Avamar Data Domain Integration Guide
Avamar Data Domain Integration Guide
Version 7.5.1
Dell believes the information in this publication is accurate as of its publication date. The information is subject to change without notice.
THE INFORMATION IN THIS PUBLICATION IS PROVIDED “AS-IS.“ DELL MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND
WITH RESPECT TO THE INFORMATION IN THIS PUBLICATION, AND SPECIFICALLY DISCLAIMS IMPLIED WARRANTIES OF
MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. USE, COPYING, AND DISTRIBUTION OF ANY DELL SOFTWARE DESCRIBED
IN THIS PUBLICATION REQUIRES AN APPLICABLE SOFTWARE LICENSE.
Dell, EMC, and other trademarks are trademarks of Dell Inc. or its subsidiaries. Other trademarks may be the property of their respective owners.
Published in the USA.
Dell EMC
Hopkinton, Massachusetts 01748-9103
1-508-435-1000 In North America 1-866-464-7381
www.DellEMC.com
Figures 7
Tables 9
Preface 11
Chapter 1 Introduction 15
Overview.....................................................................................................16
Architecture................................................................................................16
Backup........................................................................................................ 18
Avamar checkpoints....................................................................................18
Restore....................................................................................................... 18
VMware Instant Access...............................................................................18
Replication.................................................................................................. 19
Monitoring and reporting............................................................................ 19
Security...................................................................................................... 19
Token-based authentication........................................................................19
Configuring a ddboost account for token-based authentication.... 20
Data migration to an attached Data Domain system................................... 20
Chapter 4 Replication 41
Overview of replication...............................................................................42
Replication configurations.......................................................................... 42
Many to one replication................................................................. 42
Many to many replication...............................................................43
One to many replication.................................................................44
Pool-based replication................................................................... 45
Replication data flow.................................................................................. 45
Replication schedule...................................................................................45
Configuring replication............................................................................... 45
Setting the default Data Domain destination................................. 46
Mapping a domain to a Data Domain system..................................46
Deleting a domain mapping............................................................ 46
Configuring pool-based replication................................................ 47
Appendix A Troubleshooting 79
Viewing detailed status information for troubleshooting.............................80
Data Domain status and resolutions............................................................80
Monitoring status....................................................................................... 84
Common problems and solutions................................................................ 87
Reclaiming storage on a full Data Domain system....................................... 87
Re-creating the SSH public/private key pair.............................................. 89
Using legacy certificate authentication with Data Domain requires command
line flags .................................................................................................... 90
Glossary 91
1 Revision history........................................................................................................... 11
2 Typographical conventions..........................................................................................12
3 Data Domain system requirements............................................................................. 24
4 Licensing requirements...............................................................................................26
5 WAN use case bandwidth guidelines...........................................................................33
6 Supported AWS regions............................................................................................. 52
7 Data Domain system capacity details ......................................................................... 77
8 Status bar problem indicators.....................................................................................80
9 Monitoring status values and resolutions.................................................................... 80
10 Server Management monitoring status details............................................................84
Note
Purpose
This guide describes how to install, configure, administer, and use a Data Domain
system as a backup target for Avamar.
Audience
The information in this guide is primarily intended for system administrators who are
responsible for configuring and maintaining Avamar and Data Domain system
integrated backups.
Revision history
The following table presents the revision history of this document.
Related documentation
The following Avamar publications provide additional information:
l Avamar Compatibility and Interoperability Matrix
l Avamar Release Notes
l Avamar Administration Guide
l Avamar Operational Best Practices Guide
l Avamar Product Security Guide
l Avamar for IBM DB2 User Guide
l Avamar for Exchange VSS User Guide
l Avamar for Hyper-V VSS User Guide
l Avamar for SAP with Oracle User Guide
l Avamar for SharePoint VSS User Guide
l Avamar for SQL Server User Guide
l Avamar for Sybase ASE User Guide
DANGER
WARNING
CAUTION
NOTICE
Note
Typographical conventions
These type style conventions are used in this document.
Note
To open a service request, you must have a valid support agreement. Contact a sales
representative for details about obtaining a valid support agreement or with questions
about an account.
To review an open service request, click the Service Center link on the Service
Center panel, and then click View and manage service requests.
Enhancing support
We recommend that you enable ConnectEMC and Email Home on all Avamar systems:
l ConnectEMC automatically generates service requests for high priority events.
l Email Home sends configuration, capacity, and general system information to
Customer Support.
Comments and suggestions
Comments and suggestions help us to continue to improve the accuracy, organization,
and overall quality of the user publications. Send comments and suggestions about
this document to [email protected].
Please include the following information:
l Product name and version
l Document name, part number, and revision (for example, 01)
l Page numbers
l Other details to help address documentation issues
l Overview............................................................................................................ 16
l Architecture....................................................................................................... 16
l Backup................................................................................................................18
l Avamar checkpoints........................................................................................... 18
l Restore...............................................................................................................18
l VMware Instant Access...................................................................................... 18
l Replication..........................................................................................................19
l Monitoring and reporting.................................................................................... 19
l Security.............................................................................................................. 19
l Token-based authentication............................................................................... 19
l Data migration to an attached Data Domain system...........................................20
Introduction 15
Introduction
Overview
Data Domain deduplication storage systems are typically implemented to back up large
high-change rate databases. Avamar is typically implemented to back up file systems,
virtual servers, low change rate databases, remote offices, and desktop/laptops.
Avamar and Data Domain system integration enables:
l Data Domain systems to be a backup target for Avamar backups
l One or more Data Domain systems to be managed by Avamar
l Avamar clients to use the Data Domain Boost software option to use Data Domain
systems as backup targets
l The target destination of backup data, which is set by a backup policy at the
dataset level
l Transparent user interaction to the backup target (Avamar or Data Domain)
Architecture
A Data Domain system performs deduplication through DD OS software. Avamar
source based deduplication to a Data Domain system is facilitated through the use of
the Data Domain Boost library.
Avamar uses the DD Boost library through API-based integration to access and
manipulate directories, files, and so forth. contained on the Data Domain File System.
The DD Boost API gives Avamar visibility into some of the properties and capabilities
of the Data Domain system. This enables Avamar to control backup images stored on
Data Domain systems. It also enables Avamar to manage maintenance activities and to
control replication to remote Data Domain systems.
DD Boost is installed on the backup clients and on the Avamar utility node, an Avamar
single node system, or on Avamar Virtual Edition.
The following figure depicts a high-level architecture of the combined Avamar and
Data Domain solution. With Avamar and Data Domain integration you can specify
whether specific datasets in an Avamar backup policy target an Avamar server or a
Data Domain system.
When you select an Avamar server as the backup target, the Avamar client on each
host performs deduplication segment processing. Data and metadata are stored on
the Avamar server.
When you select a Data Domain system as the backup target, backup data is
transferred to the Data Domain system. The related metadata generated by the
Avamar client software is simultaneously sent to the Avamar server for storage. The
metadata enables the Avamar management system to perform restore operations
directly from the Data Domain system without first going through the Avamar server.
