
946
Brocade Network Advisor SAN User Manual
53-1003154-01
QOS, DSCP, and VLANs
22
IPSec for the 8 Gbps platforms
The 8 Gbps platforms use AES-GCM-ESP as a single, pre-defined mode of operation for protecting
all TCP traffic over an FCIP tunnel. AES-GCM-ESP is described in RFC-4106. Key features are listed
below:
•
Encryption is provided by AES with 256 bit keys.
•
The IKEv2 key exchange protocol is used by peer switches and blades for mutual
authentication.
•
IKEv2 uses UDP port 500 to communicate between the peer switches or blades.
•
All IKE traffic is protected using AES-GCM-ESP encryption.
•
Authentication requires the generation and configuration of 32 byte pre-shared secrets for
each peer switch or blade.
•
An SHA-512 hash message authentication code (HMAC) is used to check data integrity and
detect third party tampering.
•
PRF is used to strengthen security. The PRF algorithm generates output that appears to be
random data, using the SHA-512 HMAC as the seed value.
•
A 2048 bit Diffie-Hellman (DH) group is used for both IKEv2 and IPSec key generation.
•
The SA lifetime limits the length of time a key is used. When the SA lifetime expires, a new key
is generated, limiting the amount of time an attacker has to decipher a key. Depending on the
length of time expired or the length of the data being transferred, parts of a message maybe
protected by different keys generated as the SA lifetime expires. For the 8 Gbps Extension
Switch and Blade, the SA lifetime is approximately eight hours, or two gigabytes of data,
whichever occurs first.
•
ESP is used as the transport mode. ESP uses a hash algorithm to calculate and verify an
authentication value, and also encrypts the IP datagram.
QOS, DSCP, and VLANs
Quality of Service (QoS) refers to policies for handling differences in data traffic. These policies are
based on data characteristics and delivery requirements. For example, ordinary data traffic is
tolerant of delays and dropped packets, but voice and video data are not. QoS policies provide a
framework for accommodating these differences in data as it passes through a network.
QoS for Fibre Channel traffic is provided through internal QoS priorities. Those priorities can be
mapped to TCP/IP network priorities. There are two options for
TCP/IP network-based QoS
:
•
Layer three DiffServ code Points (DSCP).
•
VLAN tagging and Layer two class of service (L2CoS).
Содержание Network Advisor 12.3.0
Страница 1: ...53 1003154 01 11 July 2014 Brocade Network Advisor SAN User Manual Supporting Network Advisor 12 3 0...
Страница 4: ...iv Brocade Network Advisor SAN User Manual 53 1003154 01...
Страница 86: ...34 Brocade Network Advisor SAN User Manual 53 1003154 01 Uninstalling a patch 2...
Страница 190: ...138 Brocade Network Advisor SAN User Manual 53 1003154 01 Fabric tracking 4...
Страница 216: ...164 Brocade Network Advisor SAN User Manual 53 1003154 01 User profiles 5...
Страница 462: ...410 Brocade Network Advisor SAN User Manual 53 1003154 01 Searching for an assigned event filter 9...
Страница 478: ...426 Brocade Network Advisor SAN User Manual 53 1003154 01 Microsoft System Center Operations Manager SCOM plug in 10...
Страница 612: ...560 Brocade Network Advisor SAN User Manual 53 1003154 01 Exporting Host port mapping 13...
Страница 620: ...568 Brocade Network Advisor SAN User Manual 53 1003154 01 Exporting storage port mapping 14...
Страница 720: ...668 Brocade Network Advisor SAN User Manual 53 1003154 01 Security configuration deployment 17...
Страница 744: ...692 Brocade Network Advisor SAN User Manual 53 1003154 01 Configuring Virtual Fabrics 19...
Страница 1036: ...984 Brocade Network Advisor SAN User Manual 53 1003154 01 Troubleshooting FCIP Ethernet connections 22...
Страница 1068: ...1016 Brocade Network Advisor SAN User Manual 53 1003154 01 Removing thresholds 24...
Страница 1098: ...1046 Brocade Network Advisor SAN User Manual 53 1003154 01 Swapping blades 25...
Страница 1104: ...1052 Brocade Network Advisor SAN User Manual 53 1003154 01 Searching the configuration snapshots 26...
Страница 1176: ...1124 Brocade Network Advisor SAN User Manual 53 1003154 01 SAN connection utilization 28...
Страница 1282: ...1230 Brocade Network Advisor SAN User Manual 53 1003154 01 Removing a frame monitor from a switch 30...
Страница 1306: ...1254 Brocade Network Advisor SAN User Manual 53 1003154 01 Viewing historical reports for a configuration policy manager 31...
Страница 1378: ...1326 Brocade Network Advisor SAN User Manual 53 1003154 01 Event logs 32...
Страница 1432: ...1380 Brocade Network Advisor SAN User Manual 53 1003154 01 MAPS integration with other features 33...
Страница 1448: ...1396 Brocade Network Advisor SAN User Manual 53 1003154 01 Upload failure data capture 34...
Страница 1490: ...1438 Brocade Network Advisor SAN User Manual 53 1003154 01 SAN shortcut menus A...
Страница 1494: ...1442 Brocade Network Advisor SAN User Manual 53 1003154 01 Call Home Event Tables B...
Страница 1524: ...1472 Brocade Network Advisor SAN User Manual 53 1003154 01 About Roles and Access Levels D...
Страница 1552: ...1500 Brocade Network Advisor SAN User Manual 53 1003154 01 Regular Expressions F...
Страница 1920: ...1868 Brocade Network Advisor SAN User Manual 53 1003154 01 Views H...