Is there a benefit to using NAE and NSE?
Applies to
- ONTAP 9
- NetApp Storage Encryption
- NetApp Aggregate Encryption
- NetApp Volume Encryption
Answer
The benefit is by having software (NVE or NAE) and hardware (NSE or NVMe SED), you can achieve double encryption at rest.
Hardware-based data-at-rest encryption (NSE,NVMe SEDs):
- To prevent unauthorized access to the data, the storage system must authenticate itself with the locked disk using an authentication key at next disk powered-on or powercycle event.
Software-based data-at-rest encryption (NVE, NAE):
- NAE allows ONTAP to encrypt data for each volume, and the volumes can share keys across the aggregate. NVE allows ONTAP to encrypt data
for each volume for granularity.
These technologies encrypt data at the volume and aggregate level, respectively, making the solution agnostic of the physical drive. By using both software (NVE or NAE) and hardware (NSE or NVMe SED), you can achieve double encryption at rest.