CryptoStor Protects FC SANs Over WANs

CryptoStor Protects FC SANs Over WANs

Written By
Henry Baltazar
Henry Baltazar
Mar 21, 2005
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

NeoScale Systems Inc.s CryptoStor SAN VPN is the first VPN on the market designed to protect Fibre Channel storage area network traffic over WAN links.

As with many other storage security products, the $40,000 CryptoStor SAN VPN appliance is designed to help companies achieve compliance with regulatory mandates and reduce liability. Its true that Fibre Channel networks are not targeted by hackers as often as IP networks are. However, as SANs become larger and more commonplace, Fibre Channel will become a bigger target, and products such as CryptoStor SAN VPN will be necessary.

/zimages/2/28571.gifClick hereto read about systems that allow organizations to extend file services and SANs over WANs.

CryptoStor SAN VPN, which started shipping at the end of last year, is geared primarily for high-end enterprises that must support synchronous mirroring between their data centers and their remote sites. The protection provided by the CryptoStor SAN VPN will allow IT managers to use public MANs (metropolitan area networks) without the threat of eavesdropping.

The CryptoStor SAN VPN protects Fibre Channel traffic in transit using the Fibre Channel Security protocol, which integrates IP Security into Fibre Channel. NeoScale Systems implementation of FCSec (there currently is no standard for the protocol) is used to create an encrypted tunnel between CryptoStor SAN VPN units without altering the FCSec protocol.

The CryptoStor SAN VPN uses AES (Advanced Encryption Standard)-256 and IKE (Internet Key Exchange) to rotate keys.

During tests, eWEEK Labs found it fairly easy to set up the CryptoStor SAN VPN. Two units (one on each side of the WAN) must be used to form the tunnel.

Once keys are synchronized between the two VPN units, the traffic that runs between the units is encrypted. The Fibre Channel traffic is decrypted at the second VPN, so its not apparent that information traveled over the WAN encrypted. The device is programmed to destroy the security keys if an attempt is made to break into the chassis.

The CryptoStor SAN VPN compresses data to optimize WAN performance. The device also has a large number of Fibre Channel cache buffers, which allow it to extend the range of SAN links—2G-bps throughput across 230 kilometers and 1G-bps throughput across 460km.

/zimages/2/28571.gifCheck out eWEEK.coms for the latest news, reviews and analysis on enterprise and small business storage hardware and software.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.