Enabling encryption on a new volume
You can use the volume create command to enable encryption on a new volume.
About this task
Starting with ONTAP 9.4, if you enable cc-mode
when you set up the Onboard Key Manager, volumes you create with the volume create command are automatically encrypted, whether or not you specify -encrypt true.
Starting with ONTAP 9.6, you can use aggregate-level encryption to assign keys to the containing aggregate for the volumes to be encrypted. Volumes you create in the aggregate are encrypted by default. You can use the -encrypt option to override the default when you create the volume.
Starting with ONTAP 9.7, newly created volumes are encrypted by default when you have the LVE license and onboard or external key management.
A volume encrypted with a unique key is called an LVE volume. A volume encrypted with an aggregate-level key is called an LAE volume (for Lenovo Aggregate Encryption). Plaintext volumes are not supported in LAE aggregates.
Result
If you are using a KMIP server to store the encryption keys for a node, ONTAP automaticallypushesan encryption key to the server when you encrypt a volume.