HP Brocade 8/12c Fabric OS Encryption Administrator's Guide - Page 174

Discovering a LUN, Configuring a Crypto LUN, Configuring a, multi-path Crypto LUN

Page 174 highlights

3 Crypto LUN configuration you are configuring multi-path LUNs as part of a HA cluster or DEK cluster or as a stand-alone LUN accessed by multiple hosts, follow the instructions described in the section "Configuring a multi-path Crypto LUN" on page 166. Discovering a LUN When adding a LUN to a CryptoTarget container, you must specify a LUN Number. The LUN Number needed for configuring a given Crypto LUN is the LUN Number as exposed to a particular initiator. The Brocade Encryption platform provides LUN discovery services through which you can identify the exposed LUN number for a specified initiator. If you already know the exposed LUN numbers for the various initiators accessing the LUN, you may skip the LUN discovery step and directly configure the Crypto LUN. 1. Log in to the group leader as Admin or FabricAdmin. 2. Enter the cryptocfg --discoverLUN command followed by the CryptoTarget container Name. FabricAdmin:switch>cryptocfg --discoverLUN my_disk_tgt Container name: my_disk_tgt Number of LUN(s): 1 Host: 10:00:00:00:c9:2b:c9:3a LUN number: 0x0 LUN serial number: 200000062B0F726D0C000000 Key ID state: Key ID not available Key ID: 3a:21:6a:bd:f2:37:d7:ea:6b:73:f6:19:72:89:c6:4f CAUTION When configuring a LUN with multiple paths, perform the LUN discovery on each of the Crypto Target containers for each of the paths accessing the LUN and verify that the serial number for these LUNs discovered from these Crypto Target containers are the same. This indicates and validates that these Crypto Target containers are indeed paths to the same LUN. Refer to the section "Configuring a multi-path Crypto LUN" on page 166 for more information. Configuring a Crypto LUN You configure a Crypto LUN by adding the LUN to the CryptoTarget container and enabling the encryption property on the Crypto LUN. The LUNs of the target which are not enabled for encryption must still be added to the CryptoTarget container with the cleartext policy option. You can add a single LUN to a CryptoTarget container, or you can add multiple LUNs by providing a range of LUN Numbers. When adding a single LUN, you can either provide a 16-bit (2 byte) hex value of the LUN Number, for example, 0x07. Alternately you can provide a 64-bit (8 byte) value in WWN or LUN ID format, for example, 00:07:00:00:00:00:00:00. When adding a range of LUN Numbers, you may use two byte hex values or decimal numbers. 154 Fabric OS Encryption Administrator's Guide 53-1002159-03

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282

154
Fabric OS Encryption Administrator’s Guide
53-1002159-03
Crypto LUN configuration
3
you are configuring multi-path LUNs as part of a HA cluster or DEK cluster or as a stand-alone
LUN accessed by multiple hosts, follow the instructions described in the section
“Configuring a
multi-path Crypto LUN”
on page 166.
Discovering a LUN
When adding a LUN to a CryptoTarget container, you must specify a LUN Number. The LUN Number
needed for configuring a given Crypto LUN is the LUN Number as exposed to a particular initiator.
The Brocade Encryption platform provides LUN discovery services through which you can identify
the exposed LUN number for a specified initiator. If you already know the exposed LUN numbers for
the various initiators accessing the LUN, you may skip the LUN discovery step and directly configure
the Crypto LUN.
1.
Log in to the group leader as Admin or FabricAdmin.
2.
Enter the
cryptocfg
--
discoverLUN
command followed by the CryptoTarget container Name.
FabricAdmin:switch>
cryptocfg --discoverLUN my_disk_tgt
Container name: my_disk_tgt
Number of LUN(s): 1
Host: 10:00:00:00:c9:2b:c9:3a
LUN number: 0x0
LUN serial number: 200000062B0F726D0C000000
Key ID state: Key ID not available
Key ID: 3a:21:6a:bd:f2:37:d7:ea:6b:73:f6:19:72:89:c6:4f
CAUTION
When configuring a LUN with multiple paths, perform the LUN discovery on each of the Crypto
Target containers for each of the paths accessing the LUN and verify that the serial number for
these LUNs discovered from these Crypto Target containers are the same. This indicates and
validates that these Crypto Target containers are indeed paths to the same LUN. Refer to the
section
“Configuring a multi-path Crypto LUN”
on page 166 for more information.
Configuring a Crypto LUN
You configure a Crypto LUN by adding the LUN to the CryptoTarget container and enabling the
encryption property on the Crypto LUN. The LUNs of the target which are not enabled for encryption
must still be added to the CryptoTarget container with the
cleartext
policy option.
You can add a single LUN to a CryptoTarget container, or you can add multiple LUNs by providing a
range of LUN Numbers. When adding a single LUN, you can either provide a 16-bit (2 byte) hex
value of the LUN Number, for example, 0x07. Alternately you can provide a 64-bit (8 byte) value in
WWN or LUN ID format, for example, 00:07:00:00:00:00:00:00. When adding a range of LUN
Numbers, you may use two byte hex values or decimal numbers.