Mixed backups are supported. It is possible for backup data to span across both
Avamar servers and a Data Domain system within the same backup.
If backups are taking place to an Avamar server and then redirected to a Data Domain
system, then subsequent incremental backup data will be stored on the Data Domain
system while the original backup data is on the Avamar server. This can affect
capacity because the forever incremental data will continue to reside on the Avamar
Server while newer/changed incremental data will be stored on the Data Domain
system.
If the desire is to ensure backup data is released on the Avamar server and redirect
backups to data domain then a full backup must be initiated. This can be achieved by
renaming the client's cache files, which will force a full backup. However, note that
this will cause the client's backup to take longer and impact performance since it will
have to create a new backup on the Data Domain system. If there are many clients
that need to be moved to a Data Domain system then it is recommended that the
initial full backup be scheduled appropriately to avoid performance impact.
If the capacity on the Avamar server is not a concern then the system will continue to
backup incremental backup data to the Data Domain but its prior backup data will
remain on the Avamar server until it expires. The implication is that when the last
backup containing parts on the Avamar server expire, then a full backup will trigger.
The recommendation is to perform a controlled and/or scheduled full backup.
Architecture 17
Introduction
Backup
During a backup, the Avamar server sends a backup request to the Avamar client. If
the backup request includes the option to use a Data Domain system as the target,
backup data is stored on the Data Domain system. Metadata is stored on the Avamar
server.
The following topics provide details on the types of backup data that Avamar can
store on a Data Domain system.
Up-to-date client compatibility information is available in the Avamar Compatibility and
Interoperability Matrix on Avamar Support at http://compatibilityguide.emc.com:8080/
CompGuideApp/.
Avamar checkpoints
You can store checkpoints for a single-node Avamar server or Avamar Virtual Edition
(AVE) on a Data Domain system. Checkpoints are system-wide backups taken for
disaster recovery of the Avamar server.
Storage of checkpoints on a Data Domain system is useful in environments that do not
have a secondary Avamar server and Data Domain system for replication, or in
environments where most backups are stored on a Data Domain system.
Restore of checkpoints from a Data Domain system requires assistance from Avamar
Professional Services.
Restore
The process of data recovery from a Data Domain system is transparent to the backup
administrator. The backup administrator uses the same Avamar recovery processes
that are native to current Avamar implementations.
Replication
Replication between primary and replica Data Domain systems is integrated into the
Avamar management feature set. This is configured in Avamar Administrator through
the Avamar replication policies applied to each dataset.
All typical Avamar replication scenarios are supported for datasets that use a Data
Domain system as a target, including:
l Many-to-one, one-to-many, cascading replication
l Extension of data retention times
l Root-to-root
Security
The connection between the Avamar client and the Data Domain system is encrypted
if you use Avamar 7.1 or later clients, Avamar 7.1 or later server(s) and DD OS 5.5.x or
later. Previous versions of software do not support data encryption between the client
and the Data Domain system. Backups from the Avamar client to the Avamar server
are always compressed and encrypted by default.
Use caution when granting users access to the Data Domain system. A user should not
be able to directly access the Data Domain system and manually delete data.
Token-based authentication
By using Data Domain Boost token-based authentication, Avamar establishes a secure
connection to a Data Domain system running DDOS 5.7 or greater without passing
user name and password information.
Two parameters control token-based authentication behavior:
l use_ddr_auth_token
To enable token-based authentication, set the use_ddr_auth_token parameter
in the mcserver.xml file on the Avamar server (/usr/local/
avamar/var/mc/server_data/prefs/mcserver.xml) to true. To disable
token-based authentication, set use_ddr_auth_token to false. Restart the
Management Console server after making this change.
Replication 19
Introduction
You can also set the amount of time that an authentication token is valid. Inside
the mcserver.xml file, the parameter is set to 36000 seconds (10 hours) by
default. Some backup and replication jobs, such as NDMP backups, might require
a longer duration for the authentication token to remain valid.
l extend-token-window-sec
This parameter controls the interval (in seconds) that is used to call the extend
token before it expires. Customize this setting in the ddrmaint.cmd file on the
Avamar server (/usr/local/avamar/var/ddrmaint.cmd). For example,
--extend-token-windows-sec=60
sets the interval to 60 seconds.
Note
After you set the value for this parameter, restart the service:
ddrmaint-service restart
start performing backups to the Data Domain system. When you change the backup
target to the Data Domain system, you must perform a full backup.
After you successfully perform a backup to the Data Domain system, you can delete
the earlier backups from the Avamar server. The Avamar Administration Guide provides
details on how to delete backups.
l Pre-integration requirements............................................................................. 24
l Preparing the Data Domain system for Avamar integration................................ 27
l Configuring IP support....................................................................................... 28
l Adding a Data Domain system............................................................................ 29
l Editing a Data Domain system............................................................................ 31
l Deleting a Data Domain system.......................................................................... 32
l Best practices for WAN backups........................................................................33
l System upgrades............................................................................................... 35
Pre-integration requirements
Ensure that the environment meets all system requirements before you integrate a
Data Domain system with Avamar.
Note
This chapter assumes the Avamar server and any Data Domain systems are installed
and configured.
Data Domain device type Avamar supports any Data Domain system
that supports the execution of the required
DD OS version.
Data Domain File System Enable Data Domain File System using either
the Data Domain System Manager or CLI.
After you enable file system operations, it may
take up to 10 minutes before Avamar
Administrator correctly reflects the status of
the Data Domain system, especially if the
Data Domain system is using the DD Extended
Retention option. Do not perform backups,
restores, or system maintenance operations
until the status appears correctly in Avamar
Administrator. Otherwise, the backups,
Note
When you enable DD Boost on the Data Domain device, DD Boost becomes the
preferred method of connectivity for any clients that are enabled for DD Boost. While
this method is acceptable for clients that can take advantage of DD Boost features, it
can result in performance degradation for other clients. Proper due diligence and
effective data gathering are keys to avoiding such interactions, especially during
upgrades.
Network requirements
The following sections list network requirements for Avamar and Data Domain system
integration.
Network throughput
Before integrating a Data Domain system with an Avamar server, ensure that enough
network bandwidth is available.
To obtain the maximum throughput available on a Data Domain system (for restores,
level zero backups, and subsequent incremental backups after a level-zero backup),
verify that the network infrastructure provides more bandwidth than the bandwidth
required by the maximum throughput of the Data Domain system.
Network configuration
Configure (or verify) the following network configuration:
l Assign a fully qualified domain name (FQDN) to each Data Domain system.
l Do not use IP addresses in place of hostnames when registering a Data Domain
system. This can limit the ability to route optimized duplication traffic exclusively
through a registered interface.
l Ensure that DNS on the Data Domain system is properly configured.
Network requirements 25
Avamar and Data Domain System Integration
l Ensure forward and reverse DNS lookups work between the following systems:
n Avamar server
n Data Domain system
n Backup and restore clients
l Use hosts files to resolve hostnames to non-routable IP addresses.
l Do not create secondary hostnames to associate with alternate or local IP
interfaces.
