Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Security and Encryption Guide
  3. Section II. Encryption of data-in-transit
  4. Configuring data-in-transit encryption (DTE)
  5. About the data channel
NetBackup™ Security and Encryption Guide

About the data channel

Data communication consists of the data that is backed up using NetBackup. The security policies require the Backup Administrators to ensure that the channel on which NetBackup clients send metadata and data to NetBackup servers be secure. In NetBackup 10.0 and later, the data and metadata are encrypted over the wire. This feature is referred to as data channel encryption or data in-transit encryption (DTE).

The following channels are classified as data channels:

  • Tar stream - client to media server: Over this channel, the tar / data stream flows between the client and the media server. During a backup operation, the media server receives the data from the client and sends it to storage (for example, an OST plug-in). The direction is reversed during a restore.

  • Tar stream - media server to media server: This channel is used during duplication.

  • Catalog information - client to media server: Over this channel, the catalog information and control commands are transferred between the client and the media server. The amount of data that is transmitted over this channel is proportional to the number of files and directories that are part of the backup. The media server sends the catalog information that the client has sent to the primary server.

  • Catalog information - media server to primary server: Over this channel, the catalog information is transferred from the media server to the primary server.

Note:

After NetBackup 10.0 installation or upgrade, the data in-transit encryption is off by default. However, you can configure data in-transit encryption at various levels: global level (primary server-level) and client level.

Feedback

Was this page helpful?
Previous

Configuring data-in-transit encryption (DTE)

Next

Data-in-transit encryption support

Feedback

Was this page helpful?