HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 40

Network connections, Configuring blade processor links

Page 40 highlights

2 Network connections Network connections Before you use the encryption setup wizard for the first time, you must have the following required network connections: • The management ports on all encryption switches and 384-port Backbone Chassis CPs that have encryption blades installed must have a LAN connection to the SAN management program, and must be available for discovery. • A supported key management appliance must be connected on the same LAN as the management port of the encryption switches, 384-port Backbone Chassis CPs, and the SAN Management program. • In some cases, you may want to have an external host available on the LAN to facilitate certificate exchange between encryption nodes and the key management appliance. You may use the SAN management program host computer rather than an external host. • All switches in the planned encryption group must be interconnected on a private LAN. This LAN is used to exchange security parameters and certificates, and to synchronize encryption engine operations. Refer to "Configuring blade processor links" on page 22 for details. Configuring blade processor links Each encryption switch or blade has two GbE ports labeled Ge0 and Ge1. The Ge0 and Ge1 ports are Ethernet ports that connect encryption switches and blades to other encryption switches and blades. Both ports of each encryption switch or blade must be connected to the same IP network, and the same subnet. Static IP addresses should be assigned. VLANs should not be used, and DHCP should not be used. These two ports are bonded together as a single virtual network interface to provide link layer redundancy. All encryption switches or blades in an encryption group must be interconnected by these links through a dedicated LAN before their encryption engines are enabled. Security parameters and certificates cannot be exchanged if these links are not configured and active. Take the following steps to configure blade processor links. 1. Select Configure > Encryption from the menu bar. The Encryption Center dialog box displays. 2. Right click on the encryption engine, and select Blade Processor Link. The Blade Processor Link dialog box displays. 3. Enter the link IP address and mask, and the gateway IP address. 4. Click OK. The Blade Processor Link dialog box may also be launched from the following locations: - Select Group > HA Clusters and select the Configure Blade Processor Link button. - Select a Group, Switch or Encryption Engine, select Targets > LUN and select the Configure Blade Processor Link button. 22 Fabric OS Encryption Administrator's Guide 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

22
Fabric OS Encryption Administrator’s Guide
53-1001864-01
Network connections
2
Network connections
Before you use the encryption setup wizard for the first time, you must have the following required
network connections:
The management ports on all encryption switches and 384-port Backbone Chassis CPs that
have encryption blades installed must have a LAN connection to the SAN management
program, and must be available for discovery.
A supported key management appliance must be connected on the same LAN as the
management port of the encryption switches, 384-port Backbone Chassis CPs, and the SAN
Management program.
In some cases, you may want to have an external host available on the LAN to facilitate
certificate exchange between encryption nodes and the key management appliance. You may
use the SAN management program host computer rather than an external host.
All switches in the planned encryption group must be interconnected on a private LAN. This
LAN is used to exchange security parameters and certificates, and to synchronize encryption
engine operations. Refer to
“Configuring blade processor links”
on page 22 for details.
Configuring blade processor links
Each encryption switch or blade has two GbE ports labeled Ge0 and Ge1. The Ge0 and Ge1 ports
are Ethernet ports that connect encryption switches and blades to other encryption switches and
blades. Both ports of each encryption switch or blade must be connected to the same IP network,
and the same subnet. Static IP addresses should be assigned. VLANs should not be used, and
DHCP should not be used. These two ports are bonded together as a single virtual network
interface to provide link layer redundancy.
All encryption switches or blades in an encryption group must be interconnected by these links
through a dedicated LAN before their encryption engines are enabled. Security parameters and
certificates cannot be exchanged if these links are not configured and active.
Take the following steps to configure blade processor links.
1.
Select
Configure > Encryption
from the menu bar.
The
Encryption Center
dialog box displays.
2.
Right click on the encryption engine, and select
Blade Processor Link
.
The
Blade Processor Link
dialog box displays.
3.
Enter the link IP address and mask, and the gateway IP address.
4.
Click
OK
.
The
Blade Processor Link
dialog box may also be launched from the following locations:
-
Select
Group > HA Clusters
and select the
Configure Blade Processor Link
button.
-
Select a Group, Switch or Encryption Engine, select
Targets > LUN
and select the
Configure
Blade Processor Link
button.