N_Port ID virtualization (NPIV)

By default, all subchannels on an FCP channel path use the same local WWPN to access the fibre channel link. This means that SAN zoning and LUN masking cannot be used to manage the access rights of the individual subchannels. In this mode, only one subchannel on the channel path may establish a connection to a particular remote WWPN and LUN at a time. Permission to connect is granted on a first-come, first-served basis to any subchannel on the channel path.

N_Port ID Virtualization (NPIV) is an industry-standard way to address this security issue. When NPIV is used, each subchannel is assigned a unique local WWPN that it uses when the subchannel logs into the SAN. The subchannel will be assigned a unique 3-byte fibre channel ID by the SAN and have all the attributes of a separate physical fibre channel adapter. Consequently, each subchannel appears as a different initiator to the SAN and target devices enabling the use of SAN zoning and LUN masking access controls.

The NPIV mode of operation is not permitted in a point-to-point configuration.

When an FCP channel is shared among multiple partitions, the use of NPIV is configured separately for each partition.

Because NPIV places additional resource requirements on both the SAN and the channel, IBM recommends that the number of active subchannels on a single FCP channel be limited to a value significantly lower than the configurable subchannel maximum. Care should be taken when defining the SAN zone, as each NPIV subchannel will register for state-change notifications, significantly increasing the number of messages the fabric must generate when a zone member goes through recovery, loses a link, or logs in or out of the SAN. This and other recommended operational limits can be found in Table 6. Exceeding these limits may lead to inaccessible devices during error recovery scenarios.