Veritas NetBackup™ Virtual Appliance Documentation
- Getting to know the NetBackup Virtual Appliance
- NetBackup Virtual Appliance product description
- Preparing to deploy the appliance
- Deploying and configuring the appliance
- How to deploy and configure a NetBackup Virtual Appliance combined master and media server
- How to deploy and configure a NetBackup Virtual Appliance media server
- How to deploy and configure a NetBackup Virtual Appliance master server
- How to deploy and configure a NetBackup Virtual Appliance CloudCatalyst
- How to deploy and configure a NetBackup Virtual Appliance combined master and media server
- Post initial configuration procedures
- Appliance common tasks
- Storage management
- About NetBackup Virtual Appliance storage configuration
- About viewing storage space information using the Show command
- About OpenStorage plugin installation
- About NetBackup Virtual Appliance storage configuration
- Deduplication pool catalog backup and recovery
- Network connection management
- Managing users
- About user name and password specifications
- About authenticating LDAP users
- About authenticating Active Directory users
- About authenticating Kerberos-NIS users
- About user authorization on the NetBackup Virtual Appliance
- Creating NetBackup administrator user accounts
- Using the appliance
- About configuring Host parameters for your appliance on the NetBackup Virtual Appliance
- About Copilot functionality and Share management
- About NetBackup Virtual Appliance as a VMware backup host
- About running NetBackup commands from the appliance
- About mounting a remote NFS
- About Auto Image Replication from a NetBackup Virtual Appliance
- Monitoring the appliance
- About SNMP
- About Call Home
- Appliance security
- About Symantec Data Center Security on the NetBackup Virtual Appliance
- Setting the appliance login banner
- Upgrading the appliance
- About upgrading to NetBackup Virtual Appliance software version 3.2
- Requirements and best practices for upgrading NetBackup appliances
- Methods for downloading appliance software release updates
- NetBackup client upgrades with VxUpdate
- Appliance restore
- Decommissioning and Reconfiguring
- Troubleshooting
- About disaster recovery
- About NetBackup support utilities
- Appliance logging
- Commands overview
- Appendix A. Appliance commands
- Appendix B. Manage commands
- Appendix C. Monitor commands
- Appendix D. Network commands
- Appendix E. Reports commands
- Appendix F. Settings commands
- Appendix G. Support commands
Performing the initial configuration on a NetBackup Virtual Appliance CloudCatalyst
This section describes how to perform the initial configuration on a NetBackup Virtual Appliance CloudCatalyst.
NetBackup Virtual Appliance release 3.2 introduces support for external certificate authority certificates. This feature provides an alternative to using the NetBackup Certificate Authority for host verification and security. This procedure includes the necessary information to deploy these certificates. For more information about security certificates, see the chapter "External CA support in NetBackup" in the NetBackup Security and Encryption Guide.
You must complete the following tasks in the follow topic before you start the initial configuration.
Check the NetBackup Cloud Administrator's Guide to ensure that your cloud provider is supported and install any necessary provider compatibility updates on the appliance.
Make sure that the master server and this media server have compatible software versions.
Add the host name of this media server to the
SERVERS
list on the master server that you plan to use with it.If a firewall exists between the master server and this media server, open the appropriate ports on the master server.
Generate a set of credentials for the appliance.
Configure KMS on the master server (Optional)
The following link provides specific instructions about how to accomplish the necessary tasks:
See How to deploy and configure a NetBackup Virtual Appliance CloudCatalyst.
To perform the initial configuration of a NetBackup Virtual Appliance
- After you have deployed a new virtual appliance, log on to the NetBackup Virtual Appliance Shell Menu.
The logon is admin, and the default password is P@ssw0rd.
- (Optional) Configure the appliance date and time.
NTP is an optional parameter during the initial configuration wizard. If you do not use an NTP server in your environment, make sure to configure the appliance date and time before the initial configuration.
Caution:
If the date and time of this media server does not match the date and time of the master server, the initial configuration wizard fails.
