NetBackup™ Web UI Security Administrator's Guide

Last Published:
Product(s): NetBackup (8.1.2)
  1. Introducing the NetBackup web user interface
    1.  
      About the NetBackup web user interface
    2.  
      Terminology
    3.  
      First-time sign in to a NetBackup master server from the NetBackup web UI
    4.  
    5.  
      The NetBackup dashboard
  2. Managing role-based access control
    1.  
      About role-based access control (RBAC) in NetBackup
    2.  
      NetBackup default RBAC roles
    3.  
      Configuring RBAC
    4.  
      Add a custom role
    5.  
      Edit or delete a custom role
    6.  
      Add an object group
    7.  
      Previewing the assets, application servers, or protection plans for an object group
    8.  
      Edit or delete an object group
    9.  
      Add access for a user through access rules
    10.  
      Edit or remove user access rules
    11.  
      How can I limit role permissions to specific objects or assets?
  3. Security events and audit logs
    1.  
      About NetBackup auditing
    2.  
      View security events and audit logs
  4. Managing host mappings and certificates
    1.  
      About security management and certificates in NetBackup
    2.  
      NetBackup host IDs and host ID-based certificates
    3.  
      View NetBackup host information
    4.  
      Approve or add mappings for a host that has multiple host names
    5.  
      Reissue a certificate when a host's certificate is no longer valid
    6.  
      Remove mappings for a host that has multiple host names
    7.  
      Reset a host's attributes
    8.  
    9.  
  5. Managing global security settings
    1.  
      Disable communication with NetBackup 8.0 and earlier hosts
    2.  
      Disable automatic mapping of NetBackup host names
    3.  
      Select a security level for certificate deployment
    4.  
      Set a passphrase for disaster recovery
  6. Troubleshooting the web UI
    1.  
      Tips for accessing the NetBackup web UI
    2.  
      If a user doesn't have the correct permissions or access to workload assets in the NetBackup web UI

Add an object group

Object groups can define the assets, application servers, or protection plans that users can view or manage. You can create an object group that grant access to specific workloads or objects. For example, you can grant access to all objects in the VMware workload or to specific VMware servers. Or, you can grant access to all assets, application servers, or protection plans. For example, a backup administrator that has access for all protection plans can manage any protection plan in NetBackup.

To manage or perform recovery of assets or application servers, a user must have one or more access rules with an object group that includes those objects. To manage or subscribe assets to certain protection plans, a user must have one or more access rules with an object group that includes those plans.

Note:

Object groups can also limit what the user can create. For example, assume that a backup administrator has only one access rule that gives access to protection plans that contain the word "finance". Therefore that user can only create protection plans that contain the word "finance".

To add an object group

  1. On the left, click Security > RBAC.
  2. Click the Object groups tab and click Add.
  3. Provide the name and description for the object group.

    You may want to include any keywords that describe the type of assets in the group or the region the assets reside in.

  4. Select any assets that you want to add to this object group.

    You can define the assets for this object group in the following ways:

    • All assets in a specific workload

    • A specific VMware server and all its VMs

    • A specific VMware server and selected VMs for that server

    • Turn on Grant access to all to include all available assets

    See Selecting the assets for an object group.

    Users granted access to these assets can view or manage these assets, according to the role that they are assigned.

  5. Select any application servers that you want to add to this object group.

    You can define the application servers for this object group in the following ways:

    • All application servers, in a specific workload

    • Specific application servers

    • Turn on Grant access to all to include all available application servers

    See Selecting the application servers for an object group.

    Users granted access to these assets can view or manage these application servers, according to the role that they are assigned.

  6. Select the protection plans that you want to add to this object group.

    You can define the protection plans for this object group in the following ways:

    • Specific protection plans

    • Turn on Grant access to all to include all protection plans

    See Selecting the protection plans for an object group.

    Users granted access to these protection plans can view or manage these plans, according to the role that they are assigned. Users with "view" permissions can also subscribe assets to the protection plans in the object group.

  7. Click Save.
Selecting the assets for an object group

You can preview the assets that are included in an object group. See Preview the assets, application servers, or protection plans that are in an object group.

To include all assets in a specific workload

  • Click Add workload, then select the workload type that you want to include.

    For example, select VMware to include all VMware assets.

To include a specific VMware server and all its VMs

  1. Under Assets, click Add workload, then select the workload type that you want to include.

    For example, select VMware to include all VMware assets.

  2. Click Add VMware server.
  3. Select the name of the vCenter that you want to include. Or, click on the vCenter name to browse for a server, cluster, or datacenter.
  4. Click Save.

To include a specific VMware server and selected VMs for that server

  1. Under Assets, click Add workload, then select the workload type that you want to include.

    For example, select VMware to include all VMware assets.

  2. Click Add VMware server.
  3. Select the name of the vCenter that you want to include. Or, click on the vCenter name to browse for a server, cluster, or datacenter.
  4. Click Save.
  5. Turn off Include all VMs in this server.
  6. Define one or more conditions. Conditions are case-sensitive.

    For multiple conditions, select the operator (AND or OR).

    In the following example, the object group includes assets in the VMware workload, from the cluster servercl02 on the VMware server abc.domain.com and with a display name that starts with accounting.

Selecting the application servers for an object group

You can preview the assets that are included in an object group. See Preview the assets, application servers, or protection plans that are in an object group.

To include all application servers, in a specific workload

  • Under Application servers, click Add workload, then select the workload type that you want to include.

    For example, select VMware to include all VMware application servers.

To include specific application servers, in a specific workload

  1. Under Application servers, click Add workload, then select the workload type that you want to include.

    For example, select VMware to include all VMware application servers.

  2. Add one or more conditions. Conditions are case-sensitive.

    For multiple conditions, select the operator (AND or OR).

    In the following example, the object group includes application servers from the VMware workload with a server name that starts with HR or with a name that contains Marketing.

Selecting the protection plans for an object group

You can preview the assets that are included in an object group. See Preview the assets, application servers, or protection plans that are in an object group.

To include specific protection plans

  1. Under Protection plans, click Add condition.
  2. Select the attributes for the condition. Conditions are case-sensitive.

    For multiple conditions, select the operator (AND or OR).

    In the following example, the object group includes protection plans with a name that contains finance.

Preview the assets, application servers, or protection plans that are in an object group

You can preview the objects that are included in an object group. Note that an object group changes dynamically as objects are added and removed from the NetBackup environment. When backups run, the object group updates at run-time to reflect the objects available at the time of backup.

To preview the assets, application servers, or protection plans that are in an object group

  1. On the left, click Security > RBAC.
  2. Click the Object groups tab and the object group that you want to edit.
  3. To the right of Assets, Application Servers, or Protection Plans, click Preview.
  4. NetBackup displays a real-time view of the objects that meet the criteria that you configured. You can sort or search the objects in the preview. Note that searches are case-sensitive.
  5. When you are finished with the preview, at the top right-click the Close icon.