The present invention provides a system and a method for filtering a
plurality of frames sent between devices coupled to a fabric by Fiber
Channel connections. Frames are reviewed against a set of individual
frame filters. Each frame filter is associated with an action, and
actions selected by filter matches are prioritized. Groups of devices are
"zoned" together and frame filtering ensures that restrictions placed
upon communications between devices within the same zone are enforced.
Zone group filtering is also used to prevent devices not within the same
zone from communicating. Zoning may also be used to create LUN-level and
extent-level zones, protocol zones, and access control zones. In
addition, individual frame filters may be created that reference selected
portions of frame header or frame payload fields.