ONTAP 9 Manuals ( CA08871-402 )

Encrypt stored data using self-encrypting drives

Use disk encryption to ensure that all data in a local tier cannot be read if the underlying device is repurposed, returned, misplaced, or stolen. Disk encryption requires special self-encrypting HDDs or SSDs.

About this task

This procedure applies to ETERNUS AX/AC/HX series and current ASA series. If you have an ASA r2 system (ETERNUS AX1300 ASA, ETERNUS AX2300 ASA, ETERNUS AX4200 ASA, or ETERNUS AC2200 ASA), follow these steps to enable hardware level encryption. ASA r2 systems provide a simplified ONTAP experience specific to SAN-only customers.

Disk encryption requires a key manager. You can configure the onboard key manager using ONTAP System Manager. You can also use an external key manager, but you need to first set it up using the ONTAP CLI.

If ONTAP detects self-encrypting disks, it prompts you to configure the onboard key manager when you create the local tier.

Steps
  1. Under Encryption, click Actions icon to configure the onboard key manager.

  2. If you see a message that disks need to be rekeyed, click Menu options icon, and then click Rekey Disks.

Top of Page