Top
ETERNUS SF Storage Cruiser V16.3 Operation Guide
FUJITSU Storage

6.6.1 Overview of Functions

6.6.1.1 About NAS Management

6.6.1.1.1 Basic System Configuration

This section explains a basic system configurations required when operating NAS of the ETERNUS Disk storage system.

Figure 6.1 Basic System Configuration Diagram

Configuration of NAS is performed from the Management Server.
Connect the Management Server and the ETERNUS Disk storage system with a management LAN. Access to the Management Server is performed from either the Management Server or the Web Console of a terminal within a network capable of HTTPS communication with the Management Server.

The NAS feature of the ETERNUS Disk storage system is accessed by a client through one or more business LANs. It is recommended that a business LAN include a DNS Server for name resolution and an Authentication Server for authenticating NAS accesses into the NAS file system.

Point

  • When an authentication system is not used for the NAS file system, it is unnecessary to setup an authentication server on the system.
    If an authentication system is not implemented then the NAS file system can be accessed from any clients connected to the business LAN. It is strongly recommended that an authentication server is properly configured and implemented.

  • When the firmware version number of an ETERNUS Disk storage system is V10L53 or later, creating a local user/local group on the ETERNUS Disk storage system for connecting to NAS can implement an authentication system without setting up an authentication server.

6.6.1.1.2 Support Features

In order to perform NAS operation of the ETERNUS Disk storage system, this product is provided with the following features:

Easy Installation of NAS File System Using Wizard

The "creating of a shared folder" and the "creating of a NAS interface" which are necessary when installing a NAS file system can be configured easily by using a wizard.

Display of Configuration Information and Fault Monitoring

The configuration information resources being used for ETERNUS Disk Storage system NAS can be confirmed with the Web Console. In addition, when a failure occurs, the details of the failure are displayed in the event log and Dashboard of Web Console.

Block Level Capacity Monitoring

Capacity monitoring of NAS file system in ETERNUS Disk storage system is implemented at a level similar to that for block volumes.

Performance Management

This enables performance monitoring of resources with the ETERNUS Disk storage system below.

  • NAS volume

  • NAS system

Information

  • The performance monitoring and threshold monitoring functions cannot be used for NAS port.

  • The threshold monitoring function cannot be used for NAS volume and NAS system.

Backup/Restoration of NAS Volume

Backup and restoration of a NAS volume utilizes QuickOPC and a NAS backup volume. The use of the NAS backup volume provides protection against loss or corruption of the active NAS volume. In addition, the NAS backup volume can be accessed Read-Only for file level recovery.

Automatic Snapshot Collection of NAS Volume

This is a function that follows the specified schedule and automatically collects snapshots. The capture of the NAS volume snapshot is achieved using SnapOPC+. The NAS volume snapshot for the specified generation can be stored, and files and folders from the snapshot can be recovered without administrators.

Quantity Consumed Upper Limit Management and Monitoring (Quota Management)

This is a function for managing the upper limit of the quantity consumed by user/group or shared folder. This prevents in advance the depletion of total resources due to large disk volume consumption by certain users/groups or shared folders.

NAS Environment Antivirus

By registering the antivirus server provided by the antivirus security vendors, checking of access to files under the shared folder, detection of viruses and measures are performed automatically. This prevents data in the NAS environment being infected by viruses/illegal programs.

6.6.1.1.3 Configuration Items of NAS File System

Configure the following with the Web Console in order to perform NAS operation of the ETERNUS Disk storage system.

Shared Folder

The shared folder refers to a folder made public on the network as a NAS file system. With this product, by creating a shared folder and setting access controls, it is possible to capture a backup and snapshot.

When creating a shared folder from the Web Console, the following resources are also created simultaneously.

Resources

Explanation

NAS volume

A volume where the shared folder is created.
Multiple shared folders can be configured to a single NAS volume.

NAS backup volume

A volume for backup of the NAS volume.
When configuring NAS backup is done by a new NAS backup volume, one is created for each NAS volume. Configuring NAS backup volume is optional.

NAS snapshot volume

This is a volume for the NAS volume snapshot.
When using NAS snapshot, one is created for each generation. Configuring NAS snapshot is optional.

