fascinating content. Ensure that you update this again very soon..

  12. Thank you so much for providing individuals with such a nice chance to check tips from this site. It is often so beneficial and as well , packed with amusement for me and my office peers to search your blog particularly thrice weekly to study the latest issues you have got. And indeed, I’m so certainly pleased concerning the great inspiring ideas you give. Certain 3 tips in this article are absolutely the very best I have had.

  13. whoah this blog is great i love reading your posts. Keep up the good work! You know, lots of people are hunting around for this information, you could help them greatly.

  14. Hmm is anyone else having problems with the images on this blog loading? I’m trying to figure out if its a problem on my end or if it’s the blog. Any responses would be greatly appreciated.

  15. HIE lawyer dice:

    Hi would you mind letting me know which webhost you’re utilizing? I’ve loaded your blog in 3 different browsers and I must say this blog loads a lot faster then most. Can you suggest a good hosting provider at a reasonable price? Thanks a lot, I appreciate it!

  16. Needed to post you the very little remark so as to say thanks as before on the incredible ideas you’ve shown on this page. It has been so remarkably generous with you to offer without restraint what exactly a number of us would’ve offered as an e-book to generate some dough for their own end, most notably given that you might have tried it if you wanted. The solutions as well served to provide a great way to realize that someone else have a similar fervor just as my very own to figure out very much more with reference to this matter. I am sure there are numerous more pleasurable situations in the future for individuals who take a look at your blog.

  17. Does your site have a contact page? I’m having problems locating it but, I’d like to shoot you an e-mail. I’ve got some ideas for your blog you might be interested in hearing. Either way, great website and I look forward to seeing it improve over time.

  18. I intended to post you a little bit of remark to be able to say thank you once again for all the remarkable tactics you’ve discussed in this article. It has been quite incredibly generous with you to make extensively precisely what a lot of folks would’ve made available for an electronic book to end up making some cash for themselves, specifically considering the fact that you might have tried it in case you decided. These creative ideas likewise worked as a easy way to fully grasp most people have the identical passion much like mine to see much more when it comes to this issue. I am certain there are some more pleasant instances ahead for many who browse through your blog post.

  19. I think this is among the most significant information for me. And i’m glad reading your article. But want to remark on few general things, The web site style is great, the articles is really great : D. Good job, cheers

  20. very nice publish, i actually love this website, keep on it

  21. Really Appreciate this update, can I set it up so I receive an alert email when there is a fresh post?

  22. joker123 dice:

    Hi, i think that i saw you visited my weblog thus i came to “return the favor”.I am trying
    to find things to improve my web site!I suppose its ok to use some of your ideas!!

  23. I used to be suggested this website by way of my cousin. I am now not positive whether this submit is written via him as nobody else understand such exact about my trouble. You are incredible! Thank you!

  24. I love what you guys are usually up too. This sort of clever work and exposure! Keep up the fantastic works guys I’ve added you guys to my own blogroll.

  25. Excellent blog here! Additionally your site a lot up fast! What web host are you using? Can I am getting your associate link for your host? I want my website loaded up as fast as yours lol

  26. Admiring the hard work you put into your website and in depth information you present. It’s nice to come across a blog every once in a while that isn’t the same old rehashed information. Excellent read! I’ve saved your site and I’m including your RSS feeds to my Google account.

  27. Hello my friend! I want to say that this post is awesome, nice written and include almost all vital infos. I’d like to see more posts like this.

  28. hi!,I like your writing very much! share we communicate more about your article on AOL? I need a specialist on this area to solve my problem. May be that’s you! Looking forward to see you.

  29. Dolly Sparkman dice:

    want to test drive a smart traffic software to start your business?

    This new software makes it easy for you to completely automate your sales & marketing tasks, quickly and easily, and it works wonders. Try it here: thetrafficsoftware.com

    our business earned more than $410K in revenue in the last month ONLY.

