NetBackup™ Web UI Cloud Administrator's Guide

Last Published:
Product(s): NetBackup & Alta Data Protection (11.0)
  1. Managing and protecting cloud assets
    1.  
      About protecting cloud assets
    2.  
      Limitations and considerations
    3.  
      AWS and Azure government cloud support
    4. Configure Snapshot Manager in NetBackup
      1.  
        Add a Snapshot Manager
      2. Add a cloud provider for a Snapshot Manager
        1.  
          Adding a new region
        2.  
          IAM Role for AWS Configuration
        3.  
          IAM policy for OCI configuration
      3.  
        Associate media servers with a Snapshot Manager
      4.  
        Discover assets on Snapshot Manager
      5.  
        Enable or disable a Snapshot Manager
      6.  
        (Optional) Add the Snapshot Manager extension
    5. Managing intelligent groups for cloud assets
      1.  
        Considerations for cloud intelligent groups
      2.  
        Create an intelligent group for cloud assets
      3.  
        Delete an intelligent group for cloud assets
    6. Protecting cloud assets or intelligent groups for cloud assets
      1.  
        Customize or edit protection for cloud assets or intelligent groups
      2.  
        Remove protection from cloud assets or intelligent groups
    7. About storage lifecycle policies
      1.  
        Adding an SLP
      2.  
        SLP configurations for PaaS and IaaS policies
    8. Managing policies for cloud assets
      1.  
        Limitations and considerations
      2.  
        Planning for policies
      3.  
        Creating policies for cloud assets
      4.  
        Setting up attributes for PaaS assets
      5.  
        Setting up attributes for IaaS assets
      6.  
        Creating schedules
      7.  
        About backup frequency
      8.  
        About assigning retention periods
      9. Configuring the Start window
        1.  
          Example of schedule duration
      10.  
        Configuring the include dates
      11.  
        Configuring the exclude dates
      12.  
        Configuring the cloud assets for PaaS
      13.  
        Configuring the cloud assets for IaaS
      14.  
        Configuring backup options for IaaS
      15. Managing cloud policies
        1.  
          Copy a policy
        2.  
          Deactivating or deleting a policy
        3.  
          Manually backup assets
    9. Scan for malware
      1.  
        Scanning backup images
      2.  
        Assets by workload type
    10. Protecting Microsoft Azure resources using resource groups
      1.  
        Before you begin
      2.  
        Limitations and considerations
      3. About resource group configurations and outcome
        1.  
          Examples of resource group configurations
      4.  
        Troubleshoot resource group permissions
    11. NetBackup Accelerator for cloud workloads
      1.  
        How the NetBackup Accelerator works with virtual machines
      2.  
        Accelerator forced rescan for virtual machines (schedule attribute)
      3.  
        Accelerator backups and the NetBackup catalog
      4.  
        Accelerator messages in the backup job details log
    12.  
      Configuring backup schedules for cloud workloads using protection plan
    13.  
      Backup options for cloud workloads
    14. AWS Snapshot replication
      1.  
        Configure AWS snapshot replication
      2.  
        Using AWS snapshot replication
      3.  
        Support matrix for account replication
    15.  
      Protect applications in-cloud with application-consistent snapshots
    16.  
      Protecting AWS or Azure VMs for recovering to VMware
    17.  
      Cloud asset cleanup
    18.  
      Cloud asset filtering
  2. Protecting PaaS assets
    1.  
      Protecting PaaS assets
    2.  
      Prerequisites for protecting PaaS assets
    3.  
      Enabling binary logging for MySQL and MariaDB databases
    4.  
      Enabling backup and restore in Kubernetes
    5.  
      Prerequisites for protecting Amazon RDS SQL Server database assets
    6. Protecting RDS Custom instances
      1.  
        Protecting RDS Custom for SQL Server assets
      2.  
        Consideration for protecting RDS Custom for SQL Server assets
      3.  
        Protecting RDS Custom for Oracle assets
      4.  
        Consideration for protecting RDS Custom for Oracle assets
    7. Protecting Azure Managed Instance databases
      1.  
        Prerequisites for protecting Azure Managed Instance databases
      2.  
        Permissions required for protecting Azure Managed Instance databases
    8. Limitation and considerations
      1.  
        For all databases
      2.  
        For PostgreSQL
      3.  
        For incremental backups for Azure PostgreSQL
      4.  
        For AWS RDS PostgreSQL and AWS Aurora PostgreSQL
      5.  
        For AWS DynamoDB
      6.  
        For AWS DocumentDB
      7.  
        For AWS Neptune
