Brocade Fabric OS Encryption Administrator’s Guide Support Instrukcja Użytkownika Strona 1

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Akcesoria komputerowe Brocade Fabric OS Encryption Administrator’s Guide Support. Brocade Fabric OS Encryption Administrator’s Guide Supporting Key Management Interoperability Protocol (KMIP) Key-Compliant Environments (Supporting Fabric OS v7.1.0) User Manual [es] Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj

Podsumowanie treści

Strona 1 - Fabric OS Encryption

53-1002747-0225 March 2013®53-1002747-02Fabric OS EncryptionAdministrator’s Guide Supporting Key Management Interoperability Protocol (KMIP) Key-Compl

Strona 2 - Document History

x Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Rekeying best practices and policies. . . . . . . . . . . . . . . . . . . . . . . .238

Strona 3 - Contents

82 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target disk LUNs for encryption2Adding target disk LUNs for encryptionYou can

Strona 4

Fabric OS Encryption Administrator’s Guide (KMIP) 8353-1002747-02Adding target disk LUNs for encryption2• Encryption Mode• Encrypt Existing Data• Key

Strona 5

84 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target disk LUNs for encryption2FIGURE 75 Select Initiator Port dialog boxThe

Strona 6

Fabric OS Encryption Administrator’s Guide (KMIP) 8553-1002747-02Adding target disk LUNs for encryption2FIGURE 76 Select LUN dialog box The dialog box

Strona 7

86 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target disk LUNs for encryption2NOTEWith the introduction of Fabric OS v7.1.0,

Strona 8

Fabric OS Encryption Administrator’s Guide (KMIP) 8753-1002747-02Adding target tape LUNs for encryption2Configuring storage arraysThe Storage Array co

Strona 9

88 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target tape LUNs for encryption2FIGURE 78 Encryption Targets dialog box3. Sele

Strona 10 - 53-1002747-02

Fabric OS Encryption Administrator’s Guide (KMIP) 8953-1002747-02Adding target tape LUNs for encryption2FIGURE 80 Add Encryption Target Tape LUNs dial

Strona 11

90 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Moving Targets2• Enable Read Ahead: When selected, enables read pre-fetching on this

Strona 12

Fabric OS Encryption Administrator’s Guide (KMIP) 9153-1002747-02Configuring encrypted tape storage in a multi-path environment2Configuring encrypted

Strona 13 - About This Document

Fabric OS Encryption Administrator’s Guide (KMIP) xi53-1002747-02General encryption troubleshooting . . . . . . . . . . . . . . . . . . . . . . . .26

Strona 14 - Document conventions

92 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape LUN write early and read ahead2Tape LUN write early and read aheadThe tape LUN w

Strona 15 - Notes, cautions, and warnings

Fabric OS Encryption Administrator’s Guide (KMIP) 9353-1002747-02Tape LUN statistics2FIGURE 82 Encryption Target Tape LUNs dialog box - Setting tape L

Strona 16 - Additional information

94 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape LUN statistics2Viewing and clearing tape container statisticsYou can view LUN st

Strona 17 - Getting technical help

Fabric OS Encryption Administrator’s Guide (KMIP) 9553-1002747-02Tape LUN statistics2• Tape Session #: The number of the ongoing tape session.• Uncomp

Strona 18 - Document feedback

96 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape LUN statistics2FIGURE 85 Target Tape LUNs dialog box4. Select the LUN or LUNs fo

Strona 19 - Encryption Overview

Fabric OS Encryption Administrator’s Guide (KMIP) 9753-1002747-02Tape LUN statistics2• A Refresh button updates the statistics on the display since th

Strona 20 - Terminology

98 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption engine rebalancing2FIGURE 88 Tape LUN Statistics dialog boxThe dialog box

Strona 21

Fabric OS Encryption Administrator’s Guide (KMIP) 9953-1002747-02Master keys2During rebalancing operations, be aware of the following:• You might noti

Strona 22 - The Brocade Encryption Switch

100 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2The new master key cannot be used (no new data encryption keys can be cr

Strona 23 - Performance licensing

Fabric OS Encryption Administrator’s Guide (KMIP) 10153-1002747-02Master keys2Refer to the following procedures for more information:- “Saving the mas

Strona 24 - Usage limitations

xii Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02

Strona 25 - FIGURE 2 Encryption overview

102 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 89 Backup Destination (to file) dialog box4. Select File as the B

Strona 26 - FIGURE 3 Frame redirection

Fabric OS Encryption Administrator’s Guide (KMIP) 10353-1002747-02Master keys2FIGURE 90 Backup Destination (to key vault) dialog box4. Select Key Vaul

Strona 27 - IO Sync LAN

104 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 91 Backup Destination (to smart cards) dialog box4. Select A Reco

Strona 28 - FIGURE 5 DEK life cycle

Fabric OS Encryption Administrator’s Guide (KMIP) 10553-1002747-02Master keys2Saving a master key to a smart card set - OverviewA card reader must be

Strona 29 - Support for virtual fabrics

106 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 92 Select a Master Key to Restore (from file) dialog box4. Choose

Strona 30

Fabric OS Encryption Administrator’s Guide (KMIP) 10753-1002747-02Master keys2FIGURE 93 Select a Master Key to Restore (from key vault) dialog box4. C

Strona 31

108 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 94 Select a Master Key to Restore (from a recovery set of smart c

Strona 32 - Encryption Center features

Fabric OS Encryption Administrator’s Guide (KMIP) 10953-1002747-02Security Settings2Security Settings Security settings help you identify if system ca

Strona 33 - Encryption user privileges

110 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Zeroizing an encryption engine2NOTEZeroizing an engine affects the I/Os, but all tar

Strona 34 - Smart card usage

Fabric OS Encryption Administrator’s Guide (KMIP) 11153-1002747-02Using the Encryption Targets dialog box2Using the Encryption Targets dialog boxThe E

Strona 35

Fabric OS Encryption Administrator’s Guide (KMIP) xiii53-1002747-02About This DocumentIn this chapter•How this document is organized . . . . . . . .

