Veritas NetBackup™ Virtual Appliance Documentation
- Getting to know the NetBackup Virtual Appliance
- NetBackup Virtual Appliance product description
- NetBackup Virtual Appliance supported features
- About the NetBackup Virtual Appliance documentation
- NetBackup Virtual Appliance 3.2 new features, enhancements, and changes
- Known limitations of the NetBackup Virtual Appliance 3.2 release
- Operational Notes for the NetBackup Virtual Appliance 3.2 release
- Preparing to deploy the appliance
- Deploying and configuring the appliance
- How to deploy and configure a NetBackup Virtual Appliance combined master and media server
- Using the vSphere Client to deploy a combined master and media server appliance
- Using the OVF Tool to deploy a combined master and media server appliance
- Performing the initial configuration on a NetBackup Virtual Appliance combined master and media server
- Completing the initial configuration of the NetBackup Virtual Appliance combined master and media server
- How to deploy and configure a NetBackup Virtual Appliance media server
- How to deploy and configure a NetBackup Virtual Appliance master server
- How to deploy and configure a NetBackup Virtual Appliance CloudCatalyst
- How to deploy and configure a NetBackup Virtual Appliance combined master and media server
- Post initial configuration procedures
- Appliance common tasks
- Storage management
- About NetBackup Virtual Appliance storage configuration
- About viewing storage space information using the Show command
- Resizing a partition
- Troubleshooting resize-related issues
- Moving a partition
- Monitoring the progress of storage manipulation tasks
- Scanning storage devices using the NetBackup Virtual Appliance Shell Menu
- Adding storage space for the NetBackup Virtual Appliance
- Removing an existing storage disk
- About OpenStorage plugin installation
- About NetBackup Virtual Appliance storage configuration
- Deduplication pool catalog backup and recovery
- About the NetBackup Virtual Appliance deduplication pool catalog backup policy
- Automatic configuration of the NetBackup Virtual Appliance deduplication pool catalog backup policy
- Manually configuring the NetBackup Virtual Appliance deduplication pool catalog backup policy
- Manually updating the NetBackup Virtual Appliance deduplication pool catalog backup policy
- Recovering the NetBackup Virtual Appliance deduplication pool catalog
- Network connection management
- About IPv4-IPv6-based network support
- Network settings for the NetBackup Virtual Appliance
- Configuring DNS and host name mapping for the NetBackup Virtual Appliance
- Setting the date and time on a NetBackup Virtual Appliance
- Configuring static routes on the NetBackup Virtual Appliance
- Expanding the bandwidth on the NetBackup Virtual Appliance
- Managing users
- About managing NetBackup Virtual Appliance users
- About NetBackup Virtual Appliance account types
- Adding NetBackup Virtual Appliance users
- Deleting NetBackup Virtual Appliance users
- Adding NetBackup Virtual Appliance user groups
- Deleting NetBackup Virtual Appliance user groups
- Granting roles to NetBackup Virtual Appliance users and user groups
- Revoking roles from NetBackup Virtual Appliance users and user groups
- About user name and password specifications
- Changing NetBackup Virtual Appliance user passwords
- About password management and recovery
- About authenticating LDAP users
- Adding or modifying an LDAP server configuration on the NetBackup Virtual Appliance
- Importing an LDAP server configuration for the NetBackup Virtual Appliance
- Setting the SSL certification for LDAP on the NetBackup Virtual Appliance
- Exporting an LDAP server configuration from the NetBackup Virtual Appliance
- Unconfiguring LDAP user authentication on the NetBackup Virtual Appliance
- Disabling LDAP user authentication on the NetBackup Virtual Appliance
- Enabling LDAP user authentication on the NetBackup Virtual Appliance
- Adding an LDAP attribute mapping on the NetBackup Virtual Appliance
- Deleting an LDAP attribute mapping on the NetBackup Virtual Appliance
- About authenticating Active Directory users
- About authentication using smart cards and digital certificates
