Veritas NetBackup™ Flex Scale Administrator's Guide
- Product overview
- Viewing information about the NetBackup Flex Scale cluster environment
- NetBackup Flex Scale infrastructure management
- User management
- Considerations for managing NetBackup Flex Scale users
- Adding users
- Changing user password
- Removing users
- Modifying user roles
- Considerations for configuring AD/LDAP
- Configuring AD server for Universal shares and Instant Access
- Configuring AD/LDAP servers for NetBackup services
- Configuring additional AD/LDAP servers for managing NetBackup services/Universal Shares/Instant Access
- Configuring AD/LDAP servers on clusters deployed with only media servers
- Directory services and certificate management
- Region settings management
- About NetBackup Flex Scale storage
- About Universal Shares
- Cloud bucket support for NetBackup Flex Scale
- Backing up data to Data Domain storage
- Node and disk management
- NetBackup Flex Scale network cabling
- Adding a node to the cluster using the NetBackup Flex Scale web interface
- Adding a node using the REST APIs
- Replacing a node in a cluster
- Starting and stopping nodes
- Rebooting a node
- Adding an excluded node to the cluster
- Replacing a disk
- Adding an excluded disk to the cluster
- Viewing the disk sync status
- Viewing disk details
- Viewing node details
- Switching management console to another cluster node
- License management
- Stopping NetBackup service containers
- Starting NetBackup service containers
- Managing the Fibre Channel ports
- Requirements
- Enabling BOM (Bill of Materials) configuration for Fibre Channel
- Assigning Fibre Channel ports
- Discovering attached devices
- Rescanning Fibre Channel cards
- Cleaning Fibre Channel ports
- Unassigning Fibre Channel ports
- Viewing details about the Fibre Channel ports
- Disabling BOM (Bill of Materials) configuration for Fibre Channel
- Managing hardware vendor packages
- Updating credentials for HPE iLO administrator users
- User management
- NetBackup Flex Scale network management
- About network management
- Modifying DNS settings
- Configuring MTU on public interfaces
- Configuring the console FQDN
- About bonding Ethernet interfaces
- Bonding operations
- Configuring NetBackup Flex Scale in a non-DNS environment
- Data network configurations
- Choosing the correct input method for data network configuration
- Network configuration on plain device (eth5)
- Network configuration on VLAN (eth5)
- Network configuration on bonded interfaces (bond0 on eth5 and eth7)
- VLAN on bond of eth5 and eth7 (bond0)
- Network configuration on management interface (eth1)
- Network configurations for adding a partial data network
- Support for multiple VLAN when disaster recovery is configured
- Configuring static routes on a NetBackup Flex Scale cluster
- NetBackup Flex Scale infrastructure monitoring
- Resiliency in NetBackup Flex Scale
- EMS server configuration
- Site-based disaster recovery in NetBackup Flex Scale
- About site-based disaster recovery in NetBackup Flex Scale
- Configuring disaster recovery using GUI
- Clearing the host cache
- Automated NetBackup SLP management
- DNS key management
- Managing disaster recovery using GUI
- Performing disaster recovery using RESTful APIs
- Active-Active disaster recovery configuration
- NetBackup optimized duplication using Storage Lifecycle Policies
- NetBackup Flex Scale security
- About the security meter
- STIG overview for NetBackup Flex Scale
- FIPS overview for NetBackup Flex Scale
- Managing the login banner
- Changing the password policy
- Support for immutability in NetBackup Flex Scale
- Authenticating users using digital certificates or smart cards
- About system certificates on NetBackup Flex Scale
- Deploying external certificates on NetBackup Flex Scale
- Configuring isolated recovery environment (IRE)
- Configuring multifactor authentication
- About multifactor authentication
- Considerations before configuring multifactor authentication
- Configuring multifactor authentication for your user account
- Disabling multifactor authentication for your user account
- Enforcing multifactor authentication for all users
- Configuring multifactor authentication for your user account when it is enforced in the cluster
- Resetting multifactor authentication for a user
- Single Sign-On (SSO)
- Appendix A. Maintenance procedures for HPE servers
- Replacement procedure for a chassis fan
- Replacement procedure for power supply
- Replacement procedure for a single OS disk
- Replacement procedure for both OS disks on a non- management console node
- Replacement procedure for NVMe disks (SSDs)
- Replacement procedure for RAID controller
- Replacement procedure for an Integrated Lights-Out (iLO) port
- Replacement procedure for quad-port NIC
- Procedure for memory expansion (DIMMs)
- Replacement procedure for memory (DIMMs)
- Replacement procedure for Mellanox port
- Replacement procedure for SFP port
- Replacement procedure for chassis
- Replacement procedure for a hard disk drive
- Replacement procedure for a Fibre Channel card for a cluster node
- Replacement procedure for a Fibre Channel card for a node that is not in a cluster
- Appendix B. Configuring NetBackup optimized duplication
- Appendix C. Disaster recovery terminologies
- Appendix D. Configuring Auto Image Replication
Considerations for managing NetBackup Flex Scale users
Consider the following while managing users in your NetBackup Flex Scale cluster:
You can add up to 10 user accounts to the NetBackup Flex Scale cluster during cluster configuration. You must add at least one user for each user role during the cluster configuration. You can add additional users at any time after the cluster is configured.
