Brocade Fabric OS Encryption Administrator’s Guide Support Uživatelský manuál Strana 1

Procházejte online nebo si stáhněte Uživatelský manuál pro Počítačové příslušenství Brocade Fabric OS Encryption Administrator’s Guide Support. Brocade Fabric OS Encryption Administrator’s Guide Supporting RSA Data Protection Manager (DPM) Environments (Supporting Fabric OS v7.2.0) User Manual Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 332
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků

Shrnutí obsahu

Strany 1 - Fabric OS Encryption

53-1002922-0126 July 2013®Fabric OS EncryptionAdministrator’s Guide Supporting RSA Data Protection Manager (DPM) EnvironmentsSupporting Fabric OS v7.2

Strany 2 - Document History

viii Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Impact of tape LUN configuration changes. . . . . . . . . . . . . . . . . . 174Dec

Strany 3 - 53-1002720-02

80 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Tape LUN statistics2FIGURE 61 Tape LUN Statistics dialog boxThe dialog box contains th

Strany 4

Fabric OS Encryption Administrator’s Guide (DPM) 8153-1002922-01Tape LUN statistics23. Select a tape target storage device, then click LUNs.The Target

Strany 5 - Contents

82 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Tape LUN statistics2• Host Port WWN: The WWN of the host port that is being used for t

Strany 6

Fabric OS Encryption Administrator’s Guide (DPM) 8353-1002922-01Encryption engine rebalancing2FIGURE 65 Tape LUN Statistics dialog boxThe dialog box c

Strany 7

84 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Master keys2During rebalancing operations, be aware of the following:• You might notic

Strany 8

Fabric OS Encryption Administrator’s Guide (DPM) 8553-1002922-01Master keys2NOTEAny DEK in the key vault that is either compromised, or needs to be de

Strany 9

86 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Master keys2Master key actionsNOTEMaster keys belong to the group and are managed from

Strany 10 - 53-1002922-01

Fabric OS Encryption Administrator’s Guide (DPM) 8753-1002922-01Master keys2The Master Key Backup dialog box displays, but only if the master key has

Strany 11

88 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Master keys2FIGURE 67 Backup Master Key for Encryption Group dialog box - Backup Desti

Strany 12

Fabric OS Encryption Administrator’s Guide (DPM) 8953-1002922-01Master keys2FIGURE 68 Backup Master Key for Encryption Group dialog box - Backup Desti

Strany 13

Fabric OS Encryption Administrator’s Guide (DPM) ix53-1002922-01Thin provisioned LUNs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 14

90 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Master keys2Overview of saving a master key to a smart card set A card reader must be

Strany 15 - About This Document

Fabric OS Encryption Administrator’s Guide (DPM) 9153-1002922-01Master keys2FIGURE 69 Restore Master Key for Encryption Group dialog box - Restore fro

Strany 16 - Document conventions

92 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Master keys2FIGURE 70 Restore Master Key for Encryption Group dialog box - Restore fro

Strany 17 - Notes, cautions, and warnings

Fabric OS Encryption Administrator’s Guide (DPM) 9353-1002922-01Master keys2FIGURE 71 Restore Master Key for Encryption Group dialog box - Restore fro

Strany 18 - Additional information

94 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Security settings2Security settings Security settings help you identify if system card

Strany 19 - Getting technical help

Fabric OS Encryption Administrator’s Guide (DPM) 9553-1002922-01Zeroizing an encryption engine2NOTEZeroizing an engine affects the I/Os, but all targe

Strany 20 - Document feedback

96 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Using the Encryption Targets dialog box2Using the Encryption Targets dialog boxThe Enc

Strany 21 - Encryption Overview

Fabric OS Encryption Administrator’s Guide (DPM) 9753-1002922-01Redirection zones2Redirection zonesIt is recommended that you configure the host and t

Strany 22 - Terminology

98 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Disk device decommissioning2Provided that the crypto configuration is not left uncommi

Strany 23

Fabric OS Encryption Administrator’s Guide (DPM) 9953-1002922-01Disk device decommissioning2In order to delete keys from the key vault, you need to kn

Strany 24 - The Brocade Encryption Switch

x Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Enabling a disabled LUN. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 25 - Performance licensing

100 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Rekeying all disk LUNs manually2Displaying Universal IDsIn order to delete keys from

Strany 26 - Usage limitations

Fabric OS Encryption Administrator’s Guide (DPM) 10153-1002922-01Rekeying all disk LUNs manually2Setting disk LUN Re-key AllTo rekey all disk LUNs on

Strany 27 - FIGURE 2 Encryption overview

102 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Rekeying all disk LUNs manually2.FIGURE 76 Pending manual rekey operations Viewing di

Strany 28 - FIGURE 3 Frame redirection

Fabric OS Encryption Administrator’s Guide (DPM) 10353-1002922-01Rekeying all disk LUNs manually2FIGURE 77 Encryption Target Disk LUNs dialog box4. Cl

Strany 29 - IO Sync LAN

104 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Rekeying all disk LUNs manually2Viewing the progress of manual rekey operationsTo mon

Strany 30 - FIGURE 5 DEK life cycle

Fabric OS Encryption Administrator’s Guide (DPM) 10553-1002922-01Thin provisioned LUNs2• Current LBA: The Logical Block Address (LBA) of the block tha

Strany 31 - Support for virtual fabrics

106 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Viewing time left for auto rekey2• If you are running a Fabric OS version earlier tha

Strany 32

Fabric OS Encryption Administrator’s Guide (DPM) 10753-1002922-01Viewing and editing switch encryption properties23. Select a target disk device from

Strany 33

108 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Viewing and editing switch encryption properties2FIGURE 80 Encryption Switch Properti

Strany 34 - Encryption Center features

Fabric OS Encryption Administrator’s Guide (DPM) 10953-1002922-01Viewing and editing switch encryption properties2• Discovering• Not a member- Encrypt

Strany 35 - Encryption user privileges

Fabric OS Encryption Administrator’s Guide (DPM) xi53-1002922-01Chapter 6 Maintenance and Troubleshooting 245In this chapter . . . . . . . . . . . . .

