IBM TS3100 Setup, Operator, And Service Manual page 94

Ibm system storage tape library
Table of Contents

Advertisement

4-28
TS3100 Tape Library and TS3200 Tape Library Setup, Operator, and Service Guide
5. Select an Encryption method for each logical library.
v Without an encryption license key, select None or Application Managed
Encryption.
v With an encryption license key, select Library Managed Encryption or
System Managed Encryption.
6. Select an Encryption policy for each logical library.
v Encrypt All: This is the default policy. It encrypts all cartridges using the
default data keys specified in the EKM. This setting applies to all drives in
a 3573 logical library.
v Internal Label - Selective Encryption: This policy is based on the internal
volume label information. Currently, the only application that supports this
option is Symantec NetBackup. It only encrypts cartridges with pool
identifiers between 1500 and 9999 (inclusive), using keys specific to each
pool. Labels for these keys are generated by the tape drive based on the
pool identifier; for instance, key label IL_NBU_1505 would be generated for
a cartridge in pool 1505.
v Internal Label - Encrypt All: This policy is based on the internal volume
label information. Currently, the only application that supports this option
is Symantec NetBackup. It encrypts all cartridges. Cartridges with pool
identifiers between 2000 and 65535 (inclusive) are encrypted with keys
specific to each pool. Labels for these keys are generated by the tape drive
based on the pool identifier; for instance, key label IL_NBU_2505 would be
generated for a cartridge in pool 2505.
7. A primary and secondary EKM server can be set for each logical library. Each
partition has its own Encryption and EKM settings. Maintaining primary and
secondary EKM servers is desired for maximum availability of encrypted
backup and recovery. These settings are required for Library Managed
Encryption only. Enter the EKM Server Setting information.
v Primary IP address (IPv4 or IPv6): Enter the IP address of the primary
EKM server.
v Primary TCP port: After entering the Primary IP address, the library will
automatically set the value of the Primary TCP port.
v Secondary IP address (IPv4 or IPv6): Enter the IP address of the secondary
EKM server.
v Secondary TCP port: After entering the Secondary IP address, the library
will automatically set the value of the Secondary TCP port.
Note: The Default Port for TCP (SSL disabled) is 3801. The Default Port for
SSL is 443. These values are the default values set by the library.
They can be changed depending on the user configuration but the
user has to make sure they match the EKM properties file.
Important: The Advanced Encryption Settings are for Engineering
Support only. Ensure the Advanced Encryption Settings fields
are set to their default value of "No Advanced Setting".
8. Click Activate to apply the changes.
9. Record the Feature Activation Key (or apply one of the labels) on the
Appendix G, "Library Configuration Form," on page G-1 for future reference.
It is important to save your extra Feature Activation Key labels in a secure
location for future reference.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ts3200

Table of Contents