Wide area networks not supported
The Avamar server and all Data Domain systems must be on the same local network.
Do not connect the Avamar server and Data Domain systems over a Wide Area
Network (WAN). Configurations that use a WAN are not supported.
NTP requirements
Configure the Avamar server, all Avamar clients, and the Data Domain system to use
the same Network Time Protocol(NTP) server.
Licensing requirements
Ensure that the environment meets the licensing requirements in the following table.
Capacity requirements
Carefully assess your backup storage needs when evaluating how much data to store
on the Data Domain system and the Avamar server. Include estimates from data that
is sent to the Data Domain system from any other servers.
Review the capacity management information in the Avamar Administration Guide.
When the Data Domain system reaches its maximum storage capacity, no further
backups to the Data Domain system occur until additional capacity is added or old
backups are deleted.
Note
Avamar jobs are used for backups, restores, and replication. Avamar release 7.1 and
later integrated with a Data Domain system can support up to 336 jobs concurrently.
Each job can consist of multiple streams. Avamar release 7.1 and later integrated with
a Data Domain system supports a maximum of 500 streams (maxconn). The limits of
336 jobs/500 streams are fixed for all Avamar integrations with Data Domain systems
(Avamar Virtual Edition, Single Node Avamar, or Multi-Node Avamar). Avamar release
7.1 and later backing up to an Avamar Data Store supports the original number of jobs
per node (72) with a maximum 107 streams per node (maxconn).
the Avamar server to use to access the Data Domain system for backups and restores
(and replication, if applicable).
Note
DD OS 5.5 and later supports the use of multiple DD Boost accounts, which can be
used for segregation of accounts when multiple backup programs are sharing a
common Data Domain system.
Procedure
1. Disable DD Boost on the Data Domain system by logging in to the Data Domain
CLI as an administrative user and typing ddboost disable.
2. Create a DD Boost account and password:
a. Create the user account with admin privileges by typing the following
command:
user add user role admin
b. Set the new account as the DD Boost user by typing the following command:
ddboost set user-name user
Configuring IP support
The IP configuration depends on the versions of IP and DD OS in the environment. The
following topics provide details.
Note
b. In the DDBoost User Name box, type the username of the DD Boost
account for Avamar to use to access the Data Domain system for backups,
restores, and replication.
c. In the Password box, type the password for the account that Avamar should
use to access the Data Domain system for backups, restores, and
replication.
d. In the Verify Password box, type the password again to verify it.
e. If you have more than one Data Domain system associated with Avamar, you
can specify one Data Domain system to be the default replication storage.
Select Use system as default replication storage if this system is the
default replication storage.
f. To store checkpoints for a single-node Avamar server or Avamar Virtual
Edition (AVE) server on the Data Domain system instead of the Avamar
server, select the Use as target for Avamar Checkpoint Backups
checkbox.
g. Click Verify to view the maximum number of streams that the Data Domain
system supports.
h. Specify the maximum number of streams that Avamar can use at any one
time to perform backups and restores:
l To specify a defined number of streams, type the number in the Max
used by Avamar box.
l To specify a maximum number of streams based on the percentage of
the total number of supported streams, type the percentage in the Max
used by Avamar box and then select the As percentage of the max
limit checkbox.
Consider both the maximum number of streams that the Data Domain
system supports, as well as whether other applications are using streams to
send data to and receive data from the Data Domain system.
If the processes writing to and reading from the Data Domain system use all
available streams, then Avamar queues backup or restore requests until one
or more streams become available.
l The Getter/Setter Port Number box lists the port on the Data Domain
system from which to receive and on which to set SNMP objects. The
default value is 161.
l The SNMP Community String box lists the community string Avamar uses
for read-only access to the Data Domain system.
l The Trap Port Number box lists the trap port on the Avamar server. The
default value is 163.
7. To configure the cloud tier feature, click the Tiering tab.
Cloud tier is used by the Avamar software to move Avamar backup data from a
Data Domain system to the cloud.
8. Click OK.
A progress message appears.
9. When the operation completes, click Close.
Results
When you add a Data Domain system to the Avamar configuration, Avamar creates an
MTree on the Data Domain system for the Avamar server. The MTree refers to the
directory created within the DD Boost path. Data Domain systems support a maximum
of 100 MTrees. If you reach the limit, then you cannot add the Data Domain system to
the Avamar configuration.
checkpoint with the outdated Data Domain system name or DD Boost information,
then the rollback fails. The Avamar Administration Guide provides instructions on
creating and validating checkpoints.
2. Ensure that the Data Domain system is not the default replication storage
system.
Setting the default Data Domain destination provides details.
3. In Avamar Administrator, click the Server launcher button.
The Server window appears.
4. Click the Server Management tab.
5. Select the Data Domain system to delete.
6. Select Actions > Delete Data Domain System.
A confirmation message appears.
7. Click Yes.
A dialog box shows the progress of the operation.
8. When the deletion completes, click Close.
After you finish
Create and validate a new checkpoint. The Avamar Administration Guide provides
instructions on creating and validating checkpoints. If you perform a rollback to a
checkpoint with the deleted Data Domain system, then the Data Domain system is
restored to the configuration
Encryption in flight
When storing backups on or restoring data from a Data Domain system, you can
specify the encryption method for data transfer between the client and the Data
Domain system. The Encryption method to Data Domain system option appears in
the plug-in options during a backup or restore.
The following values are supported:
l Default
l None (clear text)
l Medium
l High
The default value is Default, which is high encryption. To edit the default value for the
option, edit the mcserver.xml file.
The following guidelines should be used for encryption best practices:
l For large backups or restores (for example, L0 backups) within the data center,
set encryption to Medium or None to improve performance.
l If you have desktop/laptop clients backing up over a WAN, set encryption to High.
Note
System upgrades
The Avamar and Data Domain upgrade path is very specific. Failure to upgrade
software in the proper order can cause Avamar maintenance functions to fail. If this
happens and the GSAN fails, then rollback operations fail.
When you are upgrading the DD OS, ensure that the DD OS version that you upgrade
to is compatible with both the current Avamar server version and the next Avamar
server version.
Upgrading the DD OS from 5.4.0.8 to 5.5 before you upgrade the Avamar server to
release 7.1 is desirable but not required. If you do not upgrade the DD OS to 5.5 before
you upgrade the Avamar server to release 7.1, then upgrade the DD OS immediately
afterward. Skipping any intermediate steps can create an incompatibility issue that
disrupts server operation.
You can upgrade a Data Domain system without product support, but you must open a
Service Request with Avamar Support before you upgrade the Avamar server. It is
recommended that you open an Avamar Service Request before you upgrade a Data
Domain system.
System upgrades 35
Avamar and Data Domain System Integration
ddboost enable
Note
Note
When you use the Avamar Plug-in for SQL Server and you perform a tail-log backup
during a restore, then the tail-log backup is always stored on the Avamar server.
l Overview of replication...................................................................................... 42
l Replication configurations..................................................................................42
l Replication data flow..........................................................................................45
l Replication schedule.......................................................................................... 45
l Configuring replication....................................................................................... 45
Replication 41
Replication
Overview of replication
The Avamar replication feature transfers data from a source Avamar server to a
destination Avamar server. When you use a Data Domain system with Avamar, then
the replication process transfers Avamar data from the source Data Domain system to
a destination Data Domain system.
If a Data Domain system is configured with a source Avamar server, then there must
be a corresponding Data Domain system configured with a destination server. If there
is no destination Data Domain system configured with the destination Avamar server,
then replication fails for backups on the source Data Domain system.
Figure 2 Data Domain basic replication
Replication configurations
If the source Avamar server uses more than one Data Domain system, then you can
use either a single destination Data Domain system or multiple destination systems.
Also, if the source Avamar server uses a single Data Domain system, then you can use
either a single destination Data Domain system or multiple destination systems. All of
the data is replicated through DD Boost.
For long-term backup retention requirements on destination Data Domain systems,
you can replicate from a source Data Domain system to destination Data Domain
system with DD Extended Retention.
The destination Data Domain system must be able accommodate the replicated data
from both source Data Domain systems.
In a configuration with multiple destination Data Domain systems, you can control
which system receives the data that replicates from the source Data Domain system
by mapping a domain on the source Avamar server to a destination Data Domain
system. Mapping a domain to a Data Domain system provides details.
Pool-based replication
Traditional Avamar replication occurs in serial, which can result in a long replication
window when the source and targets are both Data Domain systems. Pool-based
replication allows for multiple parallel replication backups from a Data Domain source
to a Data Domain target.
With traditional Avamar replication, replication is subject to a serial backup queue. This
does not guarantee that all backups can be replicated in a single day, if any single
backup takes longer to replicate than the desired recovery point objective (RPO). For
example, one backup could take 24 hours to replicate, thereby missing an 8 hour RPO.
With pool-based replication, Avamar can start as many backup replication operations
as necessary, thereby guaranteeing that the backups eventually reach their
destination at the desired RPO . However, due to potential bottlenecks in either
replicate throughput of Data Domain systems or the network throughput, it is
recommended that replication groups and clients that will be run in parallel should be
added one at a time until the desired throughput is achieved.
Pool-based replication is enabled during replication group configuration. Configuring
pool-based replication on page 47 provides instructions.
Pool-based replication can also be enabled with the avrepl command using the --
use-pool-based option. Additional options for the avrepl command you to
determine the order in which backups will be replicated and other information. The
Avamar Administration Guide contains information about the --use-pool-based
option with the avrepl command and related options.
Replication schedule
The replication of Avamar data on a Data Domain system occurs on the Avamar
replication schedule. You cannot schedule replication of data on the Data Domain
system separately from the replication of data on the Avamar server.
Configuring replication
Procedure
1. Configure replication from the source Avamar server to the destination Avamar
server by using Avamar Administrator.
The Avamar Administration Guide provides more information on configuring
Avamar replication.
2. If there is more than one destination Data Domain system, specify which Data
Domain system is the default destination.
Pool-based replication 45
Replication
3. If there is more than one destination Data Domain system, map the domains on
the source Avamar server to a destination Data Domain system.
Note
You cannot map the domains on the source Avamar server to a destination Data
Domain system until after the first replication. During the first replication, the data
replicates to the default destination.
Procedure
1. In Avamar Administrator, click the Data Movement Policy launcher button.
The Data Movement Policy window appears.
2. Click the Storage Mapping tab, and then click Add Domain.
The Select a Domain dialog box appears.
3. From the Map to Data Domain System list, select the Data Domain system to
use as the replication target.
4. Click OK.
the default destination system unless you create a new mapping to a different Data
Domain system.
Procedure
1. In Avamar Administrator, click the Data Movement Policy launcher button.
The Data Movement Policy window appears.
2. Click the Storage Mapping tab.
3. Select the mapping and click Delete.
A confirmation message appears.
4. Click Yes to confirm the mapping deletion.
Components of DD Cloud DR
The DD Cloud DR consists of the following components:
l The Cloud DR Add-on (CDRA), an on-premises DD Cloud DR virtual appliance that
manages deployment of the necessary infrastructure to the cloud, copying of
virtual machine backups to the cloud, and orchestrates the compression,
encryption and copying of the backed-up VM data to the cloud, in conjunction
with Cloud DR Server. A graphical interface is provided for managing depolyment
and configuring the Cloud DR Add-on environment. On-premises backup software
performs the actual backup of the virtual machines.
l The Cloud DR Server (CDRS), a DD Cloud DR service that runs in the customer's
domain on the public cloud and provides a graphical interface for disaster recovery
testing and failover.
Multiple Cloud DR Add-on appliances can connect to a single Cloud DR Server
instance. However, one Cloud DR Add-on appliance cannot connect to multiple
Cloud DR Server instances.
In addition to the DD Cloud DR software, the DD Cloud DR solution requires the
following components:
l An on-premises VMware vCenter environment, release 5.5 or greater.
l An on-premises supported backup solution. Currently, the supported backup
solution is Avamar release 7.5 or greater. Both the physical Avamar appliance and
the Avamar Virtual Edition (AVE) are supported.
l An on-premises Data Domain. Both the physical Data Domain system and Data
Domain Virtual Edition (DDVE) are supported.
DD Cloud DR architecture
The DD Cloud DR solution consists of two primary components: the Cloud DR Add-on
(CDRA) and the Cloud DR Server (CDRS).
Also deployed with CDRS and created in the customer's AWS domain are:
l A Virtual Private Cloud (VPC).
l An Amazon Relational Database Service (RDS) catalog, to maintain persistent
data.
l A private subnet for communication between the RDS and CDRS.
l A public subnet with internet access to be used by CDRS.
l The CDRS EC2 instance.
l A temporary Restore Service instance is launched in each region where recovery is
needed. This instance performs hydration during recovery, and is automatically
terminated after ten minutes of idle time.
DD Cloud DR architecture 51
Data Domain Cloud Disaster Recovery
Prerequisites
The following sections describe the prerequisites for the DD Cloud DR solution.
EU (Frankfurt) eu-central-1
EU (Ireland) eu-west-1
EU (London) eu-west-2
Limitations
The following limitations apply to the DD Cloud DR solution:
l For limitations in AWS support for importing VMs, see the AWS documentation at
http://docs.aws.amazon.com/vm-import/latest/userguide/vmie_prereqs.html
l Only VMware virtual machines are supported. Other virtual machines, such as
Microsoft Hyper-V, are not supported.
l You cannot change the names of AWS components, such as the EC2 instance, key
pairs, etc.
l Limitations in Avamar support:
n Ad-hoc backups of individual VMs is not supported. Only policy-based backups
can be used.
n Existing backups that do not have DD Cloud DR enabled cannot be converted
to DD Cloud DR-based backups. Only new backups created after DD Cloud DR
is enabled are supported.
l Version 17.3 provides protection for VM-level backups, including protection of
VSS-based Avamar backups for Microsoft applications.
