NetBackup and Veritas Appliances Hardening Guide
- Top recommendations to improve your NetBackup and Veritas appliances security posture
- Steps to protect Flex Appliance
- Managing single sign-on (SSO)
- About lockdown mode
- Configuring an isolated recovery environment on a WORM storage server
- Steps to protect NetBackup Appliance
- About single sign-on (SSO) authentication and authorization
- About authentication using smart cards and digital certificates
- About data encryption
- About forwarding logs to an external server
- Steps to protect NetBackup
- Configure NetBackup for single sign-on (SSO)
- Configure user authentication with smart cards or digital certificates
- Access codes
- Workflow to configure immutable and indelible data
- Add a configuration for an external CMS server
- Configuring an isolated recovery environment on a NetBackup BYO media server
- About FIPS support in NetBackup
- Workflow for external KMS configuration
- Workflow to configure data-in-transit encryption
- Workflow to use external certificates for NetBackup host communication
- About certificate revocation lists for external CA
- Configuring an external certificate for a clustered primary server
- Configuring a NetBackup host (media server, client, or cluster node) to use an external CA-signed certificate after installation
- Configuration options for external CA-signed certificates
- ECA_CERT_PATH for NetBackup servers and clients
- About protecting the MSDP catalog
- How to set up malware scanning
- About backup anomaly detection
Verify
In the verification workflow, backup image header is read, and its integrity is checked with the catalog. Therefore, a client does not come into picture. The hosts that participate are media server and primary server from the same domain.
Table: The image DTE mode is Off
Global DTE mode | NetBackup media server 9.1 and later with DTE mode | NetBackup media server earlier than 9.1 | |
---|---|---|---|
On | Off | ||
Preferred Off | Data is not encrypted | Data is not encrypted | Data is not encrypted |
Preferred On | Data is encrypted | Data is not encrypted | Data is not encrypted |
Enforced | Data is encrypted | Operation fails | Operation fails |
Table: When the image DTE mode is On and the media server DTE setting is On
Global DTE mode | DTE mode of NetBackup client 9.1 or later | Value of the DTE_IGNORE_IMAGE_MODE configuration option | ||
---|---|---|---|---|
NEVER (default) | WHERE_UNSUPPORTED | ALWAYS | ||
Preferred Off | Media server 9.1 or later | Data is encrypted | Data is encrypted | Data is not encrypted |
Media server earlier than 9.1 | Operation fails | Data is not encrypted | Data is not encrypted | |
Preferred On | Media server 9.1 or later | Data is encrypted | Data is encrypted | Data is encrypted |
Media server earlier than 9.1 | Operation fails | Data is not encrypted | Data is not encrypted | |
Enforced | Media server 9.1 or later | Data is encrypted | Data is encrypted | Data is encrypted |
Media server earlier than 9.1 | Operation fails | Operation fails | Operation fails |
Table: When the image DTE mode is On and the media server DTE setting on 10.0 or later is Off
Global DTE mode | Value of the DTE_IGNORE_IMAGE_MODE configuration option | ||
---|---|---|---|
NEVER (default) | WHERE_UNSUPPORTED | ALWAYS | |
Preferred Off | Operation fails | Operation fails | Data is not encrypted |
Preferred On | Operation fails | Operation fails | Data is not encrypted |
Enforced | Operation fails | Operation fails | Operation fails |