Veritas Flex Appliance Getting Started and Administration Guide
- Product overview
- Getting started
- Managing network settings
- Managing users
- Overview of the Flex Appliance default users
- Changing the password policy
- Managing Flex Appliance Console users and tenants
- Adding a tenant
- Editing a tenant
- Removing a tenant
- Adding a local user to the Flex Appliance Console
- Connecting an Active Directory domain to the Flex Appliance Console
- Importing an Active Directory user or user group to the Flex Appliance Console
- Editing an Active Directory domain in the Flex Appliance Console
- Changing a user password in the Flex Appliance Console
- Expiring a user password in the Flex Appliance Console
- Removing a user from the Flex Appliance Console
- Changing the hostadmin user password in the Flex Appliance Shell
- Changing the sysadmin user password in the Veritas Remote Management Interface
- Using Flex Appliance
- Managing the repository
- Creating application instances
- Managing application instances from Flex Appliance and NetBackup
- Managing application instances from Flex Appliance
- Upgrading application instances
- About Flex Appliance upgrades and updates
- Appliance security
- Monitoring the appliance
- Reconfiguring the appliance
- Troubleshooting guidelines
Security overview
Flex Appliance includes multiple features to ensure the security of your data. Each element of the appliance is tested for vulnerabilities using both industry standards and advanced security products. These measures ensure that exposure to unauthorized access and resulting data loss or theft is minimized.
Flex Appliance also uses the Security Technical Implementation Guide (STIG) template to meet security requirements per the Defense Information Systems Agency (DISA) profile. See the Flex Appliances with NetBackup Security white paper for more information.
The security features in this release include but are not limited to the following:
OS security hardening, including Security-Enhanced Linux (SELinux)
Forced password changes during initial configuration to make sure that the default password does not remain active on the system
The ability to set your own password policy, including the option to use STIG for validation
Lockdown mode and WORM storage support, which let you set additional access restrictions and block data deletion during a specified retention period
See About lockdown mode.
Session timeouts that automatically sign users out of the Flex Appliance Console and the Flex Appliance Shell after 10 minutes of inactivity
Additional password protection in the Flex Appliance Shell that locks the hostadmin account for 15 minutes after 3 incorrect login attempts
Password protection that restricts access to the GRUB menu except with assistance from Veritas Technical Support. If you need to edit GRUB, contact Technical Support and ask your representative to reference article 100048098.
Also note the following information regarding the appliance security:
IP forwarding is enabled in Flex Appliance by design; it is used to facilitate network communication between application instances and external networks.
Simultaneous multithreading (smt) is enabled by default on the Veritas 5340 Appliance.
The following vulnerabilities affect this feature:
CVE-2018-12130
CVE-2018-12126
CVE-2018-12127
CVE-2019-11091
You can disable smt to address these vulnerabilities; however, if smt is disabled, backup performance drops by up to 60%. If you want to disable smt, contact Veritas Technical Support and ask your representative to reference article 100046154.