- About authenticating Kerberos-NIS users
- Generic user authentication guidelines
- About user authorization on the NetBackup Virtual Appliance
- Creating NetBackup administrator user accounts
- Deleting NetBackup administrator user accounts
- Using the appliance
- About configuring Host parameters for your appliance on the NetBackup Virtual Appliance
- About Copilot functionality and Share management
- About NetBackup Virtual Appliance as a VMware backup host
- About running NetBackup commands from the appliance
- Running NetBackup commands from the NetBackup Virtual Appliance
- Creating a NetBackup touch file from the NetBackup Virtual Appliance
- Best practices for running NetBackup commands from the NetBackup Virtual Appliance
- About NetBackup operating system commands
- Known limitations of running NetBackup commands from the NetBackup Virtual Appliance
- About mounting a remote NFS
- About Auto Image Replication from a NetBackup Virtual Appliance
- Generating certificates
- Monitoring the appliance
- About NetBackup Virtual Appliance alerts
- Setting up email notifications for a NetBackup Virtual Appliance
- Setting up SNMP notifications for a NetBackup Virtual Appliance
- Enabling and disabling Call Home from the appliance shell menu
- Configuring a Call Home proxy server from the NetBackup Virtual Appliance Shell Menu
- About SNMP
- About Call Home
- About AutoSupport
- About storage email alerts
- Appliance security
- About Symantec Data Center Security on the NetBackup Virtual Appliance
- About data security
- About data integrity
- About data classification
- About data encryption
- About SSL usage
- About the NetBackup Virtual Appliance intrusion detection system
- About the NetBackup Virtual Appliance intrusion prevention system
- Major components of the NetBackup Virtual Appliance OS
- OS STIG hardening for NetBackup Virtual Appliance
- Unenforced STIG hardening rules
- FIPS 140-2 conformance for NetBackup Virtual Appliance
- Vulnerability scanning of the NetBackup Virtual Appliance
- About the appliance login banner
- Setting the appliance login banner
- Log Forwarding feature overview
- Upgrading the appliance
- About upgrading to NetBackup Virtual Appliance software version 3.2
- Requirements and best practices for upgrading NetBackup appliances
- Pre-upgrade tasks for appliance upgrades
- Methods for downloading appliance software release updates
- Installing a NetBackup Virtual Appliance software update using the NetBackup Virtual Appliance Shell Menu
- Troubleshooting upgrade issues
- NetBackup client upgrades with VxUpdate
- Appliance restore
- Decommissioning and Reconfiguring
- Troubleshooting
- About troubleshooting the NetBackup Virtual Appliance
- About contacting Technical Support
- Determining the NetBackup Virtual Appliance serial number
- About disaster recovery
- About NetBackup support utilities
- Troubleshooting NetBackup Virtual Appliance initial deployment issues
- Error messages displayed on the NetBackup Virtual Appliance Shell Menu
- NetBackup status codes applicable for NetBackup Virtual Appliance
- Installing an EEB
- Rolling back an EEB using the NetBackup Virtual Appliance Shell Menu
- Appliance logging
- Commands overview
- Appendix A. Appliance commands
- Appendix B. Manage commands
- Manage > Software > Delete
- Manage > Software > Download
- Manage > Software > List
- Manage > Software > Install
- Manage > Software > Share
- Manage > Software > Readme
- Manage > Software > Rollback
- Manage > Software > Cancel
- Manage > Software > DownloadProgress
- Manage > Software > UpgradeStatus
- Manage > Software > VxUpdate
- Manage > Storage > Show
- Manage > Storage > Add
- Manage > Storage > Create
- Manage > Storage > Delete
- Manage > Storage > Edit
- Manage > Storage > Monitor
- Manage > Storage > Move
- Manage > Storage > Remove
- Manage > Storage > Resize
- Manage > Storage > Scan
- Manage > OpenStorage > Install
- Manage > OpenStorage > List
- Manage > OpenStorage > Readme
- Manage > OpenStorage > Share
- Manage > OpenStorage > Uninstall
- Manage > MountPoints > List
- Manage > MountPoints > Mount
- Manage > MountPoints > Unmount
- Manage > License > Add
