NetBackup™ Snapshot Manager for Data Center Administrator's Guide
- Introduction
- Installation and Upgrade
- Configure NetBackup Snapshot Manager storage array plug-ins
- Storage array replication
- Storage array plug-ins for Snapshot Manager for Data Center
- Dell EMC PowerMax and VMax array
- Dell EMC PowerFlex array
- Dell EMC PowerScale (Isilon)
- Dell EMC PowerStore SAN and NAS plug-in
- Dell EMC XtremIO SAN array
- Dell EMC Unity Array
- Fujitsu Eternus AF/DX SAN array
- HPE RMC plug-in
- HPE XP plug-in
- HPE Alletra 9000 SAN array
- Hitachi NAS array
- Hitachi SAN array
- IBM Storwize SAN V7000 plug-in
- InfiniBox SAN array
- InfiniBox NAS array
- NetApp Storage array
- NetApp E-Series array
- Nutanix Files array
- Pure Storage FlashArray SAN
- Pure Storage FlashBlade plug-in configuration notes
- PowerMax eNAS array
- Qumulo NAS array
- Configuring storage lifecycle policies for snapshots and snapshot replication
- Operation types in a storage lifecycle policy
- Retention types for storage lifecycle policy operations
- Troubleshooting
Roles and privileges on Dell EMC Unisphere for PowerMax and VMax
To allow NetBackup to perform snapshot management operations, ensure that the Dell EMC Unisphere user account used for plug-in configuration has the following roles and privileges assigned:
Create snapshot
Export snapshot
Restore snapshot
Delete snapshot
RBAC is managed using Unisphere for VMAX, Unisphere for PowerMax, or the Solutions Enabler CLI symauth command. Using symauth, a user or group of users, may be mapped to a specific access role, which defines the operations that these users are permitted to perform on the entire VMAX array.
There are currently seven users defined roles that are available with RBAC: None, Monitor, PerfMonitor, StorageAdmin, SecurityAdmin, Admin, and Auditor. Following are the base capabilities of these current roles:
None: No capabilities.
Monitor: Performs read-only operations on an array excluding the ability to read the audit log or access control definitions.
PerfMonitor: Includes Monitor role permissions and grants additional privileges within the performance component of Unisphere for VMAX application to set up various alerts and update thresholds to monitor array performance.
StorageAdmin: Perform all management and control functions. See the specific permissions pertaining to this role:
SecurityAdmin Performs security operations (symaudit, symacl, symauth) on an array in addition to all monitor operations. Users or groups assigned the SecurityAdmin or Admin roles can create or delete component-specific authorization rules. The SecurityAdmin also has all Auditor rights.
Admin: Performs all operations on an array, including security operations and monitor operations. The Admin also has StorageAdmin rights, SecurityAdmin rights, and application performance monitoring privileges.
Auditor: Grants the ability to view, but not modify, security settings for an array (including reading the audit log, symacl list, and symauth) in addition to all monitor operations. This is the minimum role required to view the array audit log.
It is important to clarify that your Storage_Admin role remains your ssuper user, and keeps sole control of provisioning storage on the array.