Global Storage

Global Storage Forum

Connect, collaborate, and stay informed with insights from across Storage

 View Only
  • 1.  Security of Data During iSCSI-Based Storage Virtualize Migration

    Posted 6 days ago

    Hi Team,

    We are planning to use an IBM FlashSystem 7300 operating as a Spectrum Virtualize/SVC layer to virtualize an IBM V5030 as external storage.

    The V5030 storage will be connected to the FS7300 using iSCSI over an IP/WAN network. The existing volumes will be imported as image-mode volumes and then migrated to native FS7300 managed storage.

    Our customer has a security concern regarding the confidentiality of data while the data is transferred from the V5030 to the FS7300 during the migration.

    Could IBM please clarify:

    Is the data transferred between the V5030 external iSCSI storage and the FS7300/SVC encrypted in transit during image-mode migration? If not, what is the IBM-supported security mechanism for protecting the confidentiality of the data during this migration?

    We would appreciate IBM's guidance on the supported security architecture for this scenario.

    Thanks & Regards
    Sandeep Sharma



    ------------------------------
    SANDEEP SHARMA
    ------------------------------


  • 2.  RE: Security of Data During iSCSI-Based Storage Virtualize Migration

    Posted 5 days ago

    Hi Sandeep

    Short answer
    No image-mode import and migration do not inherently encrypt the data in transit between the V5030 and FlashSystem 7300. The migration is block I/O: FlashSystem/Spectrum Virtualize reads blocks from the externally virtualized V5030 volume over the backend iSCSI path and writes them to its managed storage.
     
    With a normal iSCSI configuration, the payload should be treated as unencrypted on the network.
     
    CHAP can authenticate the iSCSI initiator and target, but it does not encrypt SCSI data.
    VLANs, isolated storage networks, and ACLs limit access/exposure but do not provide cryptographic confidentiality.
    Encryption at rest on either the V5030 or FS7300 does not encrypt data while it is being read across the iSCSI connection.
    IBM documentation confirms that FlashSystem 7300 supports iSCSI-attached external storage (manually added for virtualization), but that capability alone should not be interpreted as encrypted backend transport. IBM FlashSystem external storage documentation
     
    Recommended security architecture
    For a V5030-to-FS7300 connection traversing an IP/WAN network, protect the entire backend iSCSI transport path with an independently provided, cryptographic network layer, for example:
     
    Site-to-site IPsec encryption supplied by network/security gateways at each site; or
    A provider-managed encrypted WAN service; or
    MACsec only where it is available end-to-end across every Ethernet segment carrying the iSCSI traffic.
    The encryption solution must be transparent to the storage arrays and must cover:
     
    every FS7300 node-to-V5030 iSCSI path;
    all redundant/failover paths;
    the full route between sites-not merely one LAN segment;
    routing behavior during failure, so traffic cannot fail over to an unencrypted route.
    In parallel, use defense-in-depth controls:
     
    dedicated iSCSI VLANs/subnets and non-routable segmentation where possible;
    restricted firewall/ACL rules between only the required source and target IPs;
    iSCSI CHAP/mutual CHAP where supported and appropriate;
    dedicated storage-network interfaces;
    separate, secured management-network access.
    Important support and design qualification
    I would not position an IPsec gateway, WAN encryption appliance, or MACsec design as "IBM-supported" without IBM validating the exact topology. The key question is not whether IPsec exists in the network; it is whether the resulting connectivity still meets IBM's supported external-iSCSI requirements, including latency, MTU, packet loss, multipathing, failover, and performance characteristics.
     
    This is especially important for a WAN design: backend storage I/O and image-mode migration are highly sensitive to latency and instability. A security overlay can also introduce MTU/fragmentation and throughput constraints.
     
    Recommended IBM support request
    Ask IBM Storage Support or the IBM account technical team to confirm the following in writing for the precise FS7300 Storage Virtualize level and V5030 software level:
     
    Please confirm whether FlashSystem 7300 running IBM Storage Virtualize provides payload encryption for backend iSCSI traffic when virtualizing a V5030 as external storage and migrating image-mode volumes to native managed storage.
     
    We understand that CHAP provides endpoint authentication rather than encryption. Please confirm whether any native IBM-supported IPsec or equivalent encryption capability applies specifically to this backend external-storage iSCSI path.
     
    If native payload encryption is not available, please confirm whether an externally provided, transparent site-to-site IPsec/WAN-encryption solution is supported for this topology, and provide the applicable requirements or limits for:
     
    latency, bandwidth, packet loss, and jitter;
    MTU/jumbo-frame handling after encryption encapsulation;
    multipathing and failover;
    all FS7300-node-to-V5030 paths;
    image-mode migration and sustained production I/O.
    Practical conclusion
    Until IBM confirms otherwise for the exact release levels and topology, the safe security assumption is:
     
    The FS7300 image-mode migration process does not itself provide encryption in transit for iSCSI reads from the V5030.
    If confidentiality across the IP/WAN is required, the customer must provide an approved encrypted network path around the iSCSI connection, and IBM should validate that architecture for supportability.



    ------------------------------
    Kenneth Ditmar Hansen
    Senior Storage specialist
    TDsynnex
    Birkerød
    40703827
    ------------------------------