Navigate to the Main > Network view.
Set the time zone by entering the following command:
TimeZone Set
Select the appropriate time zone from the displayed list.
Set the date and time by entering the following command:
Date Set Month Day HHMMSS Year
Where Month is the name of the month.
Where Day is the day of the month from 1 to 31.
Where HHMMSS is the hour, minute, and seconds in a 24-hour format. The fields are separated by semi-colons, for example. HH:MM:SS.
Where Year is the calendar year form 1970 through 2037.
- Launch the initial configuration wizard:
Main > Appliance > Configure
A message about the Virtual Appliance Configuration Wizard appears. This wizard will walk you through the process to configure appliance network, storage, and NetBackup CloudCatalyst.
The following prompt appears:
>> Do you want to continue? [yes, no] (no)yes
Type yes.
- The network configuration prompts appear in the following order:
Hostname
Enter a short host name or a fully qualified domain name (FQDN) for this appliance. As a best practice, Veritas recommends that you use FQDN.
Caution:
After the initial deployment has completed successfully, the only way to change the host name is to perform a factory reset.
Note:
If you plan to configure Active Directory (AD) authentication on this appliance, the host name must be 15 characters or less. Otherwise, AD configuration can fail.
DNS domain name
Enter a DNS domain name for this appliance.
IPv4 address
Enter the IPv4 address to be used for this appliance.
Netmask
Enter the netmask that corresponds to the IP address.
Gateway IP address
Enter the IPv4 address of the gateway (network point) that acts as an entrance to another network.
DNS server 1 IP address
Enter the IPv4 address of the primary DNS server for this appliance.
DNS server 2 IP address(Optional)
Enter the IPv4 address of the secondary DNS server for this appliance.
- (Optional) The following prompt appears:
The host name must be resolvable with a DNS or a HOSTS file for the initial configuration to be successful. Do you want to write the host name resolution information to the HOSTS file? [yes, no](no)
Note:
If the host name is not resolvable with a DNS or a HOSTS file during the initial configuration, the initial configuration wizard will fail.
Type yes to use the HOSTS file to resolve the appliance host name. This ensures that the host name is resolvable when DNS is not available.
Type no to use the DNS you entered.
- The following prompts appear:
NTP server (Optional)
Enter the Network Time Protocol (NTP) server for this appliance.
Master server
Enter the NetBackup master server name or IP address for this appliance.
Note:
The NetBackup Virtual Appliance combined master and media server does not support adding additional media servers. In this scenario, do not use it as the master server for the media server.
Note:
If the host name of the master server is an FQDN, Veritas recommends that you use the FQDN to specify the master server for the media server.
After you have entered the master server name, the appliance pings the master server for the Certificate Authority (CA) status and shows the result. Each of the following bullet statements describes the possible status results. Follow the instructions that appear below the applicable status result to complete the certificate configuration.
The master server <master_server_name> has an enabled External CA-signed certificate. Do you want to import the External CA-signed certificate for this Media server now [yes,no](yes):
Press Enter to continue. The following message appears:
The following shares have been opened on the appliance for you to upload certificate files:
NFS share <media_server_name>:/inst/share
CIFS share \\<media_server_name>\general_share
Enter the following details for external certificate configuration:
Enter the certificate file path:
Enter the trust store file path:
Enter the private key path:
Enter the password for the passphrase file path or skip security configuration (default: NONE):
Enter the following details for CRL usage:
Should a CRL be honored for the external certificate?
1) Use the CRL defined in the certificate.
2) Use the specific CRL directory.
3) Do not use a CRL.
q) Skip security configuration.
CRL option: Enter 1, 2, 3, or q.
Verify the External CA details that you entered:
Certificate file name:
Trust store file name:
Private key file name:
CRL check level: (Shows the selected CRL option.)
Do you want to use the above certificate files? [yes, no](yes):
After verifying that the entered information is correct, press Enter to continue and answer the following prompt:
Is this correct? [yes, no](yes):
If all of the information is correct, press Enter to continue.