Note
DD Cloud DR does not provide cloud protection for agent-based backups and
agent-based application consistency.
Note
Once the CDRA has been deployed, changing its IP address is not supported.
The navigation bar indicates the steps required to complete the configuration and
deployment process. The DD Cloud DR solution is fully deployed when these six steps
have been completed. The navigation bar provides links to each task. Tasks can be
completed in any order, except that you must connect to your cloud account and
create Cloud DR targets (Connecting to your cloud account and adding Cloud DR
targets on page 55) prior to deploying the Cloud DR Server (Deploying the Cloud DR
Server on page 56).
https://CDRA_hostname
Note
Results
The Cloud DR Add-on window opens with the Welcome page displayed.
Setting up CDRA
The Setup CDRA page of the Cloud DR Add-on window is used to configure
networking and other items for the CDRA.
Procedure
1. For Cloud DR Add-on name, enter a user-friendly name for the CDRA.
2. Enter the hostname or IP address for the primary and secondary DNS servers.
3. Enter the hostname or IP address for the primary and secondary NTP servers.
4. Select the time zone.
5. Click Save.
Procedure
1. Click Cloud Account on the top navigation bar.
The Connect to Your Cloud Account page displays.
2. Click Add Cloud Account.
3. In the Connecting to your AWS Cloud account dialog box, enter the access
key and the secret key for your AWS account. http://
docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-
keys.html contains information about obtaining the access and secret keys.
4. To copy the IAM policy, click Copy IAM Policy.
This copies to your buffer an XML version of the minimum AWS user account
permissions required for DD Cloud DR implementation, which can then be
applied to AWS to set the permissions policy for the AWS user. #unique_63 also
provides the IAM policy, as well as instructions for creating an AWS policy that
uses this IAM policy.
5. To view the Identity and Access Management (IAM) policy the represents the
minimum AWS user account permissions required for DD Cloud DR
implementation, click Show IAM Policy.
6. Click Verify & Save to save the AWS cloud account.
The CDRA will verify that the account exists before saving the cloud account
information and closing the Connecting to your AWS Cloud account dialog
box.
Note
Once you have provided credentials to an AWS account, you cannot change to
another AWS account.
a. Enter and confirm passwords for the CDRS Admin and CDRS Monitor users.
The passwords must:
l Be at least eight characters in length
l Must contain characters of a minimum of three of the following four
types:
n English uppercase: A-Z
n English lowercase: a-z
n Numerical character: 0-9
n Special (non-alphanumeric) characters
If the deployment is successful, the Cloud DR Server page displays, listing the
hostname of the CDRS host, and the region. Also deployed are:
l A Virtual Private Cloud (VPC).
l An Amazon Relational Database Service (RDS) catalog, to maintain
persistent data.
l A private subnet for communication between the RDS and CDRS.
l A public subnet with internet access to be used by CDRS.
l The CDRS EC2 instance.
The M4.Large instance type is used for the CDRS instance. To reduce
deployment costs, you may want to purchase reserved instances from AWS;
otherwise an on-demand instance will be used. An elastic IP is automatically
assigned to the CDRS instance. You cannot change the elastic IP assigned to
the CDRS.
Note
Results
Once the CDRS has been deployed, connect to the Cloud DR Server by clicking the
CDRS hostname.
Results
The Your vCenter Servers page lists vCenter servers that have been added to the
CDRA.
Note
If these settings are not configured, failback operations will fail. If you do not
configure these settings during initial DD Cloud DR configuration, you can return to
the Connect to Your vCenter Servers page at a later time to configure failback
information.
Procedure
1. At the Confirm vCenter's SSL Certificate dialog box in the Connect to Your
vCenter Server page, click Confirm & Define Failback Settings.
The Define Your Failback Staging Area dialog box displays.
2. Select one or more datastores or datastore clusters on the vCenter server.
After one or more datastores or datastore clusters have been selected, available
networks will be highlighted in the Networks pane.
3. Select one or more network as a location to for failback staging areas.
Selected networks must have connectivity to AWS.
4. For each selected network:
a. Highlight the network.
b. Enter the IP range pool by entering the first IP address in the pool, and a
number indicating how many IP addresses in that subnet are included in the
pool. Click the plus button to enter additional IP range pools.
c. Enter the network's Subnet mask.
d. Enter the network's default gateway for the Gateway.
5. Click Save.
2. Click the delete (trash can) icon next to the appropriate vCenter server.
3. Click Remove to confirm.
Note
Any individual Avamar server can only be connected to one CDRA at a time.
Connecting another CDRA to the Avamar server will cause the Avamar server to
disconnect from the previous CDRA.
Note
Note
Only policy-based backups can be used with DD Cloud DR. Ad-hoc backups of
individual VMs are not supported.
Procedure
1. Follow the instructions for creating or editing a backup group found in the
Avamar Administration Guide.
Note
You must select a dataset that has the Store backup on Data Domain system
checkbox enabled.
2. At the Enable DD Cloud DR page of the New Group wizard, select the Enable
DD Cloud DR checkbox.
3. Select the DD Cloud DR Target.
The DD Cloud DR Target is configured during CDRA configuration. Deploying
and Configuring DD Cloud DR on page 53 contains further information.
4. For the Cloud Retention Policy, select either:
l Copies to keep, and enter the maximum numbers of copies of the protected
VM that will be stored in the cloud for disaster recovery.
l Retention period, and select the amount of time that the copies will be
retained in the cloud for disaster recovery.
Note
CDRA will orchestrate the removal of copies from the cloud based on the cloud
retention policy entered here.
5. For the Last backup should not be older than option, select the maximum
interval between two backups that are copied to the cloud.
6. Complete the other information related to the group as described in the Avamar
Administration Guide and click Finish.
Results
After either an ad-hoc or scheduled group backup of the new group has been
performed, the copy will be listed as Remote-CDRA in the Restore tab of the
Backup, Restore and Manage window.
Note
When performing failovers, you must failover VMs in the appropriate order to insure
the proper functioning of servers and applications.
Procedure
1. In Avamar Administrator, click the Backup & Restore launcher button.
The Backup, Restore and Manage window appears.
2. Select Actions > Restore Now.
The Restore Options dialog box appears.
3. Locate the backup, as described in the Avamar Administration Guide.
4. Select All virtual disks in the Contents of Backup pane.
5. Right-click All virtual disks and select DR Now....
The Cloud DR Option dialog displays.
6. Select either Initiate DR Test or Initiate Failover.
7. Select the AWS network that will be used to launch the AWS instance of the
restored VM.
8. Click OK to begin the DR test or failover operation and click Yes to confirm.
Results
The progress of the restore operation can be viewed in the DR Activity Monitor tab
of the Activity Monitor window of Avamar Administrator.
