The Plug‑in for Encryption lets you enable encryption for all backups on the NetVault Server or Client where a plug-in is installed, or enable encryption only for specific jobs. Encryption can also be enabled only for the primary backup or the secondary copies. This approach lets you take advantage of both encryption and deduplication. For example, you can deduplicate the primary backup and encrypt the secondary copy.
The job-level encryption option can be used in the following situations:
| • | 
| 1  | In the Navigation pane, click Change Settings. | 
| 2  | 
| 3  | 
| After the Plug‑in for Encryption is automatically installed with NetVault on a client, you can do either of the following: For more information about enabling encryption for specific backups, see Performing job-level encryption. | |||
| Type the string that serves as the encryption key for the NetVault machine. | |||
| Re-type the encryption string here to confirm that it is correct. | |||
| 
 NOTE: For NetVault Clients version 13.0 and earlier, when you select the AES256 option, the built-in NetVault Plug-in for Encryption uses a non FIPS compliant AES-256 encryption algorithm. For NetVault Clients version 13.0 and earlier, the built-in NetVault Plug-in for Encryption does not include a FIPS compliant encryption algorithm option. NOTE: For NetVault Clients version 13.0.1 and version 13.0.2, the AES256 option instructs the built-in NetVault Plug-in for Encryption to use a FIPS compliant encryption algorithm. For NetVault Clients version 13.0.1 and version 13.0.2, the AES256_OLD (non FIPS compliant) option is not available in the built-in NetVault Plug-in for Encryption. If you are managing a NetVault Client version 13.0.1 or version 13.0.2 and prefer to use the non FIPS compliant AES-256 encryption algorithm, see the troubleshooting section of this guide for details about Enabling non FIPS encryption algorithm on NetVault Clients version 13.0.1 and 13.0.2. |