Documentation Index

Fetch the complete documentation index at: https://docs.nasuni.com/llms.txt

Use this file to discover all available pages before exploring further.

Recovery

Prev Next

This document explains the steps for performing the Recovery process for recovering a Nasuni Edge Appliance (NEA). In a recovery scenario, Nasuni can reduce the total time to recover a Nasuni Edge Appliance to about 15 minutes.

The entire recovery hinges on having complete and verified encryption keys and ensuring that all data is safely snapshotted before starting. Everything else — installation, recovery, and optional optimization (Side Load) — builds on that foundation.

Tip: If you are seeking to restore data — a file, a folder, or an entire volume — but not recover an NEA, see Restore Guide.

Tip: For a 1-page outline of the recovery process, see NEA Recovery Quick Start Guide.

Note: You can also recover the Nasuni Management Console. See NMC Recovery Guide.

Important: If this is a true disaster, and the original source Nasuni Edge Appliance is no longer available, proceed immediately to step 3 “Install new NEA …”.

WARNING: Do not attempt to restore from a virtual machine snapshot or backup.

WARNING: If you ever need to transition from one hypervisor platform to a different hypervisor platform, DO NOT use any of the migration tools of either hypervisor platform.  Instead, you can perform a recovery procedure, using the new hypervisor platform as the destination.

Outline

Here is an outline of the steps necessary to recover a NEA:

  1. Decide whether to recover existing NEA or deploy new NEA. For help with this, see Deciding whether to recover an existing NEA or deploy a new NEA.

  2. Prepare the Source NEA by following these steps:

    1. Verify that:

      1. NEA is functional. For help with this, see Verifying NEA is functional.

      2. At least one snapshot exists. For help with this, see Verifying at least one snapshot exists.

    2. Protect data in cache. For help with this, see Protecting data in the cache.

    3. Record system and volume details.  For help with this, see Recording system and volume details.

    4. Acquire encryption keys. For help with this, see Acquiring encryption keys.

    5. Remove NEA from NMC (if applicable). For help with this, see Removing NEA from NMC.

    6. Run preparedr command. For help with this, see Running the preparedr command.

  • Sets volumes to read-only.

  • Performs final snapshots.

  • Ensures all data is protected.

  1. Install new NEA. (If this is an actual disaster, start here.) For help with this, see Installing new NEA.

    1. Download appropriate NEA software. For help with this, see Downloading the Nasuni Edge Appliance Software.

    2. Deploy software on destination platform. For help with this, see Deploying software on destination platform.

    3. Install and launch new NEA. For help with this, see Installing and launching the new NEA.

    4. Record the assigned IP address. For help with this, see Recording the assigned IP address.

  2. Perform Recovery by following these steps. For help with this, see Performing Recovery.

    1. Access new NEA via browser. For help with this, see Accessing new NEA.

    2. Initiate Recovery wizard. For help with this, see Initiating Recovery wizard.

    3. Configure new NEA.  For help with this, see Configuring.

      1. Hostname.

      2. Network settings.

      3. DNS and gateway.

    4. Enter Serial number and Authorization code.  For help with this, see Entering Serial number and Authorization code.

    5. Provide encryption keys using 3 possible methods. For help with this, see Providing encryption keys.

  • Escrow passphrase.

  • Nasuni recovery key.

  • Upload key files manually.

  1. Complete setup of NEA. For help with this, see Completing setup of the NEA.

    1. Finish Recovery wizard. For help with this, see Finishing the Recovery wizard.

    2. Create administrator account. For help with this, see Creating the administrator account.

    3. Log in to recovered NEA. For help with this, see Logging in to recovered NEA.

    4. Reconfigure settings. For help with this, see Reconfiguring the recovered NEA.

      1. Active Directory or LDAP.

      2. NMC management (if used).

      3. Custom Remote Access permissions for volumes (if used).

      4. Set a new escrow passphrase (if the escrow service is used).

      5. Re-escrow encryption keys (if the escrow service is used).

      6. Automatic software updates (if used).

      7. Time zone and NTP time server settings.

  2. Optional: Side Load (cache transfer). For help with this, see Side Load and Recovery.

  • Transfers cached data from old NEA to new one. Reduces time to repopulate cache.

