MSDP backup and restore
Data-in-transit encryption (DTE) feature is now integrated with MSDP storage server for backup and restore workflows.
For backup on MSDP disk pool, the encryption of data path from client to media server is controlled by the NetBackup DTE settings (global and client DTE modes).
If the MSDP storage server has multiple load balancing servers attached to it, the storage server and the load balancing media servers should be 10.0 or later to successfully encrypt data-in-transit. If, some of these servers are earlier than 10.0, data may flow in plain text and job will always pass, even if DTE was be honored.
In case of mixed environment, where either storage server or one of the load balancing media servers is earlier than 10.0, the following configuration will be required in order to honor an end-to-end encryption:
DTE should be enabled from NetBackup side based on DTE configurations i.e. Global/Media Server/Client Settings
Encryption should be enabled from MSDP side using ENCRYPTION flag in pd.conf
See the NetBackup Deduplication Guide for details on enabling the encryption using MSDP.
Note:
If data-in-transit encryption is enabled in NetBackup, but the ENCRYPTION flag in pd.conf is not enabled, the data path from load balancing media server to storage server is not encrypted. However, the DTE mode in the job and the image may be On.
If data-in-transit encryption is enabled in NetBackup and the ENCRYPTION flag in pd.conf is also enabled, MSDP encryption takes the precedence over NetBackup DTE. This results in data-at-rest encryption and not in data-in-transit encryption.