Set up TLS secure channel for NVMe/TCP
Beginning with ONTAP 9.16.1, you can configure TLS secure channel for NVMe/TCP connections. You can use System Manager or the ONTAP CLI to either add a new NVMe subsystem with TLS enabled, or enable TLS for an existing NVMe subsystem.
Beginning with ONTAP 9.16.1, you can use System Manager to configure TLS for NVMe/TCP connections while creating or updating an NVMe subsystem, creating or cloning NVMe namespaces, or adding consistency groups with new NVMe namespaces.
-
In System Manager, click Hosts > NVMe Subsystem and then click Add.
-
Add the NVMe subsystem name, and select the storage VM and host operating system.
-
Enter the Host NQN.
-
Select Require Transport Layer Security (TLS) next to the Host NQN.
-
Provide the pre-shared key (PSK).
-
Click Save.
-
To verify that TLS secure channel is enabled, select System Manager > Hosts > NVMe Subsystem > Grid > Peek view.