- Manage > License > List
- Manage > License > ListInfo
- Manage > License > Remove
- Manage > Certificates > Generate
- Manage > Certificates > Delete
- Manage > NetBackupCLI > Create
- Manage > NetBackupCLI > Delete
- Manage > NetBackupCLI > List
- Manage > NetBackupCLI > PasswordExpiry
- Appendix C. Monitor commands
- Appendix D. Network commands
- Network > Configure
- Network > Date
- Network > DNS
- Network > Gateway
- Network > Hostname
- Network > Hosts
- Network > IPv4
- Network > IPv6
- Network > LinkAggregation
- Network > NetStat
- Network > NTPServer
- Network > Ping
- Network > SetProperty
- Network > Show
- Network > TimeZone
- Network > TraceRoute
- Network > Unconfigure
- Network > WANOptimization
- Appendix E. Reports commands
- Appendix F. Settings commands
- Settings > Deduplication
- Settings > LifeCycle
- Settings > LogForwarding
- Settings > NetBackup
- Settings > Password
- Settings > SystemLocale
- Settings > Share
- Settings > Sysctl
- Settings > NetBackup DNAT
- Settings > Notifications > LoginBanner
- Settings > Security > Authentication > LDAP
- Settings > Security > Authentication > ActiveDirectory
- Settings > Security > Authentication > Kerberos
- Settings > Security > Authentication > LocalUser
- Settings > Security > Authorization
- Main > Settings > Security > Certificate
- Main > Settings > Security > STIG
- Main > Settings > Security > FIPS
- Settings > Alerts > CallHome
- Settings > Alerts > SNMP
- Settings > Alerts > Email
- Settings > Alerts > Hardware
- Appendix G. Support commands
- Support > Checkpoint
- Support > DataCollect
- Support > Disk
- Support > Errors
- Support > FactoryReset
- Support > InfraServices
- Support > iostat
- Support > Logs
- Support > Maintenance
- Support > Messages
- Support > NBDNA
- Support > nbperfchk
- Support > NBSU
- Support > Processes
- Support > Reboot
- Support > Service
- Support > Shutdown
- Support > Storage SanityCheck
- Support > Storage Reset
- Support > Test
Performing the initial configuration on a NetBackup Virtual Appliance media server
This section describes how to perform the initial configuration on a NetBackup Virtual Appliance with the media server role.
NetBackup Virtual Appliance release 3.2 introduces support for external certificate authority certificates. This feature provides an alternative to using the NetBackup Certificate Authority for host verification and security. This procedure includes the necessary information to deploy these certificates. For more information about security certificates, see the chapter "External CA support in NetBackup" in the NetBackup Security and Encryption Guide.
You must complete the following tasks on the master server before you start the initial configuration. The following link provides specific instructions about how to accomplish the necessary tasks:
See Configuring a master server to communicate with an appliance media server.
Make sure that the master server and this media server have compatible software versions.
Add the host name of this media server to the
SERVERSlist on the master server that you plan to use with it.If a firewall exists between the master server and this media server, open the appropriate ports on the master server.
Make sure that the date and time of this media server matches the date and time on the master server.
To perform the initial configuration of a NetBackup Virtual Appliance
- After you have deployed a new virtual appliance, log on to the NetBackup Virtual Appliance Shell Menu.
The logon is admin, and the default password is P@ssw0rd.
- Use the following commands to change the admin and the maintenance account passwords from the known default password (P@ssw0rd):
Main > Settings > Password admin
Main > Settings > Password maintenance
- (Optional) Configure the appliance date and time.
NTP is an optional during the initial configuration wizard. If you do not use an NTP server in your environment, make sure to configure the appliance date and time before the initial configuration.
Caution:
If the date and time of this media server matches the date and time of the master server, the initial configuration wizard fails.
Navigate to the Main > Network view.
