Forum Discussion

liuyang's avatar
liuyang
Level 6
13 years ago

Back up servers in DMZ

HI, our master and media servers are NBU 7.1 on Windows 2008 R2. We have a few web servers which are in DMZ. My question is: is there a safe way to back up servers in DMZ? What are the best practice? Thanks in advance. 

  • TCP/IP need port connectivity to function. Two choices:

    1. Open ports to get backups working. Open ports between server and client only.
    2. Add total separate backup infrastructure for DMZ - separate master/media server with own backup devices to backup DMZ clients.

8 Replies

  • Open ports 13724 (vnetd) and 1556 (pbx) between server(s) and client(s) in both directions.

    If ALL_LOCAL_DRIVES is specified in Policy or if policy type is database agent. ensure ports are open between master and client as well as media server(s) and client.

    See http://www.symantec.com/docs/TECH136090 .

  • Hi Marianne, thanks for your replies. Our main concern is security. The servers in DMZ are web servers. Currently the master/media servers are in our internal network. We worried that if we open ports for these servers in DMZ, someone may be able to access our internal network by using using these ports. Are there any recommendations for this?

  • TCP/IP need port connectivity to function. Two choices:

    1. Open ports to get backups working. Open ports between server and client only.
    2. Add total separate backup infrastructure for DMZ - separate master/media server with own backup devices to backup DMZ clients.
  • See the ports chapter of the security guide http://www.symantec.com/business/support/index?page=content&id=TECH127044
  • You can also do SAN based backup if these DMZ server are on your production SAN.

  • TCP Comms wrt initial connection to start backup plus metadata transfer via the network is still needed.

  •  Lotus notes backup failing with error 9(client server) ---------an extension package is needed, but was not installed( AIX 5-veritas version 6.5.4)

    Master server version solaris 10 (veritas netbackup 6.5.4)

    Can any one help me out of this  please.

  • ... Are there any recommendations for this?

     

    Pretty much the same as for your web services: allow only trusted IPs to use known TCP ports. 

    Marianne's 'two choices' post from Oct 31 lays out the options.