Cloud Tier 65
Cloud Tier
b. For Filter, select either to tier all backups or to filter backup tiering by
excluding or including backups.
c. If backup filtering is selected, click Change Filter.
The Tier Filter Options dialog box opens.
d. For Backup Types, select the type of backup.
For example, if you want to limit tiering to only backups of type monthly,
deselect all the options except Monthly.
e. For Maximum backups per client, select how many existing backups will be
tiered to the cloud each time the schedule is run.
No limit will tier all backups of the type selected in Backup Types.
f. For Age Threshold, determine how long the backup will reside on the Data
Domain prior to being tiered to the cloud.
l The Younger option allows you to create a range; for example, you could
configure tiering for all backups that have been on the Data Domain
system for longer than 30 days, but less than one year.
Note
Data Domain requires that data reside on the Data Domain active tier for a
minimum of 14 days prior to being tiered to the cloud.
g. Click Next.
The Destination page appears, indicating the cloud unit that has been
configured for the selected Data Domain system.
h. Click Next.
The Expiration page appears.
i. Click Next.
The Schedule page appears.
j. Select a schedule and click Next.
Note
The schedule determines when and how often Avamar marks backups on the
Data Domain for tiering to the cloud. However, the actual movement of the
data from the Data Domain to the cloud is performed based on the Data
Domain's tier schedule.
k. Click Finish..
Note
When performing a File Level Recovery, the entire backup is recalled from the cloud
tier to the active tier. Depending the type of service you have with your cloud
provider, this may incur significant egress costs for moving the entire backup from the
cloud to the active tier, even if you are only attempting to restore a small number of
files.
DB2 restore and rollforward and SAP restore when using cloud tier
When a cloud tier policy is configured for DB2 and SAP plug-in backups, components
required to perform a restore and recovery operation may have been moved to the
cloud tier. This can cause failures for DB2 restore and rollforward through the Avamar
Administrator, and also for SAP CLI restore.
For the DB2 plug-in, the archive log backups that are needed for a restore and
rollforward through the Avamar Administrator might have been already moved to the
cloud tier. Initiating a restore and rollforward through the Avamar Administrator will
automatically trigger a recall of the full backup, but not for the archive logs. The
missing logs will cause the restore and rollforward to fail. The following error message
will be written to avdb2 log:
For the SAP plug-in, when the backup is already stored in the cloud tier, the restore
will fail with the following error message in the backint log:
where:
l Server-Name is the name of the Avamar server.
l Client-Name is the name of the Avamar client whose backups are being
recalled.
l Label-Num is the label number located in step 1.
Note
By default, the avtier logs will be generated in the following path: /usr/
local/avamar/var/client/
Note
If you experience a Data Domain or Avamar data loss, submit a service request to
Avamar Support. Support representatives manage the disaster recovery process.
Required Configurations
l To recover backups from the cloud, enable and run the Data Domain cloud tier
feature.
l To support recovering an Avamar server from the cloud, configure Data Domain
and the tier group so that checkpoint backups are tiered to the cloud. For details
on this process, see Configuring an Avamar server for recovery from the cloud on
page 70.
Limitations
There are some limitations inherent in the cloud tier disaster recovery feature:
l Data that has resided on the active tier for less than the 14-day minimum is not
tiered to the cloud and is not available for recovery from the cloud using the cloud
tier disaster recovery feature. However, you can recover from a disaster recovery
site by using the standard Avamar recovery workflows.
l Partial or intermediate backups that are not contained in the final snapshot backup
are not displayed as successful in Avamar Administrator. Such backups cannot be
tiered to or recovered from the cloud.
l Support for this feature is effective with the release of Data Domain OS 6.0.1.
l The feature does not support recovery of a multi-node Avamar server from the
cloud.
7. In the Groups tab, double-click the tier group that you want to configure, then
click Edit Group.
The Edit Tier Group window displays.
8. In the left-most pane of the Edit Tier Group window, select Overview to open
the Overview page in the right pane.
9. On the Overview page, click More Options to open the More Options dialog
box.
10. In the dialog box, select Tier checkpoint backup, then click OK.
The Avamar checkpoint backup can now be tiered to the cloud.
moved to cloud. It is generally also possible to restore older backups from the
cloud tier.
l When performing both replication and tiering, replicate the backup first before
performing tiering. This will prevent data recalls from the cloud tier, as data can
only be replicated from an active tier to active tier.
l Using the Data Domain M-Tree data movement policy to move Avamar backups to
the cloud is not supported. Avamar backups should be tiered to the cloud using the
Avamar software to configure tier groups and perform tier operations. Otherwise
the Avamar software will be unaware of the location of the backups in the cloud
and unable to perform recoveries or manage policies for those backups.
Limitations
l Cancelling a tier operation from the Avamar software, once the tier operation has
been started, is not supported.
l Cancelling a recall operation from the Avamar software during recovery is not
supported.
l Restore operations from the MCCLI are not supported.
l Restore operations from the Avamar REST API are not supported.
l When performing a File Level Recovery, the entire backup is recalled from the
cloud tier to the active tier. Depending on the type of service you have with your
cloud provider, this may incur significant egress costs for moving the entire
backup from the cloud to the active tier, even if you are only attempting to restore
a small number of files.
l Avamar Desktop/Laptop does not currently support the Avamar cloud tier feature.
3. To stop or start the service, right-click the service and select Stop Data
Domain SNMP Manager or Start Data Domain SNMP Manager, respectively.
Option Description
To view activities for all Data Domain systems Select All Systems.
Monitoring activities
You can monitor recent backup, restore, and validation activities by using the Activity
Monitor in Avamar Administrator. The Server column in the Activity Monitor lists the
server, either the Avamar server or the Data Domain system, on which the activity
occurred.
The Activity Monitor displays the most recent 5,000 client activities during the past
72 hours. You can filter the Activity Monitor to view only activities for data on a Data
Domain system.
Procedure
1. In Avamar Administrator, click the Activity launcher button.
The Activity window appears.
2. Click the Activity Monitor tab.
3. Select Actions > Filter.
The Filter Activity dialog box appears
4. Select Data Domain Systems from the Source list.
5. Select the Data Domain systems.
Option Description
To view activities for all Data Domain systems Select All Systems.
Note
When the Data Domain system reaches 99 percent capacity, maintenance operations
fail. The best practice recommendation is to limit Data Domain capacity usage to 80
percent.
Procedure
1. In Avamar Administrator, click the Server launcher button.
The Server window appears.
2. Click the Server Management tab.
3. Select the Data Domain system from the tree in the left pane.
Data Domain system details appear in the right pane.
Field Description
Total Capacity (post-comp size) The total capacity for compressed data on the
Data Domain system.
Server Utilization (post-comp use%) The percentage of capacity used on the Data
Domain system for any reason after
compression of the data.
File System Available (post-comp avail) The total amount of disk space available for
compressed data in the Data Domain File
System.
File System Used (post-comp used) The total amount of disk space used in the
Data Domain File System for compressed
data.
