The SNIA Networking Storage Forum (NSF) had an outstanding response to our live webinar, “NVMe/TCP: Performance, Deployment, and Automation.” If you missed the session, you can watch it on-demand and download a copy of the presentation slides at the SNIA Educational Library. Our live audience gave the presentation a 4.9 rating on a scale of 1-5, and they asked a lot of detailed questions, which our presenter, Erik Smith, Vice Chair of SNIA NSF, has answered here.
Q: Does the Centralized Discovery Controller (CDC) layer also provide drive access control or is it simply for discovery of drives visible on the network?
A: As defined in TP8010, the CDC only provides transport layer discovery. In other words, the CDC will allow a host to discover transport layer information (IP, Port, NQN) about the subsystem ports (on the array) that each host has been allowed to communicate with. Provisioning storage volumes to a particular host is additional functionality that COULD be added to an implementation of the CDC. (e.g., Dell has a CDC implementation that we refer to as SmartFabric Storage Software (SFSS).
Q: Can you provide some examples of companies that provide CDC and drive access control functionalities?
A: To the best of my knowledge the only CDC implementation currently available is Dell’s SFSS.
Q: You addressed the authentication piece of the security picture, but what about the other half – encryption. Are there encryption solutions available or in the works?
A: I was running out of time and flew through that section. Both Authentication (DH-HMAC-CHAP) and Secure Channels (TLS 1.3) may be used per the specification. Dell does not support either of these yet, but we are working on it.
Q: I believe NVMe/Fibre Channel is widely deployed as well. Is that true?
A: Not based on what I’m seeing. NVMe/FC has been around for a while, it works well and Dell does support it. However, adoption has been slow. Again, based on what I’m seeing, NVMe/TCP seems to be gaining more traction.
Q: Is nvme-stas an “in-box” solution, EPEL solution, or prototype solution?
A: It currently depends on the distro.
- SLES 15 SP4 and SP5 – Inbox
- RHEL 9.X – Inbox (Tech Preview) [RHEL 8.X: not available]
- Ubuntu 22.04 – Universe (Community support)
Leave a Reply