Set the time zone by entering the following command:
TimeZone Set
Select the appropriate time zone from the displayed list.
Set the date and the time by entering the following command:
Date Set Month Day HHMMSS Year
Where Month is the name of the month.
Where Day is the day of the month from 1 to 31.
Where HHMMSS is the hour, minute, and seconds in a 24-hour format. The fields are separated by semi-colons, for example, HH:MM:SS.
Where Year is the calendar year from 1970 through 2037.
- Use the following command to start the initial configuration:
Main > Appliance > Configure
A message about the Virtual Appliance Initial Configuration Wizard appears. This wizard will walk you through a two-step process to configure this appliance.
The following prompt appears:
>> Do you want to continue? [yes, no] (no)yes
Type yes.
The network configuration prompts appear in the following order:
Hostname
Enter a short host name or a fully qualified domain name (FQDN) for this appliance. As a best practice, Veritas recommends that you use FQDN.
Caution:
After the initial deployment has completed successfully, the only way to change the host name is to perform a factory reset.
Note:
If you plan to configure Active Directory (AD) authentication on this appliance, the host name must be 15 characters or less. Otherwise, AD configuration can fail.
DNS domain name
Enter a DNS domain name for this appliance.
IPv4 address
Enter the IPv4 address to be used for this appliance.
Netmask
Enter the netmask that corresponds to the IP address.
Gateway IP address
Enter the IPv4 address of the gateway (network point) that acts as an entrance to another network.
DNS server 1 IP address
Enter the IPv4 address of the primary DNS server for this appliance.
DNS server 2 IP address(Optional)
Enter the IPv4 address of the secondary DNS server for this appliance.
- (Optional) The following prompt appears:
The host name must be resolvable with a DNS or a HOSTS file for the initial configuration to be successful. Do you want to write the host name resolution information to the HOSTS file? [yes, no](no)
Note:
If the host name is not resolvable with a DNS or a HOSTS file during the initial configuration, the initial configuration wizard will fail.
Type yes to use the HOSTS file to resolve the appliance host name. This ensures that the host name is resolvable when DNS is not available.
Type no to use the DNS you entered.
- After the network configuration is completed, the wizard takes you to the second step for storage configuration.
In the second step, specify the following:
NTP server (Optional)
Enter the Network Time Protocol (NTP) server for this appliance.
Master server
Enter the NetBackup master server name or IP address for this appliance. The master server can be a traditional (non-appliance) NetBackup master server or a NetBackup physical appliance.
Note:
If the host name of the master server is an FQDN, Veritas recommends that you use the FQDN to specify the master server for the media server.
After you have entered the master server name, the appliance pings the master server for the Certificate Authority (CA) status and shows the result. Each of the following bullet statements describes the possible status results. Follow the instructions that appear below the applicable status result to complete the certificate configuration.
The master server <master_server_name> has an enabled External CA-signed certificate. Do you want to import the External CA-signed certificate for this Media server now [yes,no](yes):
Press Enter to continue. The following message appears:
The following shares have been opened on the appliance for you to upload certificate files:
NFS share <media_server_name>:/inst/shareCIFS share \\<media_server_name>\general_shareEnter the following details for external certificate configuration:
Enter the certificate file path:
Enter the trust store file path:
Enter the private key path:
Enter the password for the passphrase file path or skip security configuration (default: NONE):
Enter the following details for CRL usage:
Should a CRL be honored for the external certificate?
1) Use the CRL defined in the certificate.
2) Use the specific CRL directory.
3) Do not use a CRL.
q) Skip security configuration.
CRL option: Enter 1, 2, 3, or q.
Verify the External CA details that you entered:
Certificate file name:
Trust store file name:
Private key file name:
CRL check level: (Shows the selected CRL option.)
Do you want to use the above certificate files? [yes, no](yes):
After verifying that the entered information is correct, press Enter to continue and answer the following prompt:
Is this correct? [yes, no](yes):
If all of the information is correct, press Enter to continue.
