Home » Seguridad en una SAN Brocade I – Políticas SCC, DCC y AUTH

Seguridad en una SAN Brocade I – Políticas SCC, DCC y AUTH

En la administración de una red de fibra para almacenamiento más que medidas de seguridad de caracter preventivo son una práctica habitual el zoneado del switch ( o fabric) y el enmascaramiento de lunes (lun masking) desde la cabina en la provisión rutinaria de almacenamiento. Adiccionalmente, se puede añadir niveles de seguridad en la SAN con funcionalidades que proporcionan los fabricantes de switches de fibra. Ejemplos para tecnología Brocade son las políticas de control de las conexiones entre switches ( Switch Connection Control  – SCC)  y de control de dispositivos ( Device Connection Control – DCC). Lo que nos permiten hacer estas los políticas es restringir que switches y dispositivos se conectarán a la fabric.

SCC – Proteje las conexiónes inesperadas entre switches, se trata de verificar cada vez que se intenta realizar una conexión entre switches (ISL)  contra un listado de switches definido por la política.

DCC –   Proteje la conexiónes inesperadas entre dispositivos (HBAs de servidores, librerías, drives, VTLs, cabinas) con switches, se trata de verificar cada vez que se intenta realizar una conexión de un dispositivo de fibre  contra un listado de dispositivos definido por la política.

La aplicación de estas políticas pueden considerarse interesante en muchos casos, por ejemplo, si el parcheo de fibra y sus cambios es ajeno al personal de administración de la SAN, si se quiere minimizar el fallo humano, o evitar un intento de acceso no deseado de un equipo o un analizador de tráfico, …

La  SAN, al estar aislada sin acceso externo por otras redes es considerada segura, no necesitando medidas de protección especiales en apariencia. Pero si alguien consigue la contraseña de administración de alguno de los servidores conectado a la SAN, puede introducir driver de la HBAs modificados (o ni eso) para una  práctica de hack que es "wwn spoofing", es decir, modificar la HBA de un servidor con el wwn de otra que le permita tener acceso al recurso de almacenamiento  … y a sus datos. Recordemos que el sentido del hackering puede ser robar, corromper o destrozar el núcleo de información de la compañía. y … ¿ ésto lo evitaría DCC ? Si, ya que es una aplicación de "port locking" ( o "port binding") que es la asociación de un puerto a un wwn.

Para añadir un nivel mayor de seguridad se pueden usar protocolos de autenticación como DH-CHAP que pertenece a los protocolos FC-SP (Fibre Channel Security Protocols) definidos por la T11 y asegura mediante par de claves asociadas a wwn la negociación entre conexiones de forma segura. Aparte del "wwn spoofing" existen otras técnicas de hack en la fabric tales como "S_ID spoofing", " M-I-T-M attack" donde la aplicación de protocolos FC-SP  son eficaces para evitar cualquier riesgo de intrusión.

Para la tecnología Brocade está la política AUTH que implementa la autenticación entre switches y dispositivos a través de DH-CHAP / FCAP.

Otros puntos a revisar son las políticas de administración de contraseñas en los servidores de acceso a la SAN, en grandes compañías suelen haber muchos servidores que no son de produción con acceso a la SAN cuyas políticas de claves de administrador no suelen ser seguras y además son servidores que pueden estar fuera de las políticas restrictivas de la seguridad perimetral impuesta en el entorno de producción, y como podemos suponer ponen en grave compromiso el almacenamiento.
También es interesante para controlar este tipo de ataques la monitorización de las conexiones y desconexiones en la fabric, reinicios de servidores inesperados y wwn duplicados, además de tener procedimentados las acciones correspondientes para identificar lo más rápidamente la intrusión y aislarla. Hay muchos temas referentes a la seguridad como las virtual fabric, NPIV, interfaces de administración, políticas de distribución en la fabric,  que son muy interesantes su revisión. 

¿ Es vuestra SAN segura ? y … ¿ estás preparado para una intrusión?

734 Responses to “Seguridad en una SAN Brocade I – Políticas SCC, DCC y AUTH”

  1. I delight in, cause I discovered just what I used to be taking a look for. You’ve ended my 4 day lengthy hunt! God Bless you man. Have a nice day. Bye

  2. Greetings! Very helpful advice in this particular article! It’s the little changes which will make the largest changes. Thanks for sharing!

  3. eawch time i used to read smaller content that
    also clear their motive, and that is also happening witrh this piece of writing which I am
    reading at this place.

