In a standard IP network the delay of packets to and from an application or browser is unlikely to cause an issue.The same cannot be said for storage where a consistent response time and guaranteed delivery is essential for providing transparent disk I/O. Isolating IP and iSCSI traffic will help to reduce the potential impact to storage performance of unpredictable traffic.
Considering security, iSCSI can be run in a completely open fashion. Data packets can be visible on the network for anyone with a standard piece of software such as Ethereal. To counter this, iSCSI offers server/target validation and the suggested use of IPsec to encrypt traffic, which inevitably adds to the CPU load on both server and storage. Isolating iSCSI hosts from a physical perspective improves security and provides the choice as to whether IPsec needs to be used.
Taking the above points into consideration, a customer may choose to completely isolate iSCSI traffic into separate switches or to provide dedicated VLANs for iSCSI connections. Both approaches help to mitigate against performance and security issues and give the added benefit of making problem resolution easier to achieve.
Dig Deeper on Storage Area Network (SAN)
Related Q&A from Retired Expert - Chris Evans
Storage area network (SAN) management reliability and uptime can be enhanced by incorporating good architecture.continue reading
Learn how to use NAS to provide storage for a Web server.continue reading
Leveraging network-attached storage (NAS) properly can provide opportunities for VARs to create recurring revenue streams and build long-lasting ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.