Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. Veritas NetBackup™ Cloud Administrator's Guide
  3. About the cloud storage
  4. About the Amazon S3 cloud storage API type
  5. Protecting data with Amazon Snowball and Amazon Snowball Edge
  6. Configuring NetBackup for Amazon Snowball Edge with S3 API interface
Veritas NetBackup™ Cloud Administrator's Guide

Configuring NetBackup for Amazon Snowball Edge with S3 API interface

When you backup data to the Amazon Snowball Edge device using the S3 interface, data is moved directly from the source to the Amazon Snowball Edge device using the Amazon S3 adapter.

To configure NetBackup to transfer data to Amazon Snowball Edge using S3 API interface

  1. Configure the Amazon Snowball Edge device using the Amazon Snowball client.
  2. Create a temporary storage server (non-CloudCatalyst) and disk pool to create or list the buckets that you plan to use for the device import job.

    Note:

    It is recommended to create the buckets from the NetBackup Administration Console. However, if you create buckets from the AWS console, ensure that only characters that are supported by NetBackup are used.

  3. Delete the temporary storage server (non-CloudCatalyst) and disk pool.
  4. Create an import job in the AWS console. Refer to the AWS documentation for detailed steps.
  5. Configure the Amazon Snowball Edge device using the Amazon Snowball client.
  6. (Optional) To use SSL protocol for communication with the Amazon Snowball Edge, get the certificate using the Amazon snowball client and append the certificate as it is to /usr/openv/var/global/wmc/cloud/cacert.pem file on the media server. Ensure that the format and length of the newly copied certificate matches with the existing certificates in cacert.pem.

    See Configuring SSL for Amazon Snowball and Amazon Snowball Edge.

  7. Add a custom instance for the device.

    See Adding a cloud storage instance.

    Set the custom instance's cloud storage properties with details of the host on which you have installed the Amazon Snowball S3 adapter.

    Set the following in the General Settings tab:

    • Provider type: Amazon or Amazon GovCloud depending upon the end point for which you have ordered the device.

    • Service host: IP or host name

    • Service endpoint: Leave blank

    • HTTP Port: Default is 8080. Or enter the port you have configured.

    • HTTPS port: Default is 8443. Or enter the port you have configured.

    • Endpoint access style: Path Style

    Set the following in the Region Setting tab:

    • Location constraint: Region from where you have ordered the device.

    • Service host: IP or host name

    Note:

    An Amazon Snowball Edge device can be used to transfer data only from the region from where the device is obtained. Thus, use the location constraint and service host of the region from where the device is obtained.

  8. Create a storage server for the device using the custom instance.

    See Configuring cloud storage in NetBackup.

  9. Update the following storage server property:

    AMZ:OFFLINE_TRANSFER_MODE: PROVIDER_API

    See NetBackup cloud storage server connection properties.

  10. For live data, create the storage lifecycle policy, backup policy and run the backup for initial seeding.

    For old data, use the bpduplicate command and duplicate the images on the storage unit.

    See the NetBackup Commands Reference Guide.

  11. After the data transfer is complete:
    • Deactivate the backup policy or postpone the secondary operation processing in the SLP till the device is in transit.

    • Set the storage server property you have configured to NONE.

    • Save the properties you need this information during the post-backup process.

      Take an image capture of storage server properties from Administration console or use nbdevconfig -getconfig command. See the NetBackup Commands Reference Guide.

      Also, note down the object size (for non-CloudCatalyst) that was configured.

  12. Ship the device to the cloud vendor. Refer to the AWS documentation for detailed steps.

Note:

After backups are imported into the cloud bucket, before restore you need to perform the post backup procedures. See Post backup procedures if you have used S3 API interface.

Feedback

Was this page helpful?
Previous

Configuring NetBackup with Amazon Snowball Edge with file interface

Next

Configuring NetBackup for Amazon Snowball and Amazon Snowball Edge for NetBackup CloudCatalyst Appliance

Feedback

Was this page helpful?