NAS system volume

System volumes are used to control NAS volumes.
They are created when a new NAS volume is created. It is created in the same Thin Provisioning Pool as NAS volume.

Copy group

Copy group used to back up NAS volume.
This is created only when a NAS backup volume is configured.

Copy pair

A copy pair of a NAS volume and a NAS backup volume.
This is created only when a NAS backup volume is configured.

Quota settings

Quota settings for shared folder.
This is created only when a quota settings are configured.

The shared folder that is created with this product can be accessed using the following protocols. As it is possible to use the following protocols simultaneously, it is possible to access a single shared folder from both UNIX and Windows clients.

See

Refer to the ETERNUS Disk storage system manuals for details of protocols that are supported by ETERNUS Disk storage system.

In an environment that a shared folder for home directory has been created, a shared folder (home directory) exclusively for a user is automatically created when accessing the shared folder from a client on business LAN with CIFS protocol.
To access the home directory, enter the following format to the address bar or to the network drive mapping window.

\\nasInterfaceIpAddress\userName

NAS Interface

A NAS interface refers to the definition information of a network interface that manages, over a business LAN, a public IP address for access to the shared folder and information of the port to which this IP address is assigned. When using the VLAN function, it is possible to configure multiple IP addresses for one port.

Information

There is no relation between the shared folder and the NAS interface. It is possible to reference the same shared folder from any NAS interface.

The NAS interface maybe assigned to a single port or 2 ports. The type of connections that can be configured are as follows:

Information

In order to continue business when a port is down, it is recommended to configure either Active-Active or Active-Standby connection for redundancy.

Further, with the aim of increasing communication speed and becoming more fault-resilient, multiple physical ports can be bundled and handled as one logical port. Further, a NAS interface can be allocated for that logical port (bonding port). The method of determining communication ports of bonding port is to select an operating mode and hash policy.

NAS File System Environment

6.6.1.2 Backup of NAS Environment

This section explains an overview of backup of the NAS environment in the ETERNUS Disk storage system.

See

Refer to "Backup of NAS Environment" in the ETERNUS SF AdvancedCopy Manager Operation Guide for Copy Control Module for information on the backup operation for NAS environment.

6.6.1.2.1 Backup/Restoration of NAS Volume

It is possible to back up the entire NAS volume configured with the Web Console to a NAS backup volume. In addition, it is possible to restore the entire NAS volume from the NAS backup volume.

Figure 6.4 Backup/Restoration of NAS Volume

Information

  • Backup / restore of the NAS volume can either be executed with the Web Console, or be executed with commands from the Management Server.

  • When recovering individual files from the NAS backup volume, mount the NAS backup volume and manually copy the files.

  • The number of NAS volumes and NAS backup volumes creatable on one ETERNUS Disk storage system varies with the device model and its firmware version. Refer to the ETERNUS Disk storage system manuals for details.

6.6.1.2.2 Mounting/Unmounting NAS Backup Volume

The NAS backup volume that is the backup destination of the NAS volume can be mounted onto the NAS environment as Read-Only. By mounting the NAS backup volume, users can recover files themselves. In addition, a mounted NAS backup volume can be unmounted when recovery has been completed.

Figure 6.5 Mounting/Unmounting the NAS Backup Volume

Information

  • Mounting and unmounting of the NAS backup volume can be done from the Web Console.

  • While the NAS backup volume is mounted, it is not possible to backup or restore the NAS volume.

  • When accessing the shared folder in the NAS backup volume after mounting with the CIFS protocol, the name of the shared folder is "the name of the shared folder at the time of backup" + "$bak". Furthermore, the name of the shared folder of the NAS backup volume is not displayed in Web Console.

6.6.1.3 NAS Environment Snapshot

This section provides an outline of the NAS environment snapshot function for the ETERNUS Disk storage system.

6.6.1.3.1 NAS Snapshot

NAS snapshots can be periodically captured and the captured snapshots can be browsed by a snapshot captured client. The NAS volume snapshot is achieved using SnapOPC+. This is provided for the purposes of NAS volume generation management and to be able to recover files and folders deleted due to operating errors.

