NetBackup™ Troubleshooting Guide
- Introduction
- Troubleshooting procedures- About troubleshooting procedures
- Troubleshooting NetBackup problems
- Troubleshooting installation problems
- Troubleshooting configuration problems
- Device configuration problem resolution
- Testing the primary server and clients
- Testing the media server and clients
- Resolving network communication problems with UNIX clients
- Resolving network communication problems with Windows clients
- Troubleshooting vnetd proxy connections- vnetd proxy connection requirements
- Where to begin to troubleshoot vnetd proxy connections
- Verify that the vnetd process and proxies are active
- Verify that the host connections are proxied
- Test the vnetd proxy connections
- Examine the log files of the connecting and accepting processes
- Viewing the vnetd proxy log files
 
- Troubleshooting security certificate revocation- Troubleshooting cloud provider's revoked SSL certificate issues
- Troubleshooting cloud provider's CRL download issues
- How a host's CRL affects certificate revocation troubleshooting
- NetBackup job fails because of revoked certificate or unavailability of CRLs
- NetBackup job fails because of apparent network error
- NetBackup job fails because of unavailable resource
- Primary server security certificate is revoked
- Determining a NetBackup host's certificate state
- Troubleshooting issues with external CA-signed certificate revocation
 
- About troubleshooting networks and host names
- Verifying host name and service entries in NetBackup- Example of host name and service entries on UNIX primary server and client
- Example of host name and service entries on UNIX primary server and media server
- Example of host name and service entries on UNIX PC clients
- Example of host name and service entries on UNIX server that connects to multiple networks
 
- About the bpclntcmd utility
- Using the Host properties to access configuration settings
- Resolving full disk problems
- Frozen media troubleshooting considerations
- Troubleshooting problems with the NetBackup web services
- Troubleshooting problems with the NetBackup web server certificate
- Resolving PBX problems
- Troubleshooting problems with validation of the remote host
- Troubleshooting Auto Image Replication
- Troubleshooting network interface card performance
- About SERVER entries in the bp.conf file
- About unavailable storage unit problems
- Resolving a NetBackup Administration operations failure on Windows
- Resolving garbled text displayed in NetBackup Administration Console on a UNIX computer
- Troubleshooting error messages in the NetBackup web UI and the NetBackup Administration Console
- Extra disk space required for logs and temporary files for the NetBackup Administration Console
- Unable to logon to the NetBackup Administration Console after external CA configuration
- Troubleshooting file-based external certificate issues
- Troubleshooting issues with external certificate configuration
- Troubleshooting Windows certificate store issues
- Troubleshooting backup failures
- Troubleshooting backup failure issues with NAT clients or NAT servers
- Troubleshooting issues with the NetBackup Messaging Broker (or nbmqbroker) service
- Troubleshooting issues with email notifications for Windows systems
- Troubleshooting issues with KMS configuration
- Troubleshooting issues with initiating the NetBackup CA migration because of large key size
- Troubleshooting issues with the non-privileged user (service user) account
- Troubleshooting issues with group name format in the auth.conf file
- Troubleshooting the VxUpdate add package process
- Troubleshooting issues with FIPS mode
- Troubleshooting issues with malware scanning
- Troubleshooting issues with NetBackup jobs that are enabled for data-in-transit encryption
- Troubleshooting issues with Unstructured Data Instant Access
- Troubleshooting issues with multifactor authentication
- Troubleshooting issues with multi-person authorization
- Troubleshooting connections to the NetBackup Scale-Out Relational Database
 
- Using NetBackup utilities- About NetBackup troubleshooting utilities
- About the analysis utilities for NetBackup debug logs
- About the Logging Assistant
- About network troubleshooting utilities
- About the NetBackup support utility (nbsu)
- About the NetBackup consistency check utility (NBCC)
- About the NetBackup consistency check repair (NBCCR) utility
- About the nbcplogs utility
- About the robotic test utilities
- About the NetBackup Smart Diagnosis (nbsmartdiag) utility
- About log collection by job ID
 
- Disaster recovery- About disaster recovery
- About disaster recovery requirements
- Disaster recovery packages
- About disaster recovery settings
- Recommended backup practices
- About disk recovery procedures for UNIX and Linux
- About clustered NetBackup server recovery for UNIX and Linux
- About disk recovery procedures for Windows
- About clustered NetBackup server recovery for Windows
- Generating a certificate on a clustered primary server after disaster recovery installation
- About restoring disaster recovery package
- About the DR_PKG_MARKER_FILE environment variable
- Restoring disaster recovery package on Windows
- Restoring disaster recovery package on UNIX
- About recovering the NetBackup catalog- About the catalog backup process
- Prerequisites for recovering the NetBackup catalog or NetBackup catalog image files
- About NetBackup catalog recovery on Windows computers
- About NetBackup catalog recovery from disk devices
- About NetBackup catalog recovery and symbolic links
- About NetBackup catalog recovery
- NetBackup disaster recovery email example
- About recovering the entire NetBackup catalog
- Establishing a connection with NAT media server before catalog recovery
- About recovering the NetBackup catalog image files
- About recovering the NetBackup databases
- Recovering the NetBackup catalog when NetBackup Access Control is configured
- Recovering the NetBackup catalog from a nonprimary copy of a catalog backup
- Recovering the NetBackup catalog without the disaster recovery file
- Recovering a NetBackup user-directed online catalog backup from the command line
- Restoring files from a NetBackup online catalog backup
- Unfreezing the NetBackup online catalog recovery media
- Steps to carry out when you see exit status 5988 during catalog recovery
 