Strona 36

112 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Redirection zones2Redirection zonesIt is recommended that you configure the host and

Strona 37

Fabric OS Encryption Administrator’s Guide (KMIP) 11353-1002747-02Disk device decommissioning2Provided that the crypto configuration is not left uncom

Strona 38

114 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Disk device decommissioning2In order to delete keys from the key vault, you need to

Strona 39 - Using system cards

Fabric OS Encryption Administrator’s Guide (KMIP) 11553-1002747-02Rekeying all disk LUNs manually2Displaying Universal IDsIn order to delete keys from

Strona 40

116 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Rekeying all disk LUNs manually2Setting disk LUN Re-key AllTo rekey all disk LUNs on

Strona 41 - Tracking smart cards

Fabric OS Encryption Administrator’s Guide (KMIP) 11753-1002747-02Rekeying all disk LUNs manually2.FIGURE 99 Pending manual rekey operations Viewing d

Strona 42

118 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Rekeying all disk LUNs manually2FIGURE 100 Encryption Target Disk LUNs dialog box4.

Strona 43 - Editing smart cards

Fabric OS Encryption Administrator’s Guide (KMIP) 11953-1002747-02Rekeying all disk LUNs manually2Viewing the progress of manual rekey operationsTo mo

Strona 44 - Network connections

120 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Thin provisioned LUNs2• Current LBA: The Logical Block Address (LBA) of the block th

Strona 45 - Blade processor links

Fabric OS Encryption Administrator’s Guide (KMIP) 12153-1002747-02Viewing time left for auto rekey2• If you are running a Fabric OS version earlier th

Strona 46 - (KAC) certificate

xiv Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02• Chapter 6, “Maintenance and Troubleshooting,” provides information on troubleshoot

Strona 47

122 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing switch encryption properties2The Encryption Target Disk LUNs dia

Strona 48

Fabric OS Encryption Administrator’s Guide (KMIP) 12353-1002747-02Viewing and editing switch encryption properties2FIGURE 103 Encryption Switch Proper

Strona 49

124 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing switch encryption properties2• Encryption Group: The name of the

Strona 50

Fabric OS Encryption Administrator’s Guide (KMIP) 12553-1002747-02Viewing and editing switch encryption properties2• Online• Set State To: Identifies

Strona 51

126 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2FIGURE 104 Import Signed Certificate

Strona 52

Fabric OS Encryption Administrator’s Guide (KMIP) 12753-1002747-02Viewing and editing encryption group properties2The Encryption Group Properties dial

Strona 53

128 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2General tabThe General tab (Figure 1

Strona 54 - -----BEGIN CERTIFICATE

Fabric OS Encryption Administrator’s Guide (KMIP) 12953-1002747-02Viewing and editing encryption group properties2When the first encryption engine com

Strona 55

130 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2• Not responding• Failed authenticat

Strona 56

Fabric OS Encryption Administrator’s Guide (KMIP) 13153-1002747-02Viewing and editing encryption group properties2• Connection Status: The switch’s co

Strona 57

Fabric OS Encryption Administrator’s Guide (KMIP) xv53-1002747-02Command syntax conventionsCommand syntax in this manual follows these conventions:Not

Strona 58

132 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2Members tab Remove buttonYou can cli

Strona 59

Fabric OS Encryption Administrator’s Guide (KMIP) 13353-1002747-02Viewing and editing encryption group properties2A warning message is displayed when

Strona 60

134 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2FIGURE 108 Encryption Group Properti

Strona 61

Fabric OS Encryption Administrator’s Guide (KMIP) 13553-1002747-02Viewing and editing encryption group properties2• Registered Authentication Cards ta

Strona 62

136 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2• Right- and Left-arrow buttons: You

Strona 63

Fabric OS Encryption Administrator’s Guide (KMIP) 13753-1002747-02Viewing and editing encryption group properties2Tape Pools tabTape pools are managed

Strona 64

138 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2All encryption engines in the encryp

Strona 65

Fabric OS Encryption Administrator’s Guide (KMIP) 13953-1002747-02Viewing and editing encryption group properties24. Based on your selection, do one o

Strona 66

140 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption-related acronyms in log messages2FIGURE 113 Encryption Group Properties D

Strona 67 - Encryption preparation

Fabric OS Encryption Administrator’s Guide (KMIP) 14153-1002747-02Chapter3Configuring Encryption Using the CLIIn this chapter•Overview. . . . . . . .

Strona 68 - Creating an encryption group

xvi Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Key termsFor definitions specific to Brocade and Fibre Channel, see the technical gl

Strona 69

142 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Overview3OverviewThis chapter explains how to use the command line interface (CLI) t

Strona 70

Fabric OS Encryption Administrator’s Guide (KMIP) 14353-1002747-02Command RBAC permissions and AD types34. PortMember: allows all control operations o

Strona 71

144 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Command RBAC permissions and AD types3createhaclusterNOMN N N OMN NDisallowedcreatet

Strona 72

Fabric OS Encryption Administrator’s Guide (KMIP) 14553-1002747-02Cryptocfg Help command output3Cryptocfg Help command outputAll encryption operations

Strona 73 - Protocol (KMIP)

146 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Management LAN configuration3switch:admin> cryptocfg --help -nodecfgUsage: crypto

Strona 74

Fabric OS Encryption Administrator’s Guide (KMIP) 14753-1002747-02Configuring cluster links3The following example configures a static IP address and g

Strona 75

148 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Setting encryption node initialization3IP Address change of a node within an encrypt