  • Requires source NEA still running.

  • Initiate from new NEA using source credentials.

  1. Verify all volumes and access. For help with this, see Verifying all volumes and access.

  2. Shut down source NEA permanently. For help with this, see Shutting down source NEA permanently.

    1. Confirm that data is fully accessible on new NEA.

    2. Shut down original NEA permanently.

Restoring data

The NEA enables data restoration from the cloud to be nearly instantaneous. For details of restoring data, see Restore Guide.

With Nasuni’s data services, your data is safely stored offsite in industry-leading data centers. Nasuni’s system of automatic, scheduled snapshots protects your data, with no need for additional backups.

Snapshots provide a full recovery image of your data, as frequently as every minute. This data is available at any time to any location with an Internet connection.

You can rapidly get access to your data.  

1 Deciding whether to recover an existing NEA or deploy a new NEA

Recovery is one method of replacing or migrating an appliance, but it is not always required. For example, in some planned migration scenarios, deploying a new NEA and transitioning users or volumes to the new NEA can be a better option, depending on the complexity of the configuration, downtime requirements, and operational goals.

There are several reasons you might perform recovery of a NEA, including:

  • Restoring service after failure or outage.

  • Replacing an existing appliance.

  • Migrating between appliance platforms, including hardware and virtual environments.

  • Relocating an appliance to another site or region.

This table summarizes the pros and cons of performing a recovery procedure or deploying a new NEA:

Recovery

Deploy new NEA

Advantages

  • Mandatory for NEA that owns volumes.

  • Preserves configuration automatically.

  • Familiar, well-established process.

  • Simpler conceptually.

  • Can minimize or avoid downtime.

  • Clean environment.

  • Flexible migration strategy.

Considerations

  • Requires downtime.

  • Requires encryption keys.

  • Can be complex in some environments.

  • Might have configuration issues.

  • Requires manual configuration.

  • Might require more planning for user migration.

  • Operational overhead.

The decision to perform a recovery on an existing NEA or to deploy a new NEA is up to you. Nasuni Technical Support can offer suggestions based on your specific situation.

2 Preparing the Original Source Nasuni Edge Appliance (if available)

If the original source Nasuni Edge Appliance is running and accessible, prepare the original source Nasuni Edge Appliance by performing the following steps.

2.1.1 Verifying NEA is functional

Verify that the original source Nasuni Edge Appliance is installed and properly configured on your network. For example, ensure that you can access the NEA, change to different pages, and perform actions using the NEA UI.

2.1.2 Verifying at least one snapshot exists

Important: To perform a recovery procedure, one of the following must be true:

  • The original source NEA must have at least one local volume, and at least one Nasuni snapshot of the local volume must have completed.

  • Or, a backup key must have been generated. See Backup Keys.

  1. Verify that the original source Nasuni Edge Appliance has at least one local volume.

    1. Use the NMC UI to verify that the original source Nasuni Edge Appliance has at least one local volume.

    2. Click Volumes. The Volume List appears.

    3. Click Filer. The list is sorted by the Nasuni Edge Appliance that owns a volume.

    4. If the original source Nasuni Edge Appliance appears in the list, then the original source Nasuni Edge Appliance has at least one local “owned” volume.

  2. To verify that a snapshot has completed, see Verifying Snapshots.
    Alternatively, verify that a backup key has been generated. See Backup Keys.

2.2 Protecting data in the cache

If there is unprotected data in the cache of the source NEA, and you do not want that unprotected data to be lost, you must ensure that the data is protected before decommissioning the source NEA. You can do this by performing snapshots on the data.

  1. To perform Nasuni snapshots on all volumes, follow these steps on the NMC:

    1. Click Volumes. The Volumes page appears.

    2. In the Volume List, for the volume that you want to take a Nasuni snapshot of, click Take snapshot now. A message “Snapshot requested” appears. Click x to close the message box.

      Tip: This process can take considerable time, depending on the size of the cache and the amount of changed and new data in the cache.

  2. To verify that a snapshot has completed, see Verifying Snapshots.

Warning: If all Nasuni snapshots have not completed, some data might not be protected in object storage.

