You can enable encryption when you configure a new Virtual SAN cluster.
Prerequisites
- Required privileges:
- You must have set up a KMS cluster and established a trusted connection between vCenter Server and the KMS.
Procedure
- Navigate to an existing cluster in the vSphere Web Client.
- Click the Configure tab.
- Under vSAN, select General and click the Configure vSAN button.
- On the vSAN capabilites page, select the Encryption check box, and select a KMS cluster.
Note: Make sure the
Erase disks before use check box is deselected, unless you want to wipe existing data from the storage devices as they are encrypted.
- On the Claim disks page, specify which disks to claim for the Virtual SAN cluster.
- Select a flash device to be used for capacity and click the Claim for capacity tier icon ().
- Select a flash device to be used as cache and click the Claim for cache tier icon ().
- Complete your cluster configuration.
Results
Encryption of data at rest is enabled on the Virtual SAN cluster. Virtual SAN encrypts all data added to the Virtual SAN datastore.