Strona 76

Fabric OS Encryption Administrator’s Guide (KMIP) 14953-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)3From the standpoint of

Strona 77

150 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)36. Configure the KMIP s

Strona 78 - --initnode command

Fabric OS Encryption Administrator’s Guide (KMIP) 15153-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)33. Verify the cluster s

Strona 79 - --reg keyvault

Fabric OS Encryption Administrator’s Guide (KMIP) xvii53-1002747-02For information about the Key Management Interoperability Protocol standard, visit

Strona 80

152 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3h. Aft

Strona 81

Fabric OS Encryption Administrator’s Guide (KMIP) 15353-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Signin

Strona 82

154 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)33. Und

Strona 83

Fabric OS Encryption Administrator’s Guide (KMIP) 15553-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)32. On

Strona 84 - Error Instructions dialog box

156 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Regist

Strona 85

Fabric OS Encryption Administrator’s Guide (KMIP) 15753-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Time o

Strona 86

158 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Notify

Strona 87 - Creating HA clusters

Fabric OS Encryption Administrator’s Guide (KMIP) 15953-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3The fo

Strona 88

160 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a member node to an encryption group3 Server SDK Version:

Strona 89 - Invoking failback

Fabric OS Encryption Administrator’s Guide (KMIP) 16153-1002747-02Adding a member node to an encryption group3CAUTIONAfter adding the member node to t

Strona 90 - Adding an encryption target

xviii Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-023. World Wide Name (WWN)Use the licenseIdShow command to display the WWN of the ch

Strona 91 - 4. Click Next

162 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a member node to an encryption group3NOTEIf the maximum number of certificate

Strona 92

Fabric OS Encryption Administrator’s Guide (KMIP) 16353-1002747-02Generating and backing up the master key3Additional Secondary Key Vault Information:

Strona 93

164 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability clusters32. Export the master key to the key vault. Make a note of

Strona 94

Fabric OS Encryption Administrator’s Guide (KMIP) 16553-1002747-02High availability clusters3• It is recommended that the HA cluster configuration be

Strona 95

166 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability clusters3Adding an encryption engine to an HA cluster1. Log in to

Strona 96

Fabric OS Encryption Administrator’s Guide (KMIP) 16753-1002747-02High availability clusters3Number of HA Clusters: 1HA cluster name: dthac - 2 EE ent

Strona 97 - FIGURE 70 Next Steps screen

168 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability clusters3Policy Configuration ExamplesThe following examples illus

Strona 98

Fabric OS Encryption Administrator’s Guide (KMIP) 16953-1002747-02Re-exporting a master key3Re-exporting a master keyYou can export master keys to the

Strona 99

170 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Re-exporting a master key3Exporting an additional key IDExample: Subsequent master k

Strona 100

Fabric OS Encryption Administrator’s Guide (KMIP) 17153-1002747-02Re-exporting a master key3e3:ae:aa:89:ec:12:0c:04:29:61:9c:99:44:a3:9b:9ae3:ae:aa:89

Strona 101

Fabric OS Encryption Administrator’s Guide (KMIP) 153-1002747-02Chapter1Encryption OverviewIn this chapter•Host and LUN considerations . . . . . . . .

Strona 102

172 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Enabling the encryption engine3Enabling the encryption engineEnable the encryption e

Strona 103

Fabric OS Encryption Administrator’s Guide (KMIP) 17353-1002747-02Zoning considerations3 No HA cluster membership EE Attributes: Media T

Strona 104

174 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Zoning considerations3Frame redirection zoningName Server-based frame redirection en

Strona 105 - Configuring storage arrays

Fabric OS Encryption Administrator’s Guide (KMIP) 17553-1002747-02Zoning considerations3 Redirect: No The Local Name Server has 1 entry }The nsshow co

Strona 106

176 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02CryptoTarget container configuration37. Create a zone that includes the initiator an

Strona 107

Fabric OS Encryption Administrator’s Guide (KMIP) 17753-1002747-02CryptoTarget container configuration3FIGURE 118 Relationship between initiator, virt

Strona 108 - Moving Targets

178 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02CryptoTarget container configuration3• When removing an existing disk or tape target

Strona 109

Fabric OS Encryption Administrator’s Guide (KMIP) 17953-1002747-02CryptoTarget container configuration3FabricAdmin:switch> cryptocfg --create -cont

Strona 110

180 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02CryptoTarget container configuration3zone: red_______base 00:00:00:00:00:00:00:01;

Strona 111 - Tape LUN statistics

Fabric OS Encryption Administrator’s Guide (KMIP) 18153-1002747-02CryptoTarget container configuration3Deleting a CryptoTarget containerYou may delete

Strona 112

Copyright © 2012- 2013 Brocade Communications Systems, Inc. All Rights Reserved.Brocade, Brocade Assurance, the B-wing symbol, BigIron, DCX, Fabric OS

Strona 113

2 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Terminology1TerminologyThe following are definitions of terms used extensively in this

Strona 114

182 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3NOTEIf a CryptoTarget container is moved in a configuration

Strona 115

Fabric OS Encryption Administrator’s Guide (KMIP) 18353-1002747-02Crypto LUN configuration3Discovering a LUNWhen adding a LUN to a CryptoTarget contai

Strona 116 - Encryption engine rebalancing

184 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3NOTEThere is a maximum of 512 disk LUNs per Initiator in a

Strona 117 - Master keys

Fabric OS Encryption Administrator’s Guide (KMIP) 18553-1002747-02Crypto LUN configuration3VT: 20:00:00:05:1e:41:4e:1d 20:01:00:05:1e:41:4e:1dNumber o

Strona 118 - Alternate master key

186 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3TABLE 6 LUN parameters and policies Policy name Command pa

Strona 119

Fabric OS Encryption Administrator’s Guide (KMIP) 18753-1002747-02Crypto LUN configuration3Configuring a tape LUNThis example shows how to configure a

Strona 120 - ATTENTION

188 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3LUN serial number:Key ID state: Key ID not Applicab

Strona 121

Fabric OS Encryption Administrator’s Guide (KMIP) 18953-1002747-02Crypto LUN configuration3FabricAdmin:switch> cryptocfg --remove -LUN my_disk_tgt

Strona 122

190 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3CAUTIONWhen configuring a LUN with multiple paths, do not c

Strona 123

Fabric OS Encryption Administrator’s Guide (KMIP) 19153-1002747-02Impact of tape LUN configuration changes3Impact of tape LUN configuration changesLUN

Strona 124

Fabric OS Encryption Administrator’s Guide (KMIP) 353-1002747-02Terminology1Opaque Key VaultA storage location that provides untrusted key management

Strona 125

192 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring a multi-path Crypto LUN3Multi-path LUN configuration exampleFigure 119 o

Strona 126 - Creating a master key

Fabric OS Encryption Administrator’s Guide (KMIP) 19353-1002747-02Configuring a multi-path Crypto LUN3c. Create a CryptoTarget container (CTC2) for ta

Strona 127 - Security Settings

194 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring a multi-path Crypto LUN3b. Add the same LUN to the CryptoTarget containe

Strona 128 - Setting zeroization

Fabric OS Encryption Administrator’s Guide (KMIP) 19553-1002747-02Decommissioning LUNs3Decommissioning LUNsA disk device needs to be decommissioned wh

Strona 129

196 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Decommissioning LUNs33. Enter cryptocfg --show -decommissionedkeyids to obtain a lis

Strona 130 - Disk device decommissioning

Fabric OS Encryption Administrator’s Guide (KMIP) 19753-1002747-02Decommissioning replicated LUNs3Decommissioning replicated LUNsThe following scenari

Strona 131 - Decommissioning disk LUNs

198 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Force-enabling a decommissioned disk LUN for encryption3NOTEDo not delete the key fr

Strona 132

Fabric OS Encryption Administrator’s Guide (KMIP) 19953-1002747-02Force-enabling a disabled disk LUN for encryption37. En a bl e th e LU N .FabricAd

Strona 133 - Displaying Universal IDs

200 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape pool configuration3Tape pool configurationTape pools are used by tape backup ap

Strona 134 - Setting disk LUN Re-key All

Fabric OS Encryption Administrator’s Guide (KMIP) 20153-1002747-02Tape pool configuration3CommVault Galaxy labelingCommVault uses a storage policy for

Strona 135

4 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02The Brocade Encryption Switch1The Brocade Encryption SwitchThe Brocade Encryption Swit

Strona 136

202 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape pool configuration3Creating a tape poolTake the following steps to create a tap

Strona 137

Fabric OS Encryption Administrator’s Guide (KMIP) 20353-1002747-02Tape pool configuration3Deleting a tape poolThis command does not issue a warning if

Strona 138 - Thin provisioned LUNs

204 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02First-time encryption3First-time encryptionFirst-time encryption, also referred to a

Strona 139 - Thin provisioning support

Fabric OS Encryption Administrator’s Guide (KMIP) 20553-1002747-02Thin provisioned LUNs3Thin provisioned LUNsWith the introduction of Fabric OS 7.1.0,

Strona 140

206 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Thin provisioned LUNs3Encryption algorithm: AES256-XTSKey ID state: Read

Strona 141

Fabric OS Encryption Administrator’s Guide (KMIP) 20753-1002747-02Data rekeying3• Because windows host utility “sdelete –c” sends WRITE command with z

Strona 142

208 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Data rekeying3Configuring a LUN for automatic rekeyingRekeying options are configure

Strona 143

Fabric OS Encryption Administrator’s Guide (KMIP) 20953-1002747-02Data rekeying3Initiating a manual rekey sessionYou can initiate a rekeying session m

Strona 144

210 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Data rekeying3Current LBA: 488577Operation succeeded.Suspension and resum

Strona 145

Fabric OS Encryption Administrator’s Guide (KMIP) 21153-1002747-02Chapter4Deployment ScenariosIn this chapter•Single encryption switch, two paths from

Strona 146 - General tab

Fabric OS Encryption Administrator’s Guide (KMIP) 553-1002747-02The FS8-18 blade1The FS8-18 bladeThe FS8-18 blade provides the same features and funct

Strona 147

212 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Single encryption switch, two paths from host to target4Single encryption switch, tw

Strona 148 - Members tab

Fabric OS Encryption Administrator’s Guide (KMIP) 21353-1002747-02Single fabric deployment - HA cluster4Single fabric deployment - HA clusterFigure 12

Strona 149

214 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Single fabric deployment - DEK cluster4In Figure 121, the two encryption switches pr

Strona 150 - Members tab Remove button

Fabric OS Encryption Administrator’s Guide (KMIP) 21553-1002747-02Dual fabric deployment - HA and DEK cluster4In Figure 122, two encryption switches a

Strona 151 - Security tab

216 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Multiple paths, one DEK cluster, and two HA clusters4failover for the encryption pat

Strona 152

Fabric OS Encryption Administrator’s Guide (KMIP) 21753-1002747-02Multiple paths, one DEK cluster, and two HA clusters4The configuration details shown

Strona 153 - HA Clusters tab

218 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Multiple paths, DEK cluster, no HA cluster4Multiple paths, DEK cluster, no HA cluste

Strona 154

Fabric OS Encryption Administrator’s Guide (KMIP) 21953-1002747-02Multiple paths, DEK cluster, no HA cluster4The configuration details are as follows:

Strona 155 - Tape Pools tab

220 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Deployment in Fibre Channel routed fabrics4Deployment in Fibre Channel routed fabric

