VMware Cloud Community
NeenaJim
Enthusiast
Enthusiast
Jump to solution

vSphere Encryption and vSAN Encryption

Can someone please share the Pros and Cons of vSphere Encryption and vSAN Encryption

0 Kudos
2 Solutions

Accepted Solutions
maksym007
Expert
Expert
Jump to solution

Find here all the needed info

 

https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-8D7D09AC-8579-4A3...

 

Depends how exactly you want to encrypt VMs. With KMS server or via TPM modules. 

KMS - does not require additional hardware

TPM modules does. + they have different generations. 1.2 / 2.0 

https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-3D39CBA6-E5B2-43E...

 

this is only very general look.

View solution in original post

MJMVCIX
Enthusiast
Enthusiast
Jump to solution

vSphere Encryption can be applied on a per VM basis whereas vSAN Encryption will encrypt the whole vSAN Datastore and therefore every VM.

vSAN Encryption - Increased guest VM latency may be observed as a result of writing to the storage devices. The encryption process occurs as the data is written to the write buffer, and since vSAN will not send the write acknowledgment back to the VM until the synchronous write is completed in the buffer, this may translate to higher latency as viewed by guest VM latency. The destaging process also must decrypt and re-encrypt the data as it is destaged to the capacity tier. While this process does not directly impact guest VM latency, it can slow down the destaging process, which under higher loads or hardware insufficient to handle that demand, could indirectly increase latency on the VM.

You are likely to see similar to the above with vSphere Encryption however you can enable per VM so enables you to be granular in your selection, so maybe encrypt all VMs apart from high performance, low latency VMs.

Also with vSAN Encryption you would need vSAN Enterprise licence for each CPU. vSphere Encryption would not need vSAN Enterprise.

View solution in original post

2 Replies
maksym007
Expert
Expert
Jump to solution

Find here all the needed info

 

https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-8D7D09AC-8579-4A3...

 

Depends how exactly you want to encrypt VMs. With KMS server or via TPM modules. 

KMS - does not require additional hardware

TPM modules does. + they have different generations. 1.2 / 2.0 

https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-3D39CBA6-E5B2-43E...

 

this is only very general look.

MJMVCIX
Enthusiast
Enthusiast
Jump to solution

vSphere Encryption can be applied on a per VM basis whereas vSAN Encryption will encrypt the whole vSAN Datastore and therefore every VM.

vSAN Encryption - Increased guest VM latency may be observed as a result of writing to the storage devices. The encryption process occurs as the data is written to the write buffer, and since vSAN will not send the write acknowledgment back to the VM until the synchronous write is completed in the buffer, this may translate to higher latency as viewed by guest VM latency. The destaging process also must decrypt and re-encrypt the data as it is destaged to the capacity tier. While this process does not directly impact guest VM latency, it can slow down the destaging process, which under higher loads or hardware insufficient to handle that demand, could indirectly increase latency on the VM.

You are likely to see similar to the above with vSphere Encryption however you can enable per VM so enables you to be granular in your selection, so maybe encrypt all VMs apart from high performance, low latency VMs.

Also with vSAN Encryption you would need vSAN Enterprise licence for each CPU. vSphere Encryption would not need vSAN Enterprise.