NetBackup and Veritas Appliances Hardening Guide
- Top recommendations to improve your NetBackup and Veritas appliances security posture
- Steps to protect Flex Appliance
- Managing single sign-on (SSO)
- About lockdown mode
- Configuring an isolated recovery environment on a WORM storage server
- Steps to protect NetBackup Appliance
- About single sign-on (SSO) authentication and authorization
- About authentication using smart cards and digital certificates
- About data encryption
- About forwarding logs to an external server
- Steps to protect NetBackup
- Configure NetBackup for single sign-on (SSO)
- Configure user authentication with smart cards or digital certificates
- Access codes
- Workflow to configure immutable and indelible data
- Add a configuration for an external CMS server
- Configuring an isolated recovery environment on a NetBackup BYO media server
- About FIPS support in NetBackup
- Workflow for external KMS configuration
- Workflow to configure data-in-transit encryption
- Workflow to use external certificates for NetBackup host communication
- About certificate revocation lists for external CA
- Configuring an external certificate for a clustered primary server
- Configuring a NetBackup host (media server, client, or cluster node) to use an external CA-signed certificate after installation
- Configuration options for external CA-signed certificates
- ECA_CERT_PATH for NetBackup servers and clients
- About protecting the MSDP catalog
- How to set up malware scanning
- About backup anomaly detection
Workflow to configure data-in-transit encryption
This topic provides the steps to carry out data-in-transit encryption (DTE) in your NetBackup environment. The DTE configuration comprises the following two primary options:
Global DTE mode
Client DTE mode
Table: Workflow of DTE configuration
Step number | Step | Reference topic |
---|---|---|
Step 1 | Review the configuration settings of the global DTE mode option and configure the option as per your DTE requirements | See Configure the global data-in-transit encryption setting. |
Step 2 | Review the configuration settings of the client DTE mode option and configure the option as per your DTE requirements | |
Step 3 | Review how the decision about data encryption is made based on the NetBackup operation that you want to perform and the DTE configuration settings. | See How DTE configuration settings work in various NetBackup operations. Note: If you plan to modify any existing DTE configuration settings, you must review this topic to understand the impact on the NetBackup operations. |
Apart from the primary DTE configuration settings, the following settings are used in certain scenarios:
Media server DTE mode
Backup image DTE mode