Strany 36 - Smart card usage

110 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Viewing and editing switch encryption properties2• Operational• need master/link key•

Strany 37

Fabric OS Encryption Administrator’s Guide (DPM) 11153-1002922-01Viewing and editing encryption group properties2Enabling and disabling the encryption

Strany 38

112 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Viewing and editing encryption group properties2FIGURE 82 Encryption Group Properties

Strany 39

Fabric OS Encryption Administrator’s Guide (DPM) 11353-1002922-01Viewing and editing encryption group properties2General tabThe General tab is viewed

Strany 40

114 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Viewing and editing encryption group properties2When the first encryption engine come

Strany 41 - Using system cards

Fabric OS Encryption Administrator’s Guide (DPM) 11553-1002922-01Viewing and editing encryption group properties2Members tabThe Members tab lists grou

Strany 42

116 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Viewing and editing encryption group properties2FIGURE 84 Encryption Group Properties

Strany 43 - Using smart cards

Fabric OS Encryption Administrator’s Guide (DPM) 11753-1002922-01Viewing and editing encryption group properties2The consequences of removing the last

Strany 44 - Tracking smart cards

118 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Viewing and editing encryption group properties2FIGURE 85 Encryption Group Properties

Strany 45

Fabric OS Encryption Administrator’s Guide (DPM) 11953-1002922-01Viewing and editing encryption group properties2• Registered Authentication Cards tab

Strany 46 - Editing smart cards

xii Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Brocade Encryption Switch removal and replacement. . . . . . . . . 285Multi-node EG

Strany 47 - Blade processor links

120 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Viewing and editing encryption group properties2The tab displays the includes the fol

Strany 48 - (KAC) certificate

Fabric OS Encryption Administrator’s Guide (DPM) 12153-1002922-01Viewing and editing encryption group properties2Tape Pools tabTape pools are managed

Strany 49

122 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Viewing and editing encryption group properties2All encryption engines in the encrypt

Strany 50

Fabric OS Encryption Administrator’s Guide (DPM) 12353-1002922-01Viewing and editing encryption group properties24. Based on your selection, do one of

Strany 51

124 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption-related acronyms in log messages2FIGURE 90 Encryption Group Properties Dia

Strany 52

Fabric OS Encryption Administrator’s Guide (DPM) 12553-1002922-01Chapter3Configuring Encryption Using the CLIIn this chapter•Overview. . . . . . . . .

Strany 53

126 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Overview3OverviewThis chapter explains how to use the command line interface (CLI) to

Strany 54

Fabric OS Encryption Administrator’s Guide (DPM) 12753-1002922-01Command RBAC permissions and AD types34. PortMember: allows all control operations on

Strany 55 - Creating an encryption group

128 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Command RBAC permissions and AD types3createhaclusterNOMN N N OMN NDisallowedcreateta

Strany 56

Fabric OS Encryption Administrator’s Guide (DPM) 12953-1002922-01Command RBAC permissions and AD types3rebalanceNOMN N N OMN NDisallowedreclaimNOMN N

Strany 57

Fabric OS Encryption Administrator’s Guide (DPM) xiii53-1002922-01About This DocumentIn this chapter•How this document is organized . . . . . . . . .

Strany 58

130 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Cryptocfg Help command output3Cryptocfg Help command outputAll encryption operations

Strany 59

Fabric OS Encryption Administrator’s Guide (DPM) 13153-1002922-01Configuring cluster links3Configuring cluster linksEach encryption switch or FS8-18 b

Strany 60

132 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuring cluster links3DHCP: Offeth0: 10.33.54.208/20eth1: none/noneGateway: 10.33

Strany 61

Fabric OS Encryption Administrator’s Guide (DPM) 13353-1002922-01Setting encryption node initialization34. Reboot the member node (the node on which t

Strany 62

134 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Steps for connecting to a DPM appliance3Steps for connecting to a DPM applianceAll sw

Strany 63

Fabric OS Encryption Administrator’s Guide (DPM) 13553-1002922-01Steps for connecting to a DPM appliance3Initializing the Fabric OS encryption engines

Strany 64

136 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Steps for connecting to a DPM appliance36. Register the encryption engine by entering

Strany 65 - --reg keyvault command

Fabric OS Encryption Administrator’s Guide (DPM) 13753-1002922-01Steps for connecting to a DPM appliance33. Request the signed certificate.Generally,

Strany 66

138 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Steps for connecting to a DPM appliance3Uploading the CA certificate onto the DPM app

Strany 67

Fabric OS Encryption Administrator’s Guide (DPM) 13953-1002922-01Steps for connecting to a DPM appliance3i. Repeat step a through step h for each key

Strany 68

xiv Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Supported hardware and software. The following hardware platforms support data encryp

Strany 69

140 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Steps for connecting to a DPM appliance3To create a Brocade encryption group, complet

Strany 70

Fabric OS Encryption Administrator’s Guide (DPM) 14153-1002922-01Steps for connecting to a DPM appliance3• Registration File: This file is created as

Strany 71

142 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Steps for connecting to a DPM appliance3Setting heartbeat signaling valuesEncryption

Strany 72 - Creating HA clusters

Fabric OS Encryption Administrator’s Guide (DPM) 14353-1002922-01Adding a member node to an encryption group3Adding a member node to an encryption gro

Strany 73

144 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Adding a member node to an encryption group35. Use the cryptocfg --import command to

Strany 74 - Invoking failback

Fabric OS Encryption Administrator’s Guide (DPM) 14553-1002922-01Adding a member node to an encryption group3Encryption Group state: CLUSTER_STATE_CON

Strany 75 - Adding an encryption target

146 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Generating and backing up the master key3SecurityAdmin:switch> cryptocfg --reg -ke

Strany 76

Fabric OS Encryption Administrator’s Guide (DPM) 14753-1002922-01Generating and backing up the master key3 IP address: 10.33.54.160 Certi

Strany 77

148 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01High availability clusters3SecurityAdmin:switch> cryptocfg --show -groupmember -al

Strany 78

Fabric OS Encryption Administrator’s Guide (DPM) 14953-1002922-01High availability clusters3• HA clusters of FS8-18 blades should not include blades i

Strany 79

Fabric OS Encryption Administrator’s Guide (DPM) xv53-1002922-01Command syntax conventionsCommand syntax in this manual follows these conventions:Note

Strany 80

150 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01High availability clusters3NOTEAn HA cluster configuration must have two encryption e

Strany 81

Fabric OS Encryption Administrator’s Guide (DPM) 15153-1002922-01High availability clusters3<<old node WWN> [old slot number]><<new

