{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/",
        "slug": "dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/"
        },
        "title": "Account for both virtual Fibre Channel WWN sets before live migration",
        "summary": "What Fibre Channel identity should be reviewed before migrating a VM with a virtual HBA?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:15:14+00:00",
        "modified_at": "2026-09-08T18:23:27+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 204,
        "potentially_affected": "Administrators connecting Hyper-V guests directly to Fibre Channel storage.",
        "dse_recommendation": "Create a mapping of the adapter’s two WWN sets to the authorized storage presentation on both hosts.",
        "primary_source": {
            "name": "Hyper-V Virtual Fibre Channel in Windows Server",
            "url": "https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/plan/virtual-fibre-channel-for-hyper-v",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Hyper-V virtual Fibre Channel gives a guest direct SAN access using a VM-associated World Wide Name. It relies on NPIV: starting a VM with a virtual HBA creates an NPIV port on the host, and stopping the VM removes it. The topology and SAN must support those ports. For live migration, each virtual adapter has two WWN sets and Hyper-V alternates between them. <a href=\"https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/plan/virtual-fibre-channel-for-hyper-v\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the guest workload, virtual HBA, physical ports, SAN, supported topology, and intended migration hosts. Review the complete platform requirements before adapting a virtual Fibre Channel example.</p>\n<h2>DSE recommendation</h2>\n<p>Create a mapping of the adapter’s two WWN sets to the authorized storage presentation on both hosts. Have the SAN owner review the mapping and confirm the intended LUN access. Include a maintenance and recovery decision for the workload before exercising a migration.</p>\n<h2>Verification</h2>\n<p>Validate guest storage access on the source host and after an approved migration to the destination. Record the active WWN identity and the LUNs actually visible at each step. Test the planned return move and investigate missing storage or unexpected access before authorizing routine migration of that workload.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/plan/virtual-fibre-channel-for-hyper-v\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Hyper-V Virtual Fibre Channel in Windows Server</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nHyper-V virtual Fibre Channel gives a guest direct SAN access using a VM-associated World Wide Name. It relies on NPIV: starting a VM with a virtual HBA creates an NPIV port on the host, and stopping the VM removes it. The topology and SAN must support those ports. For live migration, each virtual adapter has two WWN sets and Hyper-V alternates between them. Microsoft documentation.\nApplicability\nIdentify the guest workload, virtual HBA, physical ports, SAN, supported topology, and intended migration hosts. Review the complete platform requirements before adapting a virtual Fibre Channel example.\nDSE recommendation\nCreate a mapping of the adapter’s two WWN sets to the authorized storage presentation on both hosts. Have the SAN owner review the mapping and confirm the intended LUN access. Include a maintenance and recovery decision for the workload before exercising a migration.\nVerification\nValidate guest storage access on the source host and after an approved migration to the destination. Record the active WWN identity and the LUNs actually visible at each step. Test the planned return move and investigate missing storage or unexpected access before authorizing routine migration of that workload.\nOfficial references\nMicrosoft Learn: Hyper-V Virtual Fibre Channel in Windows Server. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nHyper-V virtual Fibre Channel gives a guest direct SAN access using a VM-associated World Wide Name. It relies on NPIV: starting a VM with a virtual HBA creates an NPIV port on the host, and stopping the VM removes it. The topology and SAN must support those ports. For live migration, each virtual adapter has two WWN sets and Hyper-V alternates between them. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/plan/virtual-fibre-channel-for-hyper-v).\n\n## Applicability\n\nIdentify the guest workload, virtual HBA, physical ports, SAN, supported topology, and intended migration hosts. Review the complete platform requirements before adapting a virtual Fibre Channel example.\n\n## DSE recommendation\n\nCreate a mapping of the adapter’s two WWN sets to the authorized storage presentation on both hosts. Have the SAN owner review the mapping and confirm the intended LUN access. Include a maintenance and recovery decision for the workload before exercising a migration.\n\n## Verification\n\nValidate guest storage access on the source host and after an approved migration to the destination. Record the active WWN identity and the LUNs actually visible at each step. Test the planned return move and investigate missing storage or unexpected access before authorizing routine migration of that workload.\n\n## Official references\n\n[Microsoft Learn: Hyper-V Virtual Fibre Channel in Windows Server](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/plan/virtual-fibre-channel-for-hyper-v). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Account for both virtual Fibre Channel WWN sets before live migration",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/",
                "headline": "Account for both virtual Fibre Channel WWN sets before live migration",
                "description": "What Fibre Channel identity should be reviewed before migrating a VM with a virtual HBA?",
                "abstract": "What Fibre Channel identity should be reviewed before migrating a VM with a virtual HBA?",
                "articleBody": "Source facts\nHyper-V virtual Fibre Channel gives a guest direct SAN access using a VM-associated World Wide Name. It relies on NPIV: starting a VM with a virtual HBA creates an NPIV port on the host, and stopping the VM removes it. The topology and SAN must support those ports. For live migration, each virtual adapter has two WWN sets and Hyper-V alternates between them. Microsoft documentation.\nApplicability\nIdentify the guest workload, virtual HBA, physical ports, SAN, supported topology, and intended migration hosts. Review the complete platform requirements before adapting a virtual Fibre Channel example.\nDSE recommendation\nCreate a mapping of the adapter’s two WWN sets to the authorized storage presentation on both hosts. Have the SAN owner review the mapping and confirm the intended LUN access. Include a maintenance and recovery decision for the workload before exercising a migration.\nVerification\nValidate guest storage access on the source host and after an approved migration to the destination. Record the active WWN identity and the LUNs actually visible at each step. Test the planned return move and investigate missing storage or unexpected access before authorizing routine migration of that workload.\nOfficial references\nMicrosoft Learn: Hyper-V Virtual Fibre Channel in Windows Server. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:15:14+00:00",
                "dateModified": "2026-09-08T18:23:27+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-117-account-for-both-virtual-fibre-channel-wwn-sets-before-live-migration/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Account for both virtual Fibre Channel WWN sets before live migration"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 204,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Hyper-V Virtual Fibre Channel in Windows Server",
                    "url": "https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/plan/virtual-fibre-channel-for-hyper-v"
                }
            }
        ]
    }
}