  4. Herb Girsh dice:

    I’m pretty pleased to find this great site. I want to to thank you. Here is my web: dingdong casino onlineCan I just say what a comfort to discover a person that actually knows what they’re

  5. Thanks , I’ve recently been looking for information about this subject for ages and yours is the best I have discovered so far. But, what about the bottom line? Are you sure about the source?

  6. whoah this blog is magnificent i love reading your posts. Keep up the good work! You know, many people are searching around for this info, you could aid them greatly.

  7. I have read some good stuff here. Certainly worth bookmarking for revisiting. I surprise how much effort you put to make such a excellent informative web site.

  8. We’re a group of volunteers and opening a brand new scheme in our community. Your web site offered us with helpful info to paintings on. You’ve done an impressive job and our whole community will probably be grateful to you.

  9. Does your site have a contact page? I’m having a tough time locating it but, I’d like to send you an e-mail. I’ve got some recommendations for your blog you might be interested in hearing. Either way, great blog and I look forward to seeing it grow over time.|

  10. Appearances are deceptive.

  11. There may be noticeably a bundle to find out about this. I assume you made sure nice points in options also.

  12. Greetings! I’ve been reading your site for a long time now and finally got the bravery to go ahead and give you a shout out from New Caney Texas! Just wanted to tell you keep up the good job!

  13. I know this if off topic but I’m looking into startiong my own weblog and
    waas curious what all iss needed to get setup?
    I’m asssuming having a blog like yours would cost a preyty penny?
    I’m noot very internet savvy so I’m not 100% positive.
    Any recommendations or advice would be greatly appreciated.
    Thanks

  14. Rickey Feutz dice:

    Lightweight led grow light reviews Informative Post

  15. Hey There. I discovered your blog using msn. This is an extremely smartly written article. I’ll make sure to bookmark it and return to read more of your useful info. Thank you for the post. I will definitely return.

  16. hello there and thanks on your information Ive definitely picked up something new from right here. I did on the other hand expertise several technical issues using this web site, since I experienced to reload the website lots of instances previous to I could get it to load properly. I were brooding about if your hosting is OK? Now not that I’m complaining, but slow loading instances occasions will sometimes affect your placement in google and could injury your quality rating if ads and ***********|advertising|advertising|advertising and *********** with Adwords. Anyway Im adding this RSS to my e-mail and can glance out for much extra of your respective fascinating content. Make sure you replace this again very soon..

  17. Do you have a spam problem on this website; I also am a blogger, and I was curious about your situation; we have created some nice procedures and we are looking to swap strategies with other folks, be sure to shoot me an email if interested.

  18. hello!,I like your writing so much! share we communicate more about your post on AOL? I need a specialist on this area to solve my problem. May be that’s you! Looking forward to see you.

  19. Wow! Thank you! I continuously wanted to write on my site something like that. Can I implement a fragment of your post to my blog?

  20. fake id dice:

    It’s very simple to find out any matter on net as compared to textbooks, as I found this article at this website.|

  21. I do not even know how I ended up here, but I thought this post was good. I don’t know who you are but definitely you are going to a famous blogger if you are not already 😉 Cheers!

  22. best penis extender weblink dice:

    I cling on to listening to the news update speak about getting free online grant applications so I have been looking around for the finest site to get one. Could you advise me please, where could i acquire some?

  23. Hello my friend! I wish to say that this post is amazing, nice written and include almost all vital infos. I would like to see more posts like this.

  24. Hi my friend! I want to say that this article is amazing, nice written and include approximately all important infos. I would like to see more posts like this.

  25. best penis extender additional reading dice:

    Hello there, You’ve done an excellent job. Ill certainly digg it and individually suggest to my friends. I am sure they’ll be benefited from this site.

  26. Adina Lipsky dice:

    Useful information. Lucky me I found your web site by accident, and I am shocked why this twist of fate did not came about earlier! I bookmarked it.

  27. Hmm it looks like your site ate my first comment (it was super long) so I guess I’ll just sum it up what I submitted and say, I’m thoroughly enjoying your blog. I too am an aspiring blog blogger but I’m still new to everything. Do you have any tips for novice blog writers? I’d definitely appreciate it.|

  28. Hi there just wanted to give you a brief heads up and let you know a few of the pictures aren’t loading correctly. I’m not sure why but I think its a linking issue. I’ve tried it in two different internet browsers and both show the same outcome.

  29. I just like the helpful information you provide on your articles.
    I’ll bookmark your weblog and test once moree right here regularly.
    I’m somewwhat sure I will be infotmed a lot of new stuff prkper here!
    Good luck for tthe following!