Strany 82

152 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01High availability clusters3Policy Configuration ExamplesThe following examples illust

Strany 83 - FIGURE 46 Next Steps screen

Fabric OS Encryption Administrator’s Guide (DPM) 15353-1002922-01Re-exporting a master key3Re-exporting a master keyWith the introduction of Fabric OS

Strany 84

154 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Re-exporting a master key3The exported key ID is displayed with the master key ID, as

Strany 85

Fabric OS Encryption Administrator’s Guide (DPM) 15553-1002922-01Re-exporting a master key3The following example lists the exported master key IDs for

Strany 86

156 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Enabling the encryption engine3Enabling the encryption engineEnable the encryption en

Strany 87

Fabric OS Encryption Administrator’s Guide (DPM) 15753-1002922-01Zoning considerations3 No HA cluster membership EE Attributes: Media Ty

Strany 88

158 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Zoning considerations3Frame redirection zoningName Server-based frame redirection ena

Strany 89

Fabric OS Encryption Administrator’s Guide (DPM) 15953-1002922-01Zoning considerations3 The Local Name Server has 1 entry }The nsshow command shows al

Strany 90

xvi Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Key termsFor definitions specific to Brocade and Fibre Channel, see the technical glo

Strany 91 - Remote replication LUNs

160 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01CryptoTarget container configuration3FabricAdmin:switch> zonecreate itzone, "

Strany 92

Fabric OS Encryption Administrator’s Guide (DPM) 16153-1002922-01CryptoTarget container configuration3FIGURE 91 Relationship between initiator, virtua

Strany 93

162 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01CryptoTarget container configuration3You may be prompted to rebalance during the foll

Strany 94

Fabric OS Encryption Administrator’s Guide (DPM) 16353-1002922-01CryptoTarget container configuration3The following example creates a disk container n

Strany 95

164 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01CryptoTarget container configuration3 10:00:00:00:c9:2b:c9:3a; 20:0c:00:06:2b:0f:7

Strany 96 - Moving targets

Fabric OS Encryption Administrator’s Guide (DPM) 16553-1002922-01CryptoTarget container configuration3Deleting a CryptoTarget containerYou may delete

Strany 97

166 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Crypto LUN configuration31. Log in to the group leader as Admin or FabricAdmin.2. Ent

Strany 98

Fabric OS Encryption Administrator’s Guide (DPM) 16753-1002922-01Crypto LUN configuration3Discovering a LUNWhen adding a LUN to a CryptoTarget contain

Strany 99 - Tape LUN statistics

168 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Crypto LUN configuration3NOTEThere is a maximum of 512 disk LUNs per Initiator in a c

Strany 100

Fabric OS Encryption Administrator’s Guide (DPM) 16953-1002922-01Crypto LUN configuration3Number of host(s): 1Configuration status: committedHost: 10:

Strany 101

Fabric OS Encryption Administrator’s Guide (DPM) xvii53-1002922-01Getting technical helpContact your switch support supplier for hardware, firmware, a

Strany 102

170 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Crypto LUN configuration3Encryption formatDisk LUN: yesTape LUN: yesModify? Yes-encry

Strany 103 - Encryption engine rebalancing

Fabric OS Encryption Administrator’s Guide (DPM) 17153-1002922-01Crypto LUN configuration3Configuring a tape LUNThis example shows how to configure a

Strany 104 - Master keys

172 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Crypto LUN configuration3Operation Succeededd. Display the LUN configuration.FabricAd

Strany 105 - Alternate master key

Fabric OS Encryption Administrator’s Guide (DPM) 17353-1002922-01Crypto LUN configuration3CAUTIONIn case of multiple paths for a LUN, each path is exp

Strany 106 - Master key actions

174 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Impact of tape LUN configuration changes3LUN modification considerationsMake sure you

Strany 107 - ATTENTION

Fabric OS Encryption Administrator’s Guide (DPM) 17553-1002922-01Decommissioning LUNs3Decommissioning LUNsA disk device needs to be decommissioned whe

Strany 108

176 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Decommissioning replicated LUNs3Complete the following procedure to decommission a di

Strany 109

Fabric OS Encryption Administrator’s Guide (DPM) 17753-1002922-01Decommissioning replicated LUNs3• “Decommissioning primary R1 LUNs only”• “Decommissi

Strany 110

178 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Force-enabling a decommissioned disk LUN for encryption3Decommissioning primary R1 an

Strany 111

Fabric OS Encryption Administrator’s Guide (DPM) 17953-1002922-01Force-enabling a disabled disk LUN for encryption36. Modify the LUN to encrypted. Fab

Strany 112

Copyright © 2013 Brocade Communications Systems, Inc. All Rights Reserved.ADX, AnyIO, Brocade, Brocade Assurance, the B-wing symbol, DCX, Fabric OS, I

Strany 113 - Creating a master key

xviii Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Document feedbackQuality is our first concern at Brocade and we have made every eff

Strany 114 - Security settings

180 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01SRDF LUNs3• Adaptive Copy Replication transfers data from the source devices to the r

Strany 115 - Setting zeroization

Fabric OS Encryption Administrator’s Guide (DPM) 18153-1002922-01SRDF LUNs3NOTEWhen Symmetrix arrays are managed in-band, the gatekeeper LUNs must be

Strany 116

182 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Using SRDF, TimeFinder and RecoverPoint with encryption3Be aware that when an individ

Strany 117 - Disk device decommissioning

Fabric OS Encryption Administrator’s Guide (DPM) 18353-1002922-01Using SRDF, TimeFinder and RecoverPoint with encryption3Initial Configuration Require

Strany 118 - Decommissioning disk LUNs

184 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuring LUNs for SRDF/TF or RP deployments3SecurityAdmin:switch> cryptocfg --r

Strany 119

Fabric OS Encryption Administrator’s Guide (DPM) 18553-1002922-01Configuring LUNs for SRDF/TF or RP deployments3Migrating LUNs with existing data to L

Strany 120 - Displaying Universal IDs

186 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuring LUNs for SRDF/TF or RP deployments34. Copy the data from the old LUN to t

Strany 121 - Setting disk LUN Re-key All

Fabric OS Encryption Administrator’s Guide (DPM) 18753-1002922-01Configuring LUNs for SRDF/TF or RP deployments3Alternatively, simply bringing the rem

Strany 122

188 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01SRDF/TF/RP manual rekeying procedures3NOTEIf the target device specified above is a s

Strany 123

Fabric OS Encryption Administrator’s Guide (DPM) 18953-1002922-01SRDF/TF/RP manual rekeying procedures3NOTEDuring all rekeying operations, data synchr

Strany 124

Fabric OS Encryption Administrator’s Guide (DPM) 153-1002922-01Chapter1Encryption OverviewIn this chapter•Host and LUN considerations . . . . . . . .

