HP Brocade 8/12c Fabric OS Encryption Administrator's Guide - Page 173

Moving a CryptoTarget container, Crypto LUN configuration

Page 173 highlights

Crypto LUN configuration 3 Moving a CryptoTarget container You can move a CryptoTarget container from one encryption engine to another. The encryption engines must be part of the same fabric and the same encryption group, and the encryption engines must be online for this operation to succeed. This operation permanently transfers the encryption engine association of a given CryptoTarget container from an existing encryption engine to an alternate encryption engine. NOTE If a CryptoTarget container is moved in a configuration involving FCR, the LSAN zones and manually created redirect zones will need to be reconfigured with new VI and VT WWNs. Refer to the section "Deployment in Fibre Channel routed fabrics" on page 183 for instructions on configuring encryption in an FCR deployment scenario. 1. Log in to the group leader as Admin or FabricAdmin. 2. Enter the cryptocfg --move -container command followed by the CryptoTarget container name and the node WWN of the encryption engine to which you are moving the CryptoTarget container. Provide a slot number if the encryption engine is a blade. FabricAdmin:switch>cryptocfg --move -container my_disk_tgt \ 10:00:00:05:1e:53:4c:91 Operation Succeeded 3. Commit the transaction. FabricAdmin:switch>cryptocfg --commit Operation Succeeded Crypto LUN configuration A Crypto LUN is the LUN of a target disk or tape storage device that is enabled for and capable of data-at-rest encryption. Crypto LUN configuration is done on a per-LUN basis. You configure the LUN for encryption by explicitly adding the LUN to the CryptoTarget container and turning on the encryption property and policies on the LUN. Any LUN of a given target that is not enabled for encryption must still be added to the CryptoTarget container with the cleartext policy option. • The general procedures described in this section apply to both disk and tape LUNs. The specific configuration procedures differ with regard to encryption policy and parameter setting. • You configure the Crypto LUN on the group leader. You need the FabricAdmin role to perform LUN configuration tasks. • There is a maximum of 512 Disk LUNs per Initiator in a container. • There is a maximum of 8 Tape LUNs per Initiator in a container. CAUTION When configuring a LUN with multiple paths (which means the LUN is exposed and configured on multiple Crypto Target containers located on the same Encryption switch or blade or on different encryption switches or blades), the same LUN policies must be configured on all of the LUN's paths. Failure to configure all LUN paths with the same LUN policies results in data corruption. If Fabric OS Encryption Administrator's Guide 153 53-1002159-03

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282

Fabric OS Encryption Administrator’s Guide
153
53-1002159-03
Crypto LUN configuration
3
Moving a CryptoTarget container
You can move a CryptoTarget container from one encryption engine to another. The encryption
engines must be part of the same fabric and the same encryption group, and the encryption
engines must be online for this operation to succeed. This operation permanently transfers the
encryption engine association of a given CryptoTarget container from an existing encryption engine
to an alternate encryption engine.
NOTE
If a CryptoTarget container is moved in a configuration involving FCR, the LSAN zones and manually
created redirect zones will need to be reconfigured with new VI and VT WWNs. Refer to the section
“Deployment in Fibre Channel routed fabrics”
on page 183 for instructions on configuring
encryption in an FCR deployment scenario.
1.
Log in to the group leader as Admin or FabricAdmin.
2.
Enter the
cryptocfg
--
move -container
command followed by the CryptoTarget container name
and the node WWN of the encryption engine to which you are moving the CryptoTarget
container. Provide a slot number if the encryption engine is a blade.
FabricAdmin:switch>
cryptocfg --move -container my_disk_tgt \
10:00:00:05:1e:53:4c:91
Operation Succeeded
3.
Commit the transaction.
FabricAdmin:switch>
cryptocfg --commit
Operation Succeeded
Crypto LUN configuration
A Crypto LUN is the LUN of a target disk or tape storage device that is enabled for and capable of
data-at-rest encryption. Crypto LUN configuration is done on a per-LUN basis. You configure the
LUN for encryption by explicitly adding the LUN to the CryptoTarget container and turning on the
encryption property and policies on the LUN. Any LUN of a given target that is not enabled for
encryption must still be added to the CryptoTarget container with the
cleartext
policy option.
The general procedures described in this section apply to both disk and tape LUNs. The
specific configuration procedures differ with regard to encryption policy and parameter setting.
You configure the Crypto LUN on the group leader. You need the FabricAdmin role to perform
LUN configuration tasks.
There is a maximum of 512 Disk LUNs per Initiator in a container.
There is a maximum of 8 Tape LUNs per Initiator in a container.
CAUTION
When configuring a LUN with multiple paths (which means the LUN is exposed and configured on
multiple Crypto Target containers located on the same Encryption switch or blade or on different
encryption switches or blades), the same LUN policies must be configured on all of the LUN’s
paths. Failure to configure all LUN paths with the same LUN policies results in data corruption. If