Post 3.2 upgrades checklist
After the upgrade process has completed successfully, perform the following tasks as needed for your environment:
- Re-import IPsec certificates
If you exported IPsec certificates before the upgrade, you must re-import them after the upgrade. After completing the upgrade, place the backed-up certificate files from the non-appliance location to an appliance share such as /inst/patch/incoming. Import the files from the share as follows:- Log in to the NetBackup Appliance Shell Menu and navigate to the following view:
Network > Security > Import
- Enter the following import option details:
Import [EnterPasswd] [PathValue]
Where [EnterPasswd] is the field used to answer the question, "Do you want to enter a password?". You must enter yes or no.
Where [PathValue] is the location where you want to place the imported certificates.
- Log in to the NetBackup Appliance Shell Menu and navigate to the following view:
- Install the following Patches
NetBackup Appliance 3.2 Maintenance Release 1
https://www.veritas.com/content/support/en_US/downloads/update.UPD638953
NetBackup Appliance VxFS inconsistencies fix (install this AFTER installing Maintenance Release 1)
https://www.veritas.com/content/support/en_US/downloads/update.UPD286766
NetBackup 8.2 MSDP EEB Bundle
https://www.veritas.com/content/support/en_US/downloads/update.UPD171508
NetBackup 8.2 CloudCatalyst EEB Bundle (If using CloudCatalyst)
https://www.veritas.com/content/support/en_US/downloads/update.UPD772994
Make sure to check Veritas Download Center for additional NetBackup (not appliance-specific) fixes periodically.
SDCS mode
After any upgrades from 2.7.3 and later, the Symantec Data Center Security (SDCS) feature is set to the unmanaged mode. If the feature was set to the managed mode before these upgrades, make sure to change it to the managed mode and apply the latest IDS and IPS policies after the upgrade has completed.
For complete details, refer to one of the following documents:
NetBackup Appliance Administrator's Guide
NetBackup Appliance Security Guide.
- SDCS console and server
Starting with software version 3.1, the SDCS console and the server are no longer included in NetBackup appliance software releases.
For appliances that do not currently have an SDCS environment configured, you must obtain the console and the server binaries from the Veritas Support website before you can set it up.
For appliances with an existing SDCS environment and console set up, you are only required to update the policy files and make sure that the SDCS agent points to the correct SDCS server. You do not need to obtain the binaries.
For complete details, refer to one of the following documents:
NetBackup 52xx and 53xx Appliance Administrator's Guide
NetBackup 52xx and 53xx Appliance Security Guide.
- STIG feature
If this feature was enabled before the upgrade, it must be re-enabled after the upgrade has been completed. For appliances (nodes) in an HA setup, you must re-enable the feature on each node after the upgrades have been completed.
- Restart backups
For appliance master server upgrades, restart all jobs and Storage Lifecycle Policies (SLPs) that were stopped or paused before the upgrade.
For appliance media server upgrades, after all appliance media servers have been upgraded, restart all jobs that were stopped before the upgrade.
- Running latest version of your SSH Client
Make sure you are running the latest version of your SSH client. Upgrading to version 3.2 changes the key-exchange algorithms used for connecting to the appliance. Make sure that your SSH client supports the following key-exchange algorithms:
diffie-hellman-group-exchange-sha256
diffie-hellman-group18-sha512
diffie-hellman-group16-sha512
diffie-hellman-group14-sha256
ecdh-sha2-nistp256
ecdh-sha2-nistp384
ecdh-sha2-nistp521
If your SSH client does not support any of the above algorithms after the upgrade has completed, the following error appears: