Brocade Fabric OS Encryption Administrator’s Guide Support Handbücher

Bedienungsanleitungen und Benutzerhandbücher für Computerzubehör Brocade Fabric OS Encryption Administrator’s Guide Support.
Wir stellen 4 PDF-Handbücher Brocade Fabric OS Encryption Administrator’s Guide Support zum kostenlosen herunterladen nach Dokumenttypen zur Verfügung Bedienungsanleitung


Inhaltsverzeichnis

Fabric OS Encryption

1

Document History

2

Document Title iii

3

53-1002720-02

3

Contents

5

53-1002922-01

10

About This Document

15

What’s new in this document

16

Document conventions

16

Command syntax conventions

17

Notes, cautions, and warnings

17

Additional information

18

Getting technical help

19

Document feedback

20

Encryption Overview

21

Terminology

22

The Brocade Encryption Switch

24

The FS8-18 blade

25

FIPS mode

25

Performance licensing

25

Usage limitations

26

FIGURE 2 Encryption overview

27

FIGURE 3 Frame redirection

28

IO Sync LAN

29

FIGURE 5 DEK life cycle

30

Master key management

31

Support for virtual fabrics

31

Encryption Center features

34

Encryption user privileges

35

Smart card usage

36

Using system cards

41

Deregistering system cards

43

Using smart cards

43

Tracking smart cards

44

Editing smart cards

46

Network connections

47

Blade processor links

47

(KAC) certificate

48

Encryption preparation

55

Creating an encryption group

55

--initnode command

65

--set -keyvault command

65

--reg keyvault command

65

Creating HA clusters

72

Failback option

74

Invoking failback

74

Adding an encryption target

75

FIGURE 46 Next Steps screen

83

Configuring storage arrays

91

Remote replication LUNs

91

Moving targets

96

Tape LUN statistics

99

Encryption engine rebalancing

103

Master keys

104

Active master key

105

Alternate master key

105

Master key actions

106

ATTENTION

107

Creating a master key

113

Security settings

114

Setting zeroization

115

Redirection zones

117

Disk device decommissioning

117

Decommissioning disk LUNs

118

Displaying Universal IDs

120

Setting disk LUN Re-key All

121

Thin provisioned LUNs

125

Thin Provisioning support

126

General tab

133

Members tab

135

Members tab Remove button

136

Security tab

137

HA Clusters tab

139

Tape Pools tab

141

Adding tape pools

142

Engine Operations tab

143

TABLE 3 Encryption acronyms

144

In this chapter

145

Overview

146

Command validation checks

146

(Continued)

148

Cryptocfg Help command output

150

Management LAN configuration

150

Configuring cluster links

151

Node is a group leader node

152

Node is a member node

152

• FIPS crypto officer

153

• FIPS user

153

• Node CP certificate

153

Submitting the CSR to a CA

156

• cryptocfg --initEE

163

• cryptocfg --regEE

163

• cryptocfg --enableEE

163

High availability clusters

168

Creating an HA cluster

169

Policy Configuration Examples

172

Re-exporting a master key

173

Viewing the master key IDs

174

Zoning considerations

177

Frame redirection zoning

178

Gathering information

182

Crypto LUN configuration

186

Discovering a LUN

187

Configuring a Crypto LUN

187

Configuring a tape LUN

191

Decommissioning LUNs

195

SRDF LUNs

199

SRDF pairs

200

Adding replication LUNs

201

Reading metadata after sync

202

-newLUN option

203

TF snapshot rekeying details

208

ID> <initiator PWWN>

209

-not_ready option of TF

209

<initiator PWWN>

209

Tape pool configuration

213

Tape pool labeling

214

NetBackup labeling

215

NetWorker labeling

215

Creating a tape pool

216

Deleting a tape pool

216

Modifying a tape pool

217

First-time encryption

222

Data rekeying

225

Resource allocation

226

Rekeying modes

226

Deployment Scenarios

231

--rdcreate [host wwn]

