170 likes | 386 Views
StorageSecure / KeySecure Training [City], [Date]. The StorageSecure / KeySecure Solution. StorageSecure Solution Overview. Files stored on the remotely located file server are encrypted. ?b64YDTTGR3kjnIS4ro50GYSyJZJEaxnGlBKs1EgTpTiEl2I691wAMXlVgBS50vG
E N D
StorageSecure Solution Overview • Files stored on the remotely located file server are encrypted. ?b64YDTTGR3kjnIS4ro50GYSyJZJEaxnGlBKs1EgTpTiEl2I691wAMXlVgBS50vG 0qsrZ7r05Ja4l/1DszNj+rvosH85bQz0cj8N1pWpufGmBVCXvdspPMgEexIUAmon iGbH?64b Name CC Number John Smith 1234 5432 4545 1334 Fred Jonson 3456 2456 7896 5365 Sam Brown 4567 6523 6823 4567 • The file passes through the Storage Encryption device before being sent to the requester. • User Requests file from remote server Storage Client Storage StorageSecure KeySecure
StorageSecure Knowledge Prerequisites • Information Security • Cryptography • Storage Architectures • NAS, SAN • Networking • TCP/IP, Ethernet • Microsoft • Active Directory, CIFS, NTFS • Unix/Linux • NFS, LDAP / NIS • System Monitoring • Syslog, SNMP
History • Decru, Inc. Redwood City, CA. Founded 2001. • Build DataFort storage security appliances for protection of SAN, NAS, DAS and tape backup environments. • DataFort appliances encrypt data in transit to storage. • Lifetime Key Management System • Centralized key management. • NetApp acquire Decru in 2005. • Lifetime Key Management 3.0 Appliance (LKM Appliance). • SafeNet build next generation appliances • SafeNet StorageSecure • SafeNet KeySecure
Decru Products • Decru/NetApp DataFort appliance available in three flavours: • DataFort FC-Series • Fibre Channel for SAN/Tape. Fiber channel interface. • DataFort S-Series • SCSI Tape – LVD SCSI interface. • DataFort E-Series • NAS/iSCSI – Ethernet interface. • LKM Appliance: • Lifetime Key Management Appliance • Central location allowing an administrator to load, view, manage, share and save all keys generated by all DataForts appliances in an installation. • Lifetime Key Management Server Software • Designed to run on a network server. Provides a solution to manage and archive key information for multiple DataFort appliances.
Decru DataFort E-Series • Secures file-based data in NAS systems. Can also be used on the file server side of a SAN when file level control is required. • Support for Common Internet File System (CIFS) and Network File System (NFS) protocols. • Secure block or sector based data over IP networks that support the iSCSI protocol. • Authentication, Access control, Key Management, Signed Logging.
DataFort / StorageSecure Terminology • DataFort’s “Cryptainer” was changed to “Storage Vault” in StorageSecure • DataFort’s “Cryptoshred” was changed to “Zeroize” in StorageSecure. • Some terms such as “Cryptainer" and “LKM” are still used in the CLI commands in order to maintain backward compatibility. This is mainly done for customers that have already-prepared scripts for NetApp’sDataFortand LKM.
Information Sheet and Teams • Network diagram, IP addresses, credentials and all relevant information required for the hand’s on session can be found on the following Hand‘s on document: • “01 StorageSecure Hands-On’sInformation Sheet – All Teams.docx”