Veritas NetBackup™ Flex Scale Administrator's Guide
- Product overview
- Viewing information about the NetBackup Flex Scale cluster environment
- NetBackup Flex Scale infrastructure management
- User management
- About Universal Shares
- Node and disk management
- Adding a node to the cluster using the NetBackup Flex Scale web interface
- License management
- Managing the Fibre Channel ports
- Requirements
- Managing hardware vendor packages
- User management
- NetBackup Flex Scale network management
- Bonding operations
- Data network configurations
- Network configuration on plain device (eth5)
- Network configuration on bonded interfaces (bond0 on eth5 and eth7)
- NetBackup Flex Scale infrastructure monitoring
- Resiliency in NetBackup Flex Scale
- EMS server configuration
- Site-based disaster recovery in NetBackup Flex Scale
- Performing disaster recovery using RESTful APIs
- NetBackup Flex Scale security
- STIG overview for NetBackup Flex Scale
- FIPS overview for NetBackup Flex Scale
- Support for immutability in NetBackup Flex Scale
- Deploying external certificates on NetBackup Flex Scale
- Configuring multifactor authentication
- Single Sign-On (SSO)
- Appendix A. Maintenance procedures for HPE servers
- Appendix B. Configuring NetBackup optimized duplication
- Appendix C. Disaster recovery terminologies
- Appendix D. Configuring Auto Image Replication
Considerations for managing NetBackup Flex Scale users
Consider the following while managing users in your NetBackup Flex Scale cluster:
You can add up to 10 user accounts to the NetBackup Flex Scale cluster during cluster configuration. You must add at least one user for each user role during the cluster configuration. You can add additional users at any time after the cluster is configured.
You can also add users without assigning a role. You can assign the required role to such user accounts later.
Note:
If you have deployed the cluster with only media servers, only the appliance administrator role option is available during cluster configuration and both appliance administrator and universal share user roles are available post cluster configuration.
Note:
When disaster recovery is configured between two NetBackup Flex Scale clusters, Veritas recommends that you add local user accounts on both clusters using the same credentials. This is to ensure that the same credentials work when the NetBckup primary is failed over between the clusters.
You can use a single user account and assign both NetBackup Flex Scale and NetBackup administrator roles to the same account. However, two separate user accounts are recommended.
You can assign the NetBackup admin role to a user account only during the cluster configuration. After the cluster is configured, you must use the NetBackup Web UI to manage NetBackup admin role assignment to user accounts.
You cannot use the NetBackup Flex Scale infrastructure UI console to manage NetBackup roles post cluster configuration.
Veritas recommends that you use the NetBackup Web UI to manage assignment of NetBackup roles. Use the NetBackup Flex Scale infrastructure UI console to manage assignment of NetBackup Flex Scale roles.
Note:
NetBackup roles assigned from the NetBackup Web UI are not visible in the NetBackup Flex Scale infrastructure UI console.
You can add local as well as AD and LDAP user accounts to the user roles.
NetBackup Flex Scale supports AD and LDAP in Secure Sockets Layer (SSL) and Non-SSL mode.
Note:
For AD/LDAP user account access to remain active in a NetBackup Flex Scale cluster on which both primary and media servers are deployed, the NetBackup primary server service must be running and healthy in the cluster.
If both primary server and media servers are deployed on the cluster, AD and LDAP users cannot access the appliance SSH, cluster-level CLI and REST APIs. If only media servers, are deployed, AD/LDAP users having appliance administrator role can access SSH, GUI, cluster-level CLI and REST APIs.
Note:
If you have deployed the cluster with only media servers, the appliance administrator role is assigned to AD/LDAP users using the NetBackup Flex Scale Infrastructure Web UI.
Local users that have the NetBackup Flex Scale appliance administrator role assigned have access to the cluster-level CLI and the infrastructure REST APIs. Users that have the NetBackup administrator role assigned have access to the NetBackup REST APIs.
While removing user accounts from the cluster, you cannot delete all the users from the users list. At least one user with the NetBackup Administrator and the NetBackup Flex Scale Appliance Administrator role should always remains in the users list.
While assigning roles from the NetBackup UI, you must use the IP or the FQDN of the server that was used during the configuration instead of the "NBU_LDAP_DOMAIN" string.
If domain name was provided during AD/LDAP configuration, then you can also use the domain names for assigning roles.
Veritas recommends that LDAP and AD user UIDs start from 10000. Otherwise, when you assign a role to the AD/LDAP user, the UIDs of some of the local user may conflict with the UID of a user from the directory server
Nested LDAP group for role assignment is not supported.
You can configure multiple AD/LDAP servers.
Consider the following while managing users in your NetBackup Flex Scale cluster after upgrade:
You must use the "LDAP_Server_FQDN/IP" string for the AD/LDAP server that was configured before upgrade.
You should use the server name to assign role to AD/LDAP server that is configured after upgrade
You can use the NetBackup REST API to get the ID value and use the ID value while assigning a role to configured AD/LDAP server users.
See User management.
See Adding users.
See Removing users.