240

FIGURE 103 FCIP deployment

242

Data mirroring deployment

243

VMware ESX server deployments

245

General guidelines

248

Enabling a disabled LUN

253

HP-UX considerations

253

AIX considerations

253

Disk metadata

254

Tape metadata

254

Tape data compression

255

Tape pools

255

Tape block zero handling

256

Tape key expiry

256

Avoid double encryption

258

PID failover

258

Manual rekey

259

Latency in rekey operations

259

Key vault best practices

263

Tape device LUN mapping

263

Deleting an encryption group

269

Removing an HA cluster member

269

Deleting an HA cluster member

273

Failover/failback example

274

Recovery

275

-hbmisses and -hbtimeout

280

Key vault diagnostics

286

--perfshow

287

-portperfshow

287

Command Activity

291

Problem Resolution

291

General errors and conditions

292

LUN policy troubleshooting

299

MPIO and internal LUN states

301

Multi-node EG replacement

302

Single-node EG replacement

304

Multi-node EG Case

305

Single-node EG Replacement

308

Deregistering a DPM key vault

310

FIGURE 111 DPM Clients page

311

TABLE 15 Compatibility Matrix

313

Encryption group Nodes

314

State and Status Information

317

Security processor KEK status

318

Encrypted LUN states

318

TABLE 22 Tape LUN states

321

Inhaltsverzeichnis

Fabric OS Encryption

1

Administrator’s Guide

1

Document History

2

Document Title iii

3

Contents

5

53-1002923-01

10

About This Document

15

What’s new in this document

16

Document conventions

16

Notes, cautions, and warnings

17

Additional information

18

Getting technical help

19

Document feedback

20

Encryption Overview

21

Terminology

22

The Brocade Encryption Switch

24

The FS8-18 blade

25

FIPS mode

25

Performance licensing

25

Usage limitations

26

FIGURE 2 Encryption overview

27

FIGURE 3 Frame redirection

28

IO Sync LAN

29

FIGURE 5 DEK life cycle

30

Master key management

31

Support for virtual fabrics

31

Encryption Center features

34

Encryption user privileges

35

Smart card usage

36

Using system cards

41

Deregistering system cards

43

Using smart cards

43

Tracking smart cards

43

Editing smart cards

46

Network connections

47

Blade processor links

47

(KAC) certificate

48

<primary

58

Encryption preparation

60

Creating an encryption group

61

(ESKM/SKM)

65

--initnode command

70

--set -keyvault command

70

--reg keyvault command

70

Creating HA clusters

78

Failback option

80

Invoking failback

80

Adding an encryption target

81

4. Click Next

82

FIGURE 42 Next Steps screen

88

Configuring storage arrays

95

Moving targets

99

Tape LUN statistics

101

Encryption engine rebalancing

105

Master keys

106

Active master key

107

Alternate master key

107

Master key actions

108

ATTENTION

109

Creating a master key

115

Security settings

116

Setting zeroization

117

Redirection zones

119

Disk device decommissioning

119

Decommissioning Disk LUNs

120

Displaying Universal IDs

122

Setting disk LUN Re-key All

123

Thin provisioned LUNs

127

Thin provisioning support

128

General tab

135

Members tab

137

Members tab Remove button

138

Security tab

139

HA Clusters tab

141

Tape Pools tab

143

Tape pools overview

144

Adding tape pools

144

Engine Operations tab

145

TABLE 3 Encryption acronyms

146

Overview

148

Command validation checks

148

(Continued)

150

Cryptocfg Help command output

152

Management LAN configuration

152

Configuring cluster links

153

Node is a group leader node

154

Node is a member node

154

• FIPS crypto officer

155

• FIPS user

155

• Node CP certificate

155

Configuring a Brocade group

156

• Use SSL

160

• Allow Key Export

160

Data Encryption Keys

168

Tape LUN support

169

• cryptocfg --initEE

170

• cryptocfg --regEE

170

• cryptocfg --enableEE

170

High availability clusters

174

Creating an HA cluster

175

Policy Configuration Examples

178

Re-exporting a master key

179

Viewing the master key IDs

180

Zoning considerations

183

Frame redirection zoning

184

Gathering information

188

Crypto LUN configuration

193

Configuring a Crypto LUN

194

Configuring a tape LUN

197

Decommissioning LUNs

205

Tape pool configuration

210

CommVault Galaxy labeling

211

NetBackup labeling

211

NetWorker labeling

211

Creating a tape pool

212

Deleting a tape pool

213

Modifying a tape pool

213

First-time encryption

214

Space reclamation

216

Data rekeying

217

Resource allocation

218

Rekeying modes

218

Deployment Scenarios

223

--rdcreate [host wwn]

