This guide is intended for the IT administrator or person responsible for installing the File IQ Appliance on the Google Cloud platform.
General Information
This section includes general information about the File IQ Appliance and technical specifications.
File IQ
The File IQ feature is designed to provide insights and analytics on your file data usage patterns. File IQ enables you to quickly take advantage of several important capabilities, including:
File Usage Analytics: Track usage and collaboration patterns across users, departments, file types, volumes, and more. Gain visibility to optimize storage, plan capacity, and facilitate capacity-based chargeback.
Health Monitoring: Monitor system component metrics to proactively identify resource contention and capacity limits so administrators can take preventative measures.
Forensic Capabilities: Perform historical analysis of file, user, or application activity when troubleshooting issues or investigating information security events.
Automated Reporting: Leverage prebuilt reports and dashboards that deliver actionable intelligence to technical and business users and support chargeback reporting.
Key Terms
The following terms are helpful for understanding the File IQ Appliance:
Cache: The local storage of the File IQ Appliance. All volume metadata accessed regularly is kept locally in the File IQ Appliance cache. If the requested metadata is not locally resident, it is staged into the cache and provided for the request.
Cloud Storage: Internet-based, highly protected, unlimited storage.
Event Hubs: A cloud-native data streaming service used to forward events between components of the File IQ Solution.
GCE Disk: Google Compute Engine Disk. Storage provided by Google for the File IQ Appliance. Nasuni recommends using SSD Persistent disks for both the File IQ Appliance cache and COW disks. For more information on GCE Disk https://gcloud-compute.com/disks.html.
Grafana: Grafana is a multi-platform open-source analytics and interactive visualization web application. It provides charts, graphs, and alerts for the web when connected to supported data sources.
Nasuni Edge Appliance (NEA): The virtual or physical Nasuni appliance in your data center that integrates with your infrastructure via CIFS (SMB), NFS, FTP/SFTP, or HTTPS/REST protocols. The Nasuni Edge Appliance can be mapped as a network drive.
Nasuni Edge Appliance user interface: The Web-based graphical user interface with which you configure and manage the Nasuni Edge Appliance. The Nasuni Edge Appliance user interface is accessible with supported Web browsers, including Mozilla Firefox, Microsoft Edge, Apple Safari, and Google Chrome.
File IQ: The File IQ Appliance contains the database, Grafana server, event processing, and volume scanning capabilities that the File IQ Solution uses to give insight into Nasuni Edge Appliance and volume usage across your Nasuni deployments.
Nasuni Management Console (NMC): The Web-accessible appliance with which you can configure and manage multiple Nasuni Edge Appliances. The Nasuni Management Console is accessible with supported Web browsers, including Mozilla Firefox, Microsoft Edge, Apple Safari, and Google Chrome.
Nasuni Orchestration Center (NOC): Nasuni’s zero-maintenance control path built on elastic, multi-region cloud services that enables file data to be shared across locations at any scale and without version conflict. The NOC, also called the Nasuni Account Dashboard, gives you access to File IQ Serial Numbers, which are used to install File IQ.
File IQ Dashboard: A custom dashboard deployed within the File IQ Appliance-hosted Grafana to display information gathered by the File System Metadata Service (FSMS) and the File System Event Processor (FSEP).
File IQ Service: The File IQ Service collects audit events and forwards them to the File IQ Appliance via the Azure EventHub.
Note: The audit events collected by the File IQ Service are independent of the standard auditing feature enabled on the NEAs.
Share/export: An access point to a folder on a volume that can be shared or exported on your network. Access to a CIFS (SMB) share can be customized on a user-level or group-level basis. You can create many shares or exports on a volume for different purposes or audiences.
Volume: A set of files and directories (CIFS (SMB), NFS, and FTP/SFTP).
File IQ Solution Specifications
This section contains specifications for configuring the File IQ Appliance.
Supported Web Browsers
The File IQ Appliance supports the following Web browsers:
Virtual Machine Requirements
Use the Sizing Tool for recommendations on the most appropriate VM size.
Installing on the Google Cloud Platform
This chapter explains how to install the File IQ Solution on the Google Cloud Platform.
Tip: This document is about deploying virtual machines. It does not cover configuring a storage account for use with Nasuni volumes.
Warning: DO NOT attempt to restore from a virtual machine snapshot or backup. Attempting to restore from a virtual machine snapshot or backup puts the IQ Appliance in an unknown state in relation to the Nasuni Orchestration Center (NOC) and will result in data loss for the File IQ database.
Tip: You should leverage your cloud provider's role-based access and identity access management features as part of your security strategy. Based on your policies, such features can limit or prohibit administrative access to the cloud account.
Note: The vendor changes their interfaces occasionally with little notice to the users. The exact screens and text on these platforms might change at any time.
Tip: Check out the File IQ Installation and Configuration videos for a general reference on the File IQ installation process. Your specific hypervisor installation will include unique steps not included in this video reference series.
Day 1 File IQ Installation Checklist
To complete a day 1 File IQ installation, follow this checklist:
Step | Action |
1 | Complete 1. Before you Begin section in this document. Your account manager can assist you with this item. |
2 | Complete 2 Installing File IQ using the GCP Virtual Hard Disk section in this document. |
3 | Complete 3. Running the File IQ Appliance First Boot Wizard section in this document. |
4 | Complete 4. Add the File IQ Database Disk to the File IQ Appliance section in this document. |
5 | Complete 5. Connect the Nasuni Volumes to the File IQ Appliance section in this document. |
6 | Complete 6. Disabling Quality of Service for the File IQ Appliance section in this document. |
7 | Complete 7. Enabling the File IQ and Configure File IQ Service section in this document. |
8 | Complete 8. Accessing the File IQ Dashboards section in this document. |
9 | For more information, see the following sections: |
1. Before you Begin
The following items should be readily available so that you can navigate the File IQ installation and setup process. It is recommended that you complete these requirements before starting or have a way to fulfill them during the installation process.
