564
Brocade Network Advisor SAN User Manual
53-1002696-01
Steps for connecting to an ESKM/SKM appliance
20
Disk keys and tape pool keys support
DEK creation, retrieval, and update for disk and tape pool keys are as follows:
•
DEK creation: The DEK is first archived to the virtual IP address of the ESKM/SKM cluster. The
request gets routed to the primary or secondary ESKM/SKM, and is synchronized with other
ESKMs or SKMs in the cluster. If archival is successful, the DEK is read from both the primary
or secondary ESKMs or SKMs in the cluster until the DEK is read successfully from both. If
successful, then the DEK created can be used for encrypting disk LUNs or tape pools in
Brocade native mode. If key archival of the DEK to the ESKM/SKM cluster fails, an error is
logged and the operation is retried. If the failure occurs after archival to one of the ESKMs or
SKMs, but synchronization to all ESKMS or SKMs in the cluster times out, then an error is
logged and the operation is retried. Any DEK archived in this case is not used.
•
DEK retrieval: The DEK is retrieved from the ESKM/SKM cluster using the cluster’s virtual
IP address. If DEK retrieval fails, it is retried.
•
DEK Update: DEK Update behavior is the same as DEK Creation.
Tape LUN support
•
DEK Creation: The DEK is created and archived to the ESKM/SKM cluster using the cluster’s
virtual IP address. The DEK is synchronized with other ESKMs or SKMs in the cluster. Upon
successful archival of the DEK to the ESKM/SKM cluster, the DEK can be used for encryption
of the tape LUN. If archival of the DEK to the ESKM/SKM cluster fails, an error is logged and
the operation is retried.
•
DEK retrieval: The DEK is retrieved from the ESKM/SKM cluster using the cluster’s virtual
IP address. If DEK retrieval fails, it is retried.
•
DEK update: DEK update behavior is the same as DEK Creation.
ESKM/SKM key vault deregistration
Deregistration of either the primary or secondary ESKM/SKM key vault from an encryption switch
or blade is allowed independently.
•
Deregistration of Primary ESKM: You can deregister the primary ESKM/SKM from an
encryption switch or blade without deregistering the backup or secondary ESKM/SKM for
maintenance or replacement purposes. However, when the primary ESKM/SKM is
deregistered, key creation operations will fail until either the primary ESKM/SKM is
reregistered, or the secondary ESKM/SKM is deregistered and reregistered as the primary
ESKM/SKM.
When the primary ESKM/SKM is replaced with a different ESKM/SKM, you must first
synchronize the DEKs from the secondary ESKM/SKM before reregistering the primary
ESKM/SKM.
•
Deregistration of Secondary ESKM: You can deregister the secondary ESKM/SKM
independently. Future key operations will use only the primary ESKM/SKM until the secondary
ESKM/SKM is reregistered on the encryption switch or blade.
When the secondary ESKM/SKM is replaced with a different ESKM/SKM, you must first
synchronize the DEKs from primary ESKM/SKM before reregistering the secondary
ESKM/SKM.
Содержание Network Advisor 12.0.0
Страница 36: ...xxxvi Brocade Network Advisor SAN User Manual 53 1002696 01...
Страница 82: ...34 Brocade Network Advisor SAN User Manual 53 1002696 01 License downgrade 2...
Страница 86: ...38 Brocade Network Advisor SAN User Manual 53 1002696 01 Uninstalling a patch 3...
Страница 122: ...74 Brocade Network Advisor SAN User Manual 53 1002696 01 VM Manager discovery 4...
Страница 184: ...136 Brocade Network Advisor SAN User Manual 53 1002696 01 Fabric tracking 5...
Страница 214: ...166 Brocade Network Advisor SAN User Manual 53 1002696 01 User profiles 6...
Страница 236: ...188 Brocade Network Advisor SAN User Manual 53 1002696 01 Searching for an assigned event filter 7...
Страница 284: ...236 Brocade Network Advisor SAN User Manual 53 1002696 01 User defined performance monitors 8...
Страница 320: ...272 Brocade Network Advisor SAN User Manual 53 1002696 01 Grouping on the topology 9...
Страница 336: ...288 Brocade Network Advisor SAN User Manual 53 1002696 01 Microsoft System Center Operations Manager SCOM plug in 10...
Страница 434: ...386 Brocade Network Advisor SAN User Manual 53 1002696 01 Port Auto Disable 12...
Страница 442: ...394 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting Host port mapping 13...
Страница 450: ...402 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting storage port mapping 14...
Страница 536: ...488 Brocade Network Advisor SAN User Manual 53 1002696 01 Virtual FCoE port configuration 16...
Страница 552: ...504 Brocade Network Advisor SAN User Manual 53 1002696 01 Security configuration deployment 17...
Страница 878: ...830 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing thresholds 24...
Страница 922: ...874 Brocade Network Advisor SAN User Manual 53 1002696 01 VLAN routing 26...
Страница 990: ...942 Brocade Network Advisor SAN User Manual 53 1002696 01 SAN Connection utilization 29...
Страница 998: ...950 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing a frame monitor from a switch 30...
Страница 1138: ...1090 Brocade Network Advisor SAN User Manual 53 1002696 01 Call Home Event Tables B...
Страница 1144: ...1096 Brocade Network Advisor SAN User Manual 53 1002696 01 IP Performance monitoring events C...
Страница 1186: ...1138 Brocade Network Advisor SAN User Manual 53 1002696 01 Regular Expressions F...
Страница 1486: ...1438 Brocade Network Advisor SAN User Manual 53 1002696 01 Views H...