Strona 156 - Adding tape pools

Fabric OS Encryption Administrator’s Guide (KMIP) 22153-1002747-02Deployment in Fibre Channel routed fabrics4The following is a summary of steps for c

Strona 157 - Engine Operations tab

6 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Recommendation for connectivity1Recommendation for connectivityIn order to achieve hig

Strona 158 - TABLE 3 Encryption acronyms

222 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Deployment as part of an edge fabric4Deployment as part of an edge fabricIn this dep

Strona 159 - In this chapter

Fabric OS Encryption Administrator’s Guide (KMIP) 22353-1002747-02Deployment with FCIP extension switches4Deployment with FCIP extension switchesEncry

Strona 160 - Command validation checks

224 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02VMware ESX server deployments4VMware ESX server deploymentsVMware ESX servers may ho

Strona 161

Fabric OS Encryption Administrator’s Guide (KMIP) 22553-1002747-02VMware ESX server deployments4Figure 131 shows a VMware ESX server with two guest op

Strona 162 - (Continued)

226 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02VMware ESX server deployments4

Strona 163 - Cryptocfg Help command output

Fabric OS Encryption Administrator’s Guide (KMIP) 22753-1002747-02Chapter5Best Practices and Special TopicsIn this chapter•Firmware upgrade and downgr

Strona 164 - Configuring cluster links

228 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Firmware upgrade and downgrade considerations5Firmware upgrade and downgrade conside

Strona 165

Fabric OS Encryption Administrator’s Guide (KMIP) 22953-1002747-02Firmware upgrade and downgrade considerations5• Guidelines for firmware upgrade of e

Strona 166 - Node is a member node

230 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuration upload and download considerations58. Check that CryptoTarget Containe

Strona 167

Fabric OS Encryption Administrator’s Guide (KMIP) 23153-1002747-02Configuration upload and download considerations5• Certificates generated internally

Strona 168 - Creating a cluster

Fabric OS Encryption Administrator’s Guide (KMIP) 753-1002747-02Brocade encryption solution overview1Brocade encryption solution overviewThe loss of s

Strona 169 - Adding a node to the cluster

232 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02HP-UX considerations5Steps after configuration downloadFor all opaque key vaults, re

Strona 170 - KeySecure)

Fabric OS Encryption Administrator’s Guide (KMIP) 23353-1002747-02AIX Considerations5Best practices are as follows:• Create a cryptoTarget container f

Strona 171

234 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape metadata5Tape metadataOne kilobyte of metadata is added per tape block for both

Strona 172

Fabric OS Encryption Administrator’s Guide (KMIP) 23553-1002747-02Tape block zero handling5Tape pool configuration is used only when labeling of tape

Strona 173

236 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Redirection zones5• Before committing CryptoTarget container or LUN configurations o

Strona 174 - Verify connectivity

Fabric OS Encryption Administrator’s Guide (KMIP) 23753-1002747-02Deployment with Admin Domains (AD)5Deployment with Admin Domains (AD)Virtual devices

Strona 175 - • Node CP certificate

238 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02PID failover5PID failover Virtual device PIDs do not persist upon failover within a

Strona 176

Fabric OS Encryption Administrator’s Guide (KMIP) 23953-1002747-02KAC certificate registration expiry5Allow rekey to complete before deleting a contai

Strona 177

240 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Changing IP addresses in encryption groups5Changing IP addresses in encryption group

Strona 178 - • cryptocfg --enableEE

Fabric OS Encryption Administrator’s Guide (KMIP) 24153-1002747-02Best practices for host clusters in an encryption environment5FIGURE 132 Fan-in rati

Strona 179

8 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Brocade encryption solution overview1Data flow from server to storageThe Brocade Encry

Strona 180

242 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02HA Cluster deployment considerations and best practices5• For AIX-based Power HA Sys

Strona 181

Fabric OS Encryption Administrator’s Guide (KMIP) 24353-1002747-02Chapter6Maintenance and TroubleshootingIn this chapter•Encryption group and HA clust

Strona 182 - High availability clusters

244 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6Encryption group and HA cluster maintena

Strona 183 - Creating an HA cluster

Fabric OS Encryption Administrator’s Guide (KMIP) 24553-1002747-02Encryption group and HA cluster maintenance6FIGURE 133 Removing a node from an encry

Strona 184

246 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6 IP Address: 10.32.33

Strona 185

Fabric OS Encryption Administrator’s Guide (KMIP) 24753-1002747-02Encryption group and HA cluster maintenance6Deleting an encryption groupYou can dele

Strona 186 - Policy Configuration Examples

248 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6Displaying the HA cluster configurationN

Strona 187 - Re-exporting a master key

Fabric OS Encryption Administrator’s Guide (KMIP) 24953-1002747-02Encryption group and HA cluster maintenance6Replacing an HA cluster member1. Log in

Strona 188 - Viewing the master key IDs

250 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6FIGURE 134 Replacing a failed encryption

Strona 189

Fabric OS Encryption Administrator’s Guide (KMIP) 25153-1002747-02Encryption group and HA cluster maintenance6Case 2: Replacing a “live” encryption en

Strona 190

Fabric OS Encryption Administrator’s Guide (KMIP) 953-1002747-02Data encryption key life cycle management1Data encryption key life cycle managementDat

Strona 191 - Zoning considerations

252 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6Performing a manual failback of an encry

Strona 192 - Frame redirection zoning

Fabric OS Encryption Administrator’s Guide (KMIP) 25353-1002747-02Encryption group merge and split use cases6• After the failback completes, the crypt

Strona 193

254 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6NOTEWhen attempting to reclaim a failed B

Strona 194

Fabric OS Encryption Administrator’s Guide (KMIP) 25553-1002747-02Encryption group merge and split use cases6RecoveryIf auto failback policy is set, n

Strona 195

256 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6• The isolation of N3 from the group lead

Strona 196 - Gathering information

Fabric OS Encryption Administrator’s Guide (KMIP) 25753-1002747-02Encryption group merge and split use cases6Recovery1. Restore the connection between

Strona 197

258 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6NOTEThe collective time allowed (the hear

Strona 198

Fabric OS Encryption Administrator’s Guide (KMIP) 25953-1002747-02Encryption group merge and split use cases6NOTEIf one or more EG status displays as

Strona 199

260 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6Display the encryption group state again.

