Do I need self-encrypting drives to use NetApp Storage Encryption (NSE)?
Applies to
- ONTAP 9
- NetApp Storage Encryption (NSE)
- Self-encrypting drives (SED)
- Federal Information Processing Standards (FIPS) drives
Answer
- Self-encrypting drives (SED) are necessary for hardware-based encryption
- These drives automatically encrypt data at rest using built-in encryption capabilities
- If the storage system does not have SEDs, the storage encryption disk show command will not list any disks because there are no drives with encryption capabilities to display
- To determine if your storage system has SEDs or FIPS drives, you can use the following command. Note: the fields are hidden
::> storage disk show -fields is-sed,is-fips-sed,is-non-fips-sed- Alternative encryption options: If upgrading to SEDs is not feasible, consider using software-based encryption options such as NVE or NAE, which do not require SEDs
