Veritas Access Appliance 8.3 Administrator's Guide
- Section I. Introducing Access Appliance
- Section II. Configuring Access Appliance
- Managing users
- Managing licenses
- Configuring the network
- About configuring the Access Appliance network
- About bonding Ethernet interfaces
- Bonding Ethernet interfaces
- Considerations for configuration a LACP bond
- Configuring DNS settings
- About Ethernet interfaces
- Displaying current Ethernet interfaces and states
- Configuring IP addresses
- Configuring IP addresses and FQDNs in a non-DNS environment
- Configuring VLAN interfaces
- Configuring NIC devices
- About configuring routing tables
- Configuring routing tables
- Changing the firewall settings
- Configuring Access Appliance in IPv4 and IPv6 mixed mode
- Support for multiple data subnets
- Adding console FQDN to the network and accessing the GUI using the console FQDN
- Configuring authentication services
- About configuring LDAP settings
- Configuring LDAP server settings
- Administering the Access Appliance cluster's LDAP client
- About Active Directory (AD)
- Configuring AD server settings
- Configuring entries for Access Appliance DNS for authenticating to Active Directory (AD)
- Configuring AD/LDAP using the GUI
- Configuring NSS lookup order
- Sign-in options for the Access Appliance UI
- Configuring user authentication using digital certificates or smart cards
- Section III. Managing Access Appliance storage
- Configuring storage
- About storage provisioning and management
- About configuring disks
- About configuring storage pools
- Configuring storage pools
- About quotas for usage
- Enabling, disabling, and displaying the status of file system quotas
- Setting and displaying file system quotas
- Setting user quotas for users of specified groups
- About quotas for CIFS home directories
- Workflow for configuring and managing storage using the Access Appliance CLI
- Displaying information for all disk devices associated with the nodes in a cluster
- Displaying WWN information
- Importing new LUNs forcefully for new or existing pools
- Initiating host discovery of LUNs
- Managing disks
- Access Appliance as an iSCSI target
- Configuring storage
- Section IV. Managing Access Appliance file access services
- Configuring the NFS server
- About using the NFS server with Access Appliance
- Using the kernel-based NFS server
- Accessing the NFS server
- Displaying and resetting NFS statistics
- Configuring Access Appliance for ID mapping for NFS version 4
- Configuring the NFS client for ID mapping for NFS version 4
- About authenticating NFS clients
- Setting up Kerberos authentication for NFS clients
- Using Access Appliance as a CIFS server
- About configuring Access Appliance for CIFS
- About configuring CIFS for Active Directory (AD) domain mode
- Adding an SPN entry on the Windows client
- About setting trusted domains
- About storing account information
- Storing user and group accounts
- Reconfiguring the CIFS service
- About mapping user names for CIFS/NFS sharing
- About the mapuser commands
- Adding, removing, or displaying the mapping between CIFS and NFS users
- Automatically mapping UNIX users from LDAP to Windows users
- About managing home directories
- About CIFS clustering modes
- About migrating CIFS shares and home directories
- Setting the CIFS aio_fork option
- Enabling CIFS data migration
- Using Access Appliance as an Object Store server
- About the Object Store server
- Use cases for configuring the Object Store server
- Configuring the Object Store server
- About buckets and objects
- File systems used for objectstore buckets
- Enabling WORM on buckets
- Object Access SSL certificate
- Object Access endpoints
- S3 with NFS use case
- S3 with NSP use case
- Configuring the S3 server using GUI
- Configuring the NFS server
- Section V. Managing Access Appliance security
- Managing security
- Setting up FIPS mode
- Configuring STIG
- Setting the banner
- Setting the password policy
- Immutability in Access Appliance
- Deploying certificates on Access Appliance
- Single Sign-On (SSO)
- Configuring multifactor authentication
- About multifactor authentication
- Considerations when configuring multifactor authentication
- Configuring multifactor authentication for your user account
- Disabling multifactor authentication for your user account
- Enforcing multifactor authentication for all users