  30. Really enjoyed this article, can you make it so I get an alert email every time you publish a fresh update?

  31. phpshell dice:

    r57 shell c99 shell php shell alfa shell wso shell

  32. I like the helpful information you provide in your articles. I will bookmark your blog and check again here frequently. I am quite certain I will learn a lot of new stuff right here! Good luck for the next!

  33. I like the helpful information you provide in your articles. Ill bookmark your weblog and check again here frequently. I am quite sure Ill learn plenty of new stuff right here! Best of luck for the next!

  34. Attractive section of content. I just stumbled upon your blog and in accession capital to assert that I acquire in fact enjoyed account your blog posts. Any way I’ll be subscribing to your augment and even I achievement you access consistently quickly.

  35. Heya i am for the primary time here. I found this board and I in finding It truly useful & it helped me out a lot. I am hoping to provide one thing back and help others like you helped me.

  36. Sherry G dice:

    Hello,

    Right now we are living in severe times, there have actually a recorded 360,000 confirmed deaths because of the viral pandemic globally. The quickest means it spreads is through your mouth as well as your hands. N-95 Masks have been recommended worldwide due to its reliable 3 layer protective filter.

    These masks and other clinical products have run out supply for months in many local and online stores.

    My name is Sherry I am the Founder of https://covid19protectivemasks.com we have actually collaborated with supply store owners all around the globe to be able to bring you an online shop that’s completely equipped with everything you need to fight this pandemic.

    In stock are protective masks, hand sanitizer, latex sterilie gloves & more!

    The very best part is our prices are reasonable we don’t think its right to take advantage of individuals during their time of need!

    Best Regards,
    Sherry G.
    covid19protectivemasks.com

  37. I’m curious to find out what blog platform you are using? I’m experiencing some minor security issues with my latest blog and I’d like to find something more safeguarded. Do you have any suggestions?

  38. Your home is valueble for me. Thanks!…

  39. Jae Reisdorf dice:

    The very next time I read a blog, I hope that it does not fail me just as much as this one. I mean, I know it was my choice to read, but I truly thought you would probably have something interesting to talk about. All I hear is a bunch of moaning about something you could fix if you weren’t too busy seeking attention.

  40. I seriously love your website.. Pleasant colors & theme. Did you build this site yourself? Please reply back as I’m looking to create my own website and want to learn where you got this from or just what the theme is called. Cheers!|

  41. If you desire to take a great deal from this post thesn yoou have to apply such methods tto your won weblog.

  42. I’ve learn several excellent stuff here. Definitely price bookmarking for revisiting. I wonder how much effort you place to make this type of fantastic informative website.

  43. I paay a visit everyda a feew websites and blogs to
    read content, however this weblog provides quality based posts.

  44. Do you have a spam issue on this website; I also am a blogger, and I was wanting to know your situation; we have created some nice practices and we are looking to swap techniques with other folks, please shoot me an email if interested.

  45. voetbal dice:

    Jammer genoeg existentie er vele sites die valse beloftes scheppen plus indien jou eenmaal doodmoe
    de website belandt doodgegooid wordt met advertenties, doch aanvankelijk geen gratis live streams van voetbal ter lonken krijgt.

    Jammergenoeg existentie er vele sites die valse beloftes maken plus indien je
    eenmaal op den website belandt doodgegooid worden alsmede advertenties, maar aanvankelijk geen kosteloos
    live streams van voetbal bij oogopslagen krijgt. De voetbalwedstrijden te voornoemd uiteenzetting streamen de
    wedstrijden niet aanzien, maar neuzen het internet geëindigd akelig aanbieders
    van den livestreams plus aanreiken dit te een overzichtelijke webstek opnieuw.
    Realisatie website tijdens Spruit Digital.
    De onderzoeksvraag was: Hoe hebben fatsoenlijkheid, interetnische contacten plus den participatie vanwege geneesmiddel
    van vrijwilligerswerk zichzelf erop VV De Meern ontwikkeld te de afgelopen paar klas?
    Mede doodop basis van de nulmeting wezen er sedert 2008
    honingbij en door VV De Meern activiteiten ingezet zoals de Fair Play Cup plus batig trainen, maatschappelijke stage en het
    Young Professional Project en een aantal andere
    projecten. Daarnaast is het commentaar ter den wedstrijden haast immer in een andere taal dan Nederlands.

  46. Bitcoin wallets generally exist on the spectrum.

  47. Wow, amazing weblog structure! How long have you ever been blogging for? you made blogging glance easy. The overall glance of your site is great, as smartly as the content material!

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *