Cisco MDS Fibre Channel Zoning and VSAN Configuration - 夜莺博客

Cisco MDS Fibre Channel Zoning and VSAN Configuration

Fibre Channel zoning is the SAN equivalent of an access control list: it decides which host ports may talk to which storage ports inside a fabric. Get it wrong and either a server cannot see its LUNs or, worse, a host logs into storage it was never provisioned for. On Cisco MDS 9000 switches the work happens in three layers — VSANs for fabric isolation, aliases for readable names, and zones/zonesets for the access rules themselves. This guide walks the full sequence and the verification commands that prove the fabric is compliant.

VSANs First, Zones Second

A VSAN is a logical fabric carved out of the physical switches. Every protocol instance — FSPF, domain manager, name server and zoning database — runs independently inside each VSAN, and no zone can cross a VSAN boundary. Production designs routinely separate a fabric into an A VSAN and a B VSAN for multipathing, plus extra VSANs for replication or tape traffic. Ports must be members of a VSAN before any zoning matters.

switch# config terminal
switch(config)# vsan database
switch(config-vsan-db)# vsan 10
switch(config-vsan-db)# vsan 10 interface fc1/1 - 8
switch(config-vsan-db)# vsan 10 name PROD-A
switch(config-vsan-db)# exit
switch(config)# show vsan membership
switch(config)# show vsan 10

Fcaliases Make Zones Readable

Zones become unmaintainable when every member is a raw hex pWWN. Define an fcalias per device port — or use device-alias, which is distributed fabric-wide through CFS — and zone members reference the alias instead.

switch(config)# device-alias database
switch(config-device-alias-db)# device-alias name esxi01-hba0 pwwn 20:00:00:25:b5:01:00:0a
switch(config-device-alias-db)# device-alias name array01-sp-a pwwn 50:00:14:40:5b:01:00:01
switch(config-device-alias-db)# device-alias commit
switch(config)# show device-alias database

Build Zones and a Zoneset

switch(config)# zone name ESXI01-ARRAY01 vsan 10
switch(config-zone)# member device-alias esxi01-hba0
switch(config-zone)# member device-alias array01-sp-a
switch(config-zone)# exit

switch(config)# zoneset name PROD-ZONESET vsan 10
switch(config-zoneset)# member ESXI01-ARRAY01
switch(config-zoneset)# exit

! activate fabric-wide (only the active zoneset is enforced and distributed)
switch(config)# zoneset activate name PROD-ZONESET vsan 10
switch(config)# zone commit vsan 10

Zoning is enforced by default (hard zoning on the MDS platform), name server queries are soft-zoned, and unzoned devices cannot talk to each other. Multiple zones may overlap by design, but a member must be in an active zoneset for the rule to take effect.

Verify Before You Walk Away

show zoneset active vsan 10
show zone active vsan 10
show zoneset brief vsan 10
show flogi database vsan 10
show fcns database vsan 10
show interface fc1/1 | include vsan
show device-alias database

Cross-check the show zone active output against show flogi database: every host pWWN that appears in the FLOGI table must be present in at least one active zone together with exactly the storage ports it is entitled to reach. A host missing from the zone-active output but present in FLOGI is a zoning omission; the reverse — a zone referencing a pWWN that never logs in — usually means a cable, SFP or HBA problem rather than a zoning error.

Safe Change Practice

  • Take a configuration backup (copy running-config startup-config and a remote copy) before activating a new zoneset; a bad zoneset can remove production LUN visibility instantly.
  • Add one host at a time and verify the initiator logs in and paths stay online from the OS side (multipath tools report the path state).
  • Never edit the active zoneset in place — copy it, change the copy, activate it, then clean up the old one.
  • Keep a single source of truth for WWN-to-hostname mapping; drift between the SAN and the CMDB is the root cause of most "wrong zone" incidents.

Related reading: SAN HBA queue depth and multipath tuning, ONTAP fpolicy configuration, and Dell/Brocade switch commands worth knowing.

原文链接:https://www.cisco.com/c/en/us/td/docs/switches/datacenter/mds9000/sw/8_x/config/fabric/cisco_mds9000_fabric_config_guide_8x.pdf