Home » Seguridad en una SAN Brocade I – Políticas SCC, DCC y AUTH

Seguridad en una SAN Brocade I – Políticas SCC, DCC y AUTH

En la administración de una red de fibra para almacenamiento más que medidas de seguridad de caracter preventivo son una práctica habitual el zoneado del switch ( o fabric) y el enmascaramiento de lunes (lun masking) desde la cabina en la provisión rutinaria de almacenamiento. Adiccionalmente, se puede añadir niveles de seguridad en la SAN con funcionalidades que proporcionan los fabricantes de switches de fibra. Ejemplos para tecnología Brocade son las políticas de control de las conexiones entre switches ( Switch Connection Control  – SCC)  y de control de dispositivos ( Device Connection Control – DCC). Lo que nos permiten hacer estas los políticas es restringir que switches y dispositivos se conectarán a la fabric.

SCC – Proteje las conexiónes inesperadas entre switches, se trata de verificar cada vez que se intenta realizar una conexión entre switches (ISL)  contra un listado de switches definido por la política.

DCC –   Proteje la conexiónes inesperadas entre dispositivos (HBAs de servidores, librerías, drives, VTLs, cabinas) con switches, se trata de verificar cada vez que se intenta realizar una conexión de un dispositivo de fibre  contra un listado de dispositivos definido por la política.

La aplicación de estas políticas pueden considerarse interesante en muchos casos, por ejemplo, si el parcheo de fibra y sus cambios es ajeno al personal de administración de la SAN, si se quiere minimizar el fallo humano, o evitar un intento de acceso no deseado de un equipo o un analizador de tráfico, …

La  SAN, al estar aislada sin acceso externo por otras redes es considerada segura, no necesitando medidas de protección especiales en apariencia. Pero si alguien consigue la contraseña de administración de alguno de los servidores conectado a la SAN, puede introducir driver de la HBAs modificados (o ni eso) para una  práctica de hack que es "wwn spoofing", es decir, modificar la HBA de un servidor con el wwn de otra que le permita tener acceso al recurso de almacenamiento  … y a sus datos. Recordemos que el sentido del hackering puede ser robar, corromper o destrozar el núcleo de información de la compañía. y … ¿ ésto lo evitaría DCC ? Si, ya que es una aplicación de "port locking" ( o "port binding") que es la asociación de un puerto a un wwn.

Para añadir un nivel mayor de seguridad se pueden usar protocolos de autenticación como DH-CHAP que pertenece a los protocolos FC-SP (Fibre Channel Security Protocols) definidos por la T11 y asegura mediante par de claves asociadas a wwn la negociación entre conexiones de forma segura. Aparte del "wwn spoofing" existen otras técnicas de hack en la fabric tales como "S_ID spoofing", " M-I-T-M attack" donde la aplicación de protocolos FC-SP  son eficaces para evitar cualquier riesgo de intrusión.

Para la tecnología Brocade está la política AUTH que implementa la autenticación entre switches y dispositivos a través de DH-CHAP / FCAP.

Otros puntos a revisar son las políticas de administración de contraseñas en los servidores de acceso a la SAN, en grandes compañías suelen haber muchos servidores que no son de produción con acceso a la SAN cuyas políticas de claves de administrador no suelen ser seguras y además son servidores que pueden estar fuera de las políticas restrictivas de la seguridad perimetral impuesta en el entorno de producción, y como podemos suponer ponen en grave compromiso el almacenamiento.
También es interesante para controlar este tipo de ataques la monitorización de las conexiones y desconexiones en la fabric, reinicios de servidores inesperados y wwn duplicados, además de tener procedimentados las acciones correspondientes para identificar lo más rápidamente la intrusión y aislarla. Hay muchos temas referentes a la seguridad como las virtual fabric, NPIV, interfaces de administración, políticas de distribución en la fabric,  que son muy interesantes su revisión. 

¿ Es vuestra SAN segura ? y … ¿ estás preparado para una intrusión?

734 Responses to “Seguridad en una SAN Brocade I – Políticas SCC, DCC y AUTH”

  1. I simply could not go away your web site before suggesting that I actually enjoyed the standard info an individual provide in your guests? Is going to be again incessantly to investigate cross-check new posts

  2. Good blog you have here.. It’s difficult to find high quality writing like yours nowadays. I honestly appreciate individuals like you! Take care!!|

  3. This is a topic that is close to my heart… Cheers! Exactly where are your contact details though?

  4. bookmarked!!, I love your site!

