ACSG News November 2015 Sehr geehrte Kunden, IBM hat kürzlich

ACSG News November 2015
Sehr geehrte Kunden,
IBM hat kürzlich die IBM Spectrum Virtualize Release 7.6 mit Verfügbarkeit ab 27.
November für Software und 18. Dezember d. J. für Hardware angekündigt.
Die IBM Spectrum Virtualize Software wird mit dem/den



IBM SVC Storage Virtual Controller
IBM Storwize Systemen
IBM FlashSystem V9000
mitgeliefert.
Die neuen Funktionen sind

Die Verschlüsselung des virtualisierten externen Speichers
wird auf dem IBM SVC DH8, der Storwize V7000 und dem FlashSystem V9000
unterstützt. Dieses geschieht als "Data at rest", d. h. die Daten werden direkt
auf den Plattenlaufwerken verschlüsselt, mit minimalem Einfluss auf die
Performance.

Distributed RAID 6
Im Gegensatz zum traditionellen RAID6 mit doppelter Parität werden die
Daten über bis zu 128 Laufwerke verteilt. Im Rebuild-Fall sind alle
Laufwerke beteiligt, was einen enormen Geschwindigkeits-Vorteil mit
sich bringt, insbesondere bei Platten mit hoher Kapazität. Weiterhin
erbringen alle Laufwerke ihren Anteil an der Gesamt-Performance,
insbesondere bei Einsatz von Flash-Laufwerken.

HyperSwap und Stretched Cluster Erweiterungen
Ein erweiterter GUI-Support mit starker Vereinfachung der Bedienung,
auch für das Command Line Interface, ist hierfür einsetzbar.
Das Quorum ist bei IBM Spectrum Virtualize notwendig um Situationen
zu vermeiden, in denen die Clusterkomponenten die Verbindung
verlieren. Für Stretched Cluster und HyperSwap war bisher am dritten
Standort die Kommunikation über Fiber Channel notwendig.
Mit dem neuen Release steht eine Java App mit IP Verbindung zur
Verfügung, die Fiber Network und Fiber Storage eliminieren kann.

Intergrierter Comprestinator
Dieses Tool ermittelt den Grad an Komprimierung von Daten, die von den
verschiedenen Server Applikationen stammen. Das Tool ist jetzt Bestandteil
des IBM Spectrum Virtualize 7.6 Code und somit auf den vorgenannten IBM
Systemen integriert verfügbar.
Somit werden Anwender in die Lage versetzt, aus dem System heraus
unterbrechungsfrei in kurzer Zeit die prozentuale Ersparnis von Speicherplatz
zu ermitteln.

4 Port 16 Gbs Fiber Adapter
Diese sind für den IBM SVC DH8, IBM Storwize V7000 Gen. 2 sowie
IBM FlashSystem V9000 lieferbar. Das bedeutet für den SVC ein einem
8 Node Cluster bis zu 128 Ports á 16 Gbs und für die V7000 bzw.
V9000 bis zu 16 Ports á 16 Gbs pro System mit Auto Negotiation 8 /16
Gbs.
Die anliegenden Präsentationsfolien enthalten die Details zu den oben genannten
Kurz-Beschreibungen.
Für Fragen, weitergehende Informationen und Vorschläge bzw. Angebote stehen wir
Ihnen zur Verfügung.
Wir freuen uns auf Ihren Anruf oder eine Email.
Mit freundlichem Gruß
Herausgeber:
ACSG + DELTA Systems Gesellschaft für Informations-Technologie mbH
Bramfelder Straße 123 - 22305 Hamburg
Tel: 040 / 611 709-0 - Fax: 040 / 611 709-55 - [email protected] - www.acsg.de
ACSG + DELTA Systems Gesellschaft für Informations-Technologie mbH Geschäftsführer: Wolfgang Wiegand
Gesellschafter: Wiegand Verwaltungsgesellschaft GbR - Geschäftsführer: Wolfgang Wiegand
Sitz der Gesellschaft: Hamburg - HRB: 53997 Amtsgericht Hamburg - USt. IdNr.: DE 160 951 973
© Alle Rechte vorbehalten. Nachdruck oder Übernahme einzelner Meldungen sind nur mit ausdrücklicher schriftlicher
Genehmigung des Herausgebers gestattet.
