Skip to main content
NetApp Response to Russia-Ukraine Cyber Threat
In response to the recent rise in cyber threat due to the Russian-Ukraine crisis, NetApp is actively monitoring the global security intelligence and updating our cybersecurity measures. We follow U.S. Federal Government guidance and remain on high alert. Customers are encouraged to monitor the Cybersecurity and Infrastructure Security (CISA) website for new information as it develops and remain on high alert.
NetApp Knowledge Base

NSE - Do NetApp Storage Encryption and SnapMirror transfer data in plain text?

Last Updated:

Applies to

NetApp Storage Encryption (NSE)


Scenario 1 - A NetApp Storage Encryption (NSE) system is the source of a SnapMirror and the destination is non-NSE a standard controller not supporting encryption.
In this topology, the data on the NSE system will be decrypted when reading from the disk, transferred decrypted over the network, and then written to the destination in plain text.

Scenario 2 - An NSE system is the source of a SnapMirror and the destination is also an NSE controller.
In the event that both the source and destination are NSE controllers, data will be decrypted when reading from the source, transferred in plain text, and then encrypted when writing to the destination SnapMirror.

Note: As of ONTAP 9.6, InterCluster SnapMirror network traffic can be encrypted by encrypting the cluster peer relationship. See the following KB for more details: How to enable encryption for cluster peering and data replication in ONTAP 9.6 and later

Additional Information



Scan to view the article on your device