  5. Tree Care dice:

    Hey would you mind letting me know which hosting company you’re using?
    I’ve loaded your blog in 3 different web browsers and I must say this
    blog loads a lot faster then most. Can you recommend a good web hosting
    provider at a reasonable price? Cheers, I appreciate it!

  6. wonderful points altogether, you simply gained a brand new reader. What would you suggest in regards to your post that you made some days ago? Any positive?

  7. you are in reality a just right webmaster. The site loading pace is incredible. It sort of feels that you are doing any distinctive trick. Furthermore, The contents are masterwork. you have performed a magnificent process in this matter!

  8. asmr of dice:

    Thank you for sharing your thoughts. I truly appreciate your efforts and I will be waiting for
    your next post thank you once again.

  9. Tremendous issues here. I’m very glad to peer your post. Thanks
    a lot and I’m having a look forward to touch you.
    Will you kindly drop me a mail?

  10. Len Tibbetts dice:

    Everything is very open with a clear explanation of the challenges. It was definitely informative. Your website is very useful. Thanks for sharing!

  11. Right here is the right blog for anyone who hopes to find out about this topic. You know a whole lot its almost tough to argue with you (not that I really would want to…HaHa). You certainly put a new spin on a subject which has been discussed for many years. Wonderful stuff, just great!

  12. Hey there! This is kind of off topic but I need some guidance from an established blog. Is it difficult to set up your own blog? I’m not very techincal but I can figure things out pretty quick. I’m thinking about setting up my own but I’m not sure where to start. Do you have any tips or suggestions? With thanks

  13. Rosalia Tell dice:

    Can I simply say what a relief to find somebody that really knows cara pasang taruhan bola This site is something that is needed on the internet, someone with some originality!

  14. I as well as my friends have already been checking the best key points found on the website and so instantly got a terrible feeling I never expressed respect to the web blog owner for them. Most of the people came as a result excited to read all of them and have now definitely been having fun with those things. We appreciate you truly being really thoughtful and for obtaining such outstanding useful guides millions of individuals are really desperate to be aware of. Our own sincere regret for not expressing gratitude to you sooner.

  15. Thanks for finally talking about > Seguridad en una SAN Brocade I – Políticas SCC, DCC y AUTH |
    Almacenamiento Abierto < Loved it!

    Here is my webpage SurfCAM 2015 R2

  16. If some one desires expert view concerning blogging and site-building after that i advise him/her to pay a visit this weblog, Keep up the nice work.

    Feel free to surf to my web site propecia .5 mg every other day

  17. I discovered your blog web site on google and examine just a few of your early posts. Proceed to maintain up the very good operate. I just further up your RSS feed to my MSN News Reader. Seeking ahead to reading more from you later on!…

  18. Pendik Bölgesi ve halı yıkama firmaları arasında lider Penta Halı Yıkama Ücretleri & Öneriler Tuzla halı yıkama sonrasında ise durulama işlemine alınır ve bu sırada saf ve temiz sular kullanılır. Tuzla Halı Yıkama olarak Halılarınızda berrak ve mükemmel temizlik için hizmetinizdeyiz. tüm bölgelerde 7/24 Ekiplerimiz sizlerledir. Neler yapıyoruz ? Tüm halı çeşitleri; Yorgan; Stor perde; Yerinde koltuk yıkama. Tüm ürünlerinizi organik deterjanlarımız ile otomatik makinemizde yıkıyoruz. Servisimizde Tuzla bölgesinde tüm halı, yorgan, yastık, battaniye, stor ve zebra perdelerinizi en kaliteli hizmet ayrıcalığı ile temizletebilirsiniz.

  19. Pendik Bölgesi ve halı yıkama firmaları arasında lider Penta Halı Yıkama Ücretleri & Öneriler Tuzla halı yıkama sonrasında ise durulama işlemine alınır ve bu sırada saf ve temiz sular kullanılır. Tuzla Halı Yıkama olarak Halılarınızda berrak ve mükemmel temizlik için hizmetinizdeyiz. tüm bölgelerde 7/24 Ekiplerimiz sizlerledir. Neler yapıyoruz ? Tüm halı çeşitleri; Yorgan; Stor perde; Yerinde koltuk yıkama. Tüm ürünlerinizi organik deterjanlarımız ile otomatik makinemizde yıkıyoruz. Servisimizde Tuzla bölgesinde tüm halı, yorgan, yastık, battaniye, stor ve zebra perdelerinizi en kaliteli hizmet ayrıcalığı ile temizletebilirsiniz.

