HP Cisco MDS 9134 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 71

Specifying the Key Management Center Server, Media Key Setting, Definition

Page 71 highlights

Chapter 4 Cisco SME Cluster Management Creating a Cisco SME Cluster Using the Cisco SME Wizard Send documentation comments to [email protected] Table 4-2 Media Key Settings Media Key Setting Definition Use unique key per In unique key mode, a unique key is issued for each tape volume. The default is media unique key mode. Store key on tape If you choose unique key mode (see above), this mode allows you to store the encrypted media key on the tape volume not in the Cisco KMC. This provides better scaling when your backup environment includes a large number of tapes. This is recommended for managing a large number of tape volume keys. Key-on-tape mode is disabled by default. Auto-volume grouping Cisco SME automatically creates a volume group and categorizes the appropriate tape volumes encrypted under this group based on the backup application's volume pool configuration. Auto-volume grouping is disabled by default. Compression Cisco SME can perform compression followed by encryption if this option is selected. Compression is enabled by default. Note Compression will be enabled for a tape drive in one of two ways: (a) configuration or (b) if the compression is not enabled through configuration and the tape drive is enabled for compression, compression is implicitly enabled for this tape drive. Recycle Tapes Select this option to enable purging of the keys upon tape recycling. When a tape is recycled or relabeled, a new key is generated and used for encryption. Enabling this option purges the key that was used to encrypt data before the tape was recycled. Note This option must be disabled if the tapes are cloned offline without the involvement of the backup application itself. Tape recycling is enabled by default. Specifying the Key Management Center Server In the Key Management Server screen, you can choose the primary and the secondary key management center servers from the drop-down menu. You can specify an IP address or a host name for the servers. Click Next. The dual server settings will be available after you configure the high availability settings in the Key Manager Settings screen. For more information on the configuration, see the "Choosing High Availability Settings" section on page 6-5. OL-18091-01, Cisco MDS NX-OS Release 4.x Cisco MDS 9000 Family Storage Media Encryption Configuration Guide 4-9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
4-9
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Chapter 4
Cisco SME Cluster Management
Creating a Cisco SME Cluster Using the Cisco SME Wizard
Specifying the Key Management Center Server
In the Key Management Server screen, you can choose the primary and the secondary key management
center servers from the drop-down menu. You can specify an IP address or a host name for the servers.
Click
Next
.
The dual server settings will be available after you configure the high availability settings in the Key
Manager Settings screen. For more information on the configuration, see the
“Choosing High
Availability Settings” section on page 6-5
.
Table 4-2
Media Key Settings
Media Key Setting
Definition
Use unique key per
media
In unique key mode, a unique key is issued for each tape volume. The default is
unique key mode.
Store key on tape
If you choose unique key mode (see above), this mode allows you to store the
encrypted media key on the tape volume not in the Cisco KMC. This provides
better scaling when your backup environment includes a large number of tapes.
This is recommended for managing a large number of tape volume keys.
Key-on-tape mode is disabled by default.
Auto-volume
grouping
Cisco SME automatically creates a volume group and categorizes the appropriate
tape volumes encrypted under this group based on the backup application's
volume pool configuration.
Auto-volume grouping is disabled by default.
Compression
Cisco SME can perform compression followed by encryption if this option is
selected.
Compression is enabled by default.
Note
Compression will be enabled for a tape drive in one of two ways: (a)
configuration or (b) if the compression is not enabled through
configuration and the tape drive is enabled for compression, compression
is implicitly enabled for this tape drive.
Recycle Tapes
Select this option to enable purging of the keys upon tape recycling.
When a tape is recycled or relabeled, a new key is generated and used for
encryption. Enabling this option purges the key that was used to encrypt data
before the tape was recycled.
Note
This option must be disabled if the tapes are cloned offline without the
involvement of the backup application itself.
Tape recycling is enabled by default.