Announcement Banner
UNSOLVED

V_M_Ramkumar

updated

13 years ago

V

V_M_Ramkumar

1 Rookie

•

97 Posts

0

6350

May 27th, 2013 23:00

Mapping and Masking

In symmetrix i have a small doubt. Why Mapping and Why Masking. what it actually does. what is the difference between them in functionality.

  • Vipin VK

    2 Intern

    •

    812 Posts

    2187

    0

    Posted May 28th, 2013 00:00

    you will find similar posts in community as one below.

    Difference between device masking and mapping

    In short, Masking  is the way you define which WWN (HBA's ) will be able to access the LUNs mentioned

    and Mapping is the way you define through which FA port the LUNs will be available

  • V_M_Ramkumar

    1 Rookie

    •

    97 Posts

    2194

    0

    Posted May 28th, 2013 00:00

    so Mapping is for Connecting lun and HBA

    and masking is for security.

    is that right?

  • V_M_Ramkumar

    1 Rookie

    •

    97 Posts

    2194

    0

    Posted May 28th, 2013 00:00

    In clarrion we do masking as separate task and mapping as separate task and then configure in iscsi software.

    I believe in symmetrix we dont do these stuffs. is that right?

  • Zikas

    278 Posts

    2194

    0

    Posted May 28th, 2013 00:00

    Hi ramkumar,

    is that a question or you were thinking loud?

    Do you want to know the difference between map and mask?

    Map is when we provision a device to a specific FA/FAs and a specific port/ports with a unique available address on the FA/FAs.

    Mask is when we "isolate" a device to be viewed by a host/hosts ONLY

  • 2194

    0

    Posted May 28th, 2013 01:00

    v.m.ramkumar wrote:

    so Mapping is for Connecting lun and HBA

    and masking is for security.

    is that right?

    Security is already enabled on Symmetrix (ACLX) and it prevents all LUNs except ACLX or VCM devices to be seen on the initiators. By masking, you allow a LUN to be visible on the initiators.

    regards,

    Saurabh

  • V_M_Ramkumar

    1 Rookie

    •

    97 Posts

    2194

    0

    Posted May 28th, 2013 01:00

    Hi Yankees,

    i disagree with this. as per your explaination. i would say allowing masking only for particular HBA and giving access is northing but security

  • Zikas

    278 Posts

    2194

    0

    Posted May 28th, 2013 01:00

    Hi ramkumar,

    as Saurabh said security is something different and has nothing to do with masking.

    By masking a device to a WWN/HBA, you define that this device will be visible and accessed only by this WWN/HBA.

  • V_M_Ramkumar

    1 Rookie

    •

    97 Posts

    2194

    0

    Posted May 28th, 2013 01:00

    hi saurabh,

    can u elaborate ACLX and VCM stands for?

  • Avinash V

    91 Posts

    2194

    0

    Posted May 28th, 2013 02:00

    On Vmax we call them as ACLX

    On DMX we call them as VCM.

    There is one device created on the symmetrix array which is set with VCM flag during initial setup.

    You can check this with # symdev list -vcm (Solutions enabler needs to be installed to run this command)

    VCM and ACLX devices do not need to be masked. If a host is zoned to an FA that has VCM/ACLX device mapped to it, it will show up on the host automatically.

    For doing any masking or mapping, solutions enabler needs a device to send low level SCSI commands to the symmetrix array. Normally this is achieved by assigning GK devices to the host.

    How do you create a GK devices, when you cannot run SE command (as said SE needs atleast a device from symm to send the commands)

    When a brand new Symmetrix is bought, CE usually would map the VCM/ACLX devices to the FA. Whichever hosts are zoned to the FA can see this device.

    As this point, customer would see this VCM device on the host.

    This VCM device would help customer to run SE command to create/map/mask 5-6 GK devices(size 3 MB).

    After the initial setup is done, you can unmap the VCM/ACLX device.(this is after enguinity 5771 and above).

    You can unmap the VCM/ACLX, since this devices would be visible to all the host that is zoned to an FA that has VCM/ACLX device mapped to it. This is only after your Management host is having enough GK devices to perform SE operation.

    In old Enguinity VCMDB(masking database) used to reside on VCM device.

    As you seem to be well versed with Clariion, it something like LUNZ.

  • Zikas

    278 Posts

    283

    0

    Posted May 28th, 2013 03:00

    Hi Ramkumar,

    as i told you by masking a device to a specific HBA, you "oblige" it to be seen/viewed only by this HBA.

    I don't know if this you can call it security.

    Security for myself is Symmetrix Access Control, Symauth etc.

    Masking operations allow for the restriction of access for a giver WWN to mapped devices regardless of the physical or zoned connectivity in the environment.

    Masking records define which WWN is allowed to acees which Symmetrix devices on which director ports. Masking operations also allow for the modification of LUN addresses as seen by the host to provide a more predictable, uniform approach.