NetBackup™ Web UI Administrator's Guide
- Section I. About NetBackup
- Section II. Monitoring and notifications- Monitoring NetBackup activity- The NetBackup dashboard
- Activity monitor
- Job monitoring- Workloads that require a custom RBAC role for specific job permissions
- View a job
- View the jobs in the List view
- View the jobs in the Hierarchy view
- Jobs: cancel, suspend, restart, resume, delete
- Search for or filter jobs in the jobs list
- Create a jobs filter
- Edit, copy, or delete a jobs filter
- Import or export job filters
- View the status of a redirected restore
- Troubleshooting the viewing and managing of jobs
 
 
- Device monitor
- Notifications
- Registering the data collector
 
- Monitoring NetBackup activity
- Section III. Configuring hosts- Managing host properties- Overview of host properties
- View or edit the host properties of a server or client
- Host information and settings in Host properties
- Reset a host's attributes
- Active Directory properties
- Backup pool host properties
- Busy file settings properties
- Clean up properties
- Client name properties
- Client attributes properties
- Client settings properties for UNIX clients
- Client settings properties for Windows clients
- Cloud Storage properties
- Credential access properties
- Data Classification properties
- Default job priorities properties
- Distributed application restore mapping properties
- Encryption properties
- Enterprise Vault properties
- Enterprise Vault hosts properties
- Exchange properties
- Exclude list properties
- Fibre transport properties
- Firewall properties
- General server properties
- Global attributes properties
- Logging properties
- Lotus Notes properties
- Media properties
- Network properties
- Network settings properties
- Nutanix AHV access hosts
- Port ranges properties
- Preferred network properties- Add or edit a Preferred network setting
- How NetBackup uses the directives to determine which network to use
- Configurations to use IPv6 networks
- Configurations to use IPv4 networks
- Order of directive processing in the Preferred network properties
- bptestnetconn utility to display Preferred network information
- Configuration to prohibit using a specified address
- Configuration to prefer a specified address
- Configuration that restricts NetBackup to one set of addresses
- Configuration that limits the addresses, but allows any interfaces
 
- Properties setting in host properties
- RHV access hosts properties
- Resilient network properties
- Resource limit properties
- Restore failover properties
- Retention periods properties
- Scalable Storage properties
- Servers properties
- SharePoint properties
- SLP settings properties
- Throttle bandwidth properties
- Timeouts properties
- Universal settings properties
- UNIX client properties
- UNIX Server properties
- User account settings properties
- VMware access hosts properties
- Windows client properties
- Configuration options not found in the host properties
- About using commands to change the configuration options on UNIX or Linux clients and servers
 
- Managing credentials for workloads and systems that NetBackup accesses
- Managing deployment
 
- Managing host properties
- Section IV. Configuring storage- Overview of storage options
- Configuring disk storage- Create a Media Server Deduplication Pool storage server
- Integrating MSDP Cloud and CMS
- Create a Media Server Deduplication Pool (MSDP) storage server for image sharing
- Create an AdvancedDisk, OpenStorage (OST), or Cloud Connector storage server
- Create an MSDP server for MSDP volume group (MVG)
- Create the MVG volume
- Edit a storage server
- About configuring disk pool storage
- Share images from an on-premises location to the cloud
- Overview of universal shares
- About the MSDP object store
 
- Managing media servers
- Configuring storage units
- Managing robots and tape drives- NetBackup robot types
- Add a robot to NetBackup manually
- Managing robots
- Managing tape drives- Change a drive comment
- About downed drives
- Change a drive operating mode
- Change a tape drive path
- Change the operating mode for a drive path
- Change tape drive properties
- Change a tape drive to a shared drive
- Clean a tape drive
- Delete a drive
- Reset a drive
- Reset the mount time of a drive
- Set the drive cleaning frequency
- View drive details
 
 
- Managing tape media- About NetBackup tape volumes
- About NetBackup volume pools
- About NetBackup volume groups
- NetBackup media types
- About adding volumes
- Managing volumes- Edit a volume
- About moving volumes
- Move volumes
- About recycling a volume
- About assigning and deassigning volumes
- Delete a volume
- Changing the media owner of a volume
- Changing the volume group assignment
- About rules for moving volumes between groups
- Rescan and update barcodes
- About barcode rules
- About injecting and ejecting volumes
- Label a volume
- Erase a volume
- Freeze or unfreeze a volume
- Suspend or unsuspend volumes
 
- Managing volume pools
- Managing volume groups
 
- Inventorying robots- About robot inventory
- When to inventory a robot
- About showing a robot's contents
- Showing the media in a robot
- About comparing a robot's contents with the volume configuration
- Comparing media in a robot with the volume configuration
- About previewing volume configuration changes
- Previewing volume configuration changes for a robot
- About updating the NetBackup volume configuration
- Update the NetBackup volume configuration with a robot's contents
- Robot inventory options
- Advanced options for robot inventory settings
- Configure media ID generation rules
- Barcode rules settings
- Media ID generation options
- Configure media settings
- About media type mapping rules
- Configure media type mappings
 
