Enabling vSAN Data-At-Rest encryption on a two node vSAN Cluster with vSAN Advance License
search cancel

Enabling vSAN Data-At-Rest encryption on a two node vSAN Cluster with vSAN Advance License

book

Article ID: 396924

calendar_today

Updated On:

Products

VMware vSAN VMware vSAN 7.x VMware vSAN 8.x

Issue/Introduction

  • Can vSAN Data-At-Rest encryption be enabled for a two node vSAN  Cluster with vSAN Advance License.
  • Will enabling the encryption erases existing data or it will not affect the existing data and will only encrypt the new data.

Environment

VMware vSAN 7.x
VMware vSAN 8.x

Resolution

  • Can vSAN Data-At-Rest encryption be enabled for a two node vSAN  Cluster with vSAN Advance License.

No this feature is only supported with Enterprise and Enterprise plus license.

Yes stretched cluster are supported for this feature.

but the witness host in a vSAN  stretched cluster does not participate in vSAN  encryption. The witness host does not store customer data, only metadata, such as the size and UUID of vSAN object and components.

  • Will enabling the encryption erases existing data or it will not affect the existing data and will only encrypt the new data.

No the data will be preserved but A rolling reformat of all disk groups takes places as vSAN encrypts all data in the vSAN datastore.

Additional Information