Veritas NetBackup™ Appliance Administrator's Guide
- Overview
- About accessing the NetBackup Appliance Web Console
- About the NetBackup Appliance Shell Menu
- About appliance console components
- Monitoring the NetBackup appliance
- About hardware monitoring and alerts
- About Symantec Data Center Security on the NetBackup appliance
- Managing a NetBackup appliance from the NetBackup Appliance Web Console
- About storage configuration
- About Copilot functionality and Share management
- About viewing storage space information using the Show command
- About appliance supported tape devices
- About configuring Host parameters for your appliance
- Manage > Appliance Restore
- Manage > License
- About the Migration Utility
- Software release updates for NetBackup Appliances
- About installing EEBs
- About installing NetBackup Administration Console and client software
- Manage > Additional Servers
- Manage > High Availability
- Managing NetBackup appliance using the NetBackup Appliance Shell Menu
- About OpenStorage plugin installation
- About mounting a remote NFS
- About running NetBackup commands from the appliance
- About NetBackup administrator capabilities
- Creating a NetBackup touch file from the NetBackup appliance
- Creating NetBackup administrator user accounts
- About NetBackup administrator capabilities
- About Auto Image Replication between appliances
- About forwarding logs to an external server
- About high availability configuration
- About data erasure
- Understanding the NetBackup appliance settings
- Settings > Notifications
- Settings > Network
- Settings > Authentication
- About configuring user authentication
- About authorizing NetBackup appliance users
- Settings > Authentication > LDAP
- Settings > Authentication > Active Directory
- Settings > Authentication > User Management
- Troubleshooting
- Deduplication pool catalog backup and recovery
Generic user authentication guidelines
Use the following guidelines for authenticating users on the appliance:
Only one remote user type (LDAP, or Active Directory/AD can be configured for authentication on an appliance. For example, if you currently authenticate LDAP users on an appliance, you must remove the LDAP configuration on it before changing to AD user authentication.
The NetBackupCLI role can be assigned to a maximum of nine (9) user groups at any given time.
You cannot grant the NetBackupCLI role to an existing local user. However, you can create a local NetBackupCLI user by using the Manage > NetBackupCLI > Create command from the NetBackup Appliance Shell Menu.
You cannot add a new user or a user group to an appliance with the same user name, user ID, or group ID as an existing appliance user.
Do not use group names or user names that are already used for appliance local users or NetBackupCLI users. Additionally, do not use the appliance default names admin or maintenance for LDAP or AD users.
The appliance does not handle ID mapping for LDAP configuration. Veritas recommends that you reserve a user ID and group ID range of 1000 to 1999 only for local appliance users. For remote AD and LDAP users, reserve a user ID and group ID range greater than 1999.
NetBackup appliance uses general CIFS shares for some of its internal operations such as storing patches and installation files, uploading logs to support, forwarding logs to an external server, and uploading OST plug-ins.
Starting with appliance software version 4.0, you must manage access to the general CIFS shares for all local users and Active Directory users and user groups (except the admin user). Use the Settings > Security > Authentication > CIFSShare command to manage access to the general CIFS shares.
Guest users: Replace a Guest user by creating a new local user.
Existing local users: Change the passwords for these users.