2.3 Recording system and volume details

The following settings, if configured, are not retained after the Recovery procedure. You should record your settings so that you can reconfigure these settings after the Recovery procedure.

  • Escrow passphrase.

  • Custom Remote Access permissions.

  • Automatic Software Updates.

  • Time Zone settings.

  • NTP Time Server settings.

In addition, you might want to record information about volumes in order to verify that recovered volumes are as they should be on the destination NEA.

  1. You can obtain information about owned volumes of the original source Nasuni Edge Appliance for later verification by following these steps on the NMC:

    1. Click Volumes. The Volumes page appears.

    2. In the Volume List, click the Filer column. This sorts the list by NEA name.

    3. In the Filer column of the Volume List, find the original source Nasuni Edge Appliance. There might be several entries, for each of the volumes on the original source Nasuni Edge Appliance.

    4. Record the volume names and other volume information for all volumes of the original source Nasuni Edge Appliance.

  2. If intending to run the Side Load procedure, record the hostname or IP address of the original source Nasuni Edge Appliance. To view the hostname on the NEA UI:

    1. Click Configuration.

    2. Then select Network Configuration from the list. The Network Configuration page appears.

    3. The Host Name appears near the top of the page.

  3. If intending to run the Side Load procedure, record the username and password of an administrative user on the original source Nasuni Edge Appliance.

  4. You can obtain information about the Remote Access settings of owned volumes of the original source Nasuni Edge Appliance by following these steps on the NMC:

    1. Click Volumes. The Volumes page appears.

    2. Click Remote Access. The Volume Remote Access Setting page appears.

    3. Click Filer to sort the table by NEA.

    4. In the list, find the original source NEA.

    5. Identify any volumes owned by the original source NEA that have “Enabled” in the Remote Access column.

    6. If a volume owned by the original source NEA has “Enabled” in the Remote Access column and has Permissions of “Read Only“ or “Read/Write“, record the Permission for the volume.

    7. If a volume owned by the original source NEA has “Enabled” in the Remote Access column and has Permissions of “Custom“, select this volume, click Edit Volumes, and record the remote NEA and the custom Access that the remote NEA has for the volume.

    8. If any of the Nasuni Edge Appliance's owned volumes have "Custom" Remote Access permissions configured for other Nasuni Edge Appliances on your account, perform the recovery procedure first. Then, after the recovery procedure completes, set the correct custom Remote Access permissions for the owned volumes of the newly recovered appliance.

  5. You can also obtain information about remote volumes that the original source Nasuni Edge Appliance connects to that might have “Custom” permissions, by following these steps on the NMC:

    1. Click Volumes. The Volumes page appears.

    2. Click Remote Access. The Volume Remote Access Setting page appears.

    3. Click Permissions to sort the table by type of permission.

    4. In the list, find volumes with “Custom” permission.

    5. Select the volume and click “Edit Volumes”. The “Edit Volume Remote Access Settings” dialog box appears.

    6. If the original source NEA appears in the Description list, change the Remote Access Permissions from “Custom” to “Read/Write”.

      Important: If any remotely connected volumes use ‘Custom’ Remote Access settings, after the recovery process, the NEA cannot go back into NMC control because not all of the volumes can mount again.
      Therefore, you should change the Custom Remote Access setting for such volumes to Read/Write before performing the recovery process, then set the Remote Access setting back to Custom after the recovery process.

    7. Click “Save Remote Access Settings”.

    8. Repeat this for each volume that has “Custom” permission.

  1. Use the NMC to obtain other information about the original source NEA, such as:

  • Description of the original source NEA.

  • Escrow passphrase.

  • Automatic Software Updates.

  • Time Zone settings.

  • NTP Time Server settings.

2.4 Acquiring encryption keys

IMPORTANT! Obtain ALL ENCRYPTION KEYS for ALL VOLUMES (both local volumes and remote volumes)

Recovery requires access to the encryption keys for all local and remote volumes associated with the NEA. Before attempting to recover a Nasuni Edge Appliance, you must ensure that you have all the encryption keys for all the volumes on the Nasuni Edge Appliance. You must have all the encryption keys for both local volumes and remote volumes.

