You are on page 1of 2

Logical Unit Number masking

From Wikipedia, the free encyclopedia

This article does not cite any references or sources. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed. (September 2009)

Fibre Channel

Layer 4. Protocol mapping

LUN masking

Layer 3. Common services

Layer 2. Network

Fibre Channel fabric Fibre Channel zoning Registered State Change Notification

Layer 1. Data link

Fibre Channel 8B/10B encoding

Layer 0. Physical

Logical Unit Number Masking or LUN masking is an authorization process that makes a Logical Unit Number available to some hosts and unavailable to other hosts. The security benefits of LUN maskiing are limited, in that with many HBAs it is possible to forge source addresses (WWNs/MACs/IPs). However, it is mainly implemented not as a security measure per se, but rather as a protection against misbehaving servers which may corrupt disks belonging to other servers. For example, Windows servers attached to a SAN will, under some conditions, corrupt non-Windows (Unix, Linux, NetWare) volumes on the SAN by attempting to write Windows volume labels to them. By hiding the other LUNs from the Windows server, this can be prevented, since the Windows server does not even realize the other LUNs exist.

[edit]External

links

You might also like