Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Security and Encryption Guide
  3. Section I. Identity and access management
  4. Enhanced Auditing
  5. Configuring Enhanced Auditing
  6. Changing a server across NetBackup domains
NetBackup™ Security and Encryption Guide

Changing a server across NetBackup domains

For Enhanced Auditing, when you perform a Change Server operation from a primary or media server in one NetBackup domain to a host (primary or media server or client) in another NetBackup domain, you must execute additional steps on each NetBackup server. You must also set up a trust on both primary servers.

Note:

Executing these steps is a one-time activity.

The following steps help you to change the server and set up the trust on both primary servers.

To change server from a primary to primary server

  1. We have two NetBackup domains, NetBackup Domain 1 and NetBackup Domain 2.

    Consider two primary servers, Primary_nbu_dom1 and Primary_nbu_dom2. Primary_nbu_dom1 has media servers Media1_nbu_dom1, Media2_nbu_dom1, MediaN_nbu_dom1, and a set of clients. Similarly, Primary_nbu_dom2 has media servers Media1_nbu_dom2, Media2_nbu_dom2, MediaM_nbu_dom2, and a set of clients as shown in the image:

    The user is connected to one of the servers in NetBackup Domain 1 (either primary or media), for example, Primary_server_nbu_dom1, and wants to do a change server to one of the hosts on NetBackup Domain 2, for example Host_nbu_dom2. It is mandatory that both the primary servers (Primary_nbu_dom1 and Primary_nbu_dom2 here) establish a trust. Host_nbu_dom2 must set up a trust with Primary_server_nbu_dom1.

  2. To set up the trust, you must invoke a set of commands on UNIX and Windows:

    On UNIX and Linux:

    /usr/openv/netbackup/sec/at/bin/vssat setuptrust - b

    Master_server_nbu_dom1:1556:nbatd -s high on Host_nbu_dom2.

    On Windows:

    install_path\NetBackup\sec\at\bin\vssat.bat

  3. You must add an additional server entry in Host_nbu_dom2 for the Master_server_nbu_dom1 in the bp.conf file. Run the following command:

    SERVER = Master_server_nbu_dom1 /*this should __not__ be the first SERVER entry*/

    You can also add the additional server entry by connecting to the target primary server through the NetBackup Administration Console.

  4. The host that has the NetBackup Administration Console or the remote administration console is also required to trust the X.509 NBATD certificate on the Master_server_nbu_dom2.

    The trust can be set up by directly connecting to the Primary_server_nbu_dom2primary server through the GUI.

    You can also invoke /usr/openv/java/sec/at/bin/vssat setuptrust -b

    Master_server_nbu_dom2:1556:nbatd -s high on the NetBackup Administration Console host.

Feedback

Was this page helpful?
Previous

Connecting to a media server with Enhanced Auditing

Next

Configuration requirements if using Change Server with NBAC or Enhanced Auditing

Feedback

Was this page helpful?