Sie können den Newsletter selbstverständlich jederzeit abbestellen. ► [email protected]
What’s New in IBM Spectrum Virtualize 7.6?
IBM Spectrum Virtualize software is delivered in
SVC, Storwize family, FlashSystem V9000
•
•
•
•
•
Encryption for external virtualized storage
Distributed RAID technology
HyperSwap and Stretched Cluster enhancements
VMware Virtual Volumes (vVol) integration
Integrated Comprestimator
• Four-port 16Gbps HBA
• GA: Software, November 27; new FC HBA, December 18
© Copyright IBM Corporation 2015
1
Encryption for External Virtualized Storage
• New capability enables encryption of virtualized storage
– Helps to improve data security
– Eliminates need to purchase new storage systems or drives to enable encryption
– Provides single point of administration for encryption across multiple heterogeneous storage systems
• Supported on SVC DH8 engines, Storwize V7000 Gen2, FlashSystem V9000
• Takes advantage of Intel AES-NI processor instructions to perform encryption
– Minimal impact on performance
© Copyright IBM Corporation 2015
2
Encryption Basics
•
•
•
•
•
•
Encryption is the process of encoding data so that only authorized parties can read it
Uses secret keys to encode the data according to well known algorithms
“Data at rest” means the data is encrypted on the end device
Algorithm being used is AES: US government standard from 2001
Algorithm is public, the only secrets are the keys
Symmetric key algorithm (same key used to encrypt and decrypt data)
Importance of encryption
• Improves physical security of data
• Required by certain customers
• Allows customers to send failed hardware back to IBM under warranty
© Copyright IBM Corporation 2015
3
Encryption Use Cases
• Encryption typically of interest to industries with high privacy concerns
– Financial services
– Healthcare
– Any client concerned about possible disclosure of data
• Typical encryption use cases
– Protection against disclosure of data when drives removed
o Malicious removal of drives
o Drives returned to vendor as part of maintenance actions
– Secure erasure of storage
o Drives or arrays being reused for different data
o System being sold or otherwise disposed of
• IBM Spectrum Virtualize encryption addresses all these use cases
• Encryption helps protect against disclosure as a result of access to drives storing data
– Does not address other exposure such as unauthorized access to systems
© Copyright IBM Corporation 2015
4
When is Data Encrypted/Decrypted
• Data is encrypted/decrypted when it is written to/read from external storage
– Encryption/decryption performed in software using Intel AES-NI instructions
• Data is stored encrypted in storage systems
• Data is encrypted when transferred across SAN between IBM Spectrum Virtualize system
and external storage
• Data is not encrypted when transferred on SAN interfaces in other circumstances
– Intra-system communication for clustered systems
– Remote mirror
– Server connections
• If appropriate, consider alternative encryption for “on the fly” data
© Copyright IBM Corporation 2015
5
Using External Storage Encryption
Volumes Striped
• External encryption is enabled at the storage pool
level
• Storage pools contain multiple mdisks
• Volumes are usually striped across mdisks in a
storage pool
• With Easy Tier, volumes migrate among mdisks in a
pool
• All volumes created in an encrypted pool are
automatically encrypted
• Volumes may be moved or copied between pools of
different types
• Mdisks being encrypted by the storage system can be
identified: IBM Spectrum Virtualize won’t encrypt them
