Enabling Aggregate-level Encryption

If you plan to perform inline or background aggregate-level deduplication, you must use aggregate-level encryption. NVE does not support aggregate-level deduplication otherwise. When you encrypt a volume, ONTAP automatically “pushes” an encryption key to the Utimaco ESKM server. 

Plain text volumes are not supported in NAE aggregates 

Enable or disable aggregate-level encryption.  

  1. The following command enables aggregate-level encryption on aggr1. 

>_Console

Cluster1::> storage aggregate create -aggregate aggr1 -diskcount 6 

  1. Verify that the aggregate aggr1 is enabled for encryption.

>_Console

Cluster1::> storage aggregate show -fields encrypt-with-aggr-key 

ontap_show_aggr.png
Verifying encryption on aggregate.

Verifying encryption on aggregate