Strany 125 - Thin provisioned LUNs

190 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01SRDF/TF/RP manual rekeying procedures33. During the rekeying operation, if desired, y

Strany 126 - Thin Provisioning support

Fabric OS Encryption Administrator’s Guide (DPM) 19153-1002922-01SRDF/TF/RP manual rekeying procedures3Rekeying LUNs for RP deployments - local siteMa

Strany 127

192 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01SRDF/TF/RP manual rekeying procedures3Alternatively, simply bringing the remote site

Strany 128

Fabric OS Encryption Administrator’s Guide (DPM) 19353-1002922-01Tape pool configuration3Rekeying LUNs for RP deployments - remote siteTo rekey a remo

Strany 129

194 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Tape pool configuration3NOTETape pool configurations must be committed to take effect

Strany 130

Fabric OS Encryption Administrator’s Guide (DPM) 19553-1002922-01Tape pool configuration33. Edit the dbo.CommCellStoragePolicyquery as follows:a. Righ

Strany 131

196 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Tape pool configuration3Creating a tape poolComplete the following steps to create a

Strany 132

Fabric OS Encryption Administrator’s Guide (DPM) 19753-1002922-01Tape pool configuration3Operation succeeded.3. Commit the transactionFabricAdmin:swit

Strany 133 - General tab

198 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuring a multi-path Crypto LUN3Configuring a multi-path Crypto LUNA single LUN m

Strany 134

Fabric OS Encryption Administrator’s Guide (DPM) 19953-1002922-01Configuring a multi-path Crypto LUN3Multi-path LUN configuration exampleFigure 93 on

Strany 135 - Members tab

2 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Terminology1TerminologyThe following are definitions of terms used extensively in this

Strany 136 - Members tab Remove button

200 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuring a multi-path Crypto LUN3b. Create a CryptoTarget container (CTC2) for tar

Strany 137 - Security tab

Fabric OS Encryption Administrator’s Guide (DPM) 20153-1002922-01Configuring a multi-path Crypto LUN3b. Add the same LUN to the CryptoTarget container

Strany 138

202 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01First-time encryption3First-time encryptionFirst-time encryption, also referred to as

Strany 139 - HA Clusters tab

Fabric OS Encryption Administrator’s Guide (DPM) 20353-1002922-01Thin provisioned LUNs3Thin provisioned LUNsWith the introduction of Fabric OS 7.1.0,

Strany 140

204 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Thin provisioned LUNs3Encryption format: nativeEncrypt existing data: disabledR

Strany 141 - Tape Pools tab

Fabric OS Encryption Administrator’s Guide (DPM) 20553-1002922-01Data rekeying3Space reclamationWhen a block that was provisioned is no longer needed,

Strany 142 - Adding tape pools

206 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Data rekeying3Rekeying is only applicable to disk array LUNs or fixed block devices.

Strany 143 - Engine Operations tab

Fabric OS Encryption Administrator’s Guide (DPM) 20753-1002922-01Data rekeying3Configuring a LUN for automatic rekeyingRekeying options are configured

Strany 144 - TABLE 3 Encryption acronyms

208 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Data rekeying3Initiating a manual rekey session You can initiate a rekeying session m

Strany 145 - In this chapter

Fabric OS Encryption Administrator’s Guide (DPM) 20953-1002922-01Data rekeying3Current LBA: 488577Operation succeeded.Suspension and resump

Strany 146 - Command validation checks

Fabric OS Encryption Administrator’s Guide (DPM) 353-1002922-01Terminology1Opaque Key VaultA storage location that provides untrusted key management f

Strany 147

210 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Data rekeying3

Strany 148 - (Continued)

Fabric OS Encryption Administrator’s Guide (DPM) 21153-1002922-01Chapter4Deployment ScenariosIn this chapter•Single encryption switch, two paths from

Strany 149

212 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Single encryption switch, two paths from host to target4Single encryption switch, two

Strany 150 - Management LAN configuration

Fabric OS Encryption Administrator’s Guide (DPM) 21353-1002922-01Single fabric deployment - HA cluster4Single fabric deployment - HA clusterFigure 95

Strany 151 - Configuring cluster links

214 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Single fabric deployment - DEK cluster4In Figure 95, the two encryption switches prov

Strany 152 - Node is a member node

Fabric OS Encryption Administrator’s Guide (DPM) 21553-1002922-01Dual fabric deployment - HA and DEK cluster4In Figure 96, two encryption switches are

Strany 153 - • Node CP certificate

216 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Multiple paths, one DEK cluster, and two HA clusters4failover for the encryption path

Strany 154

Fabric OS Encryption Administrator’s Guide (DPM) 21753-1002922-01Multiple paths, DEK cluster, no HA cluster4The configuration details shown in Figure

Strany 155

218 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Multiple paths, DEK cluster, no HA cluster4The configuration details are as follows:•

Strany 156 - Submitting the CSR to a CA

Fabric OS Encryption Administrator’s Guide (DPM) 21953-1002922-01Deployment in Fibre Channel routed fabrics4Deployment in Fibre Channel routed fabrics

Strany 157

4 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01The Brocade Encryption Switch1The Brocade Encryption SwitchThe Brocade Encryption Switc

Strany 158

220 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Deployment in Fibre Channel routed fabrics4The following is a summary of steps for cr

Strany 159

Fabric OS Encryption Administrator’s Guide (DPM) 22153-1002922-01Deployment as part of an edge fabric4Deployment as part of an edge fabricIn this depl

Strany 160

222 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Deployment with FCIP extension switches4Deployment with FCIP extension switchesEncryp

Strany 161

Fabric OS Encryption Administrator’s Guide (DPM) 22353-1002922-01Data mirroring deployment4Data mirroring deploymentFigure 104 shows a data mirroring

Strany 162

224 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Data mirroring deployment4If metadata is not present on the LUNBeginning with Fabric

Strany 163 - • cryptocfg --enableEE

Fabric OS Encryption Administrator’s Guide (DPM) 22553-1002922-01VMware ESX server deployments4VMware ESX server deploymentsVMware ESX servers may hos

Strany 164

226 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01VMware ESX server deployments4Figure 106 shows a VMware ESX server with two guest ope

Strany 165

Fabric OS Encryption Administrator’s Guide (DPM) 22753-1002922-01Chapter5Best Practices and Special TopicsIn this chapter•Firmware upgrade and downgra

Strany 166

228 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Firmware upgrade and downgrade considerations5Firmware upgrade and downgrade consider

Strany 167

Fabric OS Encryption Administrator’s Guide (DPM) 22953-1002922-01Firmware upgrade and downgrade considerations5Guidelines for firmware upgrade of encr

Strany 168 - High availability clusters

Fabric OS Encryption Administrator’s Guide (DPM) 553-1002922-01The FS8-18 blade1The FS8-18 bladeThe FS8-18 blade provides the same features and functi

Strany 169 - Creating an HA cluster

230 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuration upload and download considerations53. Ensure that these CryptoTarget Co

Strany 170

Fabric OS Encryption Administrator’s Guide (DPM) 23153-1002922-01Configuration upload and download considerations5Configuration upload at an encryptio

Strany 171

232 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuration upload and download considerations5Configuration download at the encryp

Strany 172 - Policy Configuration Examples

Fabric OS Encryption Administrator’s Guide (DPM) 23353-1002922-01HP-UX considerations5HP-UX considerationsThe HP-UX OS requires LUN 0 to be present. L

Strany 173 - Re-exporting a master key

234 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Decommissioning in an EG containing mixed modes5Decommissioning in an EG containing m

Strany 174 - Viewing the master key IDs

Fabric OS Encryption Administrator’s Guide (DPM) 23553-1002922-01Tape data compression5Tape data compressionData is compressed by the encryption switc

Strany 175

236 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Tape block zero handling5Tape block zero handlingThe block zero of the tape media is

Strany 176

Fabric OS Encryption Administrator’s Guide (DPM) 23753-1002922-01Redirection zones5• To enable host MPIO, LUNs must also be available through a second

Strany 177 - Zoning considerations

238 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Ensure uniform licensing in HA clusters5Ensure uniform licensing in HA clustersLicens

Strany 178 - Frame redirection zoning

Fabric OS Encryption Administrator’s Guide (DPM) 23953-1002922-01Turn off compression on extension switches5Turn off compression on extension switches

Strany 179

6 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Recommendation for connectivity1Recommendation for connectivityIn order to achieve high

Strany 180

240 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01KAC certificate registration expiry5Do not change LUN configuration while rekeyingNev

Strany 181

Fabric OS Encryption Administrator’s Guide (DPM) 24153-1002922-01Changing IP addresses in encryption groups5Changing IP addresses in encryption groups

Strany 182 - Gathering information

242 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Recommendations for Initiator Fan-Ins5FIGURE 107 Fan-in ratios with performance licen

Strany 183

Fabric OS Encryption Administrator’s Guide (DPM) 24353-1002922-01Best practices for host clusters in an encryption environment5Best practices for host

Strany 184

244 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Tape device LUN mapping5

Strany 185

Fabric OS Encryption Administrator’s Guide (DPM) 24553-1002922-01Chapter6Maintenance and TroubleshootingIn this chapter•Encryption group and HA cluste

Strany 186 - Crypto LUN configuration

246 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption group and HA cluster maintenance6Encryption group and HA cluster maintenan

Strany 187 - Configuring a Crypto LUN

Fabric OS Encryption Administrator’s Guide (DPM) 24753-1002922-01Encryption group and HA cluster maintenance6FIGURE 108 Removing a node from an encryp

Strany 188

248 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption group and HA cluster maintenance6 IP Address: 10.32.33.

Strany 189

Fabric OS Encryption Administrator’s Guide (DPM) 24953-1002922-01Encryption group and HA cluster maintenance6Deleting an encryption groupYou can delet

Strany 190

Fabric OS Encryption Administrator’s Guide (DPM) 753-1002922-01Brocade encryption solution overview1Brocade encryption solution overviewThe loss of st

Strany 191 - Configuring a tape LUN

250 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption group and HA cluster maintenance6Displaying the HA cluster configurationNO

Strany 192

Fabric OS Encryption Administrator’s Guide (DPM) 25153-1002922-01Encryption group and HA cluster maintenance6Replacing an HA cluster member1. Log in t

Strany 193

252 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption group and HA cluster maintenance6FIGURE 109 Replacing a failed encryption

Strany 194

Fabric OS Encryption Administrator’s Guide (DPM) 25353-1002922-01Encryption group and HA cluster maintenance6Case 2: Replacing a “live” encryption eng

Strany 195 - Decommissioning LUNs

254 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption group and HA cluster maintenance6Performing a manual failback of an encryp

Strany 196

Fabric OS Encryption Administrator’s Guide (DPM) 25553-1002922-01Encryption group merge and split use cases6• After the failback completes, the crypto

Strany 197

256 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption group merge and split use cases6NOTEWhen attempting to reclaim a failed Br

Strany 198

Fabric OS Encryption Administrator’s Guide (DPM) 25753-1002922-01Encryption group merge and split use cases6RecoveryIf auto failback policy is set, no

Strany 199 - SRDF LUNs

258 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption group merge and split use cases6• The isolation of N3 from the group leade

Strany 200 - SRDF pairs

Fabric OS Encryption Administrator’s Guide (DPM) 25953-1002922-01Encryption group merge and split use cases6Recovery1. Restore the connection between

Strany 201 - Adding replication LUNs

8 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Brocade encryption solution overview1Data flow from server to storageThe Brocade Encryp

Strany 202 - Reading metadata after sync

260 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption group merge and split use cases6NOTEThe collective time allowed (the heart

Strany 203 - -newLUN option

Fabric OS Encryption Administrator’s Guide (DPM) 26153-1002922-01Encryption group merge and split use cases6NOTEIf one or more EG status displays as C

Strany 204

262 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption group merge and split use cases6Display the encryption group state again.N

Strany 205

Fabric OS Encryption Administrator’s Guide (DPM) 26353-1002922-01Encryption group merge and split use cases6If you now perform a cryptocfg --show -gro