Default Replication Storage System Specifies if the Data Domain system has been
configured as the Default Replication Storage
System.
Target for Avamar Checkpoint Backups Specifies if the Data Domain system is a
target for Avamar checkpoint backups. This
option is only available for single-node Avamar
servers and AVE.
Replication monitoring
To monitor replication activity in Avamar, including replication activities associated
with a Data Domain system, use either the Activity Monitor or the Replication Report.
Activity Monitor
The Activity Monitor in Avamar Administrator provides a list of recent replication
activities. If you select a Replication Source or Replication Destination activity, and
then select Actions > View Statistics, you can view additional statistics about the
replication, including:
l A list of backups that were replicated
l The clients associated with the replicated backups
l The scheduled start and end times for the replication
l The actual start and end times for the replication
l A list of any errors that occurred
The Avamar Administration Guide provides more information on how to access the
Activity Monitor and the available statistics.
Replication Report
The Replication Report in Avamar Administrator also provides details on recent
replication activities. You can filter the report to view only replication activities
associated with a Data Domain system.
Troubleshooting 79
Troubleshooting
If one of the icons in the previous table appears in the status bar, you can view more
detailed status information for the Data Domain system on the Server Management
tab in the Server window.
Procedure
1. In Avamar Administrator, click the Server launcher button.
The Server window appears.
2. Select the Server Management tab, and then select the Data Domain system
in the tree.
The Monitoring Status row in the right pane provides detailed status of the
Data Domain system.
OK No resolution is required.
SNMP Getter/Setter disabled Use the Data Domain SSH CLI to enable
SNMP by typing snmp enable.
Unable to get CPU, disk, and Use the Data Domain SSH CLI to enable
network statistics data SNMP by typing snmp enable.
Unable to get CPU and disk Use the Data Domain SSH CLI to enable
statistics data SNMP by typing snmp enable.
Unable to get network Use the Data Domain SSH CLI to enable
statistics data SNMP by typing snmp enable.
Unable to get file system Use the Data Domain SSH CLI to enable
statistics data SNMP by typing snmp enable.
Error invoking ssh cli command Review the system log files to determine the
cause of the problem. You should also review
the DD OS Command Reference Guide.
File system disabled Use the Data Domain SSH CLI to enable Data
Domain file system operations by typing
filesys enable.
When the Data Domain file system is disabled,
Avamar cannot perform backups to and
restores from the device.
After you enable file system operations, it
might take as long as 10 minutes before
Avamar Administrator correctly reflects the
status of the Data Domain system, especially
if the Data Domain system is a DD Extended
Retention. Do not perform backups, restores,
or system maintenance operations until the
status appears correctly in Avamar
Administrator. Otherwise, the backups,
restores, or system maintenance operations
might fail.
Unable to get SNMP file system Verify that the SNMP getter/setter port is
status valid. This is the port that you specified when
you added the Data Domain system to the
Avamar configuration.
Failed to authenticate ssh cli Verify that the SSH public/private key pair
connection with ssh key was set up correctly on both the Avamar
server and the Data Domain system. Re-
creating the SSH public/private key pair
provides more information.
Failed to authenticate SSH CLI Verify that the DD Boost user credentials are
connection with credentials correct. The credentials are the username and
password that you specified when you added
the Data Domain system to the Avamar
configuration.
Unable to retrieve ssh key Verify that the SSH public/private key pair is
file pair set up correctly on both the Avamar server
and the Data Domain system, and that the
public key is copied to the correct location on
the Data Domain system. Re-creating the
SSH public/private key pair provides more
information.
Unable to retrieve ssh public Verify that the SSH public/private key pair
key file was set up correctly on both the Avamar
server and the Data Domain system, and that
Unable to retrieve ssh private Verify that the SSH public/private key pair
key file was set up correctly on both the Avamar
server and the Data Domain system. Re-
creating the SSH public/private key pair
provides more information.
DDBoost user disabled Use the Data Domain SSH CLI to enable the
DD Boost user by typing user enable
username, where username is the username
of the DD Boost user.
When the DD Boost user is disabled, Avamar
cannot perform backups and restores to and
from the device.
DDBoost user changed on Data If you edited the DD Boost user account
Domain system information on the Data Domain system, then
you must edit the DD Boost user account
information in the Data Domain configuration
on the Avamar server.
When you edit the DD Boost user account
information in Avamar Administrator, the SSH
key may fail. To resolve this issue, re-add the
SSH key using the instructions in Re-creating
the SSH public/private key pair.
DDBoost option disabled Use the Data Domain SSH CLI to enable DD
Boost by typing ddboost option set
distributed-segment-processing
enabled.
Backups continue when DD Boost is disabled.
However, performance decreases.
DDBoost not licensed Use the Data Domain SSH CLI to add the
license for DD Boost by typing license add
license, where license is the license code.
Invalid SNMP port Verify that you specified the correct getter/
setter port when you added the Data Domain
system to the Avamar configuration, and
ensure that the getter/setter port is open on
the Data Domain system by typing snmp
show trap-hosts.
Invalid SNMP trap host or trap Use the Data Domain SSH CLI to verify that
port the Avamar server is configured as a trap host
on the Data Domain system by typing snmp
show trap-hosts.
If necessary, use the Data Domain SSH CLI to
add the Avamar server as a trap host on the
Data Domain system by typing snmp add
trap-host hostname, where hostname is
the hostname of the Avamar server. By
default, port 163 is used.
Verify that you specified the correct trap port
when you added the Data Domain system to
the Avamar configuration.
Invalid SNMP community string Use the Data Domain SSH CLI to verify the
SNMP community string by typing snmp
show ro-communities.
Verify that you specified the correct SNMP
community string when you added the Data
Domain system to the Avamar configuration.
Error getting SNMP objects Review the system log files to determine the
cause of the problem. Search the Data
Domain knowledgebase for the error message.
SNMP trap manager is not Start the Data Domain SNMP Manager
running service:
Invalid host, user name, or Ensure that you specified the hostname or IP
password address of the Data Domain system, the DD
Boost username, and password. Attempt to
log in to the Data Domain system with the
specified username and password. Verify that
the Avamar server can ping the Data Domain
system.
Monitoring status
When the monitoring status on the Server Management tab in the Server window in
Avamar Administrator is a value other than OK, additional information appears in a list
below the Monitoring Status.
The following table describes status messages and provides resolutions if the status
indicates a problem.
l SNMP Disabled
Monitoring status 85
Troubleshooting
l File System Enabled When the Data Domain file system is disabled,
Avamar cannot perform backups to and
l File System Disabled restores from the device.
l File System Unknown If the value is File System Disabled,
l File system status unknown then use the Data Domain SSH CLI to enable
Data Domain file system operations by typing
since SNMP is disabled
filesys enable.
If the value is File system status
unknown since SNMP is disabled,
then use the Data Domain SSH CLI to enable
SNMP by typing snmp enable.
If the value is File System Unknown,
then verify that the SNMP getter/setter port
is valid. This is the port that you specified
when you added the Data Domain system to
the Avamar configuration.