- Configuring multifactor authentication for your user account when it is enforced in the cluster
- Resetting multifactor authentication for a user
- Section VI. Monitoring and troubleshooting
- Monitoring the appliance
- Configuring event notifications and audit logs
- About troubleshooting
- Monitoring command activity
- Monitoring alerts
- About alert management
- Monitoring events
- Viewing reports
- Viewing cluster storage usage
- Viewing file system usage
- About event notifications
- About severity levels and filters
- About SNMP notifications
- Configuring a syslog server
- Displaying events on the console
- Appliance log files
- Section VII. Provisioning and managing Access Appliance file systems
- Creating and maintaining file systems
- About creating and maintaining file systems
- About encryption at rest
- Considerations for creating a file system
- Best practices for creating file systems
- Choosing a file system layout type
- Determining the initial extent size for a file system
- About striping file systems
- About FastResync
- About fsck operation
- Enabling WORM on a file system
- Setting retention in files
- Setting WORM over NFS
- Manually setting WORM-retention on a file over CIFS
- About managing application I/O workloads using maximum IOPS settings
- Creating a file system
- Bringing the file system online or offline
- Listing all file systems and associated information
- Modifying a file system
- Managing a file system
- Destroying a file system
- Upgrading disk layout versions
- Creating and maintaining file systems
- Section VIII. Provisioning and managing Access Appliance shares
- Creating shares for applications
- Creating and maintaining NFS shares
- About NFS file sharing
- About the NFS shares
- Displaying file systems and snapshots that can be exported
- Exporting an NFS share
- Displaying exported directories
- About managing NFS shares using netgroups
- Unexporting a directory or deleting NFS options
- Exporting an NFS share for Kerberos authentication
- Mounting an NFS share with Kerberos security from the NFS client
- Exporting an NFS snapshot
- Creating and maintaining CIFS shares
- About managing CIFS shares
- About the CIFS shares
- Exporting a directory as a CIFS share
- Configuring a CIFS share as secondary storage for an Enterprise Vault store
- Exporting the same file system/directory as a different CIFS share
- About the CIFS export options
- Setting share properties
- Displaying CIFS share properties
- Hiding system files when adding a CIFS normal share
- Allowing specified users and groups access to the CIFS share
- Denying specified users and groups access to the CIFS share
- Exporting a CIFS snapshot
- Deleting a CIFS share
- Modifying a CIFS share
- Making a CIFS share shadow copy aware
- About managing CIFS shares for Enterprise Vault
- Integrating Access Appliance with Data Insight
- Section IX. Managing Access Appliance storage services
- Configuring continuous replication
- About Access Appliance continuous replication
- How Access Appliance continuous replication works
- Starting Access Appliance continuous replication
- Setting up communication between the source and the destination clusters
- Setting up the file system to replicate
- Managing continuous replication
- Displaying continuous replication information and status
- Unconfiguring continuous replication
- Preserving the file system on the destination cluster
- Cloud tiering with continuous replication
- Configuring Enterprise Vault with continuous replication
- Configuring a continuous replication job using the GUI
- Continuous replication failover and failback
- Addition of multiple file systems to a Replicated Volume Group
- Using snapshots
- Using instant rollbacks
- About instant rollbacks
- Creating a space-optimized rollback
- Creating a full-sized rollback
- Listing Access Appliance instant rollbacks
- Restoring a file system from an instant rollback
- Refreshing an instant rollback from a file system
- Bringing an instant rollback online
- Taking an instant rollback offline
- Destroying an instant rollback
- Creating a shared cache object for Access Appliance instant rollbacks
- Listing cache objects
- Destroying a cache object of a Access Appliance instant rollback
- Configuring continuous replication
- Section X. Reference
- Index
About Access Appliance
You can use Access Appliance in any of the following ways.