232

FIGURE 100 FCIP deployment

235

VMware ESX server deployments

236

General guidelines

243

- KAC certificate

246

- CP certificate

246

HP-UX considerations

247

AIX Considerations

248

Enabling a disabled LUN

248

Disk metadata

248

Tape metadata

248

Tape data compression

249

Tape pools

249

Tape block zero handling

250

Tape key expiry

250

Avoid double encryption

252

PID failover

252

Manual rekey

253

Latency in rekey operations

253

Key Vault Best Practices

256

Tape device LUN mapping

257

Deleting an encryption group

263

Removing an HA cluster member

263

Deleting an HA cluster member

267

Failover/failback example

268

Recovery

269

-hbmisses and -hbtimeout

274

Key vault diagnostics

280

--perfshow

281

-portperfshow

281

Command Activity

285

Problem Resolution

285

General errors and conditions

286

LUN policy troubleshooting

293

MPIO and internal LUN states

295

Multi-node EG replacement

296

Single-node EG replacement

298

Multi-node EG Case

299

Single-node EG Replacement

302

SKM 1.x ESKM 2.x ESKM 3.x

306

Encryption group Nodes

307

State and Status Information

311

Security processor KEK status

312

Encrypted LUN states

312

TABLE 22 Tape LUN states

315

Inhaltsverzeichnis

Fabric OS Encryption

1

Document History

2

Contents

3

53-1002747-02

10

About This Document

13

What’s new in this document

14

Document conventions

14

Command syntax conventions

15

Notes, cautions, and warnings

15

Additional information

16

Getting technical help

17

Document feedback

18

Encryption Overview

19

Terminology

20

The Brocade Encryption Switch

22

The FS8-18 blade

23

FIPS mode

23

Performance licensing

23

Usage limitations

24

FIGURE 2 Encryption overview

25

FIGURE 3 Frame redirection

26

IO Sync LAN

27

FIGURE 5 DEK life cycle

28

Master key management

29

Support for virtual fabrics

29

Encryption Center features

32

Encryption user privileges

33

Smart card usage

34

Using system cards

39

Deregistering system cards

41

Using smart cards

41

Tracking smart cards

41

Editing smart cards

43

Network connections

44

Blade processor links

45

(KAC) certificate

46

-----BEGIN CERTIFICATE

54

Encryption preparation

67

Creating an encryption group

68

Protocol (KMIP)

73

--initnode command

78

--reg keyvault

79

Error Instructions dialog box

84

Creating HA clusters

87

Failback option

89

Invoking failback

89

Adding an encryption target

90

4. Click Next

91

FIGURE 70 Next Steps screen

97

Configuring storage arrays

105

Moving Targets

108

Tape LUN statistics

111

Encryption engine rebalancing

116

Master keys

117

Active master key

118

Alternate master key

118

Master key actions

118

ATTENTION

120

Creating a master key

126

Security Settings

127

Setting zeroization

128

Redirection zones

130

Disk device decommissioning

130

Decommissioning disk LUNs

131

Displaying Universal IDs

133

Setting disk LUN Re-key All

134

Thin provisioned LUNs

138

Thin provisioning support

139

General tab

146

Members tab

148

Members tab Remove button

150

Security tab

151

HA Clusters tab

153

Tape Pools tab

155

Adding tape pools

156

Engine Operations tab

157

TABLE 3 Encryption acronyms

158

In this chapter

159

Overview

160

Command validation checks

160

(Continued)

162

Cryptocfg Help command output

163

Management LAN configuration

164

Configuring cluster links

164

Node is a group leader node

166

Node is a member node

166

Setting FIPS compliance

168

Creating a local CA

168

Creating a server certificate

168

Creating a cluster

168

Backing up the certificates

169

Configuring the KMIP server

169

Adding a node to the cluster

169

KeySecure)

170

Register the KAC certificate

174

Verify connectivity

174

• Node CP certificate

175

• cryptocfg --initEE

178

• cryptocfg --regEE

178

• cryptocfg --enableEE

178

High availability clusters

182

Creating an HA cluster

183

Policy Configuration Examples

186

Re-exporting a master key

187

Viewing the master key IDs

188

Zoning considerations

191

Frame redirection zoning

192

Gathering information

196

Crypto LUN configuration

200

Discovering a LUN

201

Configuring a Crypto LUN

201

LUN parameters and policies

204

Configuring a tape LUN

205

Decommissioning LUNs

213

Tape pool configuration

218

CommVault Galaxy labeling

219

NetBackup labeling

219

NetWorker labeling

219

Creating a tape pool

220

Deleting a tape pool

221

Modifying a tape pool

221

First-time encryption

222

Space reclamation

224

Data rekeying

225

Deployment Scenarios

229

Virtual

231

--rdcreate [host wwn]

