Veritas NetBackup™ Appliance Security Guide
- About the NetBackup appliance Security Guide
- User authentication
- About user authentication on the NetBackup appliance
- About configuring user authentication
- About authentication using smart cards and digital certificates
- About single sign-on (SSO) authentication and authorization
- About user name and password specifications
- User authorization
- Intrusion prevention and intrusion detection systems
- Log files
- Operating system security
- Data security
- Web security
- Network security
- Call Home security
- Remote Management Module (RMM) security
- STIG and FIPS conformance
About IPsec Channel Configuration
The NetBackup appliance uses IPsec channels to secure communication between two appliances, thus helping to secure data in transit. All other communication between NetBackup appliance and non-appliance, like the NetBackup primary servers, would be non-IPsec.
IPsec security works at IP level and allows securing IP traffic between two appliances. Device certificates are provisioned to the Primary and media appliances, these certificates are then enabled for configuring IPsec channels. This enables a secure interaction of the primary and media servers. The device certificates used are x509 certificates issued by DigiCert CA.
The appliance performs the following validation checks before establishing IPsec channel:
Validate the authenticity of the certificates using the x509 cert validate.
Validate whether the device certificate corresponds to the IP.
Validate and update security associations in both directions of the communication.
The appliances are detected after the device certificates are recognized. Only after this is the IPsec channel configured and enabled.
Contact Veritas Support to configure IPsec functionality on your appliance.