© Copyright IBM Corporation 2015
Unencrypted Pool
Volumes Striped
Encrypted Pool
T0
T1
Encrypted
by storage
system
T0
T1
Encrypted Easy Tier Pool
6
Implementing Encryption
•
•
•
•
Create new encrypted pool
For existing data, move volumes from existing pool to new pool
No “convert in place” function to encrypt existing pools
May require additional capacity
Unencrypted Pool
© Copyright IBM Corporation 2015
Encrypted Pool
7
Encryption Key Management
• IBM Spectrum Virtualize has built-in key management
• Two types of keys
– Master key (one per system)
– Data encryption key (one per encrypted pool)
• Master key is created when encryption enabled
–
–
–
–
Stored on USB devices
Required to use a system with encryption enabled
Required on boot, stored in volatile memory on system
May be changed
• Data encryption key is used to encrypt data and is created automatically when an encrypted pool
is created
–
–
–
–
Stored encrypted with the master key
No way to view data encryption key
Cannot be changed
Discarded when an array is deleted (secure erase)
© Copyright IBM Corporation 2015
8
Traditional RAID 6
• Double parity improves data availability by protecting against single or double drive failure in
an array
However …
• Spare drives are idle and cannot
contribute to performance
– Particularly an issue with flash drives
• Rebuild limited by throughput of single drive
– Longer rebuild time with larger drives
– Potentially exposes data to risk of dual failure
© Copyright IBM Corporation 2015
✗
9
Distributed RAID 6
• Spare capacity, not spare drives
• Rotating spare capacity position distributes
rebuild load across all drives
• More drives participate in the rebuild
– Bottleneck of one drive is removed
• More drives means faster rebuild
– 5-10x faster than traditional RAID
– Especially important when using large drives
• No “idle” drives
– All drives contribute to performance
– Especially important when using flash drives
© Copyright IBM Corporation 2015
Distribute 3+P+Q over 10 drives with 2 distributed spares
10
Additional Distributed RAID Benefits
• Improved performance during sequential write streams due to distributing the writes over
more drives
– Particularly important while rebuilding
• Maximum re-use of existing RAID code
– Majority of changes are outside the existing proven I/O path
© Copyright IBM Corporation 2015
11
Distributed RAID GUI Support
Drive classes
available
Amount of usable
capacity to be
assigned
Drives selected
out of candidates
New pool capacity
Arrays that will be
created
© Copyright IBM Corporation 2015
12
Distributed RAID Details
• Available on all systems running IBM Spectrum Virtualize 7.6 with internal drives
– Includes flash drives with SVC
•
•
•
•
Supports distributed RAID 5 and 6
Up to 128 drives in an array including up to 4 spares
Up to 10 arrays in an I/O Group, 32 per clustered system
Traditional RAID remains available
– No in-place conversion from traditional to distributed RAID
© Copyright IBM Corporation 2015
13
HyperSwap and Stretched Cluster Enhancements
• GUI support for HyperSwap
• Simplified CLI
• IP Quorum
© Copyright IBM Corporation 2015
14
GUI Support for HyperSwap
• Enhanced GUI now supports HyperSwap
– Dramatically simplifies setup
Topology
:
Topology:
© Copyright IBM Corporation 2015
15
Simplified CLI for HyperSwap
• Condensing multiple commands into just one
• Significantly reduces risk of error
Creating a HyperSwap volume in 7.5
Creating a HyperSwap volume in 7.6
1.
2.
3.
4.
5.
6.
7.
8.
© Copyright IBM Corporation 2015
mkvdisk master_vdisk
mkvdisk aux_vdisk
mkvdisk master_change_volume 1.
mkvdisk aux_change_volume
mkrcrelationship –activeactive
chrcrelationship -masterchange
chrcrelationship -auxchange
addvdiskacces
mkvolume my_volume
16
IP Quorum
• Quorum disk (also called “witness” in some other implementations) is required with IBM
Spectrum Virtualize to resolve situations where cluster components lose communication
• For Stretched Cluster and HyperSwap, this has required fibre channel communications to a
third site, which adds to cost
• New IBM Spectrum Virtualize capability creates custom Java app for quorum
– Deploy app on server at third location
– Use IP connectivity to cluster components
– Eliminates requirement for FC networking and FC storage at third site
© Copyright IBM Corporation 2015
17
What is Comprestimator
•
•
•
•
Tool used to estimate benefits of Real-time Compression
Minimal impact system load, fast, accurate
Free to download from IBM website
External (host based) CLI tool
– Some clients do not want to have to run a tool on their servers
• Supports data on any storage system
© Copyright IBM Corporation 2015
18
Integrated Comprestimator
• Comprestimator now integrated as part of IBM Spectrum Virtualize 7.6 code
– CLI only
– Does not require compression license
– Does not start RACE (RtC compression engine) – saves resources for host IO
• Enables compression estimates for data stored on systems based on IBM Spectrum
Virtualize
– No need to install software on servers
• Same algorithm as host based tool (so same results are expected)
• Keeps host I/O uninterrupted
• Minimal impact system load, fast, accurate
– Usually <1 minute per volume, could be longer on loaded system
• <5% error margin (same as stand-alone tool)
© Copyright IBM Corporation 2015
19
Four Port 16Gbps Fibre Channel Adapter
• New adapter provides four 16Gbps FC ports
– Up to four adapters (#AH14) per SVC DH8 engine (16 ports per engine / 128 per clustered system)
– Up to two adapter pair features (#AHB3) per Storwize V7000 Gen2 control enclosure (16 ports per
control enclosure / 64 per clustered system)
– Up to four adapters (#AF44) per FlashSystem V9000 controller (16 ports per controller / 128 per
clustered system)
– Auto negotiates 8Gbps/16Gbps
– 16Gbps and 8Gbps host HBAs supported in direct attach mode
• Up to four 8Gbps FC adapters now supported with SVC DH8
• IBM Spectrum Virtualize software 7.6 required
• More ports provide more connectivity options
and enable separation of workloads
© Copyright IBM Corporation 2015
20
Adapter Configuration Options
SVC DH8 Engine and FlashSystem V9000 controller
Slot
Slot
1
Fibre Channel: 4x8, 2x16, 4x16
4
Compression / or none
2
Fibre Channel: 4x8, 2x16, 4x16
or 10Gbps Ethernet (DH8 only)
5
Fibre Channel: 4x8, 2x16, 4x16
or 10Gbps Ethernet
3
Fibre Channel: 4x8 (DH8 only), 2x16, 4x16
or 12Gbps SAS (DH8 only)
6
Compression / or none
Storwize V7000 Gen2 node canister
Slot
© Copyright IBM Corporation 2015
1
Compression
2
Fibre Channel: 4x8, 2x16, 4x16
or 10Gbps Ethernet
3
Fibre Channel: 4x8, 2x16, 4x16
or 10Gbps Ethernet
21
SVC System Support
• SVC Models 8G4 and 8A4 were withdrawn from marketing in 2009 and 2010 respectively
• IBM Spectrum Virtualize 7.6 does not support these engines and cannot be installed on
them
• Clients should upgrade to SVC DH8 engines for much better performance and to obtain IBM
Spectrum Virtualize 7.6 functionality
• No change to service status for these engines
© Copyright IBM Corporation 2015
22
Storwize V3700 and Storwize V3500
• Systems will continue to ship with IBM Storwize licensed machine code 7.5
• Clients can upgrade to IBM Spectrum Virtualize 7.6
– 4GB to 8GB cache upgrade feature (#ACHB) required for upgrade
– Additional cache is used only after upgrade to IBM Spectrum Virtualize 7.6
© Copyright IBM Corporation 2015
23
Information and Trademarks
IBM, the IBM logo, ibm.com, IBM System Storage, IBM Spectrum Storage, IBM Spectrum Control, IBM Spectrum Protect, IBM Spectrum Archive, IBM Spectrum Virtualize, IBM Spectrum Scale, IBM Spectrum
Accelerate, Softlayer, and XIV are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. A current list of IBM trademarks is available on the Web at "Copyright and
trademark information" at http://www.ibm.com/legal/copytrade.shtml
The following are trademarks or registered trademarks of other companies.
Adobe, the Adobe logo, PostScript, and the PostScript logo are either registered trademarks or trademarks of Adobe Systems Incorporated in the United States, and/or other countries.
IT Infrastructure Library is a Registered Trade Mark of AXELOS Limited.
Linear Tape-Open, LTO, the LTO Logo, Ultrium, and the Ultrium logo are trademarks of HP, IBM Corp. and Quantum in the U.S. and other countries.
Intel, Intel logo, Intel Inside, Intel Inside logo, Intel Centrino, Intel Centrino logo, Celeron, Intel Xeon, Intel SpeedStep, Itanium, and Pentium are trademarks or registered trademarks of Intel Corporation or its
subsidiaries in the United States and other countries.
Linux is a registered trademark of Linus Torvalds in the United States, other countries, or both.
