The present invention provides a system and a method for filtering a
plurality of frames sent between devices coupled to a fabric by Fibre
Channel connections. Frames are reviewed against a set of individual
frame filters. Each frame filter is associated with an action, and
actions selected by filter matches are prioritized. Groups of devices are
"zoned" together and frame filtering ensures that restrictions placed
upon communications between devices within the same zone are enforced.
Zone group filtering is also used to prevent devices not within the same
zone from communicating. Zoning may also be used to create LUN-level
zones, protocol zones, and access control zones. In addition, individual
frame filters may be created that reference selected portions of frame
header or frame payload fields.