Brocade encryption switch removal and replacement, Multi-node eg case – Brocade Fabric OS Encryption Administrator’s Guide Supporting NetApp Lifetime Key Manager (LKM) and KeySecure Storage Secure Key Manager (SSKM) Environments (Supporting Fabric OS v7.2.0) User Manual
Page 269
![background image](/manuals/361663/269/background.png)
Fabric OS Encryption Administrator’s Guide (LKM/SSKM)
251
53-1002925-01
Brocade Encryption Switch removal and replacement
6
14. If “manual” failback was set on the HA cluster, you must manually fail back the LUNs owned by
the newly replaced EE.
Brocade Encryption Switch removal and replacement
The following procedures identify steps for removing and replacing a Brocade Encryption Switch.
•
For a multi-node replacement, refer to
•
For a single-node replacement, refer to
Multi-node EG Case
1. If possible, upload the configuration from the group leader node using the Fabric OS
configupload command.
2. Power off the Brocade Encryption Switch. Remove the Mgmt Link, I/O links, and FC cables from
the Brocade Encryption Switch, noting where each was attached so that the replacement
Brocade Encryption Switch can be cabled properly.
3. From the group leader node, invoke the following command to deregister the old Brocade
Encryption Switch.
Admin:switch> cryptocfg -–dereg –membernode
Switch>
WARNING:
Do not use Brocade Network Advisor to deregister a member node. Use the CLI
only. Otherwise you will remove containers belonging to the member node, which
will need to be recreated after the replacement is done.
4. From the group leader node, invoke the following command to reclaim the WWN base from the
old Brocade Encryption Switch.
Admin:switch> cryptocfg -–reclaim –membernode
Switch>
5. Issue commit.
Admin:switch> cryptocfg –-commit
6. Replace the old Brocade Encryption Switch with the new Brocade Encryption Switch and
reconnect the Mgmt link, I/O links, and FC cables.
7. Reconnect the I/O sync ports to the same private LAN as the I/O sync ports of the failed node.
8. Power on the new Brocade Encryption Switch. Note that the FC cables have not yet been
plugged in.
9. Set the IP address for the new Brocade Encryption Switch using the ipAddrSet command for
the Mgmt and I/O links. Check that the switch name and domain ID associated with the
replacement switch match that of the original.
10. If the encryption group (EG) has a system card authentication enabled, you need to reregister
the system card through the BNA client for the new EE. Refer to Chapter 2, Configuring
Encryption Using the Management Application.”