Unsolved
This post is more than 5 years old
13 Posts
0
1349
June 23rd, 2009 18:00
SAN Security/encryption
I am wondering what encryption or security features are available on the CX300.
I am planning to deploy a CX300 with one directly FC attached Server in an off-site location. Now we will not be too worried if the SAN is stolen but we will be worried about the data that resides on the disks.
Is there some encryption option here?
Am i safe enough anyway as if one puts a boot disk into the server it will not pick up the LUN's at all?
Or should I enable EFS or some 3rd party encryption software on the OS layer to protect the data. Is there anything else I should be worried about. I am just throwing out ideas here...
I am planning to deploy a CX300 with one directly FC attached Server in an off-site location. Now we will not be too worried if the SAN is stolen but we will be worried about the data that resides on the disks.
Is there some encryption option here?
Am i safe enough anyway as if one puts a boot disk into the server it will not pick up the LUN's at all?
Or should I enable EFS or some 3rd party encryption software on the OS layer to protect the data. Is there anything else I should be worried about. I am just throwing out ideas here...
No Events found!


dynamox
11 Legend
•
20.4K Posts
•
87.4K Points
0
June 23rd, 2009 18:00
http://www.netapp.com/us/products/storage-security-systems/datafort/
Ultan1
13 Posts
0
June 23rd, 2009 18:00
RRR
6 Operator
•
5.7K Posts
0
June 24th, 2009 07:00
If your SAN is stolen, your Storage Array is still at your site, so data is not lost. You can either direct attach hosts to your array or buy new switches and hook up all servers to the array again
dynamox
11 Legend
•
20.4K Posts
•
87.4K Points
0
June 24th, 2009 08:00
RRR
6 Operator
•
5.7K Posts
0
June 24th, 2009 08:00
Is the data stored encrypted or only being transported encrypted ?
dynamox
11 Legend
•
20.4K Posts
•
87.4K Points
0
June 24th, 2009 08:00
Ultan1
13 Posts
0
June 24th, 2009 14:00
The data will be at rest. TBH I am looking for the least costly solution here.
RRR
6 Operator
•
5.7K Posts
0
June 25th, 2009 02:00
RRR
6 Operator
•
5.7K Posts
0
June 25th, 2009 02:00
AranH1
2.2K Posts
0
June 25th, 2009 08:00
This all goes back to one of the key security statements regarding data center security:
"Once someone has physical access to your systems, they own your system"
HankDorsett
66 Posts
0
June 25th, 2009 09:00
Even though we are looking for a hardware based encryption I think application based is the more secure route to go. Gaining access to a server shouldn't be the only requirement to get at the data. As we upgrade our applications we are looking at application or even Oracle encryption.
If you are concerned about the physical security of your server, SAN and array you should look at adding an RSA like server into the mix. Put the RSA server at another location or some other part of the building.
Ultan1
13 Posts
0
June 25th, 2009 18:00
Just thought there might have been some EMC utility or some free 3rd party utility to have Hardware based encryption on the DPE's and DPA's.
There is lots of stuff out there for Laptops in case they get lifted to prevent data access. Hmmm is it even worth doing a simple Microsoft EFS? Probably not.
I suppose one just has to make sure I have very strong password for the Navisphere Manager as one could log in and assign my LUNs to another server and get access to my data.... Thats about it I suppose other than buying some RSA/Cisco appliances. I cant do that due to budget constraints.
dynamox
11 Legend
•
20.4K Posts
•
87.4K Points
0
June 25th, 2009 21:00
http://www.emc.com/products/detail/software/powerpath-encryption-rsa.htm
AranH1
2.2K Posts
0
June 26th, 2009 07:00
Encrypting the local drives on the server would help as long as key was required to boot the server. That would limit the ability of a thief to crack a server to get to the data on the storage array.