beautypg.com

Dell POWEREDGE M1000E User Manual

Page 237

background image

Fabric OS Command Reference

209

53-1002746-01

cryptoCfg

2

initiator_PWWN

Specifies the initiator port WWN.

--add -LUN

Adds a LUN to a CTC and optionally sets encryption policies for the LUN. The
maximum number of Tape LUNs that can be added to an Initiator in a container is
8. LUN policies may be set at this time or after the LUN is added. The maximum
number of LUNs you can add in one commit operation is 25. There is a delay of
five seconds for each commit operation.

This command is valid only on the group leader. The following operands are
supported:

crypto_target_container_name

Specifies the name of the CTC to which the LUN is added. This operand is
required.

LUN_Num | LUN_Num_Range

Specifies the LUN number or a range of LUN numbers. These operands are
mutually exclusive. The LUN number can be either a 16-bit (2 bytes) number in
hex notation (for example, 0x07) or a 64-bit (8 bytes) number in WWN format (for
example, 00:07:00:00:00:00:00:00). When specifying a range, the LUN numbers
must be 16-bit numbers in hex format. The Range parameter is not supported for
64-bit LUN numbers.

The LUN number must be zero when a tape LUN is specified and the tape drive is
a single LUN device.

initiator_PWWN initiator_NWWN

Optionally specifies one or more hosts (initiators) that will be permitted to access
the LUN. For each initiator added, the port WWN and the node WWN must be
specified. You may add more than one initiator.

Encryption policy parameters: The following encryption policy configuration
parameters can be optionally set for disk and tape devices when adding a LUN to
a CTC, or they can be set at a later time with the --modify -LUN command.

The tape policies specified at the LUN level take effect if you do not create tape
pools or configure policies at the tape pool level.

LUN policies are configured per HA or DEK cluster. For multi-path LUNs exposed
through multiple target ports and thus configured on multiple CTCs on different
EEs in an HA cluster or DEK cluster, the same LUN policies must be configured.
Refer to the Fabric OS Administrator's Guide for more information.

The following LUN policy parameters can be optionally set:

-lunstate encrypted | cleartext

Sets the encryption state of a specified disk LUN. When set to encrypted,
metadata on the LUN containing the key ID of the DEK that was used for
encrypting the LUN is used to retrieve the DEK from the key vault. If the LUN state
is not specified, the default state is cleartext. This operand is not valid for tape
LUNs.

-keyID keyID

Specifies the Key ID. Use this operand only if the LUN was encrypted but does not
include the metadata containing the keyID for the LUN. This is a rare case for
LUNS encrypted in Brocade native mode. However for LUNS encrypted with
DataFort v2.0, a Key ID is required, because these LUNs do not contain any
metadata. This operand is not valid for tape LUNs.

-encryption_format native | DF_compatible

Specifies the LUN encryption format. Two encryption formats are supported: