HP Cisco MDS 9216A Cisco MDS 9000 Family Storage Media Encryption Configuratio - Page 30

Cisco SME Prerequisites, Java Cryptography Extension Requirement, Zoning Requirement

Page 30 highlights

Cisco SME Prerequisites Chapter 1 Product Overview Send documentation comments to [email protected] Smart Card Readers To employ standard and advanced security levels, Cisco SME requires the following: • Smart Card Reader for Cisco SME (DS-SCR-K9) • Smart Card for Cisco SME (DS-SC-K9) The smart card reader is a USB device that is connected to a management workstation. The management workstation is used to configure the Cisco SME cluster. The smart card reader requires the smart card drivers that are included on the installation CD. These must be installed on the management workstation where the reader is attached. Note The smart card reader is supported on Windows-only platforms. Cisco SME Prerequisites This section describes the following requirements: • Java Cryptography Extension Requirement, page 1-12 • Zoning Requirement, page 1-12 • FC-Redirect Requirements, page 1-12 Java Cryptography Extension Requirement Cisco SME requires Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files 5C0 (for JRE 1.5). You will need to extract and copy the local_policy.jar and the US_export_policy.jar files to the $JAVA_HOME\jre\lib\security\ directory. You can obtain these files from the Fabric Manager Installation CD. Zoning Requirement Zoning requirements include the following: • Internal virtual N-ports are created by Cisco SME in the default zone. The default zone must be set to deny and these virtual N-ports must not be zoned with any other host or target. For information on zoning, refer to the Cisco MDS 9000 Family CLI Configuration Guide. FC-Redirect Requirements FC-Redirect requirements include the following: • The MDS switch with the MSM-18/4 module installed or the 9222i switch needs to be running Cisco MDS SAN-OS Release 3.2(2c) or later, or Cisco NX-OS 4.x. • The target must be connected to an MDS 95XX/9216/9222i switch running Cisco MDS SAN-OS Release 3.2(2c) or later, or Cisco NX-OS 4.x. • 32 targets per MSM-18/4 module can be FC-redirected. 1-12 Cisco MDS 9000 Family Storage Media Encryption Configuration Guide OL-18091-01, Cisco MDS NX-OS Release 4.x

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
1-12
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Chapter 1
Product Overview
Cisco SME Prerequisites
Smart Card Readers
To employ standard and advanced security levels, Cisco SME requires the following:
Smart Card Reader for Cisco SME (DS-SCR-K9)
Smart Card for Cisco SME (DS-SC-K9)
The smart card reader is a USB device that is connected to a management workstation. The management
workstation is used to configure the Cisco SME cluster. The smart card reader requires the smart card
drivers that are included on the installation CD. These must be installed on the management workstation
where the reader is attached.
Note
The smart card reader is supported on Windows-only platforms.
Cisco SME Prerequisites
This section describes the following requirements:
Java Cryptography Extension Requirement, page 1-12
Zoning Requirement, page 1-12
FC-Redirect Requirements, page 1-12
Java Cryptography Extension Requirement
Cisco SME requires Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files
5C0 (for JRE 1.5). You will need to extract and copy the local_policy.jar and the US_export_policy.jar
files to the $JAVA_HOME\jre\lib\security\ directory. You can obtain these files from the Fabric Manager
Installation CD.
Zoning Requirement
Zoning requirements include the following:
Internal virtual N-ports are created by Cisco SME in the default zone. The default zone must be set
to deny and these virtual N-ports must not be zoned with any other host or target.
For information on zoning, refer to the
Cisco MDS 9000 Family CLI Configuration Guide
.
FC-Redirect Requirements
FC-Redirect requirements include the following:
The MDS switch with the MSM-18/4 module installed or the 9222i switch needs to be running Cisco
MDS SAN-OS Release 3.2(2c) or later, or Cisco NX-OS 4.x.
The target must be connected to an MDS 95XX/9216/9222i switch running Cisco MDS SAN-OS
Release 3.2(2c) or later, or Cisco NX-OS 4.x.
32 targets per MSM-18/4 module can be FC-redirected.