The appliance performs an ECA health check and shows the result of each validation check. When the health check has completed successfully, the following messages appear:
ECA health check was successful.
The external certificate has been registered successfully.
The master server <master_server_name> currently uses an external CA issued certificate and its own internal certificate. Would you like to proceed with the external CA issued certificate? [yes,no](yes):
If you select no, the following message appears:
This appliance will use a NetBackup issued certificate for secure communication.
If you select yes, enter the following details for external certificate configuration:
Enter the certificate file path:
Enter the trust store file path:
Enter the private key path:
Enter the password for the passphrase file path or skip security configuration (default: NONE):
Enter the following details for CRL usage:
Should a CRL be honored for the external certificate?
1) Use the CRL defined in the certificate.
2) Use the specific CRL directory.
3) Do not use a CRL.
q) Skip security configuration.
CRL option: Enter 1, 2, 3, or q.
Verify the External CA details that you entered:
Certificate file name:
Trust store file name:
Private key file name:
CRL check level: (Shows the selected CRL option.)
Do you want to use the above certificate files? [yes, no](yes):
After verifying that the entered information is correct, press Enter to continue and answer the following prompt:
Is this correct? [yes, no](yes):
If all of the information is correct, press Enter to continue.
The appliance performs an ECA health check and shows the result of each validation check. When the health check has completed successfully, the following messages appear:
ECA health check was successful.
The external certificate has been registered successfully.
This appliance will use a NetBackup issued certificate for secure communication.
No further certificate configuration is required. Click Next to continue
For more information about security certificates, refer to the NetBackup Security and Encryption Guide.
- Log in to the NetBackup Administration Console and configure the cloud storage provider that you want to use. From the console, launch the Cloud Storage Configuration wizard. For complete configuration details, see the Veritas NetBackup Cloud Administrator's Guide.
Note the following important points about cloud storage provider configuration on the appliance:
Each NetBackup Virtual Appliance CloudCatalyst can only be configured for a single cloud storage provider. For example, the appliance cannot be configured to use both Amazon S3 and Amazon GovCloud.
Each NetBackup Virtual Appliance CloudCatalyst must have its Local cache directory set to the /msdpc path. The following shows the Local cache directory as it appears in the Cloud Storage Configuration wizard:
- To complete the appliance configuration, you must create a backup policy for the deduplication (MSDP) pool catalog. See Manually configuring the NetBackup Virtual Appliance deduplication pool catalog backup policy.
For complete details about the MSDP catalog backup policy and how to configure and update the policy, see the Veritas NetBackup Deduplication Guide.
- Return to the NetBackup Virtual Appliance Shell Menu and use the following command to verify that the automatic configuration completed successfully:
Main > Appliance > Status
The command output should contain a message similar to the following:
Appliance Version is 3.2. Appliance is configured as media appliance for NetBackup CloudCatalyst.
If the output does not show that the appliance is configured as a media appliance, you need to redeploy the appliance or perform other troubleshooting steps to fix the issue before you proceed to the next step. See Troubleshooting NetBackup Virtual Appliance initial deployment issues.
- Add a permanent license key before the evaluation key expires with the following command:
Main > Manage > License > Add
You can locate your permanent license key from the Veritas Entitlement Management System (VEMS). To access VEMS, click Licensing on the Veritas Support website.
Warning:
If the correct license key is not installed, the appliance services stop functioning after the evaluation key expires. Make sure that the NetBackup license you add includes support for NetBackup Virtual Appliance.
See Managing license keys on the NetBackup Virtual Appliance.
- Use the following commands to change the admin and the maintenance account passwords from the known default password (P@ssw0rd):
Main > Settings > Password admin
Main > Settings > Password maintenance
After the appliance is configured and operational, you are ready to install NetBackup client software on the computers that you want to back up.
See the NetBackup Installation Guide for how to install NetBackup clients.