 
Restoring disaster recovery package on Windows
After a disaster, you need to restore disaster recovery package corresponding to the catalog backup that you want to restore. Disaster recovery package gets the primary server host identity back. You need to restore the host identity before you perform catalog recovery.
- In a clustered primary server setup: - The disaster recovery package contains the identity files and configuration only for the virtual name. 
- After the DR installation, the virtual name's certificate is restored. 
- Cluster node-specific certificates and configuration options are not backed up and therefore are not recovered. You need to redeploy or reconfigure NetBackup or external certificates after the DR installation. 
 
If external CA-signed certificates are used in your NetBackup domain, ensure the following:
- The certificate file path is configured, accessible, and is the same as the one that was backed up. 
- You have configured the required certificate revocation lists (CRL) before you begin the disaster recovery installation, if applicable. - Refer to the NetBackup Security and Encryption Guide. 
- You have copied the required external certificates in Windows certificate store, if applicable. 
- If an external certificate was configured on the primary server before the disaster and DR installation fails, you can set the environment variable called DR_PKG_MARKER_FILE to enable you to correct the external certificate configuration towards the end of the DR installation. 
To restore the disaster recovery package during NetBackup installation
- Start the NetBackup software installation.Refer to the Installing server software on Windows systems section from the NetBackup Installation Guide. 
- On the NetBackup License Key and Server Type screen, select the Disaster Recovery Master Server option.
- On the NetBackup Disaster Recovery screen, specify the location of the disaster recovery package. Click Browse to select the package location that you want to restore.
- Specify the passphrase that is associated with the disaster recovery package that you want to restore.Ensure that you specify the appropriate passphrase: - If you specify a wrong passphrase or the passphrase is lost, you need to deploy security certificates on all hosts after installation. The disaster recovery package cannot be restored during installation. To restore the disaster recovery package after installation, refer to the following article: 
- If the passphrase is validated, continue with the installation. 
 
- If external CA-signed certificates were used in your NetBackup domain at the time of catalog backup before the disaster, during the DR installation, the Installer shows a WARNING message to configure the certificate revocation list (CRL). The CRL settings are also displayed that you can configure.- Review the value of the ECA_CRL_CHECK configuration option. - For more information on catalog backup and external certificate configuration options, refer to the NetBackup Administrator's Guide, Volume I. - If the ECA_CRL_CHECK configuration option is set to DISABLE, you do not need to do the CRL configurations. 
- If the ECA_CRL_CHECK configuration option is enabled, you are prompted to configure the CRL. - Configure the CRLs and continue with the DR installation. 
 
- Depending on the value that is specified for the ECA_CRL_PATH option, make the required CRLs available. - If ECA_CRL_PATH is not specified, NetBackup uses the CRLs from CRL distribution point (CDP) of the peer host's certificate. Ensure that the URLs that are available in the CDP are accessible. 
- If ECA_CRL_PATH is specified, NetBackup uses the CRLs that are available in the directory specified for this option. Copy the valid CRLs in the directory that you specify for ECA_CRL_PATH. 
 
- In case Windows certificate store was used to store the external CA-signed and this certificate was not backed up in the DR package, you can see a warning to configure the external CA-signed certificates. Configure the following external certificate configuration options on the primary server as per the values provided in the Installer or in the corresponding disaster recovery email: - ECA_CERT_PATH 
- ECA_PRIVATE_KEY_PATH 
- ECA_KEY_PASSPHRASEFILE 
- ECA_TRUST_STORE_PATH 
- ECA_CRL_PATH 
 - For more information on catalog backup and external certificate configuration options, refer to the NetBackup Administrator's Guide, Volume I. 
- In case the DR_PKG_MARKER_FILE environment variable was set before the DR installation, the installer displays a message, which conveys that the touch file exists. Once the external certificate configuration is done, delete the touch file that you have set for the DR_PKG_MARKER_FILE environment variable. - NetBackup services are started. 
 
- If the key management service (KMS) was configured on the primary server before the disaster, run the following command to start the KMS service: - Install_path\bin\nbkmscmd -discoverNBKMS 
- Refer to the Installing server software on Windows systems section from the NetBackup Installation Guide.
To restore the disaster recovery package after NetBackup installation
- Run the nbhostidentity -import -infile file_path command after NetBackup installation.Refer to the NetBackup Commands Reference Guide. 
- Clean up the allowed list cache and restart the NetBackup services on all hosts in the domain.
- Refresh the certificate revocation list (CRL) using the following command:nbcertcmd -getcrl 
- If the key management service (KMS) was configured on the primary server before the disaster, run the following command to start the KMS service:Install_path\bin\nbkmscmd -discoverNBKMS 
- Carry out the given  step to remove the NetBackup certificate files in the following scenario:NetBackup was configured to use only external CA-signed certificates before the disaster and NetBackup was configured to use NetBackup certificates or both NetBackup and external certificates before you manually imported the disaster recovery package. Remove the NetBackup certificate files using the following command: configureWebServerCerts -removeNBCert