Veritas NetBackup™ Virtual Appliance Documentation
- Getting started
- Deployment and initial configuration
- Post initial configuration procedures
- Configuring
- About configuring Host parameters for your appliance on the NetBackup Virtual Appliance
- Alerting
- About SNMP
- About Call Home
- Using
- About storage configuration
- About viewing storage space information using the Show command
- About NetBackup Virtual Appliance as a VMware backup host
- About running NetBackup commands from the appliance
- About mounting a remote NFS
- About Auto Image Replication from a NetBackup Virtual Appliance
- About storage configuration
- Logging
- Troubleshooting
- About NetBackup support utilities
- Security
- About Symantec Data Center Security on the NetBackup Virtual Appliance
- Setting the appliance login banner
- Managing users
- About authenticating LDAP users
- About authenticating Active Directory users
- About authenticating Kerberos-NIS users
- About user authorization on the NetBackup Virtual Appliance
- Creating NetBackup administrator user accounts
- Section I. Commands
- Commands overview
- Appendix A. Appliance commands
- Appendix B. Network commands
- Appendix C. Support commands
- Appendix D. Monitor commands
- Appendix E. Settings commands
- Appendix F. Reports commands
- Appendix G. Manage commands
About the NetBackup Virtual Appliance intrusion prevention system
The appliance intrusion prevention system (IPS) consists of a custom Symantec Data Center Security (SDCS) policy that runs automatically at startup. The IPS policy is an in-line policy that can proactively block unwanted resource access behaviors before they can be acted upon by the operating system.
The following list contains some of the IPS policy features:
Real-time tight confinement of the appliance operating system processes and common applications, such as the following:
nscd - which caches DNS requests to cut down on remote DNS lookups.
cron
syslog-ng
klogd
rpcd for NFS
rpc.idmapd
rpc.mountd
rpc.statd
rpcbind
Self-Protection for the SDCS agent itself to ensure that the security features and monitoring features of SDCS are not compromised.
Lock-down of access to system binaries, except by identified and trusted applications, users, and user groups.
Confinements that protect the system from the applications that try to install software, such as sbin) or change system configuration settings, such as
hosts
file.Prohibits applications from executing critical system calls such as mknod, modctl, link, mount, and so on.
Prohibits unauthorized users or applications from accessing backup data, such as
/advanceddisk
,/cat
,/disk
,/opt/NBUAppliance/db/config/data
, and so on.Restricted access to the root account by maintenance user.
More Information
Overriding the NetBackup Virtual Appliance intrusion prevention system policy
Re-enabling the NetBackup Virtual Appliance intrusion prevention system policy
About the NetBackup Virtual Appliance intrusion detection system
Vulnerability scanning of the NetBackup Virtual Appliance
About Symantec Data Center Security on the NetBackup Virtual Appliance