HP 1606 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 199

Maintenance and Troubleshooting, In this Encryption group and HA cluster maintenance

Page 199 highlights

Chapter Maintenance and Troubleshooting 6 In this Chapter •Encryption group and HA cluster maintenance 181 •Troubleshooting examples using the CLI 198 •Management application encryption wizard troubleshooting 200 •Errors related to adding a switch to an existing group 200 •LUN policy troubleshooting 204 •MPIO and internal LUN states 206 Encryption group and HA cluster maintenance This section describes advanced configuration options that you can use to modify existing encryption groups and HA clusters, and to recover from problems with one or more member nodes in the group. All group-wide configuration commands are executed on the group leader. Commands that clear group-related states from an individual node are executed on the node. The commands require Admin or SecurityAdmin permissions. Removing a node from an encryption group This procedure permanently removes a node from the encryption group as shown in Figure 71. Upon removal, the HA cluster failover capability and target associations pertaining to the node are no longer present. If you wish to take a node out of a group without disrupting these relationships, use the cryptocfg --replaceEE command. Refer to the section "Replacing an HA cluster member" on page 185 for instructions. The procedure for removing a node depends on the node's status within an encryption group. HA cluster membership and Crypto LUN configurations must be cleared before you can permanently remove a member node from an encryption group. 1. Log into the group leader as Admin or SecurityAdmin. 2. If the node is part of an HA cluster, perform the following steps: a. Remove the node from the HA cluster with the cryptocfg --rem -haclustermember command. b. Clear all CryptoTarget configurations from the member node with the cryptocfg --delete -container command. 3. Determine the state of the node. Log into the member node and enter the cryptocfg --show -groupmember command followed by the node WWN. Provide a slot number if the encryption engine is a blade. Fabric OS Encryption Administrator's Guide 181 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS Encryption Administrator’s Guide
181
53-1001864-01
Chapter
6
Maintenance and Troubleshooting
In this Chapter
Encryption group and HA cluster maintenance. . . . . . . . . . . . . . . . . . . . . . 181
Troubleshooting examples using the CLI . . . . . . . . . . . . . . . . . . . . . . . . . . . 198
Management application encryption wizard troubleshooting . . . . . . . . . . 200
Errors related to adding a switch to an existing group . . . . . . . . . . . . . . . . 200
LUN policy troubleshooting. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 204
MPIO and internal LUN states. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 206
Encryption group and HA cluster maintenance
This section describes advanced configuration options that you can use to modify existing
encryption groups and HA clusters, and to recover from problems with one or more member nodes
in the group.
All group-wide configuration commands are executed on the group leader. Commands that clear
group-related states from an individual node are executed on the node. The commands require
Admin or SecurityAdmin permissions.
Removing a node from an encryption group
This procedure permanently removes a node from the encryption group as shown in
Figure 71
.
Upon removal, the HA cluster failover capability and target associations pertaining to the node are
no longer present. If you wish to take a node out of a group without disrupting these relationships,
use the
cryptocfg
--
replaceEE
command
.
Refer to the section
“Replacing an HA cluster member”
on page 185
for instructions.
The procedure for removing a node depends on the node’s status within an encryption group. HA
cluster membership and Crypto LUN configurations must be cleared before you can permanently
remove a member node from an encryption group.
1.
Log into the group leader as Admin or SecurityAdmin.
2.
If the node is part of an HA cluster, perform the following steps:
a.
Remove the node from the HA cluster with the
cryptocfg
--
rem -haclustermember
command.
b.
Clear all CryptoTarget configurations from the member node with the
cryptocfg
--
delete
-container
command.
3.
Determine the state of the node. Log into the member node and enter the
cryptocfg
--
show
-groupmember
command followed by the node WWN. Provide a slot number if the encryption
engine is a blade.