Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Does anybody knows if we can setup a Snapmirror replication from a non-encrypted source volume to an NVE destination volume, running DO 9.3 ?
And also, what are the requirement to establish an end to end data encryption using NVE and Snapmirror between two separated Netapp Cluster.
Thanks !
Solved! See The Solution
1 ACCEPTED SOLUTION
kahad has accepted the solution
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Right. NVE provides at-rest encryption only for the source and/or destination array locally. NVE is independent of snapmirro and thus can be unconfigured at the source and configured at the destination and vice-versa. For in-flight encryption of snapmirror transfers you would need to configure ipsec as described in this KB article https://kb.netapp.com/app/answers/answer_view/a_id/1032413/loc/en_US#__highlight
3 REPLIES 3
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What's the souce cluster version, but usually you can do non-NVE on oneside and NVE on the other.
And I don't believe there is any feature yet built in to ONTAP for encrypting NVE snapmirrors in-flight.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DO 9.3 is running on both cluster.
This means we can establish a snapmirror replication from a non NVE source cluster to a NVE destination cluster, without in flight encryption, right ?
kahad has accepted the solution
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Right. NVE provides at-rest encryption only for the source and/or destination array locally. NVE is independent of snapmirro and thus can be unconfigured at the source and configured at the destination and vice-versa. For in-flight encryption of snapmirror transfers you would need to configure ipsec as described in this KB article https://kb.netapp.com/app/answers/answer_view/a_id/1032413/loc/en_US#__highlight