Note: File IQ does not support a proxy server.
Item | Description |
Contact Nasuni | Contact your Account Manager to enable the File IQ license and configure your account for the File IQ Appliance. |
GCP Login | Authentication and Authorization to your organization’s GCP Account is needed to create the File IQ Virtual Machine. |
GCP Region | The GCP region that you wish to install the File IQ Appliance into. |
GCP Network Details for the File IQ virtual machine (VM) | When installing the File IQ Virtual Machine in GCP, the following items are required for the virtual machine network Interface:
Each organization has its own requirements for how the networking of the virtual machine is fulfilled. Nasuni recommends defining this before you start the installation process. |
NMC Login | Authentication and authorization to your organization’s Nasuni Management Console to configure the File IQ for your environment. |
NOC Login | Authentication and authorization to your organization’s Nasuni Orchestration Center account to retrieve your File IQ serial and Authorization code, and to configure the File IQ. |
Volumes List | When setting up File IQ, use at least one volume. Ideally, choose one small volume to see the result quickly when you enable the File IQ Appliance. |
NEAs List | You need at least one Nasuni Edge Appliance to configure sending activity to the File IQ Virtual Machine. Ideally, pick an NEA from which you can mount volumes to generate traffic and see it in the File IQ dashboards. The NEA must be running version 9.14.3 or later. |
File IQ Serial Number and Authorization Code | The File IQ Appliance serial number is located in your Nasuni Account. It is paired with an Authorization Code, which is located in a table at the bottom of the page. Note: Configuration of the File IQ Appliance and NEAs for File IQ can also be found in this location of your Nasuni Account. Note: If the File IQ Config menu or File IQ Serial Numbers are unavailable, contact your Nasuni Account Manager to confirm that the File IQ License is correctly configured for your account. Note: To enable a single sign-on user to access the File IQ Config menu, follow these steps: 1. Log in to account.nasuni.com. |
File IQ Username and Password | The first boot setup of the File IQ Appliance requires a new username and password. These values are specific to the File IQ Appliance only. |
File IQ Hostname | When you go through the first boot wizard for the File IQ Appliance, you must provide a host name for the machine. Note: Host names longer than 15 characters cannot be added to Active Directory services. |
File IQ Network Details | You must provide the machine's network details when you go through the first boot wizard for the File IQ Appliance. |
Grafana Password | The default password for the Grafana viewer account must be changed during the first usage. Nasuni recommends having a new password ready that aligns with your corporate processes and procedures. |
Active Directory Credentials | The File IQ Appliance must connect to the same Active Directory domains as the NEAs and volumes configured in the File IQ Appliance. The following information might be necessary:
|
Sizing Tool Outputs | Use the Sizing Tool for recommendations on the most appropriate GCP Instance type. The File IQ Sizing Tool provides a Virtual Machine size suggestion, disk sizing, and configuration for Cache and File IQ DB to use when setting up the File IQ Virtual Machine in GCP. Complete the Sizing Tool exercise to receive these outputs before completing the File IQ installation process. The outputs received from the Sizing Tool include the following recommendations:
Note: File IQ does not support disk striping on cache or DB disks. |
NEA Firewall Requirements | The Nasuni Edge Appliance requires access to the Azure Event Hub when you enable File IQ. All network ports and access requirements for the File IQ Service on the NEA are documented in the Firewall and Port Requirements in the Nasuni Edge Appliance section. Before enabling the File IQ on the NEA, complete the NEA Firewall Requirements for File IQ Service. |
File IQ Firewall Requirements | When you enable File IQ, the File IQ Appliance requires access to the Azure Event Hub. The File IQ Appliance section of the Firewall and Port Requirements documents all network ports and access requirements for the File IQ Appliance. Before you activate File IQ on the File IQ Appliance, complete the File IQ Firewall Requirements for File IQ Appliance. |
2. Installing File IQ using the GCP Virtual Hard Disk
Important: Nasuni does not have access to your GCP account; you must create and maintain your own GCP account. To create an account, go to the Google Cloud Platform site.
Tip: In the Nasuni model, customers provide their own cloud accounts for storing their data. As part of their overall security strategy, customers should leverage their cloud provider's role-based access and identity access management features. Such features can be used to limit or prohibit administrative access to the cloud account based on customer policies.
Important: To access Active Directory-enabled volumes, the File IQ Appliance must be connected to an Active Directory server in the same Active Directory Forest. This requires part of your Active Directory infrastructure to also be running on the GCP Platform. Similarly, to access LDAP-enabled volumes, the File IQ Appliance must be able to access LDAP and Kerberos in the same LDAP domain.
Important: Similarly, to access LDAP-enabled volumes, the File IQ Appliance must be able to access LDAP and Kerberos in the same LDAP domain. You cannot enable Active Directory and LDAP Directory Services for a File IQ Appliance.
The File IQ Appliance can be deployed from a Google Compute Engine (GCE) disk file downloaded from the Nasuni account Web site.
There are several steps involved to installing the File IQ Appliance from the GCE disk file:
Download the GCE disk file from http://account.nasuni.com
Upload the GCE disk to Google Cloud Storage.
Create an image from the GCE disk file.
Installing the File IQ Appliance using an image.
Download the GCE Disk File
Go to http://account.nasuni.com.
Click Downloads.
In the File IQ area, click on Download Google Format.
Click the latest version. The download starts.
Once the GCE Disk is downloaded, go to the next section and upload it to Google Cloud Storage.
Upload the GCE Disk to Google Cloud Storage
Important: Do not uncompress the GCE Disk before the upload.
Log in to the Google Cloud console at https://console.cloud.google.com/. The Google Cloud Dashboard appears.
Click on Cloud Storage. The Cloud Storage view appears.
Select Buckets. The Buckets pane appears.
Click the name of the Bucket you wish to use for uploading the GCE Disk file. The Bucket details pane appears.
Click UPLOAD FILES, and the Operating System browser window opens.
Select the GCE Disk on your hard drive and click Open. The upload starts.