The appliance performs an ECA health check and shows the result of each validation check. When the health check has completed successfully, the following messages appear:
ECA health check was successful.
The external certificate has been registered successfully.
The master server <master_server_name> currently uses an external CA issued certificate and its own internal certificate. Would you like to proceed with the external CA issued certificate? [yes,no](yes):
If you select no, the following message appears:
This appliance will use a NetBackup issued certificate for secure communication.
If you select yes, enter the following details for external certificate configuration:
Enter the certificate file path:
Enter the trust store file path:
Enter the private key path:
Enter the password for the passphrase file path or skip security configuration (default: NONE):
Enter the following details for CRL usage:
Should a CRL be honored for the external certificate?
1) Use the CRL defined in the certificate.
2) Use the specific CRL directory.
3) Do not use a CRL.
q) Skip security configuration.
CRL option: Enter 1, 2, 3, or q.
Verify the External CA details that you entered:
Certificate file name:
Trust store file name:
Private key file name:
CRL check level: (Shows the selected CRL option.)
Do you want to use the above certificate files? [yes, no](yes):
After verifying that the entered information is correct, press Enter to continue and answer the following prompt:
Is this correct? [yes, no](yes):
If all of the information is correct, press Enter to continue.
The appliance performs an ECA health check and shows the result of each validation check. When the health check has completed successfully, the following messages appear:
ECA health check was successful.
The external certificate has been registered successfully.
This appliance will use a NetBackup issued certificate for secure communication.
No further certificate configuration is required. Click Next to continue
For more information about security certificates, refer to the NetBackup Security and Encryption Guide.
Complete the remaining prompts for the storage configuration as follows:
AdvancedDisk disk pool name
Enter a name for the AdvancedDisk disk pool on the appliance.
AdvancedDisk storage unit name
Enter a name for the AdvancedDisk storage unit on the appliance.
AdvancedDisk storage size
Enter a size for the AdvancedDisk storage.
MSDP storage unit name
Enter a name for the MSDP storage unit on the appliance.
MSDP disk pool name
Enter a name for the MSDP disk pool on the appliance.
MSDP storage size
Enter a size for the MSDP storage.
MSDP Catalog size
Enter a size for the MDSP Catalog storage.
- Use the following command to verify that the automatic configuration completed successfully:
Main > Appliance > Status
The command output should contain a message similar to the following:
Appliance Version is 3.2. Appliance is configured as media appliance.
If the output does not show that the appliance is configured as a media appliance, you need to redeploy the appliance or perform other troubleshooting steps to fix the issue before you proceed to the next step. See Troubleshooting NetBackup Virtual Appliance initial deployment issues.
- Use the following command to set the time zone:
Main > Network > TimeZone Set
Select the appropriate time zone from the displayed list.
- Add a permanent license key before the evaluation key expires with the following command:
Main > Manage > License > Add
You can locate your permanent license key from the Veritas Entitlement Management System (VEMS). To access VEMS, click Licensing on the Veritas Support website.
Warning:
If the correct license key is not installed, the appliance services stop functioning after the evaluation key expires. Make sure that the NetBackup license you add includes support for NetBackup Virtual Appliance.
See Managing license keys on the NetBackup Virtual Appliance.
- (Optional)
If you want to configure an IPv6 address for the appliance, run the following command:
Main > Network > IPv6 <IPAddress> <Prefix> InterfaceName
Where <IPAddress> is the IPv6 address and <Prefix> is the prefix length.
- (Optional)
If you want to an IPv6 DNS server on the appliance, run the following command:
Main > Network > DNS Add NameServer <IPAddress>
Where <IPAddress> is the IPv6 address of the additional DNS server. Only global-scope and unique-local IPv6 addresses are allowed.
See Configuring DNS and host name mapping for the NetBackup Virtual Appliance.
After the appliance is configured and operational, you are ready to install NetBackup client software on the computers that you want to back up.
See the NetBackup Installation Guide for how to install NetBackup clients.