Dell PowerVault TL4000 Dell Model TL2000/TL4000 Tape Library- User's Guide - Page 79

Secondary IP address IPv4 or IPv6

Page 79 highlights

a77ug192 3. Click Activate to save the key and expand the screen for additional encryption settings. Figure 4-24. Configure Library: Encryption Activation screen 4. Select Enable SSL for EKM to enable Secure Sockets Layer for the Dell Encryption Key Manager application. 5. Select an Encryption method for each logical library. v Without an encryption license key, select None or Application Managed Encryption. v With an encryption license key, select Library Managed Encryption. 6. Select an Encryption policy for each logical library. v Encrypt All: This is the default policy. It encrypts all cartridges using the default data keys specified in the EKM. This setting applies to all drives in a TL2000/TL4000 logical library. v Internal Label - Selective Encryption: Check your tape backup software application documentation to see if this feature is supported. v Internal Label - Encrypt All: Check your tape backup software application documentation to see if this feature is supported. 7. A primary and secondary EKM server can be set for each logical library. Each partition has its own Encryption and EKM settings. Maintaining primary and secondary EKM servers is desired for maximum availability of encrypted backup and recovery. These settings are required for Library Managed Encryption only. Enter the EKM Server Setting information. Note: The IP address of the Encryption Key Manager (EKM) host must be consistent with the library Network settings. This means if the library is set to IPV4 only network support, the EKM host must be an IPV4 address. If the Dell PowerVault library is required to function in a mixed network environment the library must be set to IPv4 + IPv6. v Primary IP address (IPv4 or IPv6): Enter the IP address of the primary EKM server. v Primary TCP port: After entering the Primary IP address, the library will automatically set the value of the Primary TCP port. v Secondary IP address (IPv4 or IPv6): Enter the IP address of the secondary EKM server. v Secondary TCP port: After entering the Secondary IP address, the library will automatically set the value of the Secondary TCP port. Note: The Default Port for TCP (SSL disabled) is 3801. The Default Port for SSL is 443. These values are the default values set by the library. They can be changed depending on the user configuration but the user has to make sure they match the EKM properties file. Chapter 4. Installation and Configuration 4-23

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283

3.
Click
Activate
to save the key and expand the screen for additional encryption
settings.
4.
Select
Enable SSL for EKM
to enable Secure Sockets Layer for the Dell
Encryption Key Manager application.
5.
Select an
Encryption method
for each logical library.
v
Without an encryption license key, select
None
or
Application Managed
Encryption
.
v
With an encryption license key, select
Library Managed Encryption
.
6.
Select an
Encryption policy
for each logical library.
v
Encrypt All
: This is the default policy. It encrypts all cartridges using the
default data keys specified in the EKM. This setting applies to all drives in a
TL2000/TL4000 logical library.
v
Internal Label - Selective Encryption
: Check your tape backup software
application documentation to see if this feature is supported.
v
Internal Label - Encrypt All
: Check your tape backup software application
documentation to see if this feature is supported.
7.
A primary and secondary EKM server can be set for each logical library. Each
partition has its own Encryption and EKM settings. Maintaining primary and
secondary EKM servers is desired for maximum availability of encrypted
backup and recovery. These settings are required for Library Managed
Encryption only. Enter the
EKM Server Setting
information.
Note:
The IP address of the Encryption Key Manager (EKM) host must be
consistent with the library Network settings. This means if the library is
set to
IPV4 only
network support, the EKM host must be an IPV4
address. If the Dell PowerVault library is required to function in a mixed
network environment the library must be set to
IPv4 + IPv6
.
v
Primary IP address (IPv4 or IPv6)
: Enter the IP address of the primary EKM
server.
v
Primary TCP port
: After entering the Primary IP address, the library will
automatically set the value of the Primary TCP port.
v
Secondary IP address (IPv4 or IPv6)
: Enter the IP address of the secondary
EKM server.
v
Secondary TCP port
: After entering the
Secondary IP address
, the library
will automatically set the value of the
Secondary TCP port
.
Note:
The Default Port for TCP (SSL disabled) is
3801
. The Default Port for
SSL is
443
. These values are the default values set by the library. They
can be changed depending on the user configuration but the user has
to make sure they match the EKM properties file.
a77ug192
Figure 4-24. Configure Library: Encryption Activation screen
Chapter 4. Installation and Configuration
4-23