Planning for protocol data security

It is recommended to adhere to the following best practices when you plan to set up data security:

  • When Windows clients use SMB 3.0, always configure SMB share with server smb encrypt = mandatory.
  • Avoid clients who use SMB 2.1 from accessing SMB data.
  • Always enforce to use UNC with NetBIOS name of the cluster to access SMB data.
  • To ensure NFSV4 encryption, use an authentication method that is configured with Kerberos.
  • For secure communication between the client system and IBM Storage Scale Object, the system administrator must configure HAProxy with Secure Sockets Layer (SSL) support.