      8.  
        For AWS RDS SQL
      9.  
        For Azure, AWS RDS, and Aurora MySQL
      10.  
        For incremental backups using Azure MySQL server
      11.  
        For incremental backups using the GCP SQL Server
      12.  
        For Azure SQL and SQL Managed Instance
      13.  
        For Azure SQL and SQL Managed Instance (without temp. database)
      14.  
        For Azure SQL Server and SQL Managed Instance incremental backup
      15.  
        For Azure Cosmos DB for MongoDB
      16.  
        For Azure Cosmos DB for NoSQL
      17.  
        For Amazon RDS for Oracle
      18.  
        For Amazon Redshift databases
      19.  
        For Amazon Redshift clusters
      20.  
        For GCP SQL Server
      21.  
        For GCP BigQuery
    9. Installing the native client utilities
      1.  
        Installing the MySQL client utility
      2.  
        Installing the sqlpackage client utility
      3.  
        Installing PostgreSQL client utility
      4.  
        Installing MongoDB client utility
    10. Configuring storage for different deployments
      1.  
        For MSDP cloud deployments
      2.  
        For Kubernetes deployments
      3.  
        For VM-based BYO deployments
    11.  
      Configuring the storage server for instant access
    12.  
      About incremental backup for PaaS workloads
    13.  
      Configuring incremental backups for Azure MySQL server
    14.  
      About archive redo log backup for PaaS workloads
    15.  
      About Auto Image Replication for PaaS workloads
    16.  
      Discovering PaaS assets
    17.  
      Viewing PaaS assets
    18. Managing PaaS credentials
      1.  
        View the credential name that is applied to a database
      2.  
        Add credentials to a database
      3.  
        Creating an IAM database username
      4.  
        Creating a system or user-managed identity username
      5.  
        Configuring permissions for the database user
    19. Add protection to PaaS assets
      1.  
        Perform backup now
  3. Recovering cloud assets
    1. Recovering cloud assets
      1.  
        About the pre-recovery check for VMs
      2.  
        Supported parameters for restoring cloud assets
      3.  
        Recovering virtual machines
      4.  
        Recovering applications and volumes to their original location
      5.  
        Recovering applications and volumes to an alternate location
      6.  
        Recovery scenarios for GCP VMs with read-only volumes
      7.  
        (GCP only) Restoring virtual machines and volumes using the autoDelete disk support
    2.  
      Perform rollback recovery of cloud assets
    3. Recovering AWS or Azure VMs to VMware
      1.  
        Post-recovery considerations for cloud VMs recovered to VMware
      2. Steps to recover images from cloud VMs to VMware
        1.  
          Recovering images from AWS to VMware
        2.  
          Recovering images from Azure to VMware
    4. Recovering PaaS assets
      1.  
        Recovering non-RDS PaaS assets
      2.  
        Recovering Redshift clusters
      3.  
        Recovering AWS DocumentDB and Neptune assets
      4.  
        Recovering RDS-based PaaS asset
      5.  
        Recovering Azure-protected assets
      6.  
        Recovering duplicate images from AdvancedDisk
  4. Performing granular restore
    1.  
      About granular restore
    2.  
      Supported environment list
    3.  
      List of supported file systems
    4.  
      Before you begin
    5.  
      Limitations and considerations
    6.  
      Restoring files and folders from cloud virtual machines
    7.  
      Restoring volumes on cloud virtual machines
    8.  
      Performing steps after volume restore containing LVM
    9.  
      Troubleshooting
  5. Troubleshooting protection and recovery of cloud assets
    1.  
      Troubleshoot cloud workload protection issues
    2.  
      Error Code 9855: Error occurred while exporting snapshot for the asset: <asset_name>
    3.  
      VMs and other OCI assets with CMK-encrypted disks are marked as deleted in NetBackup UI.
    4.  
      Backup from snapshot jobs take longer time than expected
    5.  
      Backup from snapshot job fails due to connectivity issues when Snapshot Manager is deployed on an Ubuntu host
    6.  
      Error disambiguation in NetBackup UI
    7.  
      Status Code 150: Termination requested by administrator
    8. Troubleshoot PaaS workload protection and recovery issues
      1.  
        Troubleshooting Amazon Redshift issues
      2.  
        Troubleshooting Azure Postgres issues
      3.  
        Troubleshooting Amazon RDS Custom for SQL issues

Protecting cloud assets or intelligent groups for cloud assets

You can create cloud provider-specific protection plans for your cloud workloads. Then you can subscribe the assets that are associated with the cloud provider to a provider-specific protection plan.