Microsoft, Windows, Windows NT, and the Windows logo are trademarks of Microsoft Corporation in the United States, other countries, or both.
Java and all Java-based trademarks and logos are trademarks or registered trademarks of Oracle and/or its affiliates.
Cell Broadband Engine is a trademark of Sony Computer Entertainment, Inc. in the United States, other countries, or both and is used under license therefrom.
ITIL is a Registered Trade Mark of AXELOS Limited.
UNIX is a registered trademark of The Open Group in the United States and other countries.
* All other products may be trademarks or registered trademarks of their respective companies.
Notes:
Performance is in Internal Throughput Rate (ITR) ratio based on measurements and projections using standard IBM benchmarks in a controlled environment. The actual throughput that any user will experience will
vary depending upon considerations such as the amount of multiprogramming in the user's job stream, the I/O configuration, the storage configuration, and the workload processed. Therefore, no assurance can be
given that an individual user will achieve throughput improvements equivalent to the performance ratios stated here.
All customer examples cited or described in this presentation are presented as illustrations of the manner in which some customers have used IBM products and the results they may have achieved. Actual
environmental costs and performance characteristics will vary depending on individual customer configurations and conditions.
This publication was produced in the United States. IBM may not offer the products, services or features discussed in this document in other countries, and the information may be subject to change without notice.
Consult your local IBM business contact for information on the product or services available in your area.
All statements regarding IBM's future direction and intent are subject to change or withdrawal without notice, and represent goals and objectives only.
Information about non-IBM products is obtained from the manufacturers of those products or their published announcements. IBM has not tested those products and cannot confirm the performance, compatibility,
or any other claims related to non-IBM products. Questions on the capabilities of non-IBM products should be addressed to the suppliers of those products.
Prices subject to change without notice. Contact your IBM representative or Business Partner for the most current pricing in your geography.
This presentation and the claims outlined in it were reviewed for compliance with US law. Adaptations of these claims for use in other geographies must be reviewed
by the local country counsel for compliance with local laws.
© Copyright IBM Corporation 2015
Special notices
This document was developed for IBM offerings in the United States as of the date of publication. IBM may not make these offerings available in other countries, and the information is
subject to change without notice. Consult your local IBM business contact for information on the IBM offerings available in your area.
Information in this document concerning non-IBM products was obtained from the suppliers of these products or other public sources. Questions on the capabilities of non-IBM products
should be addressed to the suppliers of those products.
IBM may have patents or pending patent applications covering subject matter in this document. The furnishing of this document does not give you any license to these patents. Send
license inquires, in writing, to IBM Director of Licensing, IBM Corporation, New Castle Drive, Armonk, NY 10504-1785 USA.
All statements regarding IBM future direction and intent are subject to change or withdrawal without notice, and represent goals and objectives only.
The information contained in this document has not been submitted to any formal IBM test and is provided "AS IS" with no warranties or guarantees either expressed or implied.
All examples cited or described in this document are presented as illustrations of the manner in which some IBM products can be used and the results that may be achieved. Actual
environmental costs and performance characteristics will vary depending on individual client configurations and conditions.
IBM Global Financing offerings are provided through IBM Credit Corporation in the United States and other IBM subsidiaries and divisions worldwide to qualified commercial and
government clients. Rates are based on a client's credit rating, financing terms, offering type, equipment type and options, and may vary by country. Other restrictions may apply. Rates
and offerings are subject to change, extension or withdrawal without notice.
IBM is not responsible for printing errors in this document that result in pricing or information inaccuracies.
All prices shown are IBM's United States suggested list prices and are subject to change without notice; reseller prices may vary.
IBM hardware products are manufactured from new parts, or new and serviceable used parts. Regardless, our warranty terms apply.
Any performance data contained in this document was determined in a controlled environment. Actual results may vary significantly and are dependent on many factors including system
hardware configuration and software design and configuration. Some measurements quoted in this document may have been made on development-level systems. There is no
guarantee these measurements will be the same on generally-available systems. Some measurements quoted in this document may have been estimated through extrapolation. Users
of this document should verify the applicable data for their specific environment.
© Copyright IBM Corporation 2015