Veritas Flex Appliance Getting Started and Administration Guide
- Product overview
- Release notes
- Getting started
- Managing network settings
- Managing users
- Managing Flex Appliance Console users and tenants
- Using Flex Appliance
- Managing the repository
- Managing application instances from Flex Appliance
- Upgrading application instances
- About Flex Appliance upgrades and updates
- Appliance security
- Monitoring the appliance
- Reconfiguring the appliance
- Troubleshooting guidelines
About lockdown mode
Flex Appliance lockdown mode offers additional security levels to protect your data. You can use lockdown mode to create WORM storage instances that prevent your data from being encrypted, modified, or deleted.
WORM is the acronym for Write Once Read Many. Any data that is saved on these instances is protected with the following security measures:
Immutability
This protection ensures that the backup image is read-only and cannot be modified, corrupted, or encrypted after backup.
Indelibility
This property protects the backup image from being deleted before it expires. The data is protected from malicious deletion.
Flex Appliance includes the following lockdown modes:
Normal mode
This mode is the default mode of the appliance. Normal mode does not support WORM storage.
Enterprise mode
This mode adds additional access restrictions but retains a level of flexibility. In this mode:
You can create WORM storage instances and also delete them, including any existing data.
Any administrator can delete WORM storage instances if there is no immutable data. However, only the default admin user can delete them if immutable data is present.
When you delete a WORM storage instance as the default admin user, the instance can be running or stopped. When you delete a WORM instance as any other user, the instance must be running so that the system can verify that there is no immutable data present.
To change from enterprise mode to normal mode, you must first delete all WORM storage instances.
Compliance mode
This mode adds the highest level of access restrictions. In this mode:
You can create WORM storage instances. You can delete the instances only if there is no immutable data present.
Any administrator can delete WORM storage instances if there is no immutable data.
When you delete a WORM storage instance, the instance must be running so that the system can verify that there is no immutable data present.
To change from compliance mode to enterprise mode or normal mode, you must first expire all data on the WORM storage instances, and then delete the instances.
In both enterprise mode and compliance mode, storage reset is disabled.
Warning:
Lockdown mode does not block access to the remote management (IPMI) port. Veritas recommends that you set up your network to restrict access and only allow security administrators or the users that manage the physical hardware to use the port.
The appliance must be in lockdown mode before you can create WORM storage instances. See Changing the lockdown mode.
For more information on creating and managing WORM storage instances, see the NetBackup Application Guide for Flex Appliance, release 8.3.0.1 or later.