239

FIGURE 129 FCIP deployment

241

VMware ESX server deployments

242

General guidelines

246

HP-UX considerations

250

AIX Considerations

251

Enabling a disabled LUN

251

Disk metadata

251

Tape metadata

252

Tape data compression

252

Tape pools

252

Tape block zero handling

253

Tape key expiry

253

PID failover

256

Key Vault Best Practices

260

Tape Device LUN Mapping

260

Deleting an encryption group

265

Removing an HA cluster member

265

Deleting an HA cluster member

269

Failover/failback example

270

Recovery

271

-hbmisses and -hbtimeout

276

Key vault diagnostics

282

--perfshow

283

-portperfshow

283

Command Activity

285

Problem Resolution

285

General errors and conditions

286

LUN policy troubleshooting

293

MPIO and internal LUN states

295

Multi-node EG replacement

296

Single-node EG replacement

298

Multi-node EG Case

299

Single-node EG Replacement

302

Encryption group Nodes

306

State and Status Information

309

Security processor KEK status

310

Encrypted LUN states

310

TABLE 21 Tape LUN states

313

Inhaltsverzeichnis

Fabric OS Encryption

1

Administrator’s Guide

1

Environments

1

Document History

2

Contents

3

53-1002925-01

10

Appendix B LUN Policies

11

About This Document

13

What’s new in this document

14

Document conventions

14

Notes, cautions, and warnings

15

Additional information

16

Getting technical help

17

Document feedback

18

Encryption Overview

19

Terminology

20

The Brocade Encryption Switch

22

The FS8-18 blade

23

FIPS mode

23

Performance licensing

23

Usage limitations

24

FIGURE 2 Encryption overview

25

FIGURE 3 Frame redirection

26

IO Sync LAN

27

FIGURE 5 DEK life cycle

28

Support for virtual fabrics

29

Encryption Center features

32

Encryption user privileges

33

Smart card usage

34

Using system cards

39

Deregistering system cards

41

Using smart cards

41

Tracking smart cards

41

Editing smart cards

44

Network connections

45

Blade processor links

45

(KAC) certificate

46

Encryption preparation

52

Creating an encryption group

52

(LKM/SSKM)

56

--initnode command

61

--set -keyvault command

61

--reg keyvault command

61

High availability clusters

68

Creating HA clusters

69

Failback option

71

Invoking failback

71

Adding an encryption target

72

4. Click Next

73

FIGURE 44 Next Steps screen

79

Configuring storage arrays

87

Moving targets

90

Tape LUN statistics

92

Encryption engine rebalancing

97

Security settings

98

Setting zeroization

99

Redirection zones

101

Disk device decommissioning

101

Decommissioning Disk LUNs

102

Displaying Universal IDs

104

Setting disk LUN Re-key All

105

Thin provisioned LUNs

109

Thin provisioning support

110

General tab

117

Members tab

118

Members tab Remove button

120

Security tab

121

HA Clusters tab

123

Link Keys tab

124

Tape Pools tab

126

Adding tape pools

127

Engine Operations tab

128

TABLE 3 Encryption acronyms

129

In this chapter

131

Overview

132

Command validation checks

132

(Continued)

134

Cryptocfg Help command output

135

Management LAN configuration

136

Configuring cluster links

136

Node is a group leader node

138

Node is a member node

138

• Node CP certificate

140

Establishing the trusted link

145

[output truncated]

146

Creating an HA cluster

151

TABLE 5 Group-wide policies

152

Zoning considerations

153

Frame redirection zoning

154

Gathering information

158

Crypto LUN configuration

162

Discovering a LUN

163

Configuring a Crypto LUN

164

Configuring a tape LUN

167

Modify example

169

Decommissioning LUNs

175

Tape pool configuration

179

Tape pool labeling

180

NetBackup labeling

181

NetWorker labeling

181

Creating a tape pool

182

Deleting a tape pool

183

Modifying a tape pool

183

First-time encryption

184

Data rekeying

187

Resource allocation

188

Rekeying modes

188

10:00:00:05:1e:53:37:99

191

Operation Succeeded

191

Deployment Scenarios

193

--rdcreate [host wwn]

