HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 117

IP Address change of a node within an encryption group

Page 117 highlights

Configuring cluster links 3 NOTE The IP address of the cluster link should be configured before enabling the encryption engine for encryption. If the IP address is configured after the encryption engine is enabled for encryption, or if the IP address of the cluster link ports is modified after encryption engine is enabled for encryption, the encryption switch needs to be rebooted, and the encryption blade needs to be powered off and powered on (slotpoweroff/slotpoweron) for the IP address configuration to take effect. Failure to do so will result in Re-Key operation not starting in the encryption group or high availability (HA) cluster. IP Address change of a node within an encryption group Modifying the IP Address of a node that is part of an encryption group is disruptive in terms of cluster operation. The change causes the encryption group to split and if the node was part of an HA cluster, failover/failback capability is lost. Note that the ipaddrset command issues no warning or prevents you from changing a node IP address that is part of a configured encryption group or HA cluster. Follow the steps below to recover from the situation. Note that this recovery does not affect existing host encryption I/O. • If the node is the group leader, perform the following steps: 1. Log into the group leader as Admin or SecurityAdmin. 2. Eject all the member nodes from the encryption group. 3. Change the group leader node IP address. 4. Delete the encryption group and then recreate the encryption group and reregister the member nodes with the group leader using the cryptocfg - -add -membernode command. NOTE A reboot is not needed beginning with version 6.4.0. • If the node is a member node, perform the following steps: 1. Log into the Group Leader as Admin or SecurityAdmin. 2. Eject and then de-register the node from the encryption group. 3. Change the IP address of the member node and then register the node member node with the group leader. NOTE A reboot is not needed beginning with version 6.4.0. Fabric OS Encryption Administrator's Guide 99 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS Encryption Administrator’s Guide
99
53-1001864-01
Configuring cluster links
3
NOTE
The IP address of the cluster link should be configured before enabling the encryption engine for
encryption. If the IP address is configured after the encryption engine is enabled for encryption, or
if the IP address of the cluster link ports is modified after encryption engine is enabled for
encryption, the encryption switch needs to be rebooted, and the encryption blade needs to be
powered off and powered on (slotpoweroff/slotpoweron) for the IP address configuration to take
effect. Failure to do so will result in Re-Key operation not starting in the encryption group or high
availability (HA) cluster.
IP Address change of a node within an encryption group
Modifying the IP Address of a node that is part of an encryption group is disruptive in terms of
cluster operation. The change causes the encryption group to split and if the node was part of an
HA cluster, failover/failback capability is lost. Note that the
ipaddrset
command issues no warning
or prevents you from changing a node IP address that is part of a configured encryption group or
HA cluster. Follow the steps below to recover from the situation. Note that this recovery does not
affect existing host encryption I/O.
If the node is the group leader, perform the following steps:
1.
Log into the group leader as Admin or SecurityAdmin.
2.
Eject all the member nodes from the encryption group.
3.
Change the group leader node IP address.
4.
Delete the encryption group and then recreate the encryption group and reregister the
member nodes with the group leader using the
cryptocfg - -add -membernode <wwn>
command.
NOTE
A reboot is not needed beginning with version 6.4.0.
If the node is a member node, perform the following steps:
1.
Log into the Group Leader as Admin or SecurityAdmin.
2.
Eject and then de-register the node from the encryption group.
3.
Change the IP address of the member node and then register the node member node with
the group leader.
NOTE
A reboot is not needed beginning with version 6.4.0.