Table: Interfaces for using Access Appliance
Interface | Description |
|---|---|
GUI | Getting Started wizard with operations for managing the Access Appliance. Centralized dashboard and Quick Actions with operations for managing your storage. See the GUI and the Online Help for more information. |
RESTful APIs | Enables automation using scripts, which run storage administration commands against the Access Appliance cluster. See the Access Appliance RESTful API Guide for more information. |
Command-line interface (CLI) | Single point of administration for the entire cluster. See the manual pages for more information. |
Table: Access Appliance key features
Feature | Description |
|---|---|
Supported protocols | Access Appliance includes support for the following protocols:
|
Creation of Partition Secure Notification (PSN) file for Enterprise Vault Archiving | A Partition Secure Notification (PSN) file is created at a source partition after the successful backup of the partition at the remote site. For more information, see the Access Appliance Solutions Guide for Enterprise Vault. |
Managing application I/O workloads using maximum IOPS settings | The MAXIOPS limit determines the maximum number of I/Os processed per second collectively by the storage underlying the file system. See About managing application I/O workloads using maximum IOPS settings. |
Snapshot | Access Appliance supports snapshots for recovering from data corruption. If files, or an entire file system, are deleted or become corrupted, you can replace them from the latest uncorrupted snapshot. See About snapshots. |
Access Appliance as an iSCSI target for RHEL 7.x | Access Appliance as an iSCSI target can be configured to serve block storage. An iSCSI target as service is hosted in an active/active mode in the Access Appliance cluster. |
Configuring Access Appliance in IPv4 and IPv6 mixed mode | Support for configuring the Access Appliance cluster in an IPv4 environment, or an IPV6 environment, or in a mixed mode environment where you have both IPv4 and IPv6 addresses. See Configuring Access Appliance in IPv4 and IPv6 mixed mode. |
NetBackup integration | Built-in NetBackup client for backing up your file systems to a NetBackup primary or media server. Once data is backed up, a storage administrator can delete unwanted data from Access Appliance to free up expensive storage for more data. See the Access Appliance Solutions Guide for NetBackup for more information. |
Quotas | Support for setting file system quotas, user quotas, and hard quotas. |
Replication | Synchronous replication of data over IP networks See About Access Appliance continuous replication. See the continuous(1) man page for more information. |
Support for LDAP and AD | You can configure LDAP and AD authentication services with Access Appliance. |
Partition Directory | With support for partitioned directories, directory entries are redistributed into various hash directories. These hash directories are not visible in the namespace view of the user or operating system. For every new create, delete, or lookup, this feature performs a lookup for the respective hashed directory and performs the operation in that directory. This leaves the parent directory inode and its other hash directories unobstructed for access, which vastly improves file system performance. By default this feature is not enabled. See the storage_fs(1) manual page to enable this feature. |
Veritas Data Deduplication | Veritas Data Deduplication technology is installed on top of Access Appliance and integrates with NetBackup. It catalogs and organizes incoming deduplicated backup data and stores it on Access Appliance storage. For more information, see the Access Appliance Solutions Guide for NetBackup. |
FIPS | FIPS 140-2 standard is enabled by default for the Veritas Operating System (VxOS). |
STIG | You can enable OS STIG hardening rules for increased security. These rules are based on the following profile from the Defense Information Systems Agency (DISA). See Enabling OS STIG hardening for Access Appliance. For more information, see the Appliance security chapter in the Veritas Access Appliance Initial Configuration Guide. |
Support for Cloud tiering | The cloud as a tier feature for a file system lets you move data to different cloud services. The data is always written to the on-premises storage tier and then data can be moved to the cloud tier using a tiering mechanism. For more information, see the Access Appliance Cloud Storage Tiering Guide. |
Separation of management and data network | Ability to configure a separate management and data network during cluster configuration. For more information, see the Veritas Access Appliance Initial Configuration Guide. |
Support for multiple data subnets | Access Appliance supports multiple data subnets. This is applicable to all the protocols that the Access Appliance supports. |
Support for immutability in Access Appliance | Access Appliance supports lockdown modes that protects your cluster data from internal and external threats by securing all the external endpoints from unauthorized access. See About lockdown modes. |
Single node configuration | Support for 3360 single node configuration, which provides the same functionality as a two-node configuration. For more information, see the Veritas Access Appliance Initial Configuration Guide. |