Once the GCE disk file is uploaded, go to the next section, and create an image.
Creating an Image from the GCE Disk File
To install the disk file on GCP as a Virtual Machine, Nasuni recommends creating an image from the disk file so that the image acts as a template and can be deployed multiple times.
To create an image of the installation software, follow this procedure:
Log in to the Google Cloud console at https://console.cloud.google.com/. The Google Cloud Dashboard appears.
From the GCP Dashboard Navigation menu, click Compute Engine, then Images. The image appears.
Click CREATE IMAGE. The Create an image pane appears.
Enter a Name for the image. The name must start with a lowercase letter, followed by up to 62 lowercase letters, numbers, or hyphens, and cannot end with a hyphen.
Set Source to Cloud Storage file.
Click BROWSE, and the Select an object pane appears with a list of Buckets.
Click the Bucket that contains the GCE Disk file. The list of files for that Bucket appears.
Select the image for the File IQ appliance (.tar.gz file).
Click SELECT. The Select an object pane closes.
Click CREATE. The Create an image pane closes, and the Images list appears, with the new image's status showing Pending.
Wait for the status indicator to become a green tick box.
The image is now created. Go to the next section to install File IQ using the image.
Installing the File IQ Virtual Machine using an image
After creating the image from the disk file, use the created image to deploy the File IQ Virtual Machine.
To create the Virtual Machine, follow this procedure:
Log in to the Google Cloud console at https://console.cloud.google.com/. The Google Cloud Dashboard appears.
Click the Search field and select Compute Engine. The VM Instances pane appears.
Click CREATE INSTANCE. The Create an Instance pane appears.
Enter an Instance Name for the File IQ Virtual Machine.
From the Zone drop-down list, select a zone for this deployment. Zones determine where data is stored and used. Also, different zones offer different resources and features. Choose a zone that is close to your point of service. For more information, see Regions and zones.
Click the General purpose tab and select the Series of the machine type as N2D.
Scroll down to the Machine type drop-down, and select Custom.
Using the Sizing Tool output entry for minimum vCPU in section 1. Before you Begin, set the number of Cores for the Instance.
Using the Sizing Tool output for minimum Memory in section 1. Before you Begin, set the Memory size for the Instance.
Click the OS and storage tab on the left-side navigation.
Click CHANGE. The Boot disk pane appears.
Click the CUSTOM IMAGES tab. The Custom Image pane appears.
From the Image dropdown list, select the File IQ image you previously created.
Click the Boot disk type drop-down, and select SSD persistent disk. Use the default disk size.
Click SELECT. The Boot disk pane closes. The name of the selected image is displayed in the Boot disk section.
Click the Networking tab on the left-side navigation.
From the Firewall area, enable Allow HTTPS traffic.
In the Network Interfaces section, expand the default interface. The Edit network interface pane appears.
Enter the corresponding fields from the GCP Network Details for the File IQ VM entry in the 1. Before you Begin section above: Network and Subnetwork.
(Optional) To disable the External IPv4 address based on your company security’s guidelines, navigate to Network Interfaces and click the trash can icon.
Click the OS and storage tab on the left-side navigation.
Click ADD NEW DISK. The Add new disk pane appears.
Enter a Name for the cache disk. Nasuni recommends as a best practice to prefix the disk name with the VM Instance name and use the -cache suffix: <instance_name>-cache.
From the Disk type drop-down, select SSD persistent disk.
Enter a Size for the cache disk that matches the outputs of the Nasuni Cache from the Sizing Tool Outputs section in the 1. Before you Begin section above.
Scroll down to Encryption. The default Encryption is Google-managed encryption key.
Scroll down to Attachment settings, and select Delete disk for the Deletion rule setting. This optional step ensures the File IQ disk is automatically deleted when the VM is deleted.
Click SAVE. The cache disk is defined and appears in the Additional disks section.
Click ADD NEW DISK. The Add new disk pane appears.
Enter a Name for the COW disk. Nasuni recommends as a best practice to prefix the disk name with the VM Instance name and use the -cow suffix: <instance_name>-cow.
From the Disk Type drop-down, select SSD persistent disk.
Enter a Size for the CoW disk that matches the outputs of the Nasuni CoW from the Sizing Tool Outputs section in the 1. Before you Begin section above.
Scroll down to Encryption. The default Encryption is Google-managed encryption key.
Scroll down to Attachment settings, and select Delete disk for the Deletion rule setting. This optional step ensures the File IQ disk is automatically deleted when the VM is deleted.
Click SAVE. The cow disk is created and appears in the list of disks. Two disks are now defined for the File IQ Virtual Machine.
Click CREATE to create the new Virtual Machine. The File IQ Virtual Machine is created and automatically started.
Via the navigation menu, select VPC network then Firewall to define one additional firewall rule used to access the File IQ Dashboard via https on port 3000. The creation of the rule is done via the following procedure:
Click CREATE FIREWALL RULE. The firewall rule editor appears.
Enter the name of the rule. For example, “fiq-fw-dashboard”.
Enter a description. For example, “File IQ TCP Ingress for port 3000”.
Select the Network used by the File IQ Appliance.
For Direction of traffic, select Ingress.
For Action on match, select Allow.
For Targets, select All instances in the network.
For Source filter, select IPv4 ranges.
For Source IPv4 ranges, enter “0.0.0.0/0”. This is a default value and is not restrictive. You may restrict the IP range based on your network security settings.
For Protocol and ports, select Specified protocols and ports.
Select TCP and in the Port field, enter “3000”.
Click CREATE to create the ingress firewall rule
3. Running the File IQ Appliance First Boot Wizard
To access the newly installed File IQ Appliance, follow this procedure:
Open the GCP Dashboard. From the navigation menu, click Compute Engine, then VM instances. The VM instances pane appears.
From the Virtual machines list, find the internal IP and external IP columns for the File IQ Appliance virtual machine created above in the previous step.