Strona 200 - Crypto LUN configuration

Fabric OS Encryption Administrator’s Guide (KMIP) 26153-1002747-02Encryption group merge and split use cases6If you now perform a cryptocfg --show -gr

Strona 201 - Configuring a Crypto LUN

10 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Data encryption key life cycle management1FIGURE 5 DEK life cycle

Strona 202

262 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases66. Verify your encryption group is re-con

Strona 203

Fabric OS Encryption Administrator’s Guide (KMIP) 26353-1002747-02Encryption group database manual operations6Encryption group database manual operati

Strona 204 - LUN parameters and policies

264 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Key vault diagnostics6Use the --sync -securitydb command to distribute the security

Strona 205 - Configuring a tape LUN

Fabric OS Encryption Administrator’s Guide (KMIP) 26553-1002747-02Measuring encryption performance6• Key class and format on the KV configured for the

Strona 206

266 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Measuring encryption performance6FabricAdmin:switch> cryptocfg --perfshow [slot]

Strona 207

Fabric OS Encryption Administrator’s Guide (KMIP) 26753-1002747-02General encryption troubleshooting6General encryption troubleshootingTable 9 lists t

Strona 208

268 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02General encryption troubleshooting6A backup fails because the LUN is always in the i

Strona 209

Fabric OS Encryption Administrator’s Guide (KMIP) 26953-1002747-02General encryption troubleshooting6A performance drop occurs when using DPM on a Mic

Strona 210

270 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Troubleshooting examples using the CLI6Troubleshooting examples using the CLIEncrypt

Strona 211

Fabric OS Encryption Administrator’s Guide (KMIP) 27153-1002747-02Troubleshooting examples using the CLI6Encryption Disabled CryptoTarget LUNIf the LU

Strona 212

Fabric OS Encryption Administrator’s Guide (KMIP) 1153-1002747-02Master key management1Master key managementCommunications with opaque key vaults are

Strona 213 - Decommissioning LUNs

272 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Management application encryption wizard troubleshooting6Management application encr

Strona 214

Fabric OS Encryption Administrator’s Guide (KMIP) 27353-1002747-02Management application encryption wizard troubleshooting6Errors related to adding a

Strona 215

274 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Management application encryption wizard troubleshooting6General errors related to t

Strona 216

Fabric OS Encryption Administrator’s Guide (KMIP) 27553-1002747-02LUN policy troubleshooting6LUN policy troubleshootingTable 14 may be used as an aid

Strona 217

276 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Loss of encryption group leader after power outage6Loss of encryption group leader a

Strona 218 - Tape pool configuration

Fabric OS Encryption Administrator’s Guide (KMIP) 27753-1002747-02MPIO and internal LUN states65. Synchronize the crypto configurations across all mem

Strona 219 - NetWorker labeling

278 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02FS8-18 blade removal and replacement61. Enter the cryptocfg --resume_rekey command,

Strona 220 - Creating a tape pool

Fabric OS Encryption Administrator’s Guide (KMIP) 27953-1002747-02FS8-18 blade removal and replacement63. If the replaced FS8-18 blade is in member no

Strona 221 - Modifying a tape pool

280 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02FS8-18 blade removal and replacement6NOTEBecause the FS8-18 blade was inserted in th

Strona 222 - First-time encryption

Fabric OS Encryption Administrator’s Guide (KMIP) 28153-1002747-02Brocade Encryption Switch removal and replacement611. If a master key is not present

Strona 223

Fabric OS Encryption Administrator’s Guide (KMIP) iii53-1002747-02ContentsAbout This DocumentIn this chapter . . . . . . . . . . . . . . . . . . . . .

Strona 224 - Space reclamation

12 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Cisco Fabric Connectivity support1Cisco Fabric Connectivity supportThe Brocade Encryp

Strona 225 - Data rekeying

282 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Brocade Encryption Switch removal and replacement68. Power on the new Brocade Encryp

Strona 226

Fabric OS Encryption Administrator’s Guide (KMIP) 28353-1002747-02Brocade Encryption Switch removal and replacement621. Import the signed CSR/Cert ont

Strona 227

284 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Brocade Encryption Switch removal and replacement631. If HA cluster membership for t

Strona 228

Fabric OS Encryption Administrator’s Guide (KMIP) 28553-1002747-02Brocade Encryption Switch removal and replacement611. Invoke the following command t

Strona 229 - Deployment Scenarios

286 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Reclaiming the WWN base of a failed Brocade Encryption Switch627. Verify that defzon

Strona 230

Fabric OS Encryption Administrator’s Guide (KMIP) 28753-1002747-02Removing stale rekey information for a LUN6NOTEWhen attempting to reclaim a failed B

Strona 231 - Virtual

288 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Splitting an encryption group into two encryption groups6NOTEYou should not join a F

Strona 232

Fabric OS Encryption Administrator’s Guide (KMIP) 28953-1002747-02Moving an encryption blade from one EG to another in the same fabric6a. Create the g

Strona 233

290 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Moving an encryption switch from one EG to another in the same fabric6Moving an encr

Strona 234

Fabric OS Encryption Administrator’s Guide (KMIP) 29153-1002747-02AppendixAState and Status InformationIn this appendix•Encryption engine security pro