If you enable file system operations, it may
take as many as 10 minutes before Avamar
Administrator correctly reflects the status of
the Data Domain system, especially if the
Data Domain system is a DD Extended
Retention. Do not perform backups, restores,
or system maintenance operations until the
status appears correctly in Avamar
Administrator. Otherwise, the backups,
restores, or system maintenance operations
may fail.
Collection. These operations may fail because they involve directory renames,
which are not allowed on a full Data Domain system.
Procedure
1. Determine the source of the data that is using the storage. The data may be
from a specific client, a group of clients associated with a specific Avamar
server, or a different backup product that stores data on the Data Domain
system.
2. Cancel any backups that are in progress:
a. In Avamar Administrator, click the Activity launcher button.
b. In the Activity window, click the Activity Monitor tab.
c. Select the backups, and then select Actions > Cancel Activity.
d. Click Yes on the confirmation message.
3. Suspend backups and restores:
a. In Avamar Administrator, click the Server launcher button.
b. In the Server window, click the Server Management tab.
c. In the tree pane, select the Avamar server node of the tree.
d. Select Actions > Suspend Backups/Restores.
e. Click Yes on the confirmation message.
4. Suspend server maintenance operations on the Avamar server:
a. In Avamar Administrator, select Tools > Manage Schedules.
b. In the Manage All Schedules window, click Suspend All.
5. On the Data Domain system, manually delete the existing STAGING, DELETED,
or cur/DELETED directories for the Avamar server.
6. Use Data Domain Enterprise Manager to initiate the Data Domain file system
cleaning operation.
This process should free enough space to enable Avamar server maintenance
operations to successfully complete.
7. Restart server maintenance operations on the Avamar server:
a. In Avamar Administrator, select Tools > Manage Schedules.
b. In the Manage All Schedules window, click Resume All.
8. Restart backups and restores:
a. In Avamar Administrator, click the Server launcher button.
b. In the Server window, click the Server Management tab.
c. In the tree pane, select the Avamar server node of the tree.
d. Select Actions > Resume Backups/Restores.
e. Click Yes on the confirmation message.
9. After server maintenance operations completes, you might need to perform the
following tasks to reclaim storage space on the Data Domain system:
l Delete backups.
l Delete checkpoints.
l Run Avamar Garbage Collection.
l Run the Data Domain file system cleaning operation.
This command sets ddr_key as the file name for the key. There is no
passphrase for the key.
4. Log in to the Data Domain system by typing the following command:
ssh Avamar_ostuser@dd_system
where Avamar_ostuser is the name of the DD Boost user for Avamar on the
Data Domain system, and dd_system is the name of the Data Domain system.
5. Add the SSH public key to the SSH authorized keys file on the Data Domain
system by typing the following command:
adminaccess add ssh-keys user Avamar_ostuser
6. Copy and paste the public key, which is the contents of the file ddr_key.pub,
in /home/admin/.ssh:
a. Open a second command shell and log in to the utility node of the Avamar
server as admin.
b. Change to the .ssh directory by typing cd ~/.ssh.
c. Display the ddr_key.pub file by typing cat ddr_key.pub.
d. Select and copy the contents of the file.
e. Return to the first command shell window.
f. Paste the contents of the file in /home/admin/.ssh.
7. Enter the key by pressing Ctrl+D.
8. Switch user to root by typing su -.
10. Copy the private key to /home/admin/.ssh/ddr_key, which is the path and
name specified by ddr_ssh_key_path_name in the mcserver.xml file, by
typing the following command:
cp /home/admin/.ssh/ddr_key .
where:
l path/ddr_key is the path and filename of the key.
l Avamar_ostuser is the name of the DD Boost user for Avamar on the Data
Domain system.
l dd_system is the name of the Data Domain system.
--ddr-auth-enabled=false
--ddr-auth-mode=3
This will force certificate authentication for metadata backups to the Avamar server
while allowing backups to the Data Domain to succeed.
Avamar Administrator A graphical management console software application that is used to remotely
administer an Avamar system from a supported Windows or Linux client computer.
Avamar client A computer or workstation that runs Avamar software and accesses the Avamar server
over a network connection. Avamar client software comprises a client agent and one or
more plug-ins.
Avamar server The server component of the Avamar client/server system. Avamar server is a fault-
tolerant, high-availability system that efficiently stores the backups from all protected
clients. It also provides essential processes and services required for data restores,
client access, and remote system administration. Avamar server runs as a distributed
application across multiple networked storage nodes.
backup A point-in-time copy of client data that can be restored as individual files, selected data,
or as an entire backup.
checkpoint A server backup taken for the express purpose of assisting with disaster recovery of the
Avamar server.
client A computer or workstation that runs Avamar software and accesses the Avamar server
over a network connection. Avamar client software consists of a client agent and one or
more plug-ins.
Data Domain system Disk-based deduplication appliances and gateways that provide data protection and
disaster recovery (DR) in the enterprise environment.
dataset A policy that defines a set of files, directories, and file systems for each supported
platform that are included or excluded in backups across a group of clients. A dataset is
a persistent and reusable Avamar policy that can be named and attached to multiple
groups.
DD Boost DD Boost is the API that Avamar clients use to access a Data Domain system. The DD
Boost API is installed automatically on the client computer when you install the Avamar
client. It is also installed automatically on the Avamar server when you install Avamar.
DD OS Data Domain Operating System (DD OS) is the internal operating system on the Data
Domain system. The DD OS provides both a command line interface (CLI) for
performing all system operations and the Enterprise Manager (a graphical user
interface, or GUI) for some configuration operations, management, and monitoring.
ddrmaint utility Installed on the utility node of a multi-node server (or the single node of a single-node
server), this utility implements all required operations on the Data Domain system on
behalf of the Avamar server. It is not installed on the storage nodes of the Avamar
server.
The ddrmaint utility also uses the DD Boost to connect to a Data Domain system. The
DD Boost is installed with the ddrmaint utility automatically when you install Avamar.
MCS Management console server. The server subsystem that provides centralized
administration (scheduling, monitoring, and management) for the Avamar server. The
MCS also runs the server-side processes used by Avamar Administrator.
plug-in Avamar client software that recognizes a particular kind of data resident on that client.
plug-in options Options that you specify during backup or restore to control backup or restore
functionality.
policy A set of rules for client backups that can be named and applied to multiple groups.
Groups have dataset, schedule, and retention policies.
replication Replication is an optional feature that enables an Avamar system to store read-only
copies of its data on a remote system. The replicated data can be replicas of client
backups and copies of Avamar system data. Replication supports disaster recovery of
the Avamar system.
restore An operation that retrieves one or more file systems, directories, files, or data objects
from a backup and writes the data to a designated location.
retention The time setting to automatically delete backups on an Avamar server. Retention can be
set to permanent for backups that should not be deleted from an Avamar server.
Retention is a persistent and reusable Avamar policy that can be named and attached to
multiple groups.