Strany 206

264 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption group merge and split use cases66. Verify your encryption group is re-conv

Strany 207

Fabric OS Encryption Administrator’s Guide (DPM) 26553-1002922-01Encryption group database manual operations6Encryption group database manual operatio

Strany 208 - TF snapshot rekeying details

266 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Key vault diagnostics6Use the --sync -securitydb command to distribute the security d

Strany 209 - <initiator PWWN>

Fabric OS Encryption Administrator’s Guide (DPM) 26753-1002922-01Measuring encryption performance6• Key class and format on the KV configured for the

Strany 210

268 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Measuring encryption performance6For example:FabricAdmin:switch> cryptocfg --perfs

Strany 211

Fabric OS Encryption Administrator’s Guide (DPM) 26953-1002922-01Measuring encryption performance6b. The user port on which a particular virtual entit

Strany 212

Fabric OS Encryption Administrator’s Guide (DPM) 953-1002922-01Data encryption key life cycle management1Data encryption key life cycle managementData

Strany 213 - Tape pool configuration

270 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Measuring encryption performance6In a DCX Backbone, the slot number is also displayed

Strany 214 - Tape pool labeling

Fabric OS Encryption Administrator’s Guide (DPM) 27153-1002922-01General encryption troubleshooting6General encryption troubleshootingTable 9 lists th

Strany 215 - NetWorker labeling

272 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01General encryption troubleshooting6A backup fails because the LUN is always in the in

Strany 216 - Deleting a tape pool

Fabric OS Encryption Administrator’s Guide (DPM) 27353-1002922-01General encryption troubleshooting6Decommissioning an R2 LUN (remote replication LUN)

Strany 217 - Modifying a tape pool

274 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Troubleshooting examples using the CLI6Troubleshooting examples using the CLIEncrypti

Strany 218

Fabric OS Encryption Administrator’s Guide (DPM) 27553-1002922-01Troubleshooting examples using the CLI6Encryption Disabled CryptoTarget LUNIf the LUN

Strany 219

276 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Management application encryption wizard troubleshooting6Management application encry

Strany 220

Fabric OS Encryption Administrator’s Guide (DPM) 27753-1002922-01Management application encryption wizard troubleshooting6Errors related to adding a s

Strany 221

278 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Management application encryption wizard troubleshooting6General errors related to th

Strany 222 - First-time encryption

Fabric OS Encryption Administrator’s Guide (DPM) 27953-1002922-01LUN policy troubleshooting6LUN policy troubleshootingTable 14 may be used as an aid i

Strany 223

Document Title iii53-1002720-02

Strany 224

10 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Data encryption key life cycle management1FIGURE 5 DEK life cycle

Strany 225 - Data rekeying

280 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Loss of encryption group leader after power outage6Loss of encryption group leader af

Strany 226 - Rekeying modes

Fabric OS Encryption Administrator’s Guide (DPM) 28153-1002922-01MPIO and internal LUN states65. Synchronize the crypto configurations across all memb

Strany 227

282 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01FS8-18 blade removal and replacement61. Enter the cryptocfg --resume_rekey command, f

Strany 228

Fabric OS Encryption Administrator’s Guide (DPM) 28353-1002922-01FS8-18 blade removal and replacement63. If the replaced FS8-18 blade is in member nod

Strany 229

284 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01FS8-18 blade removal and replacement6NOTEBecause the FS8-18 blade was inserted in the

Strany 230

Fabric OS Encryption Administrator’s Guide (DPM) 28553-1002922-01Brocade Encryption Switch removal and replacement611. If a master key is not present,

Strany 231 - Deployment Scenarios

286 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Brocade Encryption Switch removal and replacement66. Replace the old Brocade Encrypti

Strany 232

Fabric OS Encryption Administrator’s Guide (DPM) 28753-1002922-01Brocade Encryption Switch removal and replacement620. Export the KAC CSR from the new

Strany 233

288 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Brocade Encryption Switch removal and replacement632. If HA cluster membership for th

Strany 234

Fabric OS Encryption Administrator’s Guide (DPM) 28953-1002922-01Brocade Encryption Switch removal and replacement612. Recreate the EG with the same n

Strany 235

Fabric OS Encryption Administrator’s Guide (DPM) 1153-1002922-01Master key management1Master key managementCommunications with opaque key vaults are e

Strany 236

290 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Deregistering a DPM key vault630. Verify that defzone is set as no access.31. If HA c

Strany 237

Fabric OS Encryption Administrator’s Guide (DPM) 29153-1002922-01Reclaiming the WWN base of a failed Brocade Encryption Switch6Type: DPMSec

Strany 238

292 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Removing stale rekey information for a LUN6NOTEWhen attempting to reclaim a failed Br

Strany 239

Fabric OS Encryption Administrator’s Guide (DPM) 29353-1002922-01Fabric OS and DPM Compatibility Matrix6If a device decommission firmware consistency

Strany 240 - --rdcreate [host wwn]

294 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Splitting an encryption group into two encryption groups6Splitting an encryption grou

Strany 241

Fabric OS Encryption Administrator’s Guide (DPM) 29553-1002922-01Moving an encryption blade from one EG to another in the same fabric6When prompted, e

Strany 242 - FIGURE 103 FCIP deployment

296 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Moving an encryption switch from one EG to another in the same fabric6Moving an encry

Strany 243 - Data mirroring deployment

Fabric OS Encryption Administrator’s Guide (DPM) 29753-1002922-01AppendixAState and Status InformationIn this appendix•Encryption engine security proc

Strany 244

298 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Security processor KEK statusASecurity processor KEK statusTable 20 lists security pr

Strany 245 - VMware ESX server deployments

Fabric OS Encryption Administrator’s Guide (DPM) 29953-1002922-01Encrypted LUN statesALUN_1ST_TIME_REKEY_IN_PROG First time rekey is in progress.LUN_K

Strany 246

12 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Cisco Fabric Connectivity support1Cisco Fabric Connectivity supportThe Brocade Encrypt

Strany 247

300 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encrypted LUN statesALUN_DIS_WR_META_DONE_ERR Disabled (Write metadata done with fail

Strany 248 - General guidelines

Fabric OS Encryption Administrator’s Guide (DPM) 30153-1002922-01Encrypted LUN statesATABLE 22 Tape LUN statesInternal Names Console String Explanatio

