Ian's explanation near the end of the thread should address how the Avamar stripes have the potential to be encrypted, but are not guaranteed to be encrypted. The only way to ensure a stripe is encrypted is to enable it on a clean, fresh installation with no data written.
In the past, I've switched VM image backups from non-ecrypted to encrypted, but I haven't seen any evidence of backups not relying on CBT when we've switched them, but then again, we have an internal policy to run an on-demand backup outside out of our standard (evening) backup window, when we whenever we make changes like that to a client.
In terms of replication, we've noticed encryption has a "visible but not really significant" impact on the time required to replicator over the wire. We have encryption-at-rest enabled on Data Domain, and have our replication sessions set to use encryption. Our daily replication takes about four hours to long-haul over 400 nightly backups, but individual sessions take just a few minutes each. If we were to disable encryption, I don't think we'd save even an hour, probably only 40 minutes at-best. Data Domain is still able to leverage it's data reduction techniques even with encryption on, so we didn't see a "good enough" reason to disable it.
I think the original question is referring to in-flight encryption rather than at-rest encryption.
In any case, enabling encryption does not affect how the data is hashed because that happens before the data is encrypted. Same for change block tracking.
As for an impact on replication, there may be a very slight performance impact when in-flight encryption is enabled (all encryption does have some overhead) but it is unlikely to be noticeable.
umichklewis
4 Apprentice
•
1190 Posts
2973
1
Posted September 28th, 2016 11:00
There's a good discussion about data-at-rest encryption with Avamar here - Re: Avamar at-rest encryption config
Ian's explanation near the end of the thread should address how the Avamar stripes have the potential to be encrypted, but are not guaranteed to be encrypted. The only way to ensure a stripe is encrypted is to enable it on a clean, fresh installation with no data written.
In the past, I've switched VM image backups from non-ecrypted to encrypted, but I haven't seen any evidence of backups not relying on CBT when we've switched them, but then again, we have an internal policy to run an on-demand backup outside out of our standard (evening) backup window, when we whenever we make changes like that to a client.
In terms of replication, we've noticed encryption has a "visible but not really significant" impact on the time required to replicator over the wire. We have encryption-at-rest enabled on Data Domain, and have our replication sessions set to use encryption. Our daily replication takes about four hours to long-haul over 400 nightly backups, but individual sessions take just a few minutes each. If we were to disable encryption, I don't think we'd save even an hour, probably only 40 minutes at-best. Data Domain is still able to leverage it's data reduction techniques even with encryption on, so we didn't see a "good enough" reason to disable it.
Let us know if that helps!
Karl