Академический Документы
Профессиональный Документы
Культура Документы
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 1
BRKSAN-2701
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 2
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 3
SAN Technology
Overview
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 4
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 5
Link
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 6
SCSI FC
SCSI Bus
Fibre Channel
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 7
Fabric
Node NL_Port FL_Port E_Port E_Port Switch
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 8
~ 1 km per Frame
2 Gbps FC
~ ½ km per Frame
4 Gbps FC
16 Km
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 11
OX_ID and
RX_ID Exchange
Frame Fields
ULP Information Unit
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 13
Fabric virtualization—VSAN
Provide independent (‘virtual’) fabric services on a single
physical switch
VSAN—Design Foundation
Zoning
Fabric routing (Inter-VSAN Routing—IVR)
Ability to provide selected connectivity between virtual fabrics
without merging them
Virtual Fabric Trunking (VSAN Trunking)
Ability to transport multiple virtual fabrics over a single ISL
or common group of ISLs
IVR zones
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 15
Fabric virtualization—VSAN
Provide independent (‘virtual’) fabric services on a single
physical switch
VSAN—Design Foundation
Zoning
Fabric routing (Inter-VSAN Routing–IVR)
Ability to provide selected connectivity between virtual fabrics
without merging them
Virtual Fabric Trunking (VSAN Trunking)
Ability to transport multiple virtual fabrics over a single ISL
or common group of ISLs
IVR zones
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 16
Features include:
Dynamic provisioning and resizing
Improved port utilization
Shared ISL bandwidth
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 17
Virtual SANs—VSANs
Production SAN Tape SAN Test SAN
FC
FC FC
FC
FC
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 18
Soft zoning FC
FC
FC
FC
“Hard zoning” used to be synonymous FC
FC
Fabric virtualization—VSAN
Provide independent (‘virtual’) fabric services on a single
physical switch
VSAN—Design foundation
Zoning
Fabric routing (Inter-VSAN Routing—IVR)
Ability to provide selected connectivity between virtual fabrics
without merging them
Virtual fabric trunking (VSAN Trunking)
Ability to transport multiple virtual fabrics over a single ISL
or common group of ISLs
IVR zones
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 21
VSANs—Routed Connectivity
Common Physical Fabric
Sharing a Common
Resource such as Tape
Common Physical Fabric
Sales
SAN
HR
SAN
MS Sales Marketing
MS SAN
SAN MS
Marketing
SAN
SAN IP
MS Tape Production and or
SAN Extension
HR DR Interconnect Without Services FC
SAN Merging Fabrics
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 22
FC
FC FC
FC
FC FC
FC FC
FC FC
FC
FC FC
FC
FC FC
FC FC FC FC
FC
FC FC FC
FC FC
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 23
IVR Zones
IVR zone Physical Topology
VSANs ZoneC
ZoneD
A collection of IVR zones ZoneA
Disk5
that must be activated to be Host3
operational Disk6
Inter-VSAN Zone
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 24
VS On
20 cku
must have same configuration prior E_Port
AN ly
E_Port AN Ba
VS 10
10
to creating channel (e.g., TE_Port (TE_Port) AN
VS
or E_Port, VSANs-enabled, etc.)
Port Channel technology provides Trunking E_Port
E_Port
high availability and fast recovery (TE_Port)
for VSAN trunk (EISL)
4-Link (8 Gbps) Port
Multiple Port Channels yield Channel Configured
multiple paths for custom traffic as EISL
engineering
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 27
Input Output B
Port Port
Switch with no VOQ
HOL blocking FC
Input Output C
port Port
--------------------------------------------------------------------------------------------------------------------------------------------------------------
C C C C
Input Output FC
B C A C C C C C A B B Port Port A
A ARB
Input Output B
Port Port
Switch with VOQ support
FC
No HOL blocking
Input Output C
VOQ alleviates HOL Port Port
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 29
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 30
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 31
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 33
2
Not network management
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 34
Congestion
What is acceptable? Control, 4
Unavoidable? Reduce FSPF 1
Routes
3. Traffic management 8 8 8 8 8 8 8 8 8 8 8 8
Preferential routing or
resource allocation
4. Fault isolation
Host Host Host Host Host Host
Consolidation while
maintaining isolation 3
Failure of One Device Has
5. Management No Impact on Others
1. Scalability—Port Density,
Topology Requirements
Number of ports for end devices
High
How many ports are Performance
needed now? Crossbar
Large Port
2
Count
What is the expected Directors
life of the SAN? QoS,
Congestion
Control, 4
How many will be needed in Reduce FSPF 1
the future? Routes
8 8 8 8 8 8 8 8 8 8 8 8
Hierarchical SAN design
Best Practice
Design to cater for future
requirements Host Host Host Host Host Host
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 36
3. Traffic Management
Do different apps/servers
High
have different performance Performance
requirements? Crossbar
Large Port
2
Count
Should bandwidth be Directors
QoS,
reserved for specific Congestion 4
applications? Control,
Reduce FSPF 1
Is preferential treatment/ Routes
QoS necessary? 8 8 8 8 8 8 8 8 8 8 8 8
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 38
Fabric
Faults in one virtual fabric (VSAN) #1 Fabric
#2
are contained and do not impact
other virtual fabrics
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 39
5. Management
Consolidation and Large Scale SAN Becomes
More Difficult to Manage. How Can It Be More
Secure? How Can the SAN Traffic Be Monitored
as Performance Requirements Increase?
