- Community Home
- >
- Storage
- >
- Midrange and Enterprise Storage
- >
- HPE EVA Storage
- >
- Re: EVA 5000 with DMZ Hosts
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2008 02:01 AM
тАО08-08-2008 02:01 AM
EVA 5000 with DMZ Hosts
I have a project that wants to start using our SAN but the Security team is questioning this because the hosts in question are in the DMZ.
We use Cisco switches so could set up a seperate VSAN for those DMZ Hosts & our management server is within our network.
I've been unable to find any HP Docs which cover HP EVA Security using hosts in the DMZ.
Points awarded for any useful links/information
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2008 03:06 AM
тАО08-08-2008 03:06 AM
Re: EVA 5000 with DMZ Hosts
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2008 03:09 AM
тАО08-08-2008 03:09 AM
Re: EVA 5000 with DMZ Hosts
I'm mainly after any documentation about security concerns/issues using hosts in the DMZ connectng to the EVA.
I've seen other posts about this but nothing was really supplied.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2008 04:31 AM
тАО08-08-2008 04:31 AM
Re: EVA 5000 with DMZ Hosts
A VSAN for SMZ hosts would be the way to go. You would connect the VSAN ports to 2 host ports on the EVA. This is where it becomes important. How are the built-in host ports on an EVA? Are they in an internal hub or a switch? If they are on a hub i.e. all LUNs are visible to all host ports, you will have exposure of your internal-protected LUNs to the DMZ host. Of course you have LUN masking but if the DMZ host is compromized, the hacker can start altering the WWN of the DMZ host HBAs and try to match the WWN of internal host HBAs and do an FC-login to internal LUNs.
If the EVA is using an FC switch for the host ports then it is much safer. The DMZ host can only see the LUNs on that port only.
Maybe a call to HP is warranted.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2008 05:26 AM
тАО08-08-2008 05:26 AM
Re: EVA 5000 with DMZ Hosts
A virtual disk is always presented on all 4 controller ports - if you can spoof a WWPN, you can bypass the EVA's LUN masking.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2008 05:36 AM
тАО08-08-2008 05:36 AM
Re: EVA 5000 with DMZ Hosts
That would mean that the host ports on the EVA are on a mini HUB.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2008 05:54 AM
тАО08-08-2008 05:54 AM
Re: EVA 5000 with DMZ Hosts
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-10-2008 07:15 AM
тАО09-10-2008 07:15 AM
Re: EVA 5000 with DMZ Hosts
Thanks for responses