Skip to main content

Learn about ONTAP SMB encryption

Contributors netapp-andreajost netapp-aherbin netapp-aaron-holt netapp-maireadn netapp-thomi

SMB encryption for data transfers over SMB is a security enhancement that you can enable or disable on SMB servers. You can also configure the desired SMB encryption setting on a share-by-share basis through a share property setting.

By default, when you create an SMB server on the storage virtual machine (SVM), SMB encryption is disabled. You must enable it to take advantage of the enhanced security provided by SMB encryption.

To create an encrypted SMB session, the SMB client must support SMB encryption. Windows clients beginning with Windows Server 2012 and Windows 8 support SMB encryption.

SMB encryption on the SVM is controlled through two settings:

  • An SMB server security option that enables the functionality on the SVM

  • An SMB share property that configures the SMB encryption setting on a share-by-share basis

You can decide whether to require encryption for access to all data on the SVM or to require SMB encryption to access data only in selected shares. The encrypt-data share property requires SMB encryption for access to a share. Beginning in ONTAP 9.11.1, the allow-unencrypted-access share property allows SMB2 clients to access a share without encryption while SMB3 clients continue to use encryption when encrypt-data is enabled.

SVM-level settings supersede share-level settings.

The effective SMB encryption configuration depends on the combination of the two settings and is described in the following table:

SMB server SMB encryption enabled Share encrypt data setting enabled Share allow-unencrypted-access setting enabled Server-side encryption behavior

True

False

False

Server-level encryption is enabled for all of the shares in the SVM. With this configuration, encryption happens for the entire SMB session.

True

True

False

Server-level encryption is enabled for all of the shares in the SVM irrespective of share-level encryption. With this configuration, encryption happens for the entire SMB session.

False

True

False

Share-level encryption is enabled for the specific shares. SMB3 clients use encryption, but SMB2 clients can access the share without encryption because the allow-unencrypted-access property is enabled.

False

False

False

No encryption is enabled.

False

False

True

No encryption is enabled. The allow-unencrypted-access property has no effect unless encrypt-data is enabled.

SMB clients that do not support encryption cannot connect to an SMB server or share that requires encryption.

Changes to the encryption settings take effect for new connections. Existing connections are unaffected.

Note The allow-unencrypted-access property is supported beginning in ONTAP 9.11.1.
Note SVM-level SMB encryption overrides share-level settings.