To ensure that you have all the encryption keys for all the volumes on the Nasuni Edge Appliance, perform the following steps:

  1. If any of your encryption keys are escrowed with Nasuni, one of these conditions must be true:

  • You have your escrow passphrase.

  • You are going to use the NMC to set an escrow passphrase.

  • When it is time to de-escrow your encryption keys, you intend to contact Nasuni Technical Support to obtain a special one-time-use recovery key for these escrowed encryption keys.

  1. If any of your encryption keys are not escrowed with Nasuni, obtain a list of all the non-escrowed encryption keys for all the volumes (both local volumes and remote volumes) on this Nasuni Edge Appliance. The list should include for each key:

    • Key Name.

    • Fingerprint. A fingerprint looks like this:

      DC0354A8E61A2F1D09C4D73DAA1006881A9E7E6D.

    • Key ID. A key ID looks like this: 1A9E7E6D.

    • Volumes (both local and remote) that the encryption key is assigned to.

    You can obtain this information in either of the following ways:

    • On the Nasuni Edge Appliance, click Configuration, then select Encryption Keys from the list.
      The Encryption Keys page includes a list of all the encryption keys on this Nasuni Edge Appliance.

    • If this Nasuni Edge Appliance is under the management of the Nasuni Management Console (NMC), then, on the NMC, click Filers, then click Encryption Keys in the left-hand column.
      The Filer Encryption Keys page displays a list of encryption keys on managed Nasuni Edge Appliances. Sort this list by Edge Appliance name. Find all the non-escrowed encryption keys for this Nasuni Edge Appliance.

  2. Using this list of all the non-escrowed encryption keys (both local volumes and remote), obtain the encryption key files for all the non-escrowed encryption keys for this Nasuni Edge Appliance. There are three possible locations for the encryption key files:

    • If the Nasuni Edge Appliance generated the encryption key, but you did not download the encryption key: download the encryption key now. On the Encryption Keys page, click Download Encryption Keys.

    • If the Nasuni Edge Appliance generated the encryption key, and you downloaded the encryption key already: you have the encryption key file. You still can download the encryption key again, if necessary.

    • If you uploaded the encryption key to the Nasuni Edge Appliance: you have the encryption key file that you uploaded. (For security reasons, encryption keys that you upload cannot be downloaded from the system.)

Note: If an uploaded encryption key has an associated passphrase, that passphrase is removed from the encryption key when it is uploaded. The Edge Appliance does not need the passphrase in order to use the encryption key. However, if you do not escrow this encryption key, and if you ever perform a recovery procedure on the Edge Appliance, you must provide that passphrase when you upload that encryption key during the recovery procedure.

Warning: Do NOT save encryption key files to a volume on a Nasuni Edge Appliance. You will NOT be able to use these to recover data. This is NOT how to upload encryption keys to a Nasuni Edge Appliance.

  1. For the non-escrowed encryption key files that you obtained in the previous step, find the “fingerprint” of each encryption key in each encryption key file. Third-party tools such as Kleopatra/Gpg4win can do this; this particular tool is not essential.
    The fingerprint looks like this:

    Note: Each encryption key file can contain multiple encryption keys.

  • Compare the fingerprint of each non-escrowed encryption key on this Nasuni Edge Appliance to the fingerprint of each encryption key in the encryption key files. Each non-escrowed encryption key on this Nasuni Edge Appliance must be contained in at least one encryption key file.

  • Create a list of which encryption key files contain which encryption keys that are on this Nasuni Edge Appliance. You need these files to provide the encryption keys as part of the recovery process in Providing Encryption Keys.

  1. You should now have all of the encryption files that you need to recover the NEA.

2.5 Removing the NEA from the NMC

You can remove the original source Nasuni Edge Appliance from the control of the Nasuni Management Console (NMC).

If you do not remove the original source Nasuni Edge Appliance from the control of the NMC, then the following considerations are necessary:

  • When you set an administrative user username and password for the destination NEA, that username and password are overwritten by the NMC’s username and password when the destination NEA connects to the NMC.
    Therefore, you should ensure that you know the username and password of the NMC.

