NetBackup™ Web UI Cloud Administrator's Guide

Last Published:
Product(s): NetBackup & Alta Data Protection (10.4)
  1. Managing and protecting cloud assets
    1.  
      About protecting cloud assets
    2.  
      Limitations and considerations
    3. Configure Snapshot Manager in NetBackup
      1.  
        Add a Snapshot Manager
      2. Add a cloud provider for a Snapshot Manager
        1.  
          IAM Role for AWS Configuration
        2.  
          IAM Role for OCI Configuration
      3.  
        Associate media servers with a Snapshot Manager
      4.  
        Discover assets on Snapshot Manager
      5.  
        Enable or disable a Snapshot Manager
      6.  
        (Optional) Add the Snapshot Manager extension
    4. Managing intelligent groups for cloud assets
      1.  
        Considerations for cloud intelligent groups
      2.  
        Create an intelligent group for cloud assets
      3.  
        Delete an intelligent group for cloud assets
    5. Protecting cloud assets or intelligent groups for cloud assets
      1.  
        Customize or edit protection for cloud assets or intelligent groups
      2.  
        Remove protection from cloud assets or intelligent groups
    6.  
      Cloud asset cleanup
    7.  
      Cloud asset filtering
    8.  
      AWS and Azure government cloud support
    9. About protecting Microsoft Azure resources using resource groups
      1.  
        Before you begin
      2.  
        Limitations and considerations
      3. About resource group configurations and outcome
        1.  
          Examples of resource group configurations
      4.  
        Troubleshoot resource group permissions
    10. About the NetBackup Accelerator for cloud workloads
      1.  
        How the NetBackup Accelerator works with virtual machines
      2.  
        Accelerator forced rescan for virtual machines (schedule attribute)
      3.  
        Accelerator backups and the NetBackup catalog
      4.  
        Accelerator messages in the backup job details log
    11.  
      Configuring backup schedules for cloud workloads
    12.  
      Backup options for cloud workloads
    13.  
      Snapshot replication
    14.  
      Configure AWS snapshot replication
    15.  
      Using AWS snapshot replication
    16.  
      Support matrix for account replication
    17.  
      Protect applications in-cloud with application-consistent snapshots
    18.  
      Protecting AWS or Azure VMs for recovering to VMware
    19. Protecting PaaS assets
      1.  
        Prerequisites for protecting PaaS assets
      2. Installing the native client utilities
        1.  
          Installing the MySQL client utility
        2.  
          Installing the sqlpackage client utility
        3.  
          Installing PostgreSQL client utility
        4.  
          Installing MongoDB client utility
        5.  
          Installing the Amazon RDS for Oracle client utility
      3.  
        Configuring the storage server for instant access
      4.  
        Prerequisites for protecting Amazon RDS SQL Server database assets
      5. Configuring storage for different deployments
        1.  
          For MSDP cloud deployments
        2.  
          For Kubernetes deployments
        3.  
          For VM-based BYO deployments
      6.  
        About incremental backup for PaaS workloads
      7.  
        About archive redo log backup for PaaS workloads
      8.  
        Limitations and considerations
      9.  
        Discovering PaaS assets
      10.  
        Viewing PaaS assets
      11.  
        Managing PaaS credentials
      12.  
        View the credential name that is applied to a database
      13. Add credentials to a database
        1.  
          Creating an IAM database username
        2.  
          Configuring permissions for the database user
        3.  
          Creating a system or user-managed identity username
      14.  
        Add protection to PaaS assets
      15.  
        Perform backup now
  2. Recovering cloud assets
    1.  
      Recovering cloud assets
    2.  
      Perform rollback recovery of cloud assets
    3. Recovering AWS or Azure VMs to VMware
      1.  
        Post-recovery considerations for cloud VMs recovered to VMware
      2. Steps to recover images from cloud VMs to VMware
        1.  
          Recovering images from AWS to VMware
        2.  
          Recovering images from Azure to VMware
    4. Recovering PaaS assets
      1.  
        Recovering non-RDS PaaS assets
      2.  
        Recovering RDS-based PaaS asset
      3.  
        Recovering Azure-protected assets
      4.  
        Recovering duplicate images from AdvancedDisk
  3. Performing granular restore
    1.  
      About granular restore
    2.  
      Supported environment list
    3.  
      List of supported file systems
    4.  
      Before you begin
    5.  
      Limitations and considerations
    6.  
      Restoring files and folders from cloud virtual machines
    7.  
      Restoring volumes on cloud virtual machines
    8.  
      Performing steps after volume restore containing LVM
    9.  
      Troubleshooting
  4. Troubleshooting protection and recovery of cloud assets
    1.  
      Troubleshoot cloud workload protection issues
    2.  
      Error Code 9855: Error occurred while exporting snapshot for the asset: <asset_name>
    3.  
      Backup from snapshot jobs take longer time than expected
    4.  
      Backup from snapshot job fails due to connectivity issues when Snapshot Manager is deployed on an Ubuntu host
    5.  
      Error disambiguation in NetBackup UI
    6. Troubleshoot PaaS workload protection and recovery issues
      1.  
        Troubleshooting Amazon Redshift issues