If an external IP address was configured, copy the external IP address. If an external IP address was not configured, get an internal IP address. If an external IP address is not configured, you must use the internal IP address assigned to the VM.
Navigate to the First Boot Wizard for the File IQ Appliance by opening a new browser window.
To access the File IQ Appliance, enter the address in this form: https://<IP address>, where <IP address> is the IP address from step 3 immediately above this step.
The File IQ Appliance user interface appears.
Enter the Hostname you defined in the File IQ Hostname. This was defined in the 1. Before you Begin section above.
Complete the remainder of the System Settings defined in the File IQ Network Details as part of the 1. Before you Begin section above.
Click Continue. The Review the Network Settings pane appears.
If all fields are correct, click Continue. The next pane confirms if the File IQ Appliance is Configuring Network Settings. If the File IQ Appliance does not automatically reconnect, try refreshing the page and checking if the File IQ Appliance’s IP address has changed. If so, update in the browser address bar.
The Nasuni Filer Software Update pane appears. Click Continue.
Enter the File IQ Serial Number and Authorization Code obtained under the File IQ Serial Number and Authorization Code as part of the 1. Before you Begin section above.
Click Continue. The Add a New Nasuni Filer to your account pane appears.
Note: If you get an “Internal Server Error” during this step, it is because you have used a NEA Serial Number instead of an File IQ Serial Number. Nasuni recommends double-checking your serial number and try again. See the 1. Before you Begin section for the correct location to the File IQ Serial Number and Authorization Code values.
Enter ‘Install New Filer’ into the Confirmation textbox.
Click Continue. The Accept the Terms of Service and License Agreement pane appears.
Accept the Terms of Service and click Continue. The Enter or accept Filer Name pane appears.
Click Continue. The Nasuni Management Console Detected pane appears.
Enable the Join NMC Management checkbox and click Continue. Enter a username and password for Administration of this Filer pane appears.
Enter your NMC local account Username, Password, and Confirm Password. These were obtained in the File IQ Username and Password section of the 1. Before you Begin section above.
Click Continue, the First Boot Wizard is complete, and the File IQ Appliance Management window appears.
Tip: After the First Boot Wizard finishes and the main user interface (UI) is displayed, you might receive a notification advising that Nasuni suggests keeping the cache size of the File IQ appliance no larger than four times the size of the snapshot space. Disregard this warning, as all volumes are shared in read-only mode with the File IQ appliance.
3.1 Joining the File IQ appliance to your Active Directory
If the volumes you want to scan are protected by Active Directory, you must join your File IQ Appliance to the Active Directory domains to secure these volumes.
Note: The configuration of Active Directory can vary based on several factors, and your specific configuration may require additional settings that are not mentioned in this section. If you encounter any issues while connecting to Active Directory, reach out to your Nasuni Account Manager for assistance.
Follow this procedure to join Active Directory:
Open a Web Browser and access the File IQ Appliance. Enter the address in this form: https://<IP address>, where <IP address> is the IP address from step 3 in the previous section. The File IQ Appliance user interface appears.
Ensure that the host name of your File IQ Appliance is shorter than 16 characters:
From the Configuration menu, select Network Configuration under the NETWORKING section.
Verify that the host name in Hostname or FQDN is 15 characters or less.
If required, shorten the host name, and click Save Network Configuration.
Enter your Nasuni admin account details, confirm, and wait for the File IQ Appliance to apply the new settings.
Unless your Active Directory is registered publicly, you must change the File IQ’s DNS server to your Active Directory Primary Domain Controller (PDC).
From the Configuration menu, select Network Configuration under the NETWORKING section.
In Settings Source, under System Settings, select DHCP with Custom DNS.
Leave the Search Domain empty.
Set the Primary DNS server to your Active Directory PDC’s IP address.
Click Save Network Configuration. Enter your Nasuni admin account details, confirm, and wait for the appliance to apply the new settings.
Join the File IQ Appliance to Active Directory by following these steps:
From the Configuration menu, select Directory Services under the CIFS & DIRECTORY SERVICES section.
Enter your full Active Directory domain in the Domain entry field.
Unless instructed by your Nasuni Account Manager, do not change any other fields.
Click Continue. The Confirm/Authenticate Directory Service dialog box appears.
In the Confirm/Authenticate Directory Service dialog box, enter your Active Directory administrator username and password and click Submit.
Wait until the joining process is complete and the volume selection page is displayed.
Select all volumes you wish to access from the File IQ appliance and click Continue.
Wait until the volume configuration is complete and the domain configuration page is displayed.
Enable all the trusted domains you wish to monitor users from and click Continue.
Wait until the trusted domain configuration is complete and the Complete the Configuration page is displayed.
Click Finish to finish the active directory configuration.
Wait until the configuration completes. The display returns to the Directory Services configuration page and displays Active Directory domain information.
You have successfully joined Active Directory.
4. Add the File IQDB Disk to the File IQ Appliance
Before enabling the File IQ Appliance, add another disk for the File IQ Database and follow this procedure:
Log into the Nasuni Management Console associated with the File IQ Appliance.
Click the Filers menu item.
Click Shutdown & Reboot. The Shutdown and Reboot pane appears.
For the File IQ Appliance, click the associated Shutdown/Reboot action.
The Initiate Shutdown/Reboot of File IQ Appliance pane appears.
Enter ‘Change Filer Power State’ into the Confirmation Phrase textbox.
Select the Option to Shut down immediately. Click Shutdown. The Shutdown and Reboot pane appears.
Wait until the File IQ Appliance's Status column changes to a checkmark before proceeding; at that point, the appliance is shut down.
Login to the GCP portal.
From the navigation menu, click Compute Engine, then VM Instances. The Virtual machines pane appears.
Click the File IQ Appliance virtual machine name in the list. The virtual machine pane opens.
Click EDIT. The Virtual Machine editor appears.
In the Storage area under the Additional Disks section, click ADD NEW DISK. The Add new disk pane appears.