Strany 249

302 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encrypted LUN statesALUN_ENCRYPT Encryption enabled The tape medium is present, and i

Strany 250

Fabric OS Encryption Administrator’s Guide (DPM) 30353-1002922-01IndexAadd commands--add -haclustermember, 150--add -initiator, 163, 171, 200--add -LU

Strany 251

304 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01create commands--create -container, 162, 171, 199--create -encgroup, 140--create -hac

Strany 252

Fabric OS Encryption Administrator’s Guide (DPM) 30553-1002922-01DEK (data encryption keys), 9DEK life cycle, 10delete commands--delete -container, 16

Strany 253 - AIX considerations

306 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01encryption groupadding a member node to using the CLI, 143adding a switch using the m

Strany 254 - Tape metadata

Fabric OS Encryption Administrator’s Guide (DPM) 30753-1002922-01Ggeneral tabencryption group propertiesgeneral tab, 113generate commands--genmasterke

Strany 255 - Tape pools

308 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01licensingbest practices, 5LUNadding Crypto LUN to CryptoTarget container, 167adding t

Strany 256 - Tape key expiry

Fabric OS Encryption Administrator’s Guide (DPM) 30953-1002922-01PPID failover, 238policiesconfiguration examples, 152for Crypto LUN, 169impact of LUN

Strany 257

Fabric OS Encryption Administrator’s Guide (DPM) 1353-1002922-01Chapter2Configuring Encryption Using the Management ApplicationIn this chapter•Encrypt

Strany 258 - PID failover

310 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01SRDF pairs, 72, 180statesencrypted LUN, 298storage arraysconfiguring, 71storage encry

Strany 259 - Latency in rekey operations

Fabric OS Encryption Administrator’s Guide (DPM) 31153-1002922-01Uuniversal IDsdisplaying, 100user privilegesdefined, 15resource groups, 15using from

Strany 260

312 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01

Strany 261

14 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption Center features2Encryption Center featuresThe Encryption Center dialog box

Strany 262

Fabric OS Encryption Administrator’s Guide (DPM) 1553-1002922-01Encryption user privileges2Encryption user privilegesIn Brocade Network Advisor, resou

Strany 263 - Tape device LUN mapping

16 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Smart card usage2Smart card usageSmart cards are credit card-sized cards that contain

Strany 264

Fabric OS Encryption Administrator’s Guide (DPM) 1753-1002922-01Smart card usage2• Establishing a trusted link with the NetApp LKM key vault.• Decommi

Strany 265

18 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Smart card usage23. Locate the Authentication Card Quorum Size and select the quorum s

Strany 266

Fabric OS Encryption Administrator’s Guide (DPM) 1953-1002922-01Smart card usage2Registering authentication cards from the databaseSmart cards that ar

Strany 267

iv Document Title53-1002720-02

Strany 268

20 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Smart card usage2Deregistering an authentication cardAuthentication cards can be remov

Strany 269 - Removing an HA cluster member

Fabric OS Encryption Administrator’s Guide (DPM) 2153-1002922-01Smart card usage2Using system cardsSystem cards are smart cards that can be used to co

Strany 270

22 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Smart card usage2Enabling or disabling the system card requirementTo use a system card

Strany 271

Fabric OS Encryption Administrator’s Guide (DPM) 2353-1002922-01Smart card usage2Deregistering system cardsSystem cards can be removed from the databa

Strany 272

24 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Smart card usage2Tracking smart cards1. Select Configure > Encryption from the menu

Strany 273 - Deleting an HA cluster member

Fabric OS Encryption Administrator’s Guide (DPM) 2553-1002922-01Smart card usage2FIGURE 12 Smart Card asset tracking dialog box3. Select a smart card

Strany 274 - Failover/failback example

26 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Smart card usage2Editing smart cardsSmart cards can be used for user authentication, m

Strany 275 - Recovery

Fabric OS Encryption Administrator’s Guide (DPM) 2753-1002922-01Network connections2Network connectionsBefore you use the encryption setup wizard for

Strany 276

28 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Encryption node initialization and certificate generation2Configuring blade processor

Strany 277

Fabric OS Encryption Administrator’s Guide (DPM) 2953-1002922-01Steps for connecting to a DPM appliance2Setting encryption node initializationEncrypti

Strany 278

Fabric OS Encryption Administrator’s Guide (DPM) iii53-1002922-01ContentsAbout This DocumentIn this chapter . . . . . . . . . . . . . . . . . . . . .

Strany 279

30 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Steps for connecting to a DPM appliance2Exporting the KAC certificate signing request

Strany 280 - -hbmisses and -hbtimeout

Fabric OS Encryption Administrator’s Guide (DPM) 3153-1002922-01Steps for connecting to a DPM appliance2KAC certificate registration expiryIt is impor

Strany 281

32 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Steps for connecting to a DPM appliance2Uploading the CA certificate onto the DPM appl

Strany 282

Fabric OS Encryption Administrator’s Guide (DPM) 3353-1002922-01Steps for connecting to a DPM appliance2h. Click Next.i. Repeat step a through step h

Strany 283

34 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Steps for connecting to a DPM appliance2Loading the CA certificate onto the encryption

Strany 284

Fabric OS Encryption Administrator’s Guide (DPM) 3553-1002922-01Encryption preparation2Encryption preparationBefore you use the encryption setup wizar

Strany 285

36 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Creating an encryption group22. Select a switch from the <NO GROUP DEFINED> encr

Strany 286 - Key vault diagnostics

Fabric OS Encryption Administrator’s Guide (DPM) 3753-1002922-01Creating an encryption group24. From the Configure Switch Encryption welcome screen, c

Strany 287 - -portperfshow

38 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Creating an encryption group2FIGURE 20 Create a New Encryption Group dialog boxThe dia

Strany 288

Fabric OS Encryption Administrator’s Guide (DPM) 3953-1002922-01Creating an encryption group2FIGURE 21 Select Key Vault dialog boxUsing this dialog bo

Strany 289

iv Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Support for virtual fabrics. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 290

40 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Creating an encryption group2Configuring key vault settings for RSA Data Protection Ma

Strany 291 - Problem Resolution

Fabric OS Encryption Administrator’s Guide (DPM) 4153-1002922-01Creating an encryption group2FIGURE 23 Specify Certificate Signing Request File Name d

Strany 292 - General errors and conditions

42 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Creating an encryption group2FIGURE 24 Specify Master Key File Name dialog box7. Enter