Add a cloud provider for a Snapshot Manager

You can protect the assets on the Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure, Microsoft Azure Stack Hub, and Oracle Cloud Infrastructure (OCI) providers. Starting with 9.0, the Snapshot Manager can discover Amazon Web Services and Microsoft Azure US Government cloud workloads.

To add a cloud provider for Snapshot Manager

  1. On the left, click Workloads > Cloud.
  2. Click the Providers tab or click Add under the cloud provider for which you want to add a configuration.
  3. Enter a value in the Configuration Name field in the Add configuration pane.
  4. Select the preferred Snapshot Manager.
  5. Enter the required details.

    Cloud provider

    Parameter

    Description

    Microsoft Azure

    Credential type: Application service principal

    Tenant ID

    The ID of the AAD directory in which you created the application.

    Client ID

    The application ID.

    Secret key

    The secret key of the application.

    Credential type: System managed identity

    Enable system-managed identity on Snapshot Manager host in Azure.

    Note:

    Assign a role to the system-managed identity.

    Credential type: User managed identity

    Client ID

    The ID of the user-managed identity connected to the Snapshot Manager host.

    The following parameters are applicable for all the above credential types

    Regions

    One or more regions in which to discover cloud assets.

    Note:

    If you configure a government cloud, select US Gov Arizona, US Gov Texas US, or Gov Virginia.

    Resource Group prefix

    The string with which you want to append all the resources in a resource group.

    Protect assets even if prefixed Resource Groups are not found

    The check box determines whether the assets are protected if they are not associated with any resource groups.

    Microsoft Azure Stack Hub

    Using AAD:

    Azure Stack Hub Resource Manager endpoint URL

    The endpoint URL in the following format allows Snapshot Manager to connect with your Azure resources.

    https://management.<location>.<FQDN>

    Tenant ID

    The ID of the AAD directory in which you created the application.

    Client ID

    The application ID.

    Secret Key

    The secret key of the application.

    Authentication Resource URL (optional)

    The URL where the authentication token is sent to.

    Using ADFS:

    Azure Stack Hub Resource Manager endpoint URL

    The endpoint URL in the following format that allows Snapshot Manager to connect with your Azure resources.

    https://management.<location>.<FQDN>

    Tenant ID

    The ID of the AAD directory in which you created the application.

    Client ID

    The application ID.

    Secret Key

    The secret key of the application.

    Authentication Resource URL (optional)

    The URL where the authentication token is sent to.

    Amazon AWS

    Access Key

    The access key ID, when specified with the secret access key, authorizes Snapshot Manager to interact with the AWS APIs.

    Secret Key

    The secret key of the application.

    Note:

    If the Snapshot Manager is configured with IAM Config, the Access Key and Secret Key options are not available.

    Regions

    One or more AWS regions in which to discover cloud assets.

    Note:

    If you configure a government cloud, select us-gov-east-1 or us-gov-west-1.

    VPC Endpoint

    First DNS name of AWS Security Token Service (STS) endpoint service with no zone specified.

    Google Cloud Platform

    Project ID

    The ID of the project from which the resources are managed. Listed as in the project_id JSON file.

    Client Email

    The email address of the Client ID. Listed as client_email in the JSON file.

    Private Key

    The private key. Listed as private_key in the JSON file.

    Note:

    You must enter this key without quotes. Do not enter any spaces or return characters at the beginning or end of the key.

    Regions

    A list of regions in which the provider operates.

    Oracle Cloud Infrastructure

    Credential type: API Key

    User OCID

    User's OCID for which you generate the credentials.

    Tenancy

    Tenant ID of the OCI account.

    Fingerprint

    The fingerprint that you obtain while generating the credential.

    Private Key

    The private key that you obtain while generating the credential.

    Regions

    One or more OCI regions in which you want to discover the cloud assets.

    Credential type: IAM

    NetBackup Snapshot Manager must be a part of a dynamic group and that dynamic group must have enough permissions.

  6. Enter the connection and authentication details in the Add Configuration pane.
  7. Click Save.

The assets on the cloud providers are automatically discovered.