Advance SAN Services
Advance SAN Services
BRKSAN-3707
Mike Dunn
Network Consultant
July 14, 2011
BRKSAN-3707
Cisco Public
Deduplication
Backup Redesign
Technology Refresh
Technology Refresh
Archiving
Virtualization Adoption
Consolidation
Archiving
Reporting
Disaster Recovery
Virtualization Adoption
Data Migration
Thin Provisioning
Improving Performance
Data Migration
Improving Forecasting
Backup Redesign
0%
10%
20%
30%
40%
50%
0%
10%
20%
30%
40%
50%
BRKSAN-3707
Deduplication
Technology Refresh
Tiered Storage Build Out
Archiving
Consolidation
Cisco Public
Agenda
SAN Consolidation with Virtualization
Inter-VSAN Routing (IVR)
N-Port Virtualizer (NPV) / NPIV
FlexAttach
BRKSAN-3707
Cisco Public
BRKSAN-3707
Cisco Public
Physical
SAN
Physical
SAN
Physical
SAN
VSAN
Physical
Islands
VSAN
VSAN
Virtual
Fabrics
BRKSAN-3707
VSAN
VSAN
VSAN
Routed
Virtual
Fabric
Cisco Public
pwwnH
A Fabric
B Fabric
Domain 10
Domain 20
IVR Enabled
Switches
B
Domain 50
Domain 60
Backup VSAN
(V200)
pwwnT
Cisco Public
Finance
SAN
Engineering
SAN
HR
SAN
BRKSAN-3707
TAPE
SAN
Cisco Public
OLTP VSAN
(VSAN 100)
Domain 10
Email VSAN
(VSAN 300)
Database
VSAN
(VSAN 500)
swwn1
Domain 60
Needs to be activated
Backup VSAN
(VSAN 200)
BRKSAN-3707
Cisco Public
OLTP VSAN
(VSAN 100)
swwn2
Backup VSAN
(VSAN 200)
pwwnT
A Fabric Shown, Repeat for B Fabric
BRKSAN-3707
Cisco Public
OLTP VSAN
(VSAN 100)
Establishes communication
across VSANs
Similar to regular zones
Extends zoning across VSAN
boundary
Domain 10
Domain 60
ivr_zoneset1
ivr_zone1
member pwwnH vsan 100
member pwwnT vsan 200
Backup VSAN
(VSAN 200)
pwwnT
IVR_zone1
member pwwnH
member pwwnT
Cisco Public
10
OLTP VSAN
(VSAN 100)
Virtual Device
Representation of a device another
VSAN
Domain 10
Device Advertisement
Domain 60
pwwnH
10.1.2
Domain 10
pwwnT
60.1.2
Backup VSAN
(VSAN 200)
BRKSAN-3707
Cisco Public
11
VSAN Topology
Step by Step
IVR zones
Domain 60
ivr_zone1
pwwnh vsan 100
pwwnt vsan 200
pwwnH
10.3.4
OLTP VSAN
(VSAN 100)
Switches are
virtualized with
original domain ID
No FCID
Translation
60.1.2
Domain 10
Domain 60
Devices are
virtualized with
original FCID
IVR routes between
VSANs
Domain IDs have to
be unique across all
the VSANs
Backup VSAN
(VSAN 200)
pwwnT
60.1.2
Domain 10
10.3.4
BRKSAN-3707
Cisco Public
12
Domain 30
OLTP VSAN
(VSAN 100)
pwwnH
10.3.1
30.3.2
10.1.2, 70.1.2}
->
{30.3.2, 10.3.1}
{10.3.1, 30.3.2}
->
{70.1.2, 10.1.2}
Domain 10
Domain 10
Backup VSAN
(VSAN 200)
pwwnT
10.1.2
Domain 70
70.1.2
Cisco Public
13
Domain 30
pwwnH
10.3.1
30.3.2
Domain 10
Backup VSAN
(VSAN 200)
Domain 30
pwwnT
50.1.2
Domain 70
70.1.2
native-vsan 100 domain 70
BRKSAN-3707
pwwn 11:22:33:44:55:66:77:88
2011 Cisco and/or its affiliates. Allfcid
rights 70.1.2
reserved.
Cisco Public
14
OLTP VSAN
(VSAN 100)
Email VSAN
(VSAN 300)
Domain 10
Database VSAN
(VSAN 500)
Backup VSAN
(VSAN 200)
pwwnT
60.1.2
BRKSAN-3707
Cisco Public
15
OLTP VSAN
(VSAN 100)
SONET/SDH
DWDM
CWDM
IP (Metro Eth)
Remote Backup
VSAN
(VSAN 200)
swwn2
pwwnT
BRKSAN-3707
Cisco Public
16
OLTP VSAN
(VSAN 100)
Transit VSAN
(VSAN 300)
SONET/SDH
DWDM
CWDM
IP (Metro Eth)
swwn2
Backup VSAN
(VSAN 200)
pwwnT
BRKSAN-3707
Cisco Public
17
IVR Summary
Used for Consolidation of Fabric and Sharing of resources
Can Isolate Fabrics when Traversing Data Centers
Recommend use of Transit VSANs over WANs
Persistent DomainID and FCIDs are available for HP-UX and AIX
deployments
BRKSAN-3707
Cisco Public
18
BRKSAN-3707
Cisco Public
19
B
A
BRKSAN-3707
Cisco Public
20
B A
BRKSAN-3707
Cisco Public
B
A
21
Manageability
More FC domains / switches to manage
Shared management of blade switches
between storage and server
administrators
BRKSAN-3707
Cisco Public
22
SAN B
448
MDS 91x4
Number of FC Switches per Fabric
MDS 9148
29
A
B
14 Racks
32 Dual
Attached
Servers per
Rack
BRKSAN-3707
Cisco Public
23
BRKSAN-3707
Cisco Public
24
T11 standard
Assigning multiple FC IDs to a single N_Port
Uses FDISC to get additional FCIDs
Shares the physical port but separate logins
Server
3 Logins
Login1 FCID=1.1.1
FC
FLOGI
FDISC
Login2 FCID=1.2.1
F_Port
FDISC
Login3 FCID=1.2.3
N_Port Controller
3 FCIDs
HBA
BRKSAN-3707
MDS 9000
Cisco Public
25
Domain ID 10
fc1/3
ISL NPIV
NP Link
E
fc1/2
NP
Simplified Management
Fewer FC domains/switches in the fabric
Domain Id 20
Blade/
Fabric
Switch
NPV
F
fc1/1
BRKSAN-3707
Cisco Public
26
BRKSAN-3707
Aggregate multiple
physical/logical logins to the core
switch
Cisco Public
27
SAN B
448
MDS 91x4
Number of FC Switches per Fabric
MDS 9148
A
B
14 Racks
32 Dual
Attached
Servers per
Rack
BRKSAN-3707
Cisco Public
28
Blade 4
Blade 3
Blade 2
Blade 1
Benefit
Optimal uplink bandwidth utilization
Balanced
Load on NP
Links
1
3
2
4
SAN
BRKSAN-3707
Cisco Public
29
Blade 4
Blade 3
Blade 2
Blade 1
X X
NPV
SAN
BRKSAN-3707
Cisco Public
30
F-Port Port
Channel
Storage
Blade System
Blade N
Blade 2
SAN
Blade 1
N-Port
Benefits
F-Port
High-Availability - no disruption if
cable, port, or line cards fail
interface port-channel 1
channel mode active
no shut
interface fc1/1
channel-group 1
No application disruption
interface fc1/2
channel-group 1
BRKSAN-3707
Cisco Public
31
F-Port Trunking
VSAN Consolidation on NP Uplinks
F-Port Trunking
Uplinks carry multiple VSANs
NPV
F-Port Trunking
on
F-Port Channel
Benefits
Core Director
Storage
Blade System
VSAN 1
Blade N
Blade 2
VSAN 2
SAN
Blade 1
VSAN 3
N-Port
F-Port
Interface fc1/1
trunk mode on
trunk allowed-vsan 1-3
Interface port-channel 1
trunk mode on
trunk allowed-vsan 1-3
BRKSAN-3707
Cisco Public
32
Enable NPIV
on SAN Core
BRKSAN-3707
Cisco Public
33
Setup VSAN
Apply the
Configuration
BRKSAN-3707
Cisco Public
34
Nested NPIV
Connecting NPIV Capable Hosts to NPV
NPV-Core Switch
F
NPIV
P1 NP
NPIV
P3 = vP1
vP2
vP3
vP4
BRKSAN-3707
P4 = vP5
vP6
vP7
vP8
2011 Cisco and/or its affiliates. All rights reserved.
Cisco Public
35
Reference
NPV Scalability
Switching
Mode
NPV Mode
42
114
168
114
1,008
684
1,680
1,140
1,008
684
840
570
2,016
1,368
Blade 4
1
3
2
4
Number of Logins
400 Gen1/2
800 Gen 3
2,000
10,000
BRKSAN-3707
Blade 3
Logins
Blade 2
Blade 1
Server Chassis
Cisco Public
SAN
36
NPV Summary
Multiple FCIDs to a single port
NPV is a switch mode, switch acts like an NPIV aggregator
Solves the domain ID explosion
Simplifies fabric management
F-Port Channel provides failover and load-balancing
Wizard setup for simple configuration
BRKSAN-3707
Cisco Public
37
BRKSAN-3707
Cisco Public
38
BRKSAN-3707
Cisco Public
39
Virtual Servers
Email
Web
Print
Control and
Monitor VMs
in the SAN
Zone_Email
vpwwn1
pwwnD1
Zone_Web
vpwwn1
pwwnD1
Zone_Print
vpwwn1
pwwnD1
LUN1(pwwnD1)
vpwwn1 FCID=1.1.1
FC
vpwwn2 FCID=1.1.2
LUN2 (pwwnD2)
F_Port
LUN3(pwwnD3)
vpwwn2 FCID=1.1.3
N_Port Controller
HBA
BRKSAN-3707
MDS 9000
2011 Cisco and/or its affiliates. All rights reserved.
Cisco Public
40
BRKSAN-3707
Cisco Public
41
Blade N
Failed
Blade
Blade 1
HBA/Server
Failure
pwwn2
F Port
NP Port
F Port
SAN Zoning
Change
Zone myZone
member pwwn1
member pwwn2
member pwwnD
SAN
Storage
Array
Configuration
(LUN Masking)
Change
BRKSAN-3707
pwwn1
LUN 0
LUN1
pwwn2
LUN0
LUN2
Cisco Public
42
Cisco FlexAttach
Flexibility for Server Mobility
Blade Server Chassis
pwwn3
pwwn1 pwwn2
Blade N
Blade2
Blade 1
Virtual
pWWNs
NP Port
F Port
No SAN Zoning
Change
Zone myZone
member vpwwn1
member vpwwn2
member pwwnD
SAN
Benefits
Flexibility for Server Mobility - Adds, Moves
and Changes
No SAN re-configuration required
BRKSAN-3707
vpwwn1
LUN 0
LUN1
vpwwn2
LUN0
LUN2
Cisco Public
43
FlexAttach
Rewrites Real pWWN to Virtual Port WWN
Core Switch (MDS or 3rd Party Switch with NPIV Support)
1.
Interface fc1/1 is
FlexAttach enabled and
assigned a port wwn
vpwwn1
2.
3.
pwwn1 FLOGI is
rewritten to use vpwwn1
FLOGI
4.
vpwwn1 FLOGI is
converted to FDISC and
registered with FC Name
Server
Server S1 Is Known by
vpwwn1 in the SAN
F
Port WWN of S1= vpwwn1
NP
NPV
FlexAttach
F fc1/1 vpwwn1
Port WWN of S1 = pwwn1
pwwn1
Server S1
BRKSAN-3707
Cisco Public
44
Blade Server
Blade Server
Blade N
Blade 2
Blade 1
Blade N
Blade 2
Blade 1
No change needed in
SAN or on blades
vpwwn1
NPV
NPV
Zone myZone
member vpwwn1
member vpwwn2
member pwwnD
SAN Core
Storage
BRKSAN-3707
Cisco Public
45
Blade Server
vpwwn1
vpwwn1
fc1/1
Spare
Blade
Blade 2
Blade 1
Blade N
Blade 2
Blade 1
Move to a spare
server
fc5/10
NPV
NPV
Zone myZone
member vpwwn1
member vpwwn2
member pwwnD
Benefit
Flexibility for server mobility
across different Blade
chassis/Racks
Storage
Cisco Public
46
New
Blade
Pre-provision SAN
for ordered
servers
Blade Server
Blade Server
Blade N
Blade 2
Blade 1
vp1
Blade N
.
