Sangfor SCP platform can enable disk encryption settings. After enabling, it supports the encryption of storage data of virtual machines, networks, and security resources to guarantee data security and avoid information theft.
Precautions:
Currently, SCP only supports using the AES-256 encryption algorithm to encrypt data.
Once the disk encryption settings are enabled, it will not automatically adopt disk encryption to the virtual machines until the enable disk encryption has been enabled manually on the virtual machine setting.
Enabling or disabling disk encryption for a single resource pool is not supported.
The virtual machine must be powered off to enable disk encryption on the virtual machines.
After the disk has been encrypted, it doesn’t support disk decryption.
The disk encryption process takes a while to complete, and operations such as powering on are not supported. It is recommended to perform during non-business hours.
After the disk encryption is enabled on the virtual machine, the virtual machine will no longer support cloning, creating images, exporting operations, CDP backup, and disaster recovery functions and cannot be recovered.
Prerequisite
Disk encryption setting must be enabled for the virtual machine.
Steps:
Step 1.Log in to the SCP platform, and navigate to Resources > Management > Security. Select Disk Encryption Settings to enable the feature.
Step 2.After enabling the disk encryption settings, navigate to Compute > Virtual Machines, locate the appropriate virtual machine, click More, and select Disk Encryption.