Enter a Name for the File IQ DB disk. Nasuni recommends, as a best practice, to prefix the disk name with the VM Instance name and use the -fiqdb suffix: <instance_name>-fiqdb.
From the Type dropdown list, select the type of disk. Select SSD persistent disk.
Enter a Size for the File IQdb disk that matches the outputs of the File IQ DB from the Sizing Tool Outputs section in the 1. Before you Begin section.
Select a type of Encryption. The default Encryption is Google-managed key.
In the Attachment setting section, select Delete disk for the Deletion rule setting. This is an optional step that ensures the File IQ disk is deleted automatically when the VM is deleted.
Click SAVE. The editor closes, and the File IQ db disk is defined and appears in the Additional disks section.
Click SAVE to complete the operation.
Go back to the VM instance view via the navigation bar.
Select the File IQ Virtual Machine.
Navigate to the top of the screen and click START/RESUME. A confirmation dialog is displayed. Click START. A message indicates that the VM is starting. Another message appears once the VM is started.
5. Connect the Nasuni Volumes to the File IQ Appliance
Note: You might see a "File IQ unhealthy" alert displayed prior to enabling the File IQ service in step 7. This alert is expected and resolves itself after a successful File IQ service enablement.
To share and connect a volume to the File IQ Appliance, follow this procedure:
Log in to the Nasuni Management Console associated with the File IQ Appliance.
Set up remote access for the Volume by following this procedure:
Click Volumes.
Click Remote Access. The Volume Remote Access Setting pane appears.
Select the volumes that you want to share. These should match the Volumes in the Volumes List section in the 1. Before you Begin chapter above. Then click Edit Volumes. The Edit Volume Remote Access Settings dialog box appears.
Ensure that the Enabled toggle is set to On.
For Remote Access Permissions, ensure Custom is selected.
For the File IQ Appliance entry in the Custom Remote Access Permissions section, select Read Only.
Caution: Be sure to change ONLY the Remote Access entry for the File IQ appliance to Read Only. Be sure to leave the Remote Access entries for the other volumes as they were.
Click Save Remote Access Settings. The Volume Remote Access Setting pane appears.
Wait until the Status for each selected volume changes to a checkmark before proceeding.
Connect the Volumes to the File IQ Appliance by following these steps:
Click Volumes.
Click Connect Volume. The Remotely Accessible Volumes pane appears.
For the volumes for which you set up remote access to the File IQ Appliance (step 2 above), click Edit Connections. The Connect/Disconnect Volume dialog box appears.
In the Filers section, enable the File IQ Appliance checkbox.
In the Storage Access section, select Skip creating storage access point.
In the Inherit Setting section, untick the three inherit setting checkboxes.
Click Save Connections. The dialog box closes and returns to the Remotely Accessible Volumes pane.
Wait until the Volume status column changes to a checkmark before proceeding.
Disable Snapshot Schedule for the FILE IQ Appliance and Volumes pairs by following these steps:
Note: If GFA manages the volume you are connecting to FILE IQ, follow these steps:
Click Volumes Snapshot Schedule. The Volume Snapshot Schedule pane appears.
Select the volumes that you configured remote access for in step 2.
Click Edit Volumes. The Snapshot Schedule dialog box appears.
Set the Enablement Window to On.
Deselect all until all the Days turn from color to grey.
Click Save Configuration. The changes are saved.
Note: The changes might take up to 10 minutes to apply.
Disable Sync Schedule for the File IQ Appliance and Volumes pairs by following these steps:
Note: If GFA manages the volume you are connecting to File IQ, skip this step (disabling snap and sync schedules). GFA does not send snapshot or sync recommendations to File IQ for these volumes.
Click Volumes.
Click Sync Schedule. The Sync Schedule pane appears.
Select the volumes that you configured remote access for in step 2.
For each selected volume, expand its list to display the associated NEAs and File IQ Appliances.
De-select each item that is not an File IQ Appliance.
Click Edit Volumes. The Snapshot Schedule dialog box appears.
Click Select/Deselect all until all of the Days turn from color to grey.
Click Save Schedule. The changes are saved. The changes might take up to 10 minutes to apply.
Note: Repeat steps 1-5 in this section for each Volume to be connected to File IQ.
6. Disabling Quality of Service (QoS) for the File IQ Appliance
To disable the Quality of Service (QoS) for the File IQ Appliance, follow these steps:
Log in to the Nasuni Management Console associated with the File IQ Appliance.
Click Filers.
Click Quality of Service. The Filer Quality of Service pane appears.
Select the File IQ Appliance entry in the table and click Edit Filers. The Quality of Service Settings dialog box appears.
For all existing Quality of Service rules, click the Delete action button.
Click Save Rules. The dialog box closes and returns to the Filer Quality of Service pane.
7.Enabling the File IQ and configuring File IQ Service
By default, your File IQ service is turned off on the File IQ Appliance. Additionally, the File IQ Service on the NEA is off and is not configured to use any File IQ Appliance.
This section outlines how to enable File IQ on the File IQ Appliance and then configure one or more NEAs to send activity information to the File IQ Appliance.
The Nasuni Orchestration Center (NOC) User Interface is used to enable File IQ on the File IQ Appliance and the NEA.
Use this section to perform the following:
Enable the File IQ on the new File IQ Appliance.
Enable File IQ Service and Assign the File IQ Appliance for the NEA.
Before getting started, ensure that the following items from the 1. Before You Begin section are complete for this specific area:
NOC Login
NMC Login
NEAs List
Note: Before proceeding, confirm that the NMC, File IQ Appliance, and NEAs are all started and running.
a. Enabling the File IQ on the New File IQ Appliance
To enable the File IQ Appliance from the NOC UI, follow these steps:
Log in to https://account.nasuni.com.
Click the File IQ Config tab. The File IQ pane appears.
In the Configuration section, select the Disabled toggle for the new File IQ Appliance. The toggle becomes enabled, and its label changes to Enabled.
Click Save.