  1. To remove the original source Nasuni Edge Appliance from control of the Nasuni Management Console (NMC), follow these steps on the NEA UI:

    1. On the NEA UI, click Services, then select Nasuni Management Console from the list. The Nasuni Management Console page appears.

    2. From the “NMC Management is” drop-down list, click disabled.

    3. Click Save.

2.6 Running the preparedr command

  1. Run the preparedr command on the console of the original source Nasuni Edge Appliance by following these steps:

    1. Access the console for the original source Nasuni Edge Appliance.
      For a Nasuni Edge Appliance hardware appliance, use a keyboard and monitor attached to the hardware appliance.
      For a Nasuni Edge Appliance virtual machine, use the virtual machine console window.

      1. Tip: For Microsoft Azure, this article describes how to enable the service console:  https://azure.microsoft.com/en-us/blog/virtual-machine-serial-console-access/.

    2. The console prompt appears.

    3. Press Enter to access the Service menu. The login prompt appears.

    4. Enter the username and password. The login username is service, and the default password is service.

Note: For security, you can use the changepassword command to change the password for the Service console.

  1. The Service Menu appears.

  2. Enter preparedr at the prompt.

    The following processing occurs:

    • CIFS services are stopped.

    • All SMB volumes on the original source Nasuni Edge Appliance are set to read-only.

    Warning: THIS PROCESSING TEMPORARILY IMPACTS ACCESS TO DATA ON THIS NASUNI EDGE APPLIANCE.

    • Final Nasuni snapshots are performed in order to ensure that all unprotected data in the cache of the original source Nasuni Edge Appliance is protected in a snapshot before the recovery procedure.

      Tip: To revert back to previous settings after running ‘preparedr’ on the console, reboot the appliance.

      Note: The original source Nasuni Edge Appliance is not decommissioned at this point.

  3. After the preparedr command finishes, and displays the message that it is finished, to exit the console commands, enter quit.

3 Installing new NEA

Before downloading and installing the new NEA, perform the following tasks:

  1. If you intend to perform a Side Load procedure using the original source Nasuni Edge Appliance, DO NOT shut down the Nasuni Edge Appliance. Continue with 3.1 Downloading the Nasuni Edge Appliance Software.

  2. If you DO NOT intend to perform a Side Load procedure, perform a shutdown of the original source Nasuni Edge Appliance by following these steps:

    1. Ensure that all data in the cache has been protected in object storage before shutting down the Nasuni Edge Appliance. For help with this, see Protecting data in the cache.

    2. Click Power on the navigation bar at the top of the page. The Shutdown Filer dialog box appears.

    3. Enter a Username (case-sensitive) and Password (case-sensitive) that has permission to perform this operation.

    4. Select Perform snapshot before shutting down. This option performs a Nasuni snapshot before shutting down the Nasuni Edge Appliance. This ensures that data is fully protected in object storage before shutting down. However, this process can take considerable time, depending on the size of the cache and the amount of changed and new data in the cache.

    5. Click Shutdown.

      The message “The system is shutting down. Click here to cancel the shutdown.” appears at the top of the Home page.

    6. To stop the shutdown, click the hyperlink marked “here”. You have 60 seconds to cancel the shutdown.

      The message “Shutdown cancelled at user request.” appears at the top of the Home page. The shutdown stops.

    7. If you do not stop the shutdown, after 60 seconds, the Nasuni Edge Appliance shuts down, and the Nasuni Edge Appliance user interface is no longer accessible.

      Continue with 3.1 Downloading the Nasuni Edge Appliance Software.

3.1 Downloading the Nasuni Edge Appliance Software

Note: This section describes the procedure for installing on a local hypervisor. The process for installing a hardware NEA or a cloud NEA is different. You should consult the installation document for your specific platform.

The first step in recovering the NEA is to download the Nasuni Edge Appliance software on the new destination Nasuni Edge Appliance.

To download Edge Appliance software, follow these steps:

  1. If you have not already done so, obtain the Serial Number and Authorization Code for the original source Nasuni Edge Appliance from portal.nasuni.com.

