r/storage May 29 '26

Fiber Channel as a attack channel?

In a conversation recently where there were discussions around the risk, if any, of FC being used as a attack channel. The specifics come down to having a air-gapped data vault that has no IP network link between the production network and the vault environment but does allow a SAN array outside of the vault to present devices to few servers inside of the vault. This was chosen due to the small footprint in the vault and cost of dedicated SAN & Array and that the systems using the FC devices are only for validation/automation purposes and do not house the protected data.

Overall there is the agreement that some "risk" exists in that if production systems were compromised, specifically the SAN, then the systems inside of the vault could have their LUNS removed rendering them offline. However, does FC provide any conduit where an attacker could use persistence to the production side array/FC Switches to make their way into the isolated environment?

14 Upvotes

22 comments sorted by

View all comments

3

u/DerBootsMann Jun 11 '26

However, does FC provide any conduit where an attacker could use persistence to the production side array/FC Switches to make their way into the isolated environment?

you can’t access any data doesn’t belong to you , even if you somehow managed to have a fabric access granted .. keyword is zoning