You can also add users without assigning a role. You can assign the required role to such user accounts later.
Note:
If you have deployed the cluster with only media servers, only the appliance administrator role option is available during cluster configuration and both appliance administrator and universal share user roles are available post cluster configuration.
Note:
When disaster recovery is configured between two NetBackup Flex Scale clusters, Veritas recommends that you add local user accounts on both clusters using the same credentials. This is to ensure that the same credentials work when the NetBckup primary is failed over between the clusters.
You can use a single user account and assign both NetBackup Flex Scale and NetBackup administrator roles to the same account. However, two separate user accounts are recommended.
You can assign the NetBackup admin role to a user account only during the cluster configuration. After the cluster is configured, you must use the NetBackup Web UI to manage NetBackup admin role assignment to user accounts.
You cannot use the NetBackup Flex Scale infrastructure UI console to manage NetBackup roles post cluster configuration.
Veritas recommends that you use the NetBackup Web UI to manage assignment of NetBackup roles. Use the NetBackup Flex Scale infrastructure UI console to manage assignment of NetBackup Flex Scale roles.
Note:
NetBackup roles assigned from the NetBackup Web UI are not visible in the NetBackup Flex Scale infrastructure UI console.
You can add local as well as AD and LDAP user accounts to the user roles.
NetBackup Flex Scale supports AD and LDAP in Secure Sockets Layer (SSL) and Non-SSL mode.
Note:
For AD/LDAP user account access to remain active in a NetBackup Flex Scale cluster on which both primary and media servers are deployed, the NetBackup primary server service must be running and healthy in the cluster.
If both primary server and media servers are deployed on the cluster, AD and LDAP users cannot access the appliance SSH, cluster-level CLI and REST APIs. If only media servers, are deployed, AD/LDAP users having appliance administrator role can access SSH, GUI, cluster-level CLI and REST APIs.
Note:
If you have deployed the cluster with only media servers, the appliance administrator role is assigned to AD/LDAP users using the NetBackup Flex Scale Infrastructure Web UI.
Local users that have the NetBackup Flex Scale appliance administrator role assigned have access to the cluster-level CLI and the infrastructure REST APIs. Users that have the NetBackup administrator role assigned have access to the NetBackup REST APIs.
While removing user accounts from the cluster, you cannot delete all the users from the users list. At least one user with the NetBackup Administrator and the NetBackup Flex Scale Appliance Administrator role should always remains in the users list.
While assigning roles from the NetBackup UI, you must use the IP or the FQDN of the server that was used during the configuration instead of the "NBU_LDAP_DOMAIN" string.
If domain name was provided during AD/LDAP configuration, then you can also use the domain names for assigning roles.
Veritas recommends that LDAP and AD user UIDs start from 10000. Otherwise, when you assign a role to the AD/LDAP user, the UIDs of some of the local user may conflict with the UID of a user from the directory server
Nested LDAP group for role assignment is not supported.
You can configure multiple AD/LDAP servers.
Consider the following while managing users in your NetBackup Flex Scale cluster after upgrade:
You must use the "LDAP_Server_FQDN/IP" string for the AD/LDAP server that was configured before upgrade.
You should use the server name to assign role to AD/LDAP server that is configured after upgrade
You can use the NetBackup REST API to get the ID value and use the ID value while assigning a role to configured AD/LDAP server users.
See User management.
See Adding users.
See Removing users.