Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. Veritas NetBackup™ Administrator's Guide, Volume I
  3. Section II. Configuring hosts
  4. Configuring Host Properties
  5. Firewall properties
Veritas NetBackup™ Administrator's Guide, Volume I

Firewall properties

The Firewall properties describe how the selected master servers and media servers connect to legacy services running on that NetBackup host.

Servers are added to the host list of the Firewall properties. To configure port usage for clients, see the Client Attributes properties.

Figure: Firewall dialog box

Firewall dialog box

The Firewall dialog box contains the following properties.

Table: Firewall dialog box properties

Property

Description

Default connect options

By default, NetBackup selects firewall-friendly connect options under Default connect options. However, the default options can be set differently for individual servers under Attributes for selected Hosts.

By default, the firewall settings are configured to require the fewest possible ports to be open.

These properties correspond to the DEFAULT_CONNECT_OPTIONS configuration option.

To change the default connect options for the selected server, click Change.

Click Change to change the Default connect options. Change the Firewall properties in the Default Connect Options dialog box.

Note:

If VNETD only is selected as the Daemon connection port, the BPCD connect back setting is not applicable. If VNETD only is selected as the Daemon connection port, Use non-reserved ports is always used regardless of the value of the Ports setting.

Hosts list

To change the default connect options for any host name, add the host name to the host list. Servers do not automatically appear on the list.

  • Add option

    Click Add to add a host entry to the host list. A host must be listed before it can be selected for configuration.

  • Add to all option

    Click Add to All to add the listed hosts (along with the specified properties) to all hosts that are selected for host property configuration. (That is, the hosts that are selected upon opening the Host Properties.)

  • Remove option

    Select a host name in the list, then click Remove to remove the host from the list.

Attributes for selected hosts

Connect options can be configured for individual servers.

These properties correspond to the CONNECT_OPTIONS configuration option.

BPCD connect back

This property specifies how daemons are to connect back to the NetBackup Client daemon (BPCD) as follows:

  • Use default connect options (An option for individual hosts)

    Use the methods that are specified under Default connect options.

  • Random port

    NetBackup randomly chooses a free port in the allowed range to perform the traditional connect-back method.

  • VNETD port

    This method requires no connect-back. The Veritas Network Daemon (vnetd) was designed to enhance firewall efficiency with NetBackup during server-to-server and server-to-client communications. The server initiates all bpcd socket connections.

    Consider the example in which bpbrm on a media server initially connects with bpcd on a client. The situation does not pose a firewall problem because bpbrm uses the well-known PBX or vnetd port.

Ports

Select whether a reserved or non-reserved port number should be used to connect to the host name:

  • Use default connect options (An option for individual hosts)

    Use the methods that are specified under Default attributes.

  • Reserved port

    Connect to the host name by a reserved port number.

  • Use non-reserved ports

    Connect to the host name by a non-reserved port number.

Daemon connection port

This option only affects connections to NetBackup 7.0 and earlier. For connections to NetBackup 7.0.1 and later, the veritas_pbx port is used.

If configuring connections for NetBackup 7.0 and earlier, select the Daemon connection port method to use to connect to the server:

  • Use default connect options (An option for individual hosts)

    Use the methods that are specified under Default connect options.

  • Automatic

    The daemons on the server are connected to by vnetd if possible. If it is not possible to use vnetd, the daemon's traditional port number makes the connection.

  • VNETD only

    The daemons on the server are connected to by vnetd only. Select this property if your firewall rules prevent connections to the server by the traditional port number.

  • Daemon port only

    The daemons on the server are connected to by the traditional port number only.

Note:

If vnetd only is selected as the Daemon connection port, the BPCD connect back setting is not applicable. If vnetd only is selected as the Daemon connection port, Non-reserved port is always used regardless of the value of the Ports setting.

Defaults

Set property settings back to the defaults.

More Information

Client Attributes properties

Feedback

Was this page helpful?
Previous

About Linux concurrent FT connections

Next

Enabling logging for vnetd

Feedback

Was this page helpful?