FM Client FMS FM Clients
FC
SNMP FC
SNMP
SNMP
Tools and Features
RBAC on per VSAN basis
FC-SP for switch-to-switch or device-to-switch security
Fabric Manager Server
Online traffic monitoring through Device Manager
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 40
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 41
Core-Edge
Traditional SAN design for
growing SANs
High density directors in
core and fabric switches, A B
directors or blade switches
on edge
Predictable performance
A B
A B
Scalable growth up to core A B
and ISL capacity
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 42
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 43
124 Storage
Ports at 2 G
6 ISL to
Backbone at 4 G
64 ISL to
Edge at 4G
32 ISL to
Core at 4 G
496 Host
Ports at 4 G
15.5 : 1 Host
to Core
A
B
Ports Deployed: 1200
Used Ports: 1200
Storage Ports (2 G Dedicated): 192
14 Racks
Host Ports (4 G Shared): 896
32 Dual
ISL Oversubscription (Ports): 6.4 : 1 Attached
Disk Oversubscription (Ports): 9.3 : 1 Servers per
Rack
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 45
A B
2 ISL to
Core at 4G
Ports Deployed: 1608
16 Host
Used Ports: 1440 Ports at 4G Five Racks
Storage Ports (2 G Dedicated): 240 96 Dual
Host Ports (4 G Shared): 960 Attached
ISL Oversubscription (Ports): 8: 1 Blade Servers
Disk Oversubscription (Ports): 8: 1
per Rack
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 46
Full Performance
(Non-Oversubscribed,
Non-Blocking)
Host Optimized
(Oversubscribed,
Non-Blocking)
Collapsed Core
Typically a lower oversubscription ratio
Room to grow—empty slots = future port count growth
While Director ports are more expensive than Fabric switch ports,
Collapsed Core design has no wasted ports for ISLs—similar
cost/usable port
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 47
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 48
LAN Core
SAN-A SAN-B
Distribution 8
MDS 9500
10 GE/FCoE
CNA
Server Cabinet Pair 1 Server Cabinet Pair N Server Cabinet Pair 1 Server Cabinet Pair N
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 49
iSCSI Design
Take advantage of what IP (IPv4, IPv6) and IPS have to offer
Low cost with many options
Proxy initiator
iSCSI Server Load Balancing (iSLB)
Initiator Configured to See
Targets at Virtual Address MDS9509-1
Real GigE Address
IP: 10.0.0.101 Storage Array
MAC: 0005.3000.aabf
IP Network
FC SAN
pWWN a
Virtual Address
10.1.40.163 IP: 10.1.10.100
iSCSI
MAC:
0000.5e00.0101
pWWN b
Design Optimization
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 52
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 53
Oversubscription VSAN-
Enabled
Round robin fairness Fabric
Assured fairness
Potential VSAN
Port Channel to scale Bottlenecks Trunks
connectivity
Bundle ISLs between switches
Additional resiliency
Shared Storage
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 55
DWRR Weight
Priority Absolute
Queue 2 60
Queue 3 10
Queue 4 30
PQ Transmit
Queue
DWRR 2
DWRR 3
DWRR 4
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 56
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 57
Blade N
Blade N
Blade N
Blade 2
Blade 2
Blade 1
Blade 2
Blade 1
Blade 2
Blade 1
Blade 1
… HBA Mode)
…
FC Switch FC Switch NPV NPV
E-Port
NPV Enables Large Scale
N-Port
Blade Server Deployments By:
SAN Reducing Domain ID usage SAN
E-Port
F-Port
Addressing switch interop issues
Simplifying management
Storage Storage
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 59
FC
FC SAN FC
FC
FC
FC
LAN
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 60
Securing against
unauthorized user and
device access
Target
User/device authorization SAN Fabric
and authentication Host
IP Storage
Management access controls Security
SAN Management (iSCSI/FCIP)
Securing the SAN
Security
management information
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 61
Intelligent Fabric
Applications
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 62
MSM-18/4 MSM-18/4
No rewiring to insert appliances
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 63
Application
Encrypts storage media
Server (data at rest)
IEEE compliant AES-256 encryption
Name: XYZ
SSN: 1234567890
Amount: $123,456 Integrated as transparent fabric service
Status: Gold
Transparent Fabric Service
Key Management
Center Supports heterogeneous storage
SME SME IP arrays, tape devices, and VTLs
Compresses tape data
Offers secure, comprehensive key
@!$%!%!%!%%^&
management
*&^%$#&%$#$%*!^
@*%$*^^^^%$@*)
%#*@(*$%%%%#@
Allows offline media recovery
Built upon FIPS Level 3 system
Storage Tape architecture
Array Library
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 64
DMM offers
Online migration of heterogeneous arrays
Data Mobility Manager
Simultaneous migration of multiple LUNs
Unequal size LUN migration
Application Data Rate adjusted migration
I/O Migration
Verification of migrated data
Secure erase
Dual fabric support
Old Array New Array CLI and wizard-based management
with Cisco Fabric Manager
Utilizes Storage Services
Modules (SSM) Requires no SAN reconfiguration or
rewiring
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 65
Enables appliance-based
Initiator storage applications without
compromising SAN integrity
Initiator ÅÆ Target I/O About SAN Tap
SAN MDS delivers a copy of primary
I/O to an appliance
Appliance provides the storage
Copy of Appliance
Primary application
I/O
Examples of applications include
Continuous Data Protection
(CDP), replication, etc.
FAIS
High-performance fast path
SSM Integrated, HA architecture
Multiprotocol integration
Data Path
Comprehensive security
Troubleshooting and diags
Vendor agnostic
Heterogeneous Storage Arrays
Compliance
DoD, RCMP, and Gutmann
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 69
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 71
Closing Remarks
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 72
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 74
Q and A
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 76
BRKSAN-2701
14570_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 78