Note:

If you previously had a protection plan that was applied to assets from different cloud providers, it is automatically converted to the new provider-specific format. This conversion happens after an upgrade to NetBackup 9.1. For example, if you had the assets from Google Cloud and AWS Cloud that are subscribed to one protection plan, then the protection plan is split. The protection plan is split into two separate protection plans for each provider.

section.

Use the following procedure to subscribe a cloud VM, application, volume, or an intelligent group to a protection plan. When you subscribe an asset to a protection plan, you assign predefined backup settings to the asset.

Note:

The RBAC role that is assigned to you must give you access to the assets that you want to manage and to the protection plans that you want to use.

To protect a cloud asset or an intelligent group

  1. On the left, click Workloads > Cloud.
  2. On the Virtual machines tab, or Applications tab, or Volumes tab or Intelligent groups tab, click the box for the asset or the asset group and click Add protection.
  3. Select a protection plan and click Next.
  4. You can adjust the following settings:
    • Schedules and retention

    • Storage options

      For more information about storage options in the web UI, review the Configuring storage section in the NetBackup Web UI Administrator's Guide.

    • Backup options

  5. Click Protect.
Backup now option for immediate protection

Apart from the scheduled protection plans, you can also use the Backup now option to backup an asset immediately, to safeguard against any unplanned circumstances.

  1. Select a cloud asset or an intelligent group and click Backup now.

  2. Then select a protection plan to apply. Only the protection plans relevant to a specific cloud provider of the asset are displayed as options.

  3. Click Start backup.

    A backup job is triggered, which can be tracked on the Activity monitor page.

For more information, see NetBackup Web UI Administrator's Guide.

Conversion of protection plans after an upgrade to NetBackup 9.1 and later

Note the following points concerning the automatic conversion of older protection plans to the new format.

  • Protection plan conversion starts when the asset migration is completed after the upgrade of NetBackup to 9.1 and later.

  • Old protection plans with no assets subscribed are not converted to the new format. You can manually delete them.

  • Before or during conversion

    • All the assets are unsubscribed from the old protection plan and subscribed to the converted protection plan.

    • No new assets can be subscribed to the old protection plan.

    • The Backup now operation fails for the old plan.

    • Customizing or editing the old protection plan is prevented.

  • After successful conversion

    • If the old protection plan was used to protect the assets from only one cloud provider, then the new plan retains the same name and asset subscription upon conversion.

    • If the old protection plan was used to protect the assets from multiple cloud providers, then the name of the old protection plan is retained as before. The protection plan name is updated to retain the asset subscription for any one cloud provider upon conversion.

      For the other cloud providers that were part of the old plan, new protection plans are created upon conversion, and only the assets of respective providers are subscribed to them. New plans are named in the following format <old_plan_name>_<cloud_provider>.

    • Hence you may see more number of plans in your Protection Plans menu on the web UI than before.

    • Success messages are shown in the notifications as follows:

      The protection plan <protectionPlanName> created during conversion to new format.

      Successfully converted the protection plan <protectionPlanName> to the new format.

      Then you can start managing and applying the converted protection plans as normal.

Failure scenarios

Refer to the following to know how the failure scenarios are handled during or after the conversion of protection plans. Also check the notifications for any failure alerts and take the necessary action.

  • Some of the assets might fail to get unsubscribed from the old protection plan. In that case, the conversion continues with the assets that are successfully unsubscribed. The conversion process for the assets that failed, is retried every 4 hours.

  • After the conversion, some of the assets might fail to get automatically re-subscribed to the new plan. In that case, you need to manually subscribe those assets to the converted protection plan.

  • Failure might be encountered when the required access permissions are assigned to the new, converted protection plan. In that case, you need to manually assign the access permissions.