202

VMware ESX server deployments

205

General guidelines

210

HP-UX considerations

214

AIX Considerations

215

Enabling a disabled LUN

215

Disk metadata

216

Tape metadata

216

Tape data compression

217

Tape pools

217

Tape block zero handling

218

Tape key expiry

218

DF compatibility for tapes

218

Avoid double encryption

221

PID failover

221

Key Vault Best Practices

225

Tape Device LUN Mapping

225

Deleting an encryption group

231

Removing an HA cluster member

231

Deleting an HA cluster member

235

Failover/failback example

236

Recovery

237

-hbmisses and -hbtimeout

242

Key vault diagnostics

248

Command Activity

254

Problem Resolution

254

General errors and conditions

255

SSKM recommendations

256

LUN policy troubleshooting

262

MPIO and internal LUN states

264

Multi-node EG replacement

265

Single-node EG replacement

267

Multi-node EG Case

269

Single-node EG Replacement

272

Encryption group Nodes

276

State and Status Information

279

Security processor KEK status

280

Encrypted LUN states

280

TABLE 21 Tape LUN states

283

LUN Policies

285





Weitere Produkte und Handbücher für Computerzubehör Brocade

Modelle Dokumententyp
Fabric OS Upgrade Guide (Supporting Fabric OS v7.3 Bedienungsanleitung   Brocade Fabric OS Upgrade Guide (Supporting Fabric OS v7.3.0) User Manual, 34 Seiten
Fabric OS Troubleshooting and Diagnostics Guide (S Bedienungsanleitung   Brocade Fabric OS Troubleshooting and Diagnostics Guide (Supporting Fabric OS v7.3.0) User Manual, 130 Seiten
Fabric Watch Administrators Guide (Supporting Fabr Bedienungsanleitung   Brocade Fabric Watch Administrators Guide (Supporting Fabric OS v7.3.0) User Manual [en] , 116 Seiten
Flow Vision Administrators Guide (Supporting Fabri Bedienungsanleitung   Brocade Flow Vision Administrators Guide (Supporting Fabric OS v7.3.0) User Manual, 90 Seiten
Monitoring and Alerting Policy Suite Administrator Bedienungsanleitung   Brocade Monitoring and Alerting Policy Suite Administrators Guide (Supporting Fabric OS v7.3.0) User Manual [es] , 114 Seiten
5300 QuickStart Guide Bedienungsanleitung   Brocade 5300 QuickStart Guide User Manual, 2 Seiten
5300 Hardware Reference Manual Bedienungsanleitung   Brocade 5300 Hardware Reference Manual User Manual, 54 Seiten
EZSwitchSetup Administrator’s Guide (Supporting 30 Bedienungsanleitung   Brocade EZSwitchSetup Administrator’s Guide (Supporting 300, 5100, 5300, 6505, 6510, 6520, 7800, 7840, and VA-40FC) User Manual, 64 Seiten
300 Hardware Reference Manual Bedienungsanleitung   Brocade 300 Hardware Reference Manual User Manual [en] [es] , 52 Seiten
300 QuickStart Guide Bedienungsanleitung   Brocade 300 QuickStart Guide User Manual [es] , 2 Seiten
FICON Administrator’s Guide (Supporting Fabric OS Bedienungsanleitung   Brocade FICON Administrator’s Guide (Supporting Fabric OS v7.3.0) User Manual [es] , 126 Seiten
Web Tools Administrators Guide (Supporting Fabric Bedienungsanleitung   Brocade Web Tools Administrators Guide (Supporting Fabric OS v7.3.0) User Manual, 274 Seiten
6520 QuickStart Guide Bedienungsanleitung   Brocade 6520 QuickStart Guide User Manual, 2 Seiten
7800 Extension Switch Hardware Reference Manual Bedienungsanleitung   Brocade 7800 Extension Switch Hardware Reference Manual User Manual, 66 Seiten
6520 Hardware Reference Manual Bedienungsanleitung   Brocade 6520 Hardware Reference Manual User Manual, 70 Seiten
SAN Analytics Management Pack for VMware vCenter O Bedienungsanleitung   Brocade SAN Analytics Management Pack for VMware vCenter Operations Management Suite User’s Guide V1.0 User Manual, 30 Seiten
6510 QuickStart Guide Bedienungsanleitung   Brocade 6510 QuickStart Guide User Manual, 2 Seiten
6505 QuickStart Guide Bedienungsanleitung   Brocade 6505 QuickStart Guide User Manual, 2 Seiten
6510 Hardware Reference Manual Bedienungsanleitung   Brocade 6510 Hardware Reference Manual User Manual, 62 Seiten
6505 Hardware Reference Manual Bedienungsanleitung   Brocade 6505 Hardware Reference Manual User Manual, 66 Seiten