  2. You can download the Nasuni Edge Appliance software from portal.nasuni.com. For help with this, see Downloading and Installing Nasuni Software. In the Nasuni Edge area, click on the platform for the new destination Nasuni Edge Appliance.

  3. From the list, select an available release for the Edge Appliance. The list of available releases can change.

    Note: To ensure software compatibility, select the same version “family” as your existing Edge Appliance  For example, if the existing Edge Appliance is running version 10.3.1, you could select version 10.3.2 (which is in the same 10.3.x version family), but not version 10.4 (which is in a different version family).
    For specific update paths, see Updating Nasuni software.
    If you must use a different version than those offered, contact Nasuni Technical Support.

    Tip: For update paths, see Compatibility and Support.

    Note: You can perform the Recovery process to the same version of the software that you were running, or to a newer version than you were running, but not to an older version.
    It is possible that the list of available releases might not have the same version or a newer version than the version you were running. In such a case, select the newest available release. Then, during the Recovery wizard, use the Software Update page to update to the newest available release.

  4. Save the Nasuni Edge Appliance software file to a location on your local drive. The software file is larger than 3 GB.

    The amount of time to download the Nasuni Edge Appliance software file depends on your Internet connection.

  5. Unzip the Nasuni Edge Appliance software file.

3.2 Deploying software on the destination platform

After downloading the software, you must deploy the software to the new destination platform.

Nasuni provides detailed installation procedures for all supported hardware and virtual platforms. See Installing NEA and NMC.

Regardless of the procedure used to deploy the software to the new destination platform, you use the Initial Configuration Guide to finish the procedure.

Important: Internet connectivity (HTTPS port 443) is a prerequisite for setting up the NEA, or to update software during the installation.

Note: Downloading and executing the installation program for the virtual appliance is contingent upon the abilities of the virtual platform you are using.

3.3 Installing and launching the new NEA

Important: When using virtual machine Edge Appliances, Nasuni recommends running on a hypervisor that is still supported by its vendor. If a customer runs an Edge Appliance on an unsupported hypervisor version, a warning is logged at boot time. The warning is of the form:
“Nasuni recommends running the Management Console on ESX 7.0 or later.”

Follow this procedure:

  1. Launch the Nasuni Edge Appliance. The Nasuni Edge Appliance screen appears with a colored bar on the bottom that indicates the progress of the installation.

  2. After a few moments, the Nasuni Edge Appliance console screen appears, including the initial IP address.

    Tip: If you ever must log into the console service screen, press Enter and sign in. The default login username is service, and the default password is service.

3.4 Recording the assigned IP address

Record the Assigned IP Address displayed on the console screen. You use this to access the Nasuni Edge Appliance user interface using a Web browser.

4 Performing the Recovery

Now that the Nasuni Edge Appliance software is installed on the destination platform, you can recover the new destination Nasuni Edge Appliance.

Important: Internet connectivity (HTTPS port 443) is a prerequisite for setting up the Nasuni Edge Appliance, or to update software during the installation.

4.1 Accessing the new NEA via web browser

Open a Web browser and enter the IP address of the Nasuni Edge Appliance using this command:

https://<IP address> :8443

where <IP address>is the IP address from Recording the assigned IP address.

When you attempt to access the Nasuni Edge Appliance Home page for the first time, a message might appear indicating that the security certificate is not trusted. You can still access the site to proceed with the initial configuration procedure.

4.2 Initiating the Recovery wizard

The Recovery wizard begins with the “Enter the Network Parameters for this Filer” page.

4.3 Configuring

  1. In the “Hostname or FQDN” box, a default hostname for the Nasuni Edge Appliance appears.
    Nasuni recommends that you DO NOT use the same hostname as the original Edge Appliance. (However, if the original Edge Appliance is no longer available, you can use the same hostname as the original Edge Appliance.)
    Instead, you can either accept the default hostname or change it to a customized hostname. You can use ASCII letters a through z, digits 0 through 9, and hyphens.

    The name that you enter is the name that you provide to users so that they can access the Nasuni Edge Appliance. Ensure that any applications or processes that used the original hostname are updated to use the new hostname.