vp2
NPV
NPV
Storage
BRKSAN-3707
Cisco Public
47
FlexAttach Summary
Virtualize HBA (WWNs) to a switchport
Assigns a virtual WWN to a switchport
Eliminates server and storage admin coordination for changes
Allows flexibility for server moves
Eases replacement of servers and HBAs
Pre-provision SAN ports and storage in advance of servers
BRKSAN-3707
Cisco Public
48
Agenda
SAN Consolidation with Virtualization
Inter-VSAN Routing (IVR)
N-Port Virtualizer (NPV) / NPIV
FlexAttach
BRKSAN-3707
Cisco Public
49
BRKSAN-3707
Cisco Public
50
Classification Criteria
Access Times/Performance
Application Availability
Recovery Time and Point
Cost of Storage
BRKSAN-3707
Cisco Public
51
Onsite
Tier2
Minutes to
Hours
Availability
Onsite CDP
Tier3
Hours to
Day
Availability
Onsite Tape/VTL
OffSite
Tape/VTL
BRKSAN-3707
Cisco Public
Storage Media
Encryption (SME)
52
BRKSAN-3707
Cisco Public
53
Data Migration
Application Servers
Oracle
Clearcase
Exchange
SAN Fabric
How often?
Typically every 3 years upon
lease expiry for a single
Storage Array
Existing
Storage
BRKSAN-3707
New
Storage
Cisco Public
54
Servers
SAN Fabric
Servers
SAN Fabric
Existing
Storage
New
Storage
Server/Software Based
SAN Fabric
Existing
Storage
New
Storage
No additional h/w
No re-wiring
Cons
Cons
New
Storage
Appliance Based
Pros
Pros
Pros
BRKSAN-3707
Existing
Storage
Cons
Virtualizes the source disk
(PWWNs change)
LUN mapping/masking handling
Re-configuration/Reboot of all
hosts accessing this target.
Vendor lock-in
License
Cisco Public
55
Clearcase
Exchange
Advantages
SAN moves the data
Scalable
Referred to as
Cisco MDS Data Mobility Manager [DMM]
Existing
Storage
BRKSAN-3707
New
Storage
Cisco Public
56
SOLARIS1-SRVR
Fabric A
MSM
Fabric B
MSM
Existing
Storage
BRKSAN-3707
New
Storage
Cisco Public
57
SOLARIS1-SRVR
MSM
Existing
Storage
BRKSAN-3707
New
Storage
Cisco Public
58
What Is FC-Redirect?
A target centric re-direct based transport is a
low level infrastructure used for transportation
only
Application Server
FC-Redirect
Traps and
Sends the
Packets to MSM
MSM
MSM Sends
Packets to Both
Old and New
Old Array
Array
BRKSAN-3707
DMM
Programs FCRedirect to
Send Traffic
Destined to
Old Array to
MSM
New Array
Cisco Public
59
BRKSAN-3707
Cisco Public
60
DMM Method 1
The Server has one path to the existing
storage through each Fabric
SOLARIS1-SRVR
SAN B
IP
MSM
MSM
New
Storage
BRKSAN-3707
Cisco Public
61
}
Migrated
Being Migrated
To Be Migrated
Existing
Storage
LUN
BRKSAN-3707
Writes to To Be
Migrated Area Are
Written to Existing
Storage Only
New
Storage
LUN
2011 Cisco and/or its affiliates. All rights reserved.
Cisco Public
62
SOLARIS1-SRVR
SAN A
MSM performs
SAN B
MRL
MRL
MSM
MRL Bitmap
MSM
Existing
Storage
New
Storage
Cisco Public
63
Reads Are
ClearServer
MRL Region
Read from Existing
Storage Only
Multiple Passes of
MRL Done Until All
Regions Are Clear
For Cut-Over Last
MRL Pass Done with
the LUN in the Offline
Mode
Existing
Storage
LUN
BRKSAN-3707
New
Storage
LUN
2011 Cisco and/or its affiliates. All rights reserved.
Cisco Public
64
SOLARIS1-SRVR
SAN A
MRL
MSM
SAN B
MRL
MSM
Existing
Storage
Local
Data Center
FCIP
Cloud
Remote
Data Center
New
Storage
BRKSAN-3707
Cisco Public
65
SOLARIS1-SRVR
SAN B
Replication SAN
Contains Existing/New Storage
Existing
Storage
Replication SAN
New
Storage
BRKSAN-3707
Cisco Public
66
DMM Method 3
3 MSMs per DMM Job
SOLARIS1-SRVR
SAN B
MSM 1
MSM 2
Existing
Storage
MSM 3
Replication SAN
Merged
MRL
Replication SAN
Connected via DWDM links within the same
Metro Area
Cisco Public
67
Deployment Guidelines
Do not add the same initiator/target port pair into more than one migration
job simultaneously.
When using multipath ports, the server must not send simultaneous I/O
write requests to the same LUN from both multipath ports. The first I/O
request must be acknowledged as completed before initiating the second
I/O request.
BRKSAN-3707
Cisco Public
68
BRKSAN-3707
Cisco Public
69
Method 2 - Async
2 SAN topology
Server, Existing/New Storage connected to each SAN and are in the
same VSAN
MRL bitmap tracks Server WRITE I/Os in both SANs
Data Movement performed in one of the SANs
Method 3 Data Center Migration
3 SAN topology : 2 Production SANs and 1 Replication/Migration SAN
Server and Existing Storage connected to the Production SAN
Existing/New Storage connected to Replication/Migration SAN
MRL bitmap tracks Server WRITE I/Os in the Production SAN
Data Movement performed in the Replication SAN
Built on Method 2
BRKSAN-3707
Cisco Public
70
BRKSAN-3707
Cisco Public
71
Key Management
Center (KMC)
TCP/IP
Encrypt
@!$%!%!%!%%^&
Name: XYZ
*&^%$#&%$#$%*!^
SSN: 1234567890
Amount: $123,456
@*%$*^^^^%$@*)
%#*@(*$%%%%#@
Status: Gold
Tape
Devices
BRKSAN-3707
Cisco Public
72
MDS9200
Series
Name: XYZ
SSN: 1234567890
Amount: $123,456
Status: Gold
MDS 9500
Series
Storage Media
Encryption Service
@!$%!%!%!%%^&
*&^%$#&%$#$%*!^
@*%$*^^^^%$@*)
%#*@(*$%%%%#@
Cisco Public
73
MSM-18/4
BRKSAN-3707
Cisco Public
74
Host
MSM-18/4
Modes
Offline
Disk Array
BRKSAN-3707
Cisco Public
75
Wizard-Based Provisioning
BRKSAN-3707
Cisco Public
76
Application Servers
Disk Arrays,
Tape Drives
and VTL
BRKSAN-3707
MSM-18/4
Fabric B
Cisco Public
77
Advanced
Level of Security
Standard
Smart Cards with All Master Keys
No Recovery Shares
Options:
2 of 3
2 of 5
3 of 5
Basic
A file with all master keys
Master keys encrypted with a password
Regular backup and archive
Complexity
BRKSAN-3707
Cisco Public
78
Cisco Key
Management
Center
Tape Volume
Group Key
Tape Key
Tape Key
BRKSAN-3707
Cisco Public
79
BRKSAN-3707
Cisco Public
80
Cisco Public
81
SME Disk
BRKSAN-3707
Cisco Public
82
SME Node
SME Cluster
18+4 MSM/9222i
Fabric B
Fabric A
SME Node
Module 2
SME Node
Module 9
Encryption
Encryption
SME Node
Module 4
SME Node
Module 8
EMC1454-ES
BRKSAN-3707
Cisco Public
83
SRVR2
Disk1,Disk 2,Disk3,Disk4
Multiple accessible paths [I,T,L]
HB HC
HA
HD
Fabric B
SME Node
Disk Group
Disk 1
Disk 3
Disk 2
Disk 4
Storage Array
BRKSAN-3707
Cisco Public
84
LUN Key
Cisco Public
85
As per design and implementation (pending testing) SME Tape and SME Disk should
be able to co-exist in the same SME cluster with the following underlying
understanding:
SME tape backup group and SME diskgroup share the same name space, i.e. a disk group cannot have the
same name as tape backup group name
An IT nexus will either have all tape devices or all disk devices
BRKSAN-3707
Cisco Public
86
N+1 availability; in case of a failure, any available engines in the fabric picks up the
load
BRKSAN-3707
Cisco Public
87
Key Management
Integrated free key management solution as well as support for external enterprise
key manager
BRKSAN-3707
Cisco Public
88
SANTap
BRKSAN-3707
Cisco Public
89
SANTap
Enables appliance-based
storage applications without
compromising SAN integrity
Initiator
SAN
Copy of
Primary
I/O
Appliance
= SAN Tap
BRKSAN-3707
Cisco Public
90
Ease of Deployment
MDS9200
Series
MDS 9500
Series
SANTap Service
Appliance
Initiator
Target
BRKSAN-3707
Cisco Public
91
SANTap at Work
SANTap mirrors
write I/Os to RPA
Host VSAN
RecoverPoint
Appliance
RecoverPoint
Appliance
WAN
Remote Site
Local Site
SAN
Target VSAN
LUN
Production
LUN
BRKSAN-3707
Local
CDP
Copy
Local
CDP
Journal
Cisco Public
I/O integrity
I/O availability
I/O performance
92
SANTap Configuration
Host pWWN =
10:00:00:00:c9:a5:a6
DVT pWWN =
50:00:1f:e1:50:3b:09
Host
VSAN
Copy of
Primary
I/O
Target
VSAN
Appliance
Host VI pWWN =
10:00:00:00:c9:a5:a6
Target pWWN =
50:00:1f:e1:50:3b:09
= SAN Tap
BRKSAN-3707
Cisco Public
93
Host
Host
LOCAL FLOW
1.
Write I/O is sent to MSM module
2.
Write I/O is then forward to both local Storage Array
and local Appliance
3.
Both local Storage Array and local Appliance
acknowledge Write I/O back to the MSM
4.
Once MSM receives both acknowledgements, then
sends acknowledgment to Application Server
SANTap
SANTap
WAN
2
Array
BRKSAN-3707
Appliance
Appliance
REMOTE FLOW
1.
I/O is sent through the WAN to remote Appliance
2.
I/O is then sent to replication LUN(s) through the MSM
3.
I/O is then acknowledged back to the Remote
Appliance
4.
Remote Appliance then sends acknowledgement
back to Primary Data Center Appliance through the
WAN
2011 Cisco and/or its affiliates. All rights reserved.
Cisco Public
Array
94
SANTap Summary
Appliance-based storage application
MDS deliver a copy of I/O to the appliance
Enables Continuous Data Protection and Recovery
Copy of I/O is not in primary data path
No SAN re-wiring or reconfiguration required to implement
BRKSAN-3707
Cisco Public
95
Agenda
SAN Consolidation with Virtualization
Inter-VSAN Routing (IVR)
N-Port Virtualizer (NPV) / NPIV
FlexAttach
BRKSAN-3707
Cisco Public
96
FCoE
BRKSAN-3707
Cisco Public
97
Incremental Implementation
Start at the Edge
BRKSAN-3707
Cisco Public
98
SAN B
10GE
Backbone
10GE
4/8 Gbps FC
BRKSAN-3707
Cisco Public
99
SAN B
10GE
Backbone
Nexus
10GE FCoE
10GE
4/8 Gbps FC
BRKSAN-3707
Cisco Public
100
Session Summary
SAN Consolidation with Virtualization
Inter-VSAN Routing (IVR)
N-Port Virtualizer (NPV) / NPIV
FlexAttach
BRKSAN-3707
Cisco Public
101
Q&A
BRKSAN-3707
Cisco Public
102
Other Sessions
BRKSAN-1121: SAN Core Edge Design Best Practices
BRKSAN-2047: FCOE Design, Operation, and Management Best
Practices
BRKSAN-3707
Cisco Public
103
Additional Information
Cisco Storage Networking
http://www.cisco.com/go/storagenetworking
BRKSAN-3707
Cisco Public
104
Recommended Reading
Continue your Cisco Live learning
experience with further reading from
Cisco Press
Check the Recommended Reading
flyer for suggested books
Cisco Public
105
BRKSAN-3707
Cisco Public
106
BRKSAN-3707
Cisco Public
107
BRKSAN-3707
Cisco Public
108
Thank you.
BRKSAN-3707
Cisco Public
109