The NAS snapshot feature can be used by configuring the snapshot from the Web Console.

Point

There are two modes in NAS snapshot of NAS volumes: Automatic and Manual. In this product, Automatic mode can be set up/changed/cancelled.
To set up/change/cancel Manual mode that captures snapshots at any timing, refer to the ETERNUS Disk storage system manuals.

The following items are configured:

Figure 6.6 Outline of NAS Snapshot

Note

If a snapshot is collected while accessing a volume from an application, a snapshot at a point in time at which half-done data was written to the volume could be created. In this case, the data consistency in the snapshot is not ensured, so that the operation of the file in the snapshot is made impossible or the file content becomes incomplete.
Generally, to collect a snapshot whose data is consistent, the application accessing a volume must be stopped beforehand.
Configure a schedule for snapshot collection and the number of generations in a snapshot so that correct data can be traced back through generations when data inconsistency is found in the snapshot.

6.6.1.3.2 Automatic Snapshot Collection Stop/Start

Where the NAS volume is temporarily not updated due to device maintenance period or long break, overwriting of past snapshots can be prevented by stopping the automatic snapshot collection. When restarting the automatic snapshot collection, execute automatic snapshot collection start. Automatic snapshot collection can be restarted carrying on with the snapshot before stopping.

Figure 6.7 Automatic Snapshot Collection Stop/Start

6.6.1.4 About NAS Environment Quota Management

This section provides an outline of NAS environment quota management for the ETERNUS Disk storage system.

6.6.1.4.1 NAS Environment Quota Management

With quota management, the amount of usable resources can be limited. This prevents the depletion of the whole system resources that is caused by disk capacity being consumed away by some users/groups or on some shared folders.

When accessing a shared folder with CIFS protocol, disk usage and the number of files can be limited for the users and shared folders.
When accessing a shared folder with NFS protocol, disk usage and the number of files can be limited for the users, groups, and shared folders.

The following two values can be set:

Point

  • Quota can be set for the user/group and shared folder at the same time. There is no order of priority in settings, and control is executed by a warning value or limit value that is reached first.

  • Even if a disk is used with a limit value exceeded, it may not cause any error. In this case, it is used up to disk use amount limitation value + 2 GB in the maximum.

  • When a NAS volume to which quota is set is backed up, its quota setting information is backed up at the same time. For this reason, when it is restored, its quota setting information backed up is applied.

Note

When using the quota management function, enable SNMP Trap settings. If they are not enabled, no alarm notification is output when a quota threshold is exceeded.
To change SNMP Trap settings on the Web Console, refer to "Change ETERNUS Disk Storage System Information" in the ETERNUS SF Web Console Guide.

Figure 6.8 Quota Management Outline

Information

  • By using mail notification and Systemwalker Centric Manager linkup feature, you are notified by E-mail when the quota management limit value or warning value are exceeded. Refer to "6.3 Event Display and Linkage" for details.

6.6.1.4.2 Events Notified by Quota Management

With quota management, an SNMP Trap is notified by the Management Server in the following cases.

The notified event can be confirmed on the quota management log screen on the Web Console. Logs are stored for 30 days.

See

Refer to "Display Quota Information" in the ETERNUS SF Web Console Guide for the procedure to display the Quota Management Log screen.

Point

  • Events are categorized by type; warning value exceeded, limit value exceeded, warning value removed, and notified every 10 minutes.

  • The limit value exceeded event is notified when an error occurred because data update or file creation was attempted with a limit value reached.

6.6.1.5 About Antivirus for NAS Environment

This section provides an outline of the antivirus for the NAS environment on an ETERNUS Disk storage system.

6.6.1.5.1 Antivirus for NAS Environment

The antivirus function is linked to the antivirus server provided by the antivirus security vendor, and prevents data in the NAS environment being infected by viruses/illegal programs.

When the file is accessed from the client, the registered antivirus server checks the accessed file.