The configuration change is stored.
b. Enabling File IQ Service and Assigning the File IQ Appliance for the NEA
Important: The Nasuni Edge Appliance(s) that are used for data migration or third-party integration purposes should not be enabled to send events to File IQ Appliance(s).
In this section, enable the File IQ Service for each of the NEAs that you have chosen to report activity to the File IQ Appliance. You should have defined each NEA as part of the NEAs List entry in the 1. Before you Begin section above.
To enable the File IQ Service and assign the File IQ Appliance for each of these Nasuni Edge Appliances, follow these steps:
Log in to https://account.nasuni.com.
Click the File IQ Config tab. The File IQ pane appears.
In the Enable File IQ Service on appliances section, select the Disabled toggle for the specific NEAs. The toggle becomes enabled, and its label changes to Enabled.
For the same NEAs, select the new File IQ appliance from the Assign File IQs to NEAs dropdown menu. The dropdown shows the new File IQ Appliance as assigned to the NEAs.
Click Save.
The configuration change is stored.
c. Forcing the configuration to be applied on File IQ Appliance and NEAs
After the configuration is saved, it can take up to 1 hour for the configuration to become active on the File IQ Appliance and NEAs. Instead, you can force the configuration to immediately refresh using the Refresh License feature in the NMC so that you can move on to 8. Accessing the File IQ Dashboards immediately.
To force the configuration to become active, follow these steps:
Log in to the Nasuni Management Console associated with your account.
Click Filers.
Click Refresh License. The Refresh Subscription License pane appears.
Select the same File IQ Appliance and NEAs that you used in steps a and b above, and click Update Filers. The Refresh Subscription License dialog box appears.
Click Refresh License. The dialog box closes, and you return to the Refresh Subscription License pane. Wait until the Status column for the values you selected in step 4 has changed to a checkmark before proceeding.
Important: The initial scanning of your volume files begins immediately. This process can take a while, depending on the number of files and directories that must be scanned initially. It can take on the order of 1 hour per million files and directories for this first scan. Subsequent scans occur every 24 hours after the initial scan. Subsequent scans are much faster because they only deal with changes to the existing files.
8.Accessing the File IQ Dashboards
The results of scanning the selected volumes appear in numerical and graphical form on the File IQ Dashboards. For more information about the File IQ Dashboards, see File IQ Dashboards.
The File IQ Dashboards contain all the information for NEA activity and volume metadata that the File IQ Appliance receives and produces. To access the File IQ Dashboards, follow this procedure:
Open a new browser window.
Enter the address in this form:
https://<File IQ Appliance IP address>:3000
where <File IQ Appliance IP address> is the IP address of the File IQ Appliance, assigned in 3. Running the File IQ Appliance First Boot Wizard. The File IQ Dashboard user interface appears.
In the Email or username field, enter “Viewer”.
Caution: Do not rename the Grafana viewer account. The Initialization program expects the viewer account to be present. If the viewer account is not present, the Initialization of the viewer account recreates the viewer account with the default password.
In the Password field, enter “nasuni_IQ_2024!”.
Note: Nasuni highly recommends updating the default password for the Grafana viewer account during the first usage.
Click Log in. The system logs you into the File IQ Dashboard, and the Home page appears.
It is important to change the default password. To change the password, follow this procedure:
Click the avatar icon at the top right of the File IQ Dashboard. A context menu is displayed.
In the context menu, click Change password. The Change Password pane appears.
In the Old Password textbox, enter the original default password “nasuni_IQ_2024!”.
Enter the new password into the New password and Confirm password text boxes. Click Change Password. The password is saved, and a dialog appears in the top right corner with the text User password changed.
Click Home in the top left corner to return to the Home page.
Appendix A: Firewall Configuration
The File IQ Appliance and Nasuni Edge Appliance both require access to the Microsoft Azure Event Hub API. For configuration instructions, see the Firewall and Port Requirements.
Appendix B: Deletion Security
The Google Cloud Platform offers several safeguards to prevent or mitigate unwanted deletion. You might choose to employ some or all these safeguards.
For specific recommendations and guidelines on managing and safeguarding GCP instances and associated disks, GCP provides targeted documentation that can help ensure that these resources are protected from accidental or unauthorized deletion. Here are some useful links related to managing GCP instances and GCP disks:
GCP Documentation. This section includes detailed information on managing instances, including permissions and lifecycle considerations: GCP Documentation
GCP Disk Documentation. Covers all aspects of managing GCP disks including replication, performance, and reliability: GCP Disk Documentation
GCP Using IAM to Manage Access to GCP Resources. Provides guidelines on how to create and manage IAM policies for GCP resources, crucial for preventing unauthorized access or deletion: GCP Identity and Access Management Documentation
Preventing Accidental VM deletion. This guide explains how to prevent accidental VM deletion GCP Guide to prevent accidental VM deletion
Appendix C: Installing File IQ using Google Cloud Marketplace
To deploy the File IQ appliance using a virtual machine in GCP, use the Google Cloud Marketplace.
Alternatively, to deploy the File IQ appliance using the GCP Virtual Hard Disk, see 2 Installing File IQ using the GCP Virtual Hard Disk.
Important: File IQ has not yet been published on the Google Marketplace. When it is, this section can be used as an alternative to Section 2.
Important: Nasuni does not have access to your GCP account; you must create and maintain your own GCP account. To create an account, go to the Google Cloud Platform site.
Tip: In the Nasuni model, customers provide their own cloud accounts for storing their data. As part of their overall security strategy, customers should leverage their cloud provider's role-based access and identity access management features. Such features can be used to limit or prohibit administrative access to the cloud account based on customer policies.
Important: To access Active Directory-enabled volumes, the File IQ Appliance must be connected to an Active Directory server in the same Active Directory Forest. This requires part of your Active Directory infrastructure to also be running on the GCP platform. Similarly, to access LDAP-enabled volumes, the File IQ Appliance must be able to access LDAP and Kerberos in the same LDAP domain.
