NetScaler MPX™ disk encryption through NetScaler Console
-
Disk encryption is supported only on NetScaler MPX 9100 instances.
-
Disk encryption for NetScaler MPX 9100 instances can be enabled only in standalone NetScaler Console.
-
Starting from release 14.1-56.x, disk encryption is supported on NetScaler MPX 9100, 16000, and MPX 15000-50G instances manufactured after May 20, 2025.
/var/core, /var/crash, /var/log, /var/nslog, /flash/nsconfig, /var/nstrace, and /var/temp.
-
Data Protection at Rest: Prevents unauthorized access to sensitive data when the system is powered off.
-
Compliance: Helps meet regulatory and compliance requirements for data security.
-
Mitigation of Physical Theft Risks: Ensures that the sensitive and proprietary data on stolen or misplaced storage devices cannot be accessed.
-
Secure Boot Process: Requires authenticated credentials during boot-up, ensuring only authorized users can access the system.
-
Enhanced Security for Critical Data: Protects logs, configurations, and crash data from unauthorized access.
-
If the NetScaler MPX instance disk is removed, the data is not accessible.
-
If you reboot the NetScaler MPX instance, the reboot is successful only after NetScaler Console authenticates the NetScaler MPX instance using its serial number from the HSM server.
Prerequisites
-
For 9100, the NetScaler MPX instances are running build 14.1-47.x and are managed on NetScaler Console on-premises running build 14.1-47.x.Note:Disk Encryption is not supported on NetScaler Console service.
-
You have added the NetScaler MPX instance serial number in the HSM (Thales CipherTrust Manager) server for NetScaler Console to share the key after authenticating the instance using its serial number.
-
The NetScaler MPX instance is backed up through NetScaler Console. For more information, see Backup and restore NetScaler instances.
-
For MPX 16000 and MPX 15000-50G, NetScaler Console on-premises is on release 14.1 build 56.x.
Add the instance serial number in the HSM (Thales CipherTrust Manager) server
-
Log on to the Thales CipherTrust Manager server.
-
In the left pane, select Keys and click Add Key.
-
Under Key Labels, add a label with the name
serialnumber, specify the instance serial number in the Label Value text box, click the + button to add the key details, and then click Add Key.
-
In the key details page, you must enable the Exportable toggle for this key.
Notes:-
The maximum supported key size is 511 bytes. For example: AES-128 and AES-256 are supported. RSA keys between 512 and 4096 are not supported.
-
We recommend that you use only the supported key size. NetScaler® instance fails if you configure an unsupported key size.
-
Ensure that you specify the correct serial number. If there is a mismatch in the serial number, the encryption process does not start.
-
We recommend that you copy the instance serial number from NetScaler Console. In the NetScaler Console GUI, navigate to Infrastructure > Instance > MPX, select the NetScaler MPX instance, and from the Select Action list, click Get Serial Number.
-
Instance disk encryption through NetScaler Console
-
Navigate to Infrastructure > Instances > NetScaler.
-
In the NetScaler MPX tab, you can see the managed instances details. The instance that you want to encrypt displays Plain Text under Disk Encryption Status.

-
From the Select Action list, click Disk Encryption Settings.

-
From the Select Action list and click Promote device .Note:Selecting the Promote device option is mandatory to activate the Disk Encryption feature specifically for MPX appliances manufactured before May 20, 2025. Allow approximately 30 minutes for the MPX appliance to complete its conversion into a disk encryption-enabled device.

-
In the Disk Encryption Settings page:
-
Specify the IP address, user name, and password of the HSM server from where NetScaler Console can fetch the encryption key by using the serial number.
-
Enable the Key Manager Proxy. You must enable this option to continue with the disk encryption process.Note:Ensure that the Key Manager Proxy is always enabled even after the encryption is complete. If you disable this option, the encrypted instance will not reboot successfully for scenarios, such as after you upgrade the instance or force a reboot of the instance.
-
Click Save.

-
-
Select the instance and from the Select Action list, click Encrypt File System.
A confirmation window appears. Click Yes to proceed. -
A confirmation message appears in NetScaler Console stating that the encryption is started and the instance will be in Down status for approximately 30 minutes.
The instance state appears as Encryption in progress.
Validation after encryption
-
You can log on to the NetScaler MPX instance using an SSH client and then validate if the encryption is successful by using the following command:
show filesystemencryptionBefore encryption After encryption 

-
You can reboot your NetScaler MPX instance and validate if the reboot is completed after the encryption as shown in the following example:

-
You can use the following command to validate if Key Manager Proxy is successfully configured and is accessible from NetScaler:
show keymanagerproxy
Note:After the encryption, NetScaler Console usesmpx_disk_encryption_default_profileto access the NetScaler MPX instance. Thempx_disk_encryption_default_profilehas the default credentials (nsroot/nsroot).