  1. The client accesses files in the shared folder on the ETERNUS Disk storage system.

  2. The ETERNUS Disk storage system instructs the antivirus server to perform a virus check on the accessed files.

  3. The antivirus server checks the accessed files.

  4. When it discovers a virus/illegal program, it outputs a detection log to the log folder.

  5. When it discovers a virus/illegal program, the results of the detection are notified to the Web Console.

Point

  • The antivirus function only applies to shared folders using the CIFS protocol.

  • The NAS interface must be configured with the ETERNUS Disk storage system so that two CMs in the ETERNUS Disk storage system can communicate to the antivirus server.

  • We recommend establishing multiple antivirus servers. If the ETERNUS Disk storage system cannot communicate with the antivirus server, a client is not able to access files in the NAS environment.
    Refer to the ETERNUS Disk storage system manuals for the number of the antivirus server that can be registered in the ETERNUS Disk storage system.

  • Prepare an antivirus server activation code for each ETERNUS Disk storage system.

  • The antivirus function is available for shared folders that have writing authority.
    The shared folders that have no writing authority are not scanned.

  • An IPv6 link local address is not available for the IP address of an antivirus server. When using IPv6, set an IPv6 global address.
    When using FQDN, set it so that it is not converted to an IPv6 link local address.

If the antivirus server detects a virus it deals with it automatically.

Check the action taken by the antivirus server according to the following procedures:

  1. Access the shared folder and check the logs are output to the following folder.

    \\nasInterfaceIpAddress\sharedFolderName\.evscan\log

    When the shared folder is home directory, logs are output to the following folder.

    \\nasInterfaceIpAddress\userName\.evscan\log

    The log file names are as follows:

    • Latest logs

      viruslog_YYYY_MM.txt

      YYYY : year, MM : month(1~12)

    • Past logs

      viruslog_YYYY_MM_partN.txt

      YYYY : year, MM : month(1~12), N : control No.(decimal starting from 1)

    See

    Refer to the message output to the log for details of the log. Refer to the ETERNUS Disk storage system manuals for the action.

  2. Check the action taken by the antivirus server from the content of the log.

    If you want to check the detected content in detail, provide the log and relevant file to the vendor for confirmation.

    Files quarantined by the antivirus server are in the following folder.

    \\nasInterfaceIpAddress\sharedFolderName\.evscan\quarantine

    When the shared folder is home directory, files are output to the following folder.

    \\nasInterfaceIpAddress\userName\.evscan\quarantine

Point

When the capacity of the log output destination is not sufficient, an SNMP Trap is sent. When notified, perform the following to secure capacity:

  • Extend the NAS volume.

  • Delete unnecessary past logs and files in the .evscan\quarantine folder.

  • When quota management is set, raise the limit value.

Logs in the .evscan\log folder are stored for 90 days.

6.6.1.5.2 Event Notified by Antivirus

As an antivirus, in the following cases an SNMP Trap is notified to the Management Server:

Notified events can be confirmed on the Web Console antivirus log screen. Logs are stored for 90 days.

See

Refer to "Display Antivirus Information" in the ETERNUS SF Web Console Guide for the procedure to display the Antivirus Log screen.

6.6.1.6 Operating Environment

The functions of the NAS option of the ETERNUS Disk storage system can be used with the following environments.

Table 6.4 Operating Environment

Object

Environment

Platform

Platforms on which the ETERNUS SF Manager can be operated.

Required licenses (software)

  • ETERNUS SF Storage Cruiser Basic License (*1,*3)

  • ETERNUS SF Storage Cruiser Standard License (*1,*3)

  • ETERNUS SF AdvancedCopy Manager Local Copy License (*2)

ETERNUS Disk storage system

ETERNUS DX100 S3/DX200 S3/DX500 S3/DX600 S3

Required options (hardware)

NAS Option

Agent

Storage Cruiser's agent is not required.

Authentication methods (*4)

[When accessing with the CIFS protocol] Active Directory

[When accessing with the NFS protocol] LDAP

Antivirus server

Trend Micro Storage Security for FUJITSU Storage ETERNUS DX S3 series

*1: Required to construct the NAS file system.
*2: Required to back up the NAS volumes.
*3: Required to register either one.
*4: Required when performing access control using an authentication server for the NAS file system. When no authentication server is configured, all accesses are permitted.