Strany 293

Fabric OS Encryption Administrator’s Guide (DPM) 4353-1002922-01Creating an encryption group2FIGURE 25 Select Security Settings dialog box10. Set quor

Strany 294

44 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Creating an encryption group2FIGURE 26 Confirm Configuration dialog boxThe Configurati

Strany 295

Fabric OS Encryption Administrator’s Guide (DPM) 4553-1002922-01Creating an encryption group2FIGURE 28 Next Steps dialog box13. Review the post-config

Strany 296

46 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Adding a switch to an encryption group2Adding a switch to an encryption groupThe setup

Strany 297

Fabric OS Encryption Administrator’s Guide (DPM) 4753-1002922-01Adding a switch to an encryption group2FIGURE 30 Designate Switch Membership dialog bo

Strany 298

48 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Adding a switch to an encryption group2FIGURE 31 Add Switch to Existing Encryption Gro

Strany 299 - LUN policy troubleshooting

Fabric OS Encryption Administrator’s Guide (DPM) 4953-1002922-01Adding a switch to an encryption group26. Enter the location where you want to store t

Strany 300

Fabric OS Encryption Administrator’s Guide (DPM) v53-1002922-01High availability clusters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 301 - MPIO and internal LUN states

50 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Replacing an encryption engine in an encryption group2All configuration items have gre

Strany 302 - Multi-node EG replacement

Fabric OS Encryption Administrator’s Guide (DPM) 5153-1002922-01High availability clusters2FIGURE 36 Engine Operations tab3. Select the engine to repl

Strany 303

52 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01High availability clusters2NOTEIn Fabric OS 6.3.0 and later, HA cluster creation is bl

Strany 304 - Single-node EG replacement

Fabric OS Encryption Administrator’s Guide (DPM) 5353-1002922-01High availability clusters2FIGURE 37 Encryption Group Properties dialog box - HA Clust

Strany 305 - Multi-node EG Case

54 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01High availability clusters2Swapping engines in an HA clusterSwapping engines is useful

Strany 306

Fabric OS Encryption Administrator’s Guide (DPM) 5553-1002922-01Configuring encryption storage targets2Configuring encryption storage targetsAdding an

Strany 307

56 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuring encryption storage targets2FIGURE 38 Encryption Targets dialog box3. Click

Strany 308 - Single-node EG Replacement

Fabric OS Encryption Administrator’s Guide (DPM) 5753-1002922-01Configuring encryption storage targets2FIGURE 40 Select Encryption Engine dialog boxTh

Strany 309

58 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuring encryption storage targets2FIGURE 41 Select Target dialog boxThe dialog bo

Strany 310 - Deregistering a DPM key vault

Fabric OS Encryption Administrator’s Guide (DPM) 5953-1002922-01Configuring encryption storage targets2FIGURE 42 Select Hosts dialog boxThe dialog box

Strany 311 - FIGURE 111 DPM Clients page

vi Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Disk device decommissioning . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 312

60 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuring encryption storage targets2• Right arrow button: Moves a host from the Hos

Strany 313 - TABLE 15 Compatibility Matrix

Fabric OS Encryption Administrator’s Guide (DPM) 6153-1002922-01Configuring encryption storage targets2FIGURE 44 Confirmation dialog boxThe screen con

Strany 314 - Encryption group Nodes

62 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuring encryption storage targets2FIGURE 45 Configuration Status screenThe screen

Strany 315

Fabric OS Encryption Administrator’s Guide (DPM) 6353-1002922-01Configuring hosts for encryption targets2FIGURE 46 Next Steps screenThe screen contain

Strany 316

64 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Configuring hosts for encryption targets2NOTEYou can also select a group, switch, or e

Strany 317 - State and Status Information

Fabric OS Encryption Administrator’s Guide (DPM) 6553-1002922-01Configuring hosts for encryption targets2NOTEBoth the Hosts in Fabric table and the Se

Strany 318 - Encrypted LUN states

66 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Adding target disk LUNs for encryption2Adding target disk LUNs for encryptionYou can a

Strany 319

Fabric OS Encryption Administrator’s Guide (DPM) 6753-1002922-01Adding target disk LUNs for encryption2• Encryption path table: Should be LUN/Path ide

Strany 320

68 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Adding target disk LUNs for encryption24. Select the target port from the Target Port

Strany 321 - TABLE 22 Tape LUN states

Fabric OS Encryption Administrator’s Guide (DPM) 6953-1002922-01Adding target disk LUNs for encryption2FIGURE 52 Select LUN dialog box The dialog box

Strany 322

Fabric OS Encryption Administrator’s Guide (DPM) vii53-1002922-01Steps for connecting to a DPM appliance . . . . . . . . . . . . . . . . . . . 134Ini

Strany 323

70 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Adding target disk LUNs for encryption28. If REPL Support was enabled by the Configure

Strany 324

Fabric OS Encryption Administrator’s Guide (DPM) 7153-1002922-01Adding target disk LUNs for encryption2Configuring storage arraysThe Storage Array con

Strany 325

72 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Adding target disk LUNs for encryption2SRDF pairsRemote replication is implemented by

Strany 326

Fabric OS Encryption Administrator’s Guide (DPM) 7353-1002922-01Adding target tape LUNs for encryption2Note the following when using the New LUN optio

Strany 327

74 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Adding target tape LUNs for encryption2FIGURE 55 Encryption Targets dialog box3. Selec

Strany 328

Fabric OS Encryption Administrator’s Guide (DPM) 7553-1002922-01Adding target tape LUNs for encryption2FIGURE 57 Add Encryption Target Tape LUNs dialo

Strany 329

76 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Moving targets2• Enable Write Early Ack: When selected, enables tape write pipelining

Strany 330

Fabric OS Encryption Administrator’s Guide (DPM) 7753-1002922-01Tape LUN write early and read ahead2Tape LUN write early and read aheadThe tape LUN wr

Strany 331

78 Fabric OS Encryption Administrator’s Guide (DPM)53-1002922-01Tape LUN write early and read ahead2FIGURE 59 Encryption Target Tape LUNs dialog box -

Strany 332

Fabric OS Encryption Administrator’s Guide (DPM) 7953-1002922-01Tape LUN statistics2Tape LUN statisticsThis feature enables you to view and clear stat

Komentáře k této Příručce

Žádné komentáře