Strona 235

Fabric OS Encryption Administrator’s Guide (KMIP) 1353-1002747-02Chapter2Configuring Encryption Using the Management ApplicationIn this chapter•Encryp

Strona 236

292 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Security processor KEK statusASecurity processor KEK statusTable 19 lists security p

Strona 237

Fabric OS Encryption Administrator’s Guide (KMIP) 29353-1002747-02Encrypted LUN statesALUN_1ST_TIME_REKEY_IN_PROG First time rekey is in progress.LUN_

Strona 238

294 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encrypted LUN statesALUN_DIS_WR_META_DONE_ERR Disabled (Write metadata done with fai

Strona 239 - --rdcreate [host wwn]

Fabric OS Encryption Administrator’s Guide (KMIP) 29553-1002747-02Encrypted LUN statesATABLE 21 Tape LUN statesInternal Names Console String Explanati

Strona 240

296 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encrypted LUN statesALUN_ENCRYPT Encryption enabled The tape medium is present, and

Strona 241 - FIGURE 129 FCIP deployment

Fabric OS Encryption Administrator’s Guide (KMIP) 29753-1002747-02IndexAadd commands--add -haclustermember, 166--add -initiator, 179, 187, 193--add -L

Strona 242 - VMware ESX server deployments

298 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUNadding to CryptoTarget container using the CLI, 182configuring, 182, 183mo

Strona 243

Fabric OS Encryption Administrator’s Guide (KMIP) 29953-1002747-02disk lunsdecommissioning, 113rekeying manually, 115setting rekey all, 116viewing rek

Strona 244

300 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02encryption nodesetting initialization, 28encryption nodessetting initialization, 148

Strona 245

Fabric OS Encryption Administrator’s Guide (KMIP) 30153-1002747-02Iimport commands, --import, 161initialize commands--initEE, 254initEE, 158--initnode

Strona 246 - General guidelines

14 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption Center features2•Viewing and editing encryption group properties . . . . .

Strona 247

302 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02member nodesadding to an encryption group, 160members tab, 130remove button, 132modi

Strona 248

Fabric OS Encryption Administrator’s Guide (KMIP) 30353-1002747-02set commands--set -failback, 168--set -keyvault LKM, 159show commands--show, 162, 17

Strona 249

304 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02troubleshootingcfgshow command, 267configshow, 267cryptocfg --show -groupcfg command

Strona 250 - HP-UX considerations

Fabric OS Encryption Administrator’s Guide (KMIP) 1553-1002747-02Encryption user privileges2Encryption user privilegesIn BNA, resource groups are assi

Strona 251 - Disk metadata

16 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2Smart card usageSmart Cards are credit card-sized cards that contain

Strona 252 - Tape pools

Fabric OS Encryption Administrator’s Guide (KMIP) 1753-1002747-02Smart card usage2• Establishing a trusted link with the NetApp LKM key vault.• Decomm

Strona 253 - Tape key expiry

18 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage23. Locate the Authentication Card Quorum Size and select the quorum

Strona 254

Fabric OS Encryption Administrator’s Guide (KMIP) 1953-1002747-02Smart card usage2Registering authentication cards from the databaseSmart cards that a

Strona 255

20 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2Deregistering an authentication cardAuthentication cards can be remo

Strona 256 - PID failover

Fabric OS Encryption Administrator’s Guide (KMIP) 2153-1002747-02Smart card usage2Using system cardsSystem cards are smart cards that can be used to c

Strona 257

iv Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Support for virtual fabrics. . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 258

22 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2Enabling or disabling the system card requirementTo use a system car

Strona 259

Fabric OS Encryption Administrator’s Guide (KMIP) 2353-1002747-02Smart card usage2Deregistering system cardsSystem cards can be removed from the datab

Strona 260 - Tape Device LUN Mapping

24 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2FIGURE 12 Smart Card asset tracking dialog boxThe Smart Cards table

Strona 261

Fabric OS Encryption Administrator’s Guide (KMIP) 2553-1002747-02Smart card usage2• Save As button: Saves the entire list of smart cards to a file. Th

Strona 262

26 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Network connections22. Insert the smart card into the card reader.3. After the card’s

Strona 263

Fabric OS Encryption Administrator’s Guide (KMIP) 2753-1002747-02Blade processor links2Blade processor linksEach encryption switch or blade has two Gb

Strona 264

28 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption node initialization and certificate generation23. Enter the link IP addres

Strona 265 - Removing an HA cluster member

Fabric OS Encryption Administrator’s Guide (KMIP) 2953-1002747-02Key Management Interoperability Protocol2Key Management Interoperability Protocol The

Strona 266

30 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2NOTEIf you are configuri

Strona 267

Fabric OS Encryption Administrator’s Guide (KMIP) 3153-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Setting FIPS compliance1

Strona 268

Fabric OS Encryption Administrator’s Guide (KMIP) v53-1002747-02High availability (HA) clusters . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 269 - Deleting an HA cluster member

32 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Creating a local CA1. Fr

Strona 270 - Failover/failback example

Fabric OS Encryption Administrator’s Guide (KMIP) 3353-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Creating a server certif

Strona 271 - Recovery

34 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 19 KeySecure Cert

Strona 272

Fabric OS Encryption Administrator’s Guide (KMIP) 3553-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)25. Copy the certificate

Strona 273

36 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)28. Select Server as the

Strona 274

Fabric OS Encryption Administrator’s Guide (KMIP) 3753-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 24 KeySecure Cert

Strona 275

38 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Creating a cluster1. Fro

Strona 276 - -hbmisses and -hbtimeout

Fabric OS Encryption Administrator’s Guide (KMIP) 3953-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 27 KeySecure Clus