    You can see the detailed case study on thetrafficsoftware.com

    Regards

    P.S.: You are seriously missing out right now by not using it…

  30. I precisely needed to thank you very much once more. I’m not certain the things that I could possibly have followed without the actual tips revealed by you over such question. Previously it was a very terrifying circumstance for me personally, but considering this professional tactic you dealt with it took me to weep with joy. I will be happy for this service and then pray you really know what a great job you are always getting into teaching others with the aid of a blog. I am sure you have never got to know any of us.

  31. Its like you read my mind! You seem to know a lot about this, like you wrote the book in it or something. I think that you can do with a few pics to drive the message home a bit, but instead of that, this is excellent blog. A great read. I’ll certainly be back.

  32. I love your blog.. very nice colors & theme.
    Did you design this website yourself or did you hire someone to do it for you?
    Plz reply as I’m looking to construct my own blog and
    would like to know where u got this from. thanks a lot

  33. Its like you read my mind! You seem to understand so much about this, like you wrote the e book in it or something. I feel that you just can do with some p.c. to power the message home a little bit, however other than that, that is magnificent blog. An excellent read. I will definitely be back.

  34. It’s a pity you don’t have a donate button! I’d certainly donate to this outstanding blog! I guess for now i’ll settle for book-marking and adding your RSS feed to my Google account. I look forward to fresh updates and will talk about this website with my Facebook group. Chat soon!

  35. I appreciate, cause I found exactly what I was looking for. You have ended my four day long hunt! God Bless you man. Have a nice day. Bye

  36. Greetings! I know this is kinda off topic however , I’d figured I’d ask. Would you be interested in exchanging links or maybe guest writing a blog post or vice-versa? My website goes over a lot of the same topics as yours and I feel we could greatly benefit from each other. If you might be interested feel free to shoot me an e-mail. I look forward to hearing from you! Excellent blog by the way!

  37. You made some decent points there. I looked on the internet for the issue and found most persons will consent with your blog.

  38. Hi my loved one! I want to say that this post is awesome, nice written and include almost all important infos. I’d like to look more posts like this .

  39. Thanks a bunch for sharing this with all of us you actually know what you’re talking about! Bookmarked. Please also visit my website =). We could have a link exchange arrangement between us!

  40. so you can be offered by them content others in your demo like.
    Firms like MindGeek that own woman movie and internet sites
    galleries are able to also make use of that information to information video
    generation. Cookie files likewise permits them to funnel
    content material that they think you specifically will love
    immediately toward you-even if in theory they don’t realize who you are, and know
    your IP target or browser data just.

  41. metrum.org (Metrology: The Forgotten Science) is typically the web page devoted to the memory of Livio Catullo Stecchini.

    The Persian Wars, The Origin of Money in Greece and some other
    historical events.

  42. I do believe all the ideas you have offered for your post. They’re really convincing and can definitely work. Nonetheless, the posts are too quick for beginners. May just you please lengthen them a bit from subsequent time? Thank you for the post.

  43. Very pleasant atmosphere and supportive staff. The office
    is helpful and resourceful.

  44. Hello my friend! I want to say that this post is awesome, nice written and include almost all vital infos. I would like to see more posts like this.

  45. Oh my goodness! a tremendous article dude. Thank you Nonetheless I am experiencing issue with ur rss . Don’t know why Unable to subscribe to it. Is there anyone getting equivalent rss problem? Anybody who is aware of kindly respond. Thnkx

  46. Hello! I just want to give an enormous thumbs up for the great information you’ve right here on this post. I will be coming back to your weblog for extra soon.

  47. Backup Power dice:

    Hi, Neat post. There is a problem with your website in internet explorer, would check this… IE still is the market leader and a large portion of people will miss your excellent writing because of this problem.

  48. I appreciate, result in I found just what I was having a look for.
    You have ended my four day lengthy hunt! God Bless you man. Have
    a great day. Bye

  49. Boca HickOry dice:

    It’s going to be finish of mine day, however before end I am reading this impressive piece of writing to increase my know-how.

  50. Backup Power dice:

    Amazing blog! Is your theme custom made or did you download it from somewhere? A theme like yours with a few simple tweeks would really make my blog jump out. Please let me know where you got your design. Many thanks

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *