Home > Storage Magazine > Features > Secure iSCSI storage
EMAIL THIS
Storage Magazine

  CURRENT ISSUE  

  FEATURES  

  TOOLS, TRENDS & ANALYSIS  

  COLUMNS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

Secure iSCSI storage
Issue: May 2007
printer-friendly
< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   7  |   8  |   NEXT PAGE  >

Snooping iSCSI packets
Snooping the contents of iSCSI packets, one of the first threats people mention when asked about iSCSI security issues, is less likely to occur than other types of attacks. An IP SAN with no security controls will probably run on a switched Ethernet network. Switches create point-to-point paths for data, so each port sees only the traffic intended for it. To snoop on iSCSI traffic requires some sort of advanced sniffer function to send all traffic to your port, which would require administrative access to the Ethernet switch.

There are many options to protect data in motion over the network. IPsec Encapsulating Security Payload, for example, provides advanced authentication of each packet, effectively eliminating the possibility that someone could read data while it travels across the network. And if stronger encryption is required, it's possible to replace the standard encryption protocols used by IPsec with a more powe...



rful alternative.

Another option is to use an encrypting file system on the server to encrypt data before it gets to the IP SAN. This effectively encrypts data in motion as well as data at rest because no data leaves the server unencrypted. It also prevents all sorts of man-in-the-middle attacks on the network because any tampering with the content interferes with the server's ability to read the data. The downside of using an encrypting file system is the impact it can have on server performance. Even a powerful server can see a noticeable performance hit when using this type of encryption technology.

A VPN creates a point-to-point encrypted tunnel between secure networks. The use of VPN technology should be a requirement whenever sensitive data travels across an uncontrolled network. The Town of Vail relies on an encrypted VPN tunnel for replication to a disaster recovery site, leveraging an existing WAN connection for its daily synchronization.

< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   7  |   8  |   NEXT PAGE  >





TechTarget Storage Media
Storage Magazine View this month\\'s issue and subscribe today.
Storage Decisions Apply online for free conference admission.
SearchStorage.com
HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts