Fabric OS Encryption Administrator's Guide

Fabric OS Encryption Administrator’s Guide 11
53-1002159-03
Support for Virtual Fabrics
1
A set of recovery smart cards. This option is only available if the switch is managed by the Data
Center Fabric Manager (DFCM), and if a card reader is available for attachment to the DCFM
workstation.
The use of smart cards provides the highest level of security. When smart cards are used, the key is
split and written on up to 10 cards. Each card may be kept and stored by a different individual. A
quorum of key holders is needed to restore the key. If five key holders exist and the quorum is set to
three, then any three of the five key holders is needed to restore the key.
Support for Virtual Fabrics
The Brocade Encryption Switch does not support the logical switch partitioning capability and, thus,
cannot be partitioned, but the switch can be connected to any Logical Switch partition or Logical
Fabric using an E-Port.
The FS8-18 encryption blades are supported only in a default switch partition. All FS8-18 blades
must be placed in a default switch partition in a DCX or DCX-4S chassis. The encryption resource
from the default switch partition/fabric can be shared with other logical switch partitions/fabrics or
other fabrics only through external device sharing using FCR or EX_Ports through a base
switch/fabric. A separate port blade must be used in the base switch/fabric for EX_Port
connectivity from the logical switch partition (default switch partition) of FS8-18 blades and
host/target fabrics. The EX_Port can be on any external FCR switch.
NOTE
Please refer to Fabric OS Administrator’s Guide for more details on how to configure the DCX and
DCX-4S in virtual fabrics environments, including configuration of default switch partition and any
other logical switch partitions.
Cisco Fabric Connectivity support
The Brocade Encryption Switch provides NPIV mode connectivity to Cisco fabrics. Connectivity is
supported for Cisco SAN OS 3.3 and later versions.
Cisco fabric connectivity is provided only on the Brocade Encryption Switch. The FS8-18 blade for
the Brocade DCX and DCX-4S platforms does not support this feature.