Important: Similarly, to access LDAP-enabled volumes, the File IQ Appliance must be able to access LDAP and Kerberos in the same LDAP domain. You cannot enable Active Directory and LDAP Directory Services for a File IQ Appliance.
To install File IQ from the Google Cloud Marketplace, navigate to the File IQ offer on the Google Cloud Marketplace and create the Virtual Machine for File IQ from that location. You do not need to upload the Virtual Hard Disk file and create an image as part of the process below.
To begin the installation of File IQ, follow these steps:
Log in to the Google Cloud console at https://console.cloud.google.com/. The Google Cloud Dashboard appears.
Click the Navigation menu icon (three horizontal lines in the upper-left corner). The Navigation menu appears.
Click Marketplace. The Marketplace page appears.
In the Search Marketplace box, enter “Nasuni”. A list of Nasuni products appears.
Click File IQ. The File IQ page appears.
Click LAUNCH. The New File IQ Appliance deployment page appears.
Enter a Deployment name for this deployment. Alternatively, you can accept the default name generated.
From the Zone dropdown list, select a zone for this deployment. Zones determine where data is stored and used. Also, different zones offer different resources and features. Choose a zone that is close to your point of service. For more information, see Regions and zones.
Scroll down to the Machine type area, and click the General-purpose tab.
From the Series dropdown list, select the series of the machine type: N2D.
From the Machine type dropdown list, select Custom.
Enter the Number of Core recommended by the Nasuni Sizing Tool.
Enter the Memory size recommended by the Nasuni Sizing Tool.
Scroll down to the Boot Disk area.
From the Boot disk type drop-down list, select the boot disk type. Select SSD Persistent Disk.
From the Boot disk size in GB field, enter “32”.
Scroll down to the Networking area.
Enter the corresponding fields from the GCP Network Details for the File IQ VM entry in the 1. Before you Begin section above.
Configure the other settings as appropriate for your solution, including, but not limited to, security group and virtual private cloud.
In the Network Interface section, you may choose as an optional step to disable the External IPv4 address based on your company security’s guidelines.
Select your Network Interface. The Edit network interface pane appears.
For the External IPv4 address, select None.
Go to the Firewall area.
Select Allow TCP port 8443 traffic from the Internet.
Important: Please ensure that this option is selected.Scroll down to the bottom. If this is your first deployment, the Terms of Service are displayed. Accept the Terms of Service.
Click DEPLOY. The virtual machine is deployed. This might take several minutes.
This virtual machine becomes available in the Deployment Manager list (available from the Navigation menu). Go to the navigation menu, click Compute Engine, and then VM instances. The VM instance details page appears.
Select the new VM and click STOP. A confirmation dialog appears. Click STOP.
Wait for the VM to be stopped.
Click on the new File IQ Appliance name in the Name column. The details of the VM Instance are displayed.
Click Edit. An editable version of the VM instance details appears.
In the Firewalls area, select Allow HTTPS traffic.
In the Storage area, define two additional disks for the VM Instance using the following procedure.
To define a cache disk for the instance, follow these steps:
In the Additional disks area, click ADD NEW DISK. The Add new disk pane appears.
Enter a Name for the cache disk. Nasuni recommends as a best practice to prefix the disk name with the VM Instance name and use the -cache suffix: <instance_name>-cache.
From the Type drop-down list, select the type of disk. Select SSD persistent disk.
Enter a Size for the cache disk that matches the outputs of the Nasuni Cache from the Sizing Tool Outputs section in the 1. Before you Begin section above.
Select a type of Encryption. The default Encryption is Google-managed key.
In the Attachment setting section, select Delete disk for the Deletion rule setting. This is an optional step used to ensure the File IQ disk will be deleted automatically when the VM is deleted.
Click SAVE. The cache disk is defined and appears in the Additional disks section.
To define a COW disk for the instance, follow these steps:
In the Additional disks area, click ADD NEW DISK. Additional fields become available.
Enter a Name for the COW disk. Nasuni recommends as a best practice to prefix the disk name with the VM Instance name and use the -cow suffix: <instance_name>-cow.
From the Type dropdown list, select the type of disk. Select SSD persistent disk.
Enter a Size for the CoW disk that matches the outputs of the Nasuni CoW from the Sizing Tool Outputs section in the 1. Before you Begin section above
Select a type of Encryption. The default Encryption is Google-managed key.
In the Attachment setting section, select Delete disk for the Deletion rule setting. This is an optional step used to ensure the File IQ disk will be deleted automatically when the VM is deleted.
Click SAVE. The CoW disk is created and appears in the list of disks.
Click SAVE. The changes are saved. This step can take some time.
Via the navigation menu, select VPC network -> Firewall to define one additional firewall rule used to access the File IQ Dashboard via https on port 3000. The creation of the rule is done via the following procedure:
Click CREATE FIREWALL RULE. The firewall rule editor appears.
Enter the name of the rule. For example, File IQ-fw-dashboard.
Enter a description. For example, “File IQ TCP Ingress for port 3000”.
Select the Network used by the File IQ Appliance.
For Direction of traffic, select Ingress.
For Action on match, select Allow.
For Targets, select All instances in the network.
For Source filter, select IPv4 ranges.
For Source IPv4 ranges, enter “0.0.0.0/0”. This is a default value and is not restrictive. You may restrict the IP range based on your network security settings.
For Protocol and ports, select Specified protocols and ports.
Select TCP, and in the Ports text field, enter “3000”.
Using the navigation panel on the left-hand side, select Compute Engine, then VM Instances. The VM Instances pane appears.
Select the VM Instance for File IQ.
Navigate to the top of the screen and click START / RESUME. A confirmation dialog appears. Click START. A message indicates that the VM is starting. Another message appears once the VM is started.
Important: Once you have completed all the steps in this appendix, proceed to step 3. Running the File IQ Appliance First Boot Wizard to continue the File IQ Installation process.
