Encrypt stored data using software-based encryption
-
PDF of this doc site
-
Cluster administration
-
Volume administration
-
Logical storage management with the CLI
-
-
NAS storage management
-
Configure NFS with the CLI
-
Manage NFS with the CLI
-
Manage SMB with the CLI
-
Manage file access using SMB
-
-
-
Security and data encryption
-
Data protection and disaster recovery
-

Collection of separate PDF docs
Creating your file...
Use volume encryption to ensure that volume data cannot be read if the underlying device is repurposed, returned, misplaced, or stolen. Volume encryption does not require special disks; it works with all HDDs and SSDs.
This procedure applies to FAS, AFF, and current ASA systems. If you have an ASA r2 system (ASA A1K, ASA A90, ASA A70, ASA A50, ASA A30, or ASA A20), follow these steps to enable software level encryption. ASA r2 systems provide a simplified ONTAP experience specific to SAN-only customers.
Volume encryption requires a key manager. You can configure the Onboard Key Manager using System Manager. You can also use an external key manager, but you need to first set it up using the ONTAP CLI.
After the key manager is configured, new volumes are encrypted by default.
-
Click Cluster > Settings.
-
Under Encryption, click
to configure the Onboard Key Manager for the first time.
-
To encrypt existing volumes, click Storage > Volumes.
-
On the desired volume, click
and then click Edit.
-
Select Enable encryption.