  20. Pendik Bölgesi – Penta Halı Yıkama Ücretleri & Öneriler Tuzla halı yıkama sonrasında ise durulama işlemine alınır ve bu sırada saf ve temiz sular kullanılır. Tuzla Halı Yıkama olarak Halılarınızda berrak ve mükemmel temizlik için hizmetinizdeyiz. tüm bölgelerde 7/24 Ekiplerimiz sizlerledir. Neler yapıyoruz ? Tüm halı çeşitleri; Yorgan; Stor perde; Yerinde koltuk yıkama. Tüm ürünlerinizi organik deterjanlarımız ile otomatik makinemizde yıkıyoruz. Servisimizde Tuzla bölgesinde tüm halı, yorgan, yastık, battaniye, stor ve zebra perdelerinizi en kaliteli hizmet ayrıcalığı ile temizletebilirsiniz.

  21. I was wondering if you ever thought of changing the page layout of your blog? Its very well written; I love what youve got to say. But maybe you could a little more in the way of content so people could connect with it better. Youve got an awful lot of text for only having one or 2 pictures. Maybe you could space it out better?

  22. Pendik Bölgesi – Penta Halı Yıkama Ücretleri & Öneriler Tuzla halı yıkama sonrasında ise durulama işlemine alınır ve bu sırada saf ve temiz sular kullanılır. Tuzla Halı Yıkama olarak Halılarınızda berrak ve mükemmel temizlik için hizmetinizdeyiz. tüm bölgelerde 7/24 Ekiplerimiz sizlerledir. Neler yapıyoruz ? Tüm halı çeşitleri; Yorgan; Stor perde; Yerinde koltuk yıkama. Tüm ürünlerinizi organik deterjanlarımız ile otomatik makinemizde yıkıyoruz. Servisimizde Tuzla bölgesinde tüm halı, yorgan, yastık, battaniye, stor ve zebra perdelerinizi en kaliteli hizmet ayrıcalığı ile temizletebilirsiniz.

  23. Silivri SEO dice:

    Türkiye SEO Ajansı, SEO, İngilizce’de “Search Engine Optimization” tanımının kısaltılmış halidir. Günümüzde dijital pazarlama alanında en önemli alanlardan biri olan Türkiye SEO “Arama Motoru Optimizasyonu” olarak da biliniyor. SEO Uzmanı Gürkan Turhan ve ekibi; sitenizi Google SEO kurallarına uygun düzenliyor. Kurumsal SEO danışmanı olarak rakiplerinizle çalışmıyoruz. SEO hizmeti veren ajansımız, uzman kadrosu ile Arama Motoru Optimizasyonu danışmanlığı sunmaktadır. Doğal bir SEO çalışması ile Google’da zirveye ulaşın. Türkiye’nin En İyi SEO Uzmanı ve SEO Uzmanı ile SEO Uyumlu metin yazarlarından oluşan ekiple Türkiye’nin En İyi SEO Ajansı ve SEO Firması. SEO Uzmanı olarak 30 Yıllık tecrübe ile Google’da Türkiye Geneli 1. sırada olmak isteyen firmalara Profesyonel, Güvenilir, En İyi SEO hizmeti. Search Engine Optimization Analyst. Seorative. İstanbul, Türkiye. Büyüyen firmamıza SEO (arama motoru optimizasyonu) uzmanı arkadaşlar aramaktayız.

  24. Tuzla – Penta Halı Yıkama Ücretleri & Öneriler Tuzla halı yıkama sonrasında ise durulama işlemine alınır ve bu sırada saf ve temiz sular kullanılır. Tuzla Halı Yıkama olarak Halılarınızda berrak ve mükemmel temizlik için hizmetinizdeyiz. tüm bölgelerde 7/24 Ekiplerimiz sizlerledir. Neler yapıyoruz ? Tüm halı çeşitleri; Yorgan; Stor perde; Yerinde koltuk yıkama. Tüm ürünlerinizi organik deterjanlarımız ile otomatik makinemizde yıkıyoruz. Servisimizde Tuzla bölgesinde tüm halı, yorgan, yastık, battaniye, stor ve zebra perdelerinizi en kaliteli hizmet ayrıcalığı ile temizletebilirsiniz.

