HP Cisco MDS 9120 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 245

Offline Data Recovery in Cisco SME, About Offline Data Restore Tool

Page 245 highlights

Send documentation comments to [email protected] B A P P E N D I X Offline Data Recovery in Cisco SME The Cisco SME solution provides seamless encryption service through a hardware-based encryption engine. However, when the MSM-18/4 module or the Cisco MDS 9222i fabric switch is not available, you can use the Offline Data Restore Tool (ODRT). This appendix describes the basic functionalities and operations of this software application. About Offline Data Restore Tool The Offline Data Restore Tool (ODRT) is a standalone Linux application and is a comprehensive solution for recovering encrypted data on tape volume groups when the MSM-18/4 module or the Cisco MDS 9222i switch is unavailable. The Offline Data Restore Tool (ODRT) reads the tape volumes, encrypted by Cisco SME, and decrypts and decompresses the data and then writes clear-text data back to the tape volumes. Figure B-1 shows the topology supported by the Offline Data Restore Tool (ODRT). Figure B-1 Offline Data Restore Tool (ODRT) Topology A Linux host running O ffline Data Restore Tool Tape drive with Cisco SME-encrypted media SAN 186933 The encryption and decryption of data works in the following two steps: • Tape-to-disk- The Offline Data Restore Tool (ODRT) reads the encrypted data from the tape and stores it as intermediate files on the disk. • Disk-to-tape- The Offline Data Restore Tool (ODRT) reads intermediate files on the disk, decrypts and decompresses (if applicable) the data and writes the clear-text data to the tape. The decryption key is obtained from the volume group file which you need to export from the Cisco Key Management Center (KMC). For information on exporting volume groups, see Chapter 6, "Cisco SME Key Management." The Offline Data Restore Tool (ODRT) feature is invoked by entering the odrt.bin command from the Linux shell. OL-18091-01, Cisco MDS NX-OS Release 4.x Cisco MDS 9000 Family Storage Media Encryption Configuration Guide B-1

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
B-1
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
APPENDIX
B
Offline Data Recovery in Cisco SME
The Cisco SME solution provides seamless encryption service through a hardware-based encryption
engine. However, when the MSM-18/4 module or the Cisco MDS 9222i fabric switch is not available,
you can use the Offline Data Restore Tool (ODRT).
This appendix describes the basic functionalities and operations of this software application.
About Offline Data Restore Tool
The Offline Data Restore Tool (ODRT) is a standalone Linux application and is a comprehensive
solution for recovering encrypted data on tape volume groups when the MSM-18/4 module or the Cisco
MDS 9222i switch is unavailable. The Offline Data Restore Tool (ODRT) reads the tape volumes,
encrypted by Cisco SME, and decrypts and decompresses the data and then writes clear-text data back
to the tape volumes.
Figure B-1
shows the topology supported by the Offline Data Restore Tool (ODRT).
Figure B-1
Offline Data Restore Tool (ODRT) Topology
The encryption and decryption of data works in the following two steps:
Tape-to-disk– The Offline Data Restore Tool (ODRT) reads the encrypted data from the tape and
stores it as intermediate files on the disk.
Disk-to-tape– The Offline Data Restore Tool (ODRT) reads intermediate files on the disk, decrypts
and decompresses (if applicable) the data and writes the clear-text data to the tape.
The decryption key is obtained from the volume group file which you need to export from the Cisco Key
Management Center (KMC). For information on exporting volume groups, see
Chapter 6, “Cisco SME
Key Management.”
The Offline Data Restore Tool (ODRT) feature is invoked by entering the
odrt.bin
command from the
Linux shell.
A Linux host
running O ffline
Data Restore Tool
SAN
Tape drive with
Cisco SME-encrypted
media
186933