Brocade Fabric OS Encryption Administrator's Guide v7.1.0 (53-1002721-01, March 2013)

Table Of Contents
78 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)
53-1002721-01
Moving Targets
2
Moving Targets
The Move Targets dialog box is used to redistribute which engine encrypts which targets. It is also
useful for transferring all targets to another engine before replacing or removing engine hardware.
Moving targets to another engine may be done while traffic is flowing between the host and target.
Traffic is interrupted for a short time but resumes before the host applications are affected.
1. Select Configure > Encryption.
The Encryption Center dialog box displays.
2. Select one or more encryption engines from the Encryption Center Devices table, then select
Engine > Targets from the menu task bar. The encryption engine must be in the same group
and same fabric.
The Encryption Targets dialog box displays.
3. Select one or more targets in the Encryption Targets dialog and click Move.
The Move Targets dialog box is displayed.
4. Select an encryption engine, then click OK to close the dialog and start the move operation.
Configuring encrypted tape storage in a multi-path environment
This example assumes one host is accessing one storage device using two paths:
The first path is from Host Port A to Target Port A, using Encryption Engine A for encryption.
The second path is from Host Port B to Target Port B, using Encryption Engine B for encryption.
Encryption Engines A and B are in switches that are already part of Encryption Group X.
The following procedure is used to configure this scenario using BNA.
1. Configure Host Port A and Target Port A in the same zone by selecting Configure > Zoning from
BNA’s main menu.
2. Configure Host Port B and Target Port B in the same zone by selecting Configure > Zoning from
BNA’s main menu.
3. Select Configure > Encryption from the menu task bar to display the Encryption Center
dialog box (Refer to Figure 1 on page 14).
4. Click View Groups to display the encryption groups if groups are not already displayed.
5. Select Encryption Group X, then click the Targets icon.
6. From the Encryption Targets dialog box, click Add to open the Configure Storage Encryption
wizard. Use the wizard to create a target container for Encryption Engine A with Target Port A
and Host Port A.
7. Repeat Step 6 to create a target container for Encryption Engine B with Target Port B and
Host Port B.
Up to this point, BNA has been automatically committing changes as they are made. The
targets and hosts are now fully configured; only the LUN configuration remains.
8. In the Encryption Targets dialog box, select Target Port A, click LUNs, then click Add. Select the
LUNs to be encrypted and the encryption policies for the LUNs.