Strona 277

40 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Configuring a Brocade gr

Strona 278

Fabric OS Encryption Administrator’s Guide (KMIP) 4153-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Registering the KeySecur

Strona 279

vi Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Disk device decommissioning . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 280

42 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Signing the encryption n

Strona 281

Fabric OS Encryption Administrator’s Guide (KMIP) 4353-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 31 Certificate an

Strona 282 - Key vault diagnostics

44 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 32 Import Signed

Strona 283 - -portperfshow

Fabric OS Encryption Administrator’s Guide (KMIP) 4553-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 34 Backup and Res

Strona 284

46 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Configuring the KMIP ser

Strona 285 - Problem Resolution

Fabric OS Encryption Administrator’s Guide (KMIP) 4753-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Adding a node to the clu

Strona 286 - General errors and conditions

48 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 38 KeySecure Clus

Strona 287

Fabric OS Encryption Administrator’s Guide (KMIP) 4953-1002747-02Encryption preparation28. Under Restore Backup, select Upload from browser, then ente

Strona 288

50 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2• An external host is available on the LAN to facilitate

Strona 289

Fabric OS Encryption Administrator’s Guide (KMIP) 5153-1002747-02Creating an encryption group25. Select Security Settings.6. Confirm the configuration

Strona 290

Fabric OS Encryption Administrator’s Guide (KMIP) vii53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure). . . . . . . . . . . .

Strona 291

52 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2FIGURE 43 Designate Switch Membership dialog box 5. For

Strona 292

Fabric OS Encryption Administrator’s Guide (KMIP) 5353-1002747-02Creating an encryption group2The dialog box contains the following information:• Encr

Strona 293 - LUN policy troubleshooting

54 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2Using this dialog box, you can select a key vault for th

Strona 294

Fabric OS Encryption Administrator’s Guide (KMIP) 5553-1002747-02Creating an encryption group2Configuring key vault settings for Key Management Intero

Strona 295 - MPIO and internal LUN states

56 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group24. (Optional) Enter a Backup Key Vault IP address or hos

Strona 296 - Multi-node EG replacement

Fabric OS Encryption Administrator’s Guide (KMIP) 5753-1002747-02Creating an encryption group2FIGURE 48 Specify Master Key File Name dialog box9. Ente

Strona 297

58 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2FIGURE 49 Select Security Settings dialog box12. Set quo

Strona 298 - Single-node EG replacement

Fabric OS Encryption Administrator’s Guide (KMIP) 5953-1002747-02Creating an encryption group2FIGURE 50 Confirm Configuration dialog box14. Confirm th

Strona 299 - Multi-node EG Case

60 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2All configuration items have green check marks if the co

Strona 300

Fabric OS Encryption Administrator’s Guide (KMIP) 6153-1002747-02Adding a switch to an encryption group23. Register the key vault. BNA registers the k

Strona 301

viii Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 302 - Single-node EG Replacement

62 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a switch to an encryption group2FIGURE 53 Configure Switch Encryption wizard -

Strona 303

Fabric OS Encryption Administrator’s Guide (KMIP) 6353-1002747-02Adding a switch to an encryption group2The dialog box contains the following informat

Strona 304

64 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a switch to an encryption group2FIGURE 56 Specify Public Key Certificate (KAC)

Strona 305

Fabric OS Encryption Administrator’s Guide (KMIP) 6553-1002747-02Adding a switch to an encryption group2FIGURE 58 Configuration Status dialog boxAll c

Strona 306 - Encryption group Nodes

66 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a switch to an encryption group2FIGURE 59 Error Instructions dialog box8. Revi

Strona 307

Fabric OS Encryption Administrator’s Guide (KMIP) 6753-1002747-02Replacing an encryption engine in an encryption group2Replacing an encryption engine

Strona 308

68 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability (HA) clusters2High availability (HA) clusters A high availability (

Strona 309 - State and Status Information

Fabric OS Encryption Administrator’s Guide (KMIP) 6953-1002747-02High availability (HA) clusters2Creating HA clusters For the initial encryption node,

Strona 310 - Encrypted LUN states

70 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability (HA) clusters23. Click the right arrow to add the encryption engine

Strona 311

Fabric OS Encryption Administrator’s Guide (KMIP) 7153-1002747-02Configuring encryption storage targets2Failback optionThe Failback option determines

Strona 312

Fabric OS Encryption Administrator’s Guide (KMIP) ix53-1002747-02Deployment in Fibre Channel routed fabrics. . . . . . . . . . . . . . . . . .220Deplo

Strona 313 - TABLE 21 Tape LUN states

72 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets26. Configuration Status7. Important Instructio

Strona 314

Fabric OS Encryption Administrator’s Guide (KMIP) 7353-1002747-02Configuring encryption storage targets2FIGURE 63 Configure Storage Encryption welcome

Strona 315

74 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets2The dialog box contains the following informat

Strona 316

Fabric OS Encryption Administrator’s Guide (KMIP) 7553-1002747-02Configuring encryption storage targets26. Select a target from the list. (The Target

Strona 317

76 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets2NOTENote: You must enter the host node world w

Strona 318

Fabric OS Encryption Administrator’s Guide (KMIP) 7753-1002747-02Configuring encryption storage targets2FIGURE 67 Name Container dialog box10. Enter t

Strona 319

78 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets2The screen contains the following information:

Strona 320

Fabric OS Encryption Administrator’s Guide (KMIP) 7953-1002747-02Configuring encryption storage targets213. Review any post-configuration instructions

Strona 321

80 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring hosts for encryption targets2Configuring hosts for encryption targetsUse

Strona 322

Fabric OS Encryption Administrator’s Guide (KMIP) 8153-1002747-02Configuring hosts for encryption targets2FIGURE 72 Encryption Target Hosts dialog box

Komentarze do niniejszej Instrukcji

Brak uwag