Appendix D: Controlling the GCP File IQ VM
Virtual platforms allow you to control various aspects of your File IQ Appliance. This chapter presents procedures for these control functions. Because these controls depend on third-party virtual platforms, follow the procedures for your specific virtual platform.
Note: The vendor changes their interfaces occasionally with little notice to the users. The exact screens and text on these platforms might change at any time.
Starting the GCP VM
Start a stopped VM of the File IQ Appliance on the virtual platform.
To start a stopped VM, follow these steps:
Log in to the Google Cloud console at https://console.cloud.google.com/. The Google Cloud Dashboard appears.
Click Compute Engine, then VM instances. The VM Instances pane appears.
Select the File IQ Virtual Machine you want to start.
Navigate to the top of the screen and click START / A confirmation dialog appears. Click START. A message is displayed indicating that the VM is starting. Another message appears once the VM is started.
Status of the GCP VM
You can view the status of the GCP VM of the File IQ Appliance on the virtual platform.
To view the status of File IQ Appliance Virtual Machine, follow these steps:
Navigate to the GCP dashboard and click Compute Engine, then VM instances. The VM Instances pane appears.
A status indication is provided in the table component indicating if the VM is running or stopped.
Click Observability. Select Overview in the navigation pane of Observability, and information for the VMs appears, including graphs including CPU Utilization, Memory Utilization, Network Traffic, Disk Throughput and Utilization, and a list of the Top 5 processes by CPU usage.
For more information on Google Cloud Observability: https://cloud.google.com/stackdriver/docs#observability
Shutting down the GCP VM
The File IQ Appliance Virtual Machine can be shut down from the virtual platform.
To shut down the VM, follow these steps:
Log in to the Nasuni Management Console associated with the File IQ Appliance.
Click the Filers menu item.
Click Shutdown & Reboot. The Shutdown and Reboot pane appears.
For the File IQ Appliance, click the associated Shutdown/Reboot action. The Initiate Shutdown/Reboot of File IQ Appliance pane appears.
Enter ‘Change Filer Power State’ into the Confirmation Phrase textbox.
Select the Option to Shut down immediately. Click Shutdown.
The Shutdown and Reboot pane appears. Wait until the File IQ Appliance's Status column changes to a checkmark before proceeding; at that point, the File IQ Appliance is shut down.
Appendix E: Uninstalling the GCP VM
This section describes uninstalling the File IQ Appliance from the GCP platform.
Note: The vendor changes their interfaces occasionally with little notice to the users. The exact screens and text on these platforms might change at any time.
Caution: Deleting a File IQ Appliance deletes the GCP VM and all data.
To uninstall the File IQ Appliance on the GCP platform, follow these steps:
Log in to the Google Cloud console at https://console.cloud.google.com/. The Google Cloud Dashboard appears.
Open the GCP Dashboard. From the navigation menu, select Compute Engine, then VM instances.
The VM instances pane appears. Select the File IQ virtual machine.
Navigate to the top of the screen and click DELETE. A dialog box appears, confirming whether you are sure you want to delete the virtual machine.
Click DELETE.
A confirmation dialog appears, asking if you want to delete the virtual machine. Click DELETE.
Deleting a virtual machine does not automatically delete the disks associated with the Virtual Machine unless the Deletion rule of the disk was set to Delete disk when it was created.
To delete the VM disks, follow these steps:
Open the GCP dashboard.
From the navigation menu, select Compute Engine, then Disks. The Disks pane appears.
A list of disks appears. To identify the list of disks to delete:
Select the disk(s) that were previously associated with the deleted File IQ Virtual machine.
Navigate to the top of the screen and click DELETE.
A dialog box appears, confirming if you want to delete the disk(s). Click DELETE.
Appendix F: Resizing the File IQ Disks
This section describes resizing the File IQ Appliance disks from the Google Cloud platform.
Note: The vendor changes their interfaces occasionally with little notice to the users. The exact screens and text on these platforms might change at any time.
Important: You can only increase the size of GCP disks. For more information: https://cloud.google.com/compute/docs/disks/resize-persistent-disk.
Pre-requisites:
The File IQ Instance installation is complete.
The File IQ Disks are correctly named using the best practice that consists of prefixing the disk names with the File IQ Instance name and using a suffix that indicates the role name for the disk (one of: os, cow, cache, and File IQdb). See 2 Installing File IQ using Google Cloud Marketplace Step 31.a.ii
To resize the File IQ disks, follow these steps:
Log into the Nasuni Management Console associated with the File IQ Appliance.
Click Filers.
Click Shutdown & Reboot. The Shutdown and Reboot pane appears.
For the File IQ Appliance, click the associated Shutdown/Reboot action.
The Initiate Shutdown/Reboot of File IQ Appliance pane appears.
Enter “Change Filer Power State” into the Confirmation Phrase textbox.
Select Shut down immediately. Click Shutdown. The Shutdown and Reboot pane appears.
Wait until the File IQ Appliance's Status column changes to a checkmark before proceeding; then, the File IQ Appliance is shut down.
Log in to the Google Cloud console at https://console.cloud.google.com/. The Google Cloud Dashboard appears.
From the navigation menu, select Compute Engine, then Disks. The Disks pane appears.
Locate the File IQ disk(s) that need to be resized by filtering the list of disks using the File IQ Instance name.
For each of the disk(s) displayed in the list that you want to resize, execute the following:
Click on the disk name in the Name column. The Manage Disk pane appears.
In the menu bar, select More Actions, then Edit. The editor for the disk appears.
c. Using the disk editor, update the disk's size. Use the File IQ Sizing Tool to estimate the size of the Nasuni Cache and File IQ DB disks.
Click Save. A message appears at the bottom of the screen to confirm that the update has been triggered and that the disk was successfully updated.
Click Virtual Machines, then VM instances on the left pane. The list of Instances is displayed.
Select the File IQ Virtual Machine Instance.
Navigate to the top of the screen and click START/RESUME. A confirmation dialog appears. Click START. A message displays indicating that the VM is starting. Another message appears once the VM is started.