Brocade Fabric OS Encryption Administrator's Guide v7.1.0 (53-1002721-01, March 2013)

Table Of Contents
Fabric OS Encryption Administrator’s Guide (SKM/ESKM) ix
53-1002721-01
Deployment in Fibre Channel routed fabrics. . . . . . . . . . . . . . . . . .207
Deployment as part of an edge fabric . . . . . . . . . . . . . . . . . . . . . . .209
Deployment with FCIP extension switches . . . . . . . . . . . . . . . . . . .210
VMware ESX server deployments. . . . . . . . . . . . . . . . . . . . . . . . . . .211
Chapter 5 Best Practices and Special Topics
In this chapter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .283
Firmware upgrade and downgrade considerations . . . . . . . . . . . .284
General guidelines. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .285
Specific guidelines for HA clusters . . . . . . . . . . . . . . . . . . . . . .286
Configuration upload and download considerations . . . . . . . . . . .287
Configuration upload at an encryption group leader
node . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .287
Configuration upload at an encryption group member
node . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .287
Information not included in an upload . . . . . . . . . . . . . . . . . . .287
Steps before configuration download. . . . . . . . . . . . . . . . . . . .288
Configuration download at the encryption group leader. . . . .288
Configuration download at an encryption group member . . .288
Steps after configuration download . . . . . . . . . . . . . . . . . . . . .288
HP-UX considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .289
AIX Considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .290
Enabling a disabled LUN. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .290
Disk metadata. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .290
Tape metadata . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .290
Tape data compression . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .290
Tape pools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .291
Tape block zero handling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .292
Tape key expiry . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .292
Configuring CryptoTarget containers and LUNs . . . . . . . . . . . . . . .292
Redirection zones . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .293
Deployment with Admin Domains (AD) . . . . . . . . . . . . . . . . . . . . . .293
Do not use DHCP for IP interfaces . . . . . . . . . . . . . . . . . . . . . . . . . .293
Ensure uniform licensing in HA clusters . . . . . . . . . . . . . . . . . . . . .294
Tape library media changer considerations . . . . . . . . . . . . . . . . . .294
Turn off host-based encryption . . . . . . . . . . . . . . . . . . . . . . . . . . . .294
Avoid double encryption . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .294
PID failover . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .294
Turn off compression on extension switches . . . . . . . . . . . . . . . . .295