Skip to main content

IBM Fibre Channel Endpoint Security for IBM DS8000 and IBM Z

A draft IBM Redbooks publication

thumbnail 

Last updated on 07 July 2026

  1. .PDF (7.1 MB)

Share this page:   

IBM Form #: SG24-8455-01


Authors: Bertrand Dufrasne, Vasfi Gucer, Roger Hathorn, Matthew Houzenga, Jacob Sheppard, Robert Tondini and Alexander Warmuth

    menu icon

    Abstract

    This IBM Redbooks® publication provides comprehensive guidance on installing, configuring, and utilizing IBM Fibre Channel Endpoint Security (IFCES). The primary focus of this publication centers on securing critical Fibre Channel connections between IBM Z host servers and IBM DS8000 storage systems that support the IFCES framework.

    IFCES establishes a trusted storage network by delivering two distinct layers of Fibre Channel link protection: link authentication and data-in-flight encryption. Enabling link encryption automatically enforces link authentication protocols.

    This end-to-end security solution is explicitly engineered for enterprises that must strictly comply with the Payment Card Industry Data Security Standard (PCI DSS) and other stringent regulatory frameworks. as well as organizations seeking to eliminate the risk of unauthorized access or data interception across the storage area network.

    This publication is intended for IBM Z and IBM Storage architects, storage administrators, security specialists, systems programmers, implementation consultants, and support professionals who design, deploy, secure, and manage DS8000 storage environments using IFCES.

    Table of Contents

    Chapter 1. Introducing IBM Fibre Channel Endpoint Security

    Chapter 2. IBM Fibre Channel Endpoint Security solution design

    Chapter 3. Endpoint Security requirements and planning

    Chapter 4. Implementation

    Chapter 5. Monitoring and maintaining the Endpoint Security environment

    Chapter 6. Managing certificates

     

    Special Notices

    The material included in this document is in DRAFT form and is provided 'as is' without warranty of any kind. IBM is not responsible for the accuracy or completeness of the material, and may update the document at any time. The final, published document may not include any, or all, of the material included herein. Client assumes all risks associated with Client's use of this document.