- Staging backups
- Troubleshooting storage configuration
 
- Section V. Configuring backups- Overview of backups in the NetBackup web UI
- Managing protection plans
- Managing classic policies
- Protecting the NetBackup catalog- About the NetBackup catalog
- Catalog backups- The catalog backup process
- Prerequisites for backing up the NetBackup catalog
- Configuring catalog backups
- Backing up NetBackup catalogs manually
- Concurrently running catalog backups with other backups
- Catalog policy schedule considerations
- How catalog incrementals and standard backups interact on UNIX
- Determining whether or not a catalog backup succeeded
- Strategies that ensure successful NetBackup catalog backups
 
- Disaster recovery emails and the disaster recovery files
- Disaster recovery packages
- Set the passphrase to encrypt disaster recovery packages
- Recovering the catalog
 
- Managing backup images
- Pausing data protection activity
 
- Section VI. Managing security- Security events and audit logs
- Managing security certificates
- Managing host mappings
- Minimizing security configuration risk
- Configuring multi-person authorization- About multi-person authorization
- Workflow to configure multi-person authorization for NetBackup operations
- RBAC roles and permissions for multi-person authorization
- Multi-person authorization process with respect to roles
- NetBackup operations that need multi-person authorization
- Configure multi-person authorization
- View multi-person authorization tickets
- Manage multi-person authorization tickets
- Add exempted users
- Schedule expiration and purging of multi-person authorization tickets
- Disable multi-person authorization
 
- Managing user sessions
- Configuring multifactor authentication- About multifactor authentication
- Configure multifactor authentication for your user account
- Disable multifactor authentication for your user account
- Enforce multifactor authentication for all users
- Configure multifactor authentication for your user account when it is enforced in the domain
- Reset multifactor authentication for a user
 
- Managing the global security settings for the primary server- View the Certificate authority for secure communication
- Disable communication with NetBackup 8.0 and earlier hosts
- Disable automatic mapping of NetBackup host names
- Configure the global data-in-transit encryption setting
- About NetBackup certificate deployment security levels
- Select a security level for NetBackup certificate deployment
- About TLS session resumption
- Set a passphrase for disaster recovery
- Validate the disaster recovery package passphrase
- About trusted primary servers
- Configure the audit retention period
 
- Using access keys, API keys, and access codes
- Configuring authentication options
- Managing role-based access control
- Disabling access to NetBackup interfaces for OS Administrators
 
- Section VII. Detection and reporting- Detecting anomalies- About backup anomaly detection
- Configure backup anomaly detection settings
- View backup anomalies
- Disable backup anomaly detection and computation of entropy and file attributes for a client
- About system anomaly detection
- Configure system anomaly detection settings
- Configure rules-based anomaly detection
- Configure risk engine-based anomaly detection
- View system anomalies
 
- Malware scanning
- Usage reporting and capacity licensing
 
- Detecting anomalies
- Section VIII. NetBackup workloads and NetBackup Flex Scale
- Section IX. Administering NetBackup- Management topics
- Managing client backups and restores- About server-directed restores
- About client-redirected restores
- About restoring the files that have Access Control Lists (ACLs)
- About setting the original atime for files during restores on UNIX
- Restoring the System State
- About the backup and restore of compressed files on VxFS file systems
- About backups and restores on ReFS
 
 
- Section X. Disaster recovery and troubleshooting
- Section XI. Other topics- Additional NetBackup catalog information
- About the NetBackup database- About the NetBackup database installation
- Post-installation tasks
- Using the NetBackup Database Administration utility on Windows
- Using the NetBackup Database Administration utility on UNIX
 
 
Reissue a NetBackup certificate
Note:
The information here only applies to the security certificates that the NetBackup certificate authority (CA) issues. External certificates must be managed outside of NetBackup.
In some cases a host's NetBackup certificate is no longer valid. For example, if a certificate is expired, revoked, or is lost. You can reissue a certificate either with or without a reissue token.
A reissue token is a type of authorization token that is used to reissue a NetBackup certificate. When you reissue a certificate, the host gets the host ID same as the original certificate.
If you need to reissue a host's NetBackup certificate NetBackup provides a more secure method to do this reissue. You can create an authorization token that the host administrator must use to obtain a new certificate. This reissue token retains the same host ID as the original certificate. The token can only be used once. Because it is associated to a specific host, the token cannot be used to request certificates for other hosts.
To reissue a NetBackup certificate for a host
- On the left, select Security > Certificates.
- Select the NetBackup certificates tab.
- Select the host and select Actions > Generate reissue token.
- Enter a token name and indicate how long the token should be valid for.
- Select Create.
- Select Copy to clipboard and then select Close.
- Share the authorization token so the host's administrator can obtain a new certificate.
In certain scenarios you need to reissue a certificate without a reissue token. For example, for a BMR client restore. The option enables you to reissue a certificate without requiring a token.
To allow a NetBackup certificate reissue, without a token
- On the left, select Security > Host mappings.
- Locate the host and select Actions > Allow auto reissue certificate > Allow.Once you set the Allow auto reissue certificate option, a certificate can be reissued without a token within the next 48 hours, which is the default setting. After this window to reissue expires, the certificate reissue operation requires a reissue token. 
- Notify the host's administrator that you allowed a NetBackup certificate reissue without a token.
After you allow a NetBackup certificate reissue without a token, you can revoke this ability before the window to reissue expires. By default, the window is 48 hours.
To revoke the ability to reissue a NetBackup certificate without a token
- On the left, select Hosts > Host mappings.
- Locate the host and select Actions > Revoke auto reissue certificate > Revoke.