  25. Kiesha Kanta dice:

    When I initially commented I clicked the -Notify me when new comments are added- checkbox and now every time a remark is added I get 4 emails with the same comment. Is there any means you may remove me from that service? Thanks!

  26. Wen Imondi dice:

    Heya i am for the first time here. I found this board and I in finding It truly useful

  27. Ima Eisaman dice:

    May I simply just say what a relief to discover someone who truly knows potensi judi This web site is one thing that is required on the internet, someone with a bit of originality!

  28. link ini dice:

    May I simply just say what a comfort to discover a person that actually understands situs poker online resmi This web site is something that is needed on the internet, someone with some originality!

  29. It is not my first time to visit this site, i am visiting this web site dailly and get nice data from here all the time.|

  30. I’m not suee where you are getting your info, but good topic.
    I needs to spend some time learning more or understanding more.
    Thanks for grdat info I was looking for this information for my mission.

  31. Excellent beat ! I would like to apprentice at the same time as you amend your website, how could i subscribe for a weblog web site? The account helped me a appropriate deal. I had been tiny bit acquainted of this your broadcast provided vivid clear concept

  32. I discovered your weblog web site on google and test a few of your early posts. Proceed to maintain up the very good operate. I just additional up your RSS feed to my MSN News Reader. In search of ahead to reading more from you later on!…

  33. I was very pleased to discover this site. I want to to thank you for ones time for this wonderful read!! I definitely appreciated every part of it and i also have you book-marked to see new information in your blog.

  34. An interesting discussion is worth comment. I do think that you need to write more on this subject matter, it may not be a taboo matter but generally people do not speak about such subjects. To the next! Kind regards!!

  35. Can I just say what a comfort to find somebody who genuinely understands taruhan togel This site is something that is needed on the internet, someone with a bit of originality!

  36. Great website. Lots of useful information here. I’m sending it to a few pals ans additionally sharing in delicious. And certainly, thank you on your effort!

  37. I could not refrain from commenting. Perfectly written!

  38. May I simply say what a relief to uncover somebody that really knows cara sukses bermain poker This website is one thing that is required on the web, someone with some originality!

  39. Oh my goodness! Awesome article dude! Thanks, However I am experiencing issues with your RSS. I don’t know why I can’t join it. Is there anyone else having the same RSS problems? Anyone who knows the solution will you kindly respond? Thanx!!

  40. web situs dice:

    Can I just say what a relief to discover somebody who actually understands rekomendasi pasaran bola This web site is something that is needed on the internet, someone with a bit of originality!

  41. Wow! Thank you! I always wanted to write on my website something like that. Can I include a fragment of your post to my site?

  42. Can I simply just say what a relief to find an individual who truly understands panduan bermain togel This web site is something that’s needed on the web, someone with a bit of originality!

  43. We stumbled over here different website and thought I might as well check things out. I like what I see so now i am following you. Look forward to looking over your web page yet again.

  44. May I simply just say what a relief to find somebody that really knows taruhan angka lotre This web site is something that is needed on the web, someone with some originality!

  45. When I originally commented I clicked the -Notify me when new feedback are added- checkbox and now every time a remark is added I get four emails with the same comment. Is there any manner you may remove me from that service? Thanks!

  46. I’m very pleased to discover this website. I need to
    to thank you for your time for this fantastic read!! I definitely
    liked every part of it and I have you book marked to check out new things on your web site. https://accountslogin.net/create-new-hotmail-account/

  47. There are certainly a whole lot of details like that to take into consideration. That could be a nice point to bring up. I supply the ideas above as basic inspiration but clearly there are questions just like the one you convey up the place an important factor shall be working in sincere good faith. I don?t know if greatest practices have emerged round issues like that, however I’m sure that your job is clearly identified as a good game. Both boys and girls feel the impression of just a moment’s pleasure, for the remainder of their lives.

  48. Hiram Concha dice:

    I carry on listening to the rumor lecture about getting free online grant applications so I have been looking around for the most excellent site to get one. Could you advise me please, where could i get some?

  49. Keep on writing, great job!|

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *