FC Security Model
Fibre Channel security is implemented at the fabric level. Host-level authentication is not part of the FC transport. Security controls:
-
Fabric zoning: primary access control; only zoned initiators can communicate with target ports.
-
LUN masking / host registration: FlashArray independently enforces access based on WWPN registration and host group membership.
-
Hard zoning: enforce at the switch port level for strongest isolation.
No host-level firewall is required for FC storage traffic. FC does not traverse IP networks.
In-Transit Encryption
FlashArray supports encryption of FC frames in flight between host and FlashArray, providing wire-level confidentiality beyond fabric zoning. In-flight encryption operates on the HBA below the SCSI / FCP layer; LUN access, multipath, and ALUA behavior are unchanged, and the host-side multipath.conf and queue-depth settings apply identically whether encryption is enabled or not.