HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 134

Enabling the encryption engine, Checking encryption engine status

Page 134 highlights

3 Enabling the encryption engine Enabling the encryption engine Enable the encryption engine by entering the cryptocfg --enableEE command. Provide a slot number if the encryption engine is a blade. NOTE Every time a Brocade Encryption Switch or DCX or DCX-4S chassis containing one or more FS8-18 blade goes through power cycle event, or after issuing slotpoweroff followed by slotpoweron for an FS8-18 blade in DCX or DCX-4S Chassis, the encryption engine must be enabled manually by the Security Administrator. Hosts cannot access the storage LUNs through the storage paths exposed on this Brocade Encryption Switch or FS8-18 blade until the encryption engine is enabled. The encryption engine state can viewed using the cryptocfg --show -localEE command, or by displaying switch or blade properties from DFCM. An encryption engine that is not enabled indicates Waiting for Enable EE. SecurityAdmin:switch>cryptocfg --enableEE Operation succeeded. Checking encryption engine status You can verify the encryption engine status at any point in the setup process and get information about the next required configuration steps or to troubleshoot an encryption engine that behaves in unexpected ways. Use the cryptocfg --show -localEE command to check the encryption engine status. SecurityAdmin:switch> cryptocfg --show -localEE EE Slot: 1 SP state: Online Primary Link KeyID: 85:1c:ca:dd:fc:8c:31:fc:87:21:26:d1:24:a0:92:be Secondary Link KeyID: 98:4f:b4:98:c0:42:ab:6b:6d:65:ba:f2:fc:aa:b5:8a HA Cluster Membership: mace40_dcx74_1 EE Attributes: Link IP Addr : 10.32.72.75 Link GW IP Addr : 10.32.64.1 Link Net Mask : 255.255.240.0 Link MAC Addr : 00:05:1e:53:8d:cd Link MTU : 1500 Link State : UP Media Type : DISK/TAPE Rebalance Recommended: NO System Card Label : System Card CID : Remote EE Reachability : Node WWN/Slot EE IP Addr EE State IO Link State 10:00:00:05:1e:54:22:36/0 10.32.72.62 EE_STATE_ONLINE Reachable 10:00:00:05:1e:47:30:00/1 10.32.72.104 EE_STATE_ONLINE Reachable 10:00:00:05:1e:47:30:00/3 10.32.72.105 EE_STATE_ONLINE Reachable 10:00:00:05:1e:47:30:00/10 10.32.72.106 EE_STATE_ONLINE Reachable 10:00:00:05:1e:47:30:00/12 10.32.72.107 EE_STATE_ONLINE Reachable EE Slot: 2 SP state: Online Primary Link KeyID: 85:1c:ca:dd:fc:8c:31:fc:87:21:26:d1:24:a0:92:be Secondary Link KeyID: 98:4f:b4:98:c0:42:ab:6b:6d:65:ba:f2:fc:aa:b5:8a No HA cluster membership EE Attributes: 116 Fabric OS Encryption Administrator's Guide 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

116
Fabric OS Encryption Administrator’s Guide
53-1001864-01
Enabling the encryption engine
3
Enabling the encryption engine
Enable the encryption engine by entering the
cryptocfg
--
enableEE
command. Provide a slot
number if the encryption engine is a blade.
NOTE
Every time a Brocade Encryption Switch or DCX or DCX-4S chassis containing one or more
FS8-18 blade goes through power cycle event, or after issuing
slotpoweroff <slot number>
followed by
slotpoweron <slot number>
for an FS8-18 blade in DCX or DCX-4S Chassis, the
encryption engine must be enabled manually by the Security Administrator. Hosts cannot
access the storage LUNs through the storage paths exposed on this Brocade Encryption Switch
or FS8-18 blade until the encryption engine is enabled. The encryption engine state can
viewed using the
cryptocfg --show -localEE
command, or by displaying switch or blade
properties from DFCM. An encryption engine that is not enabled indicates
Waiting for Enable
EE
.
SecurityAdmin:switch>
cryptocfg --enableEE
Operation succeeded.
Checking encryption engine status
You can verify the encryption engine status at any point in the setup process and get information
about the next required configuration steps or to troubleshoot an encryption engine that behaves in
unexpected ways. Use the
cryptocfg
--
show -localEE
command to check the encryption engine
status.
SecurityAdmin:switch> cryptocfg --show -localEE
EE Slot: 1
SP state: Online
Primary Link KeyID: 85:1c:ca:dd:fc:8c:31:fc:87:21:26:d1:24:a0:92:be
Secondary Link KeyID: 98:4f:b4:98:c0:42:ab:6b:6d:65:ba:f2:fc:aa:b5:8a
HA Cluster Membership: mace40_dcx74_1
EE Attributes:
Link IP Addr : 10.32.72.75
Link GW IP Addr : 10.32.64.1
Link Net Mask : 255.255.240.0
Link MAC Addr : 00:05:1e:53:8d:cd
Link MTU : 1500
Link State : UP
Media Type : DISK/TAPE
Rebalance Recommended: NO
System Card Label :
System Card CID :
Remote EE Reachability :
Node WWN/Slot EE IP Addr EE State IO Link State
10:00:00:05:1e:54:22:36/0 10.32.72.62 EE_STATE_ONLINE Reachable
10:00:00:05:1e:47:30:00/1 10.32.72.104 EE_STATE_ONLINE Reachable
10:00:00:05:1e:47:30:00/3 10.32.72.105 EE_STATE_ONLINE Reachable
10:00:00:05:1e:47:30:00/10 10.32.72.106 EE_STATE_ONLINE Reachable
10:00:00:05:1e:47:30:00/12 10.32.72.107 EE_STATE_ONLINE Reachable
EE Slot: 2
SP state: Online
Primary Link KeyID: 85:1c:ca:dd:fc:8c:31:fc:87:21:26:d1:24:a0:92:be
Secondary Link KeyID: 98:4f:b4:98:c0:42:ab:6b:6d:65:ba:f2:fc:aa:b5:8a
No HA cluster membership
EE Attributes: