A zone in Fibre Channel is a segment of a fabric that is composed of selected targets and initiators. Like with a VLAN, only the members of a zone have access to one another. Simply because the switch allows the members to access one another doesn’t mean you can’t still limit access more granularly. You can use storage-based filters, such as LUN Masking, for which devices can access one another based on WWNN information from the initiator port. With Xsan, you can use LUN Masking to limit which of the hosts on your SAN have access to your Xserve RAIDs.
UPDATE: LUN Masking was removed as a feature from the Xserve RAID.