    Tip: You can change the hostname of the Edge Appliance at any time. In particular, you can change the hostname to the original hostname.

  2. The Nasuni Edge Appliance attempts to register the hostname in the DNS server, so that users can access this host by name.

Important: Edge Appliances must be configured with operational DNS servers and a time server (internal or external) within your environment.

  1. In the Network Interface Settings area, for each Device in the list, select the Traffic Group from the drop-down list.

    You can define your own traffic groups. See the next step.

  2. Also in the Network Interface Settings area, to configure each Traffic Group, click Edit beside the Traffic Group. The Network Settings page appears.

  3. From the Network Type drop-down list, select either Static or DHCP.

  • If you select DHCP (Dynamic Host Configuration Protocol), the IP Address, Netmask, and MTU Value fields become unavailable.

Note: DHCP cannot be enabled on more than one traffic group.

Important: If installing on the Google Compute Platform (GCP), use Static and not DHCP.

If DHCP is selected, the new Edge Appliance can reach appliances outside the local GCP subnet, but is unable to reach local appliances on the same subnet.

  • If you select Static, you must provide Network Interface Settings and System Settings. See your IT administrator for assistance.
    Enter the following information:

    • Enter the static IP address in the IP Address text box. The address of a static device must not already be present on the network. The Nasuni Edge Appliance verifies this and displays an error if a collision is detected.

      Ensure that the IP address you are using is not in use elsewhere.

      Note: If you define more than one static device, the Nasuni Edge Appliance checks that the subnets specified do not appear more than once.

      Important: If you change the IP address, also do the following:

      • Update Firewalls with the new IP address.

      • Update DNS entries so that they resolve the Edge Appliance with the new IP address.

      • Re-join the Domain after changing the IP address. You might need to remove the old computer object.

    • Enter a netmask address in the Netmask text box.

    • Enter the MTU value in the MTU Value text box.

      Tip: MTU settings should not exceed 1500.

      The maximum transmission unit (MTU) is the size (in bytes) of the largest protocol data unit that the layer can pass onwards. A larger MTU brings greater efficiency, because each packet carries more user data, while protocol overheads, such as headers, remain fixed; the resulting higher efficiency means a slight improvement in the bulk protocol throughput. A larger MTU also means processing fewer packets for the same amount of data. However, large packets can occupy a slow link for some time, causing greater delays to following packets, and increasing lag and minimum latency.

    • (Optional) You can specify a gateway for each traffic group. This gateway is used to return traffic for clients outside one of the Nasuni Edge Appliance's local networks that do not use the default gateway. In the Gateway text box, enter the IP address for the gateway.

    • Click OK to use these values. Click Cancel to exit this page without making any changes.

  1. In the System Settings area, from the Settings Source drop-down list, select either Static, DHCP, or DHCP with custom DNS as the source for system-wide configuration.

    • DHCP (Dynamic Host Configuration Protocol): Provides a network IP address for a host on an IP network automatically. The Default Gateway, Search Domain, Primary DNS Server, and Secondary DNS Server fields become unavailable.

      Important: If installing on the Google Compute Platform (GCP), use Static and not DHCP or DHCP with custom DNS.

      If DHCP or DHCP with custom DNS is selected, the new Edge Appliance can reach appliances outside the local GCP subnet, but is unable to reach local appliances on the same subnet.

    • DHCP with custom DNS: Provides a network IP address for a host on an IP network automatically. The Default Gateway field becomes unavailable.

      Important: If installing on the Google Compute Platform (GCP), use Static and not DHCP or DHCP with custom DNS.

      If DHCP or DHCP with custom DNS is selected, the new Edge Appliance can reach appliances outside the local GCP subnet, but is unable to reach local appliances on the same subnet.

      Enter the following information:

      • Enter one or more local search domains in the Search Domain text box, each separated by a space. You must enter valid hostnames.

        You can use search domains to avoid typing the complete address of domains that you use frequently. The search domains that you enter are automatically appended to names that you specify for purposes such as Active Directory configuration, HTTPS proxy, and NTP server. For example, if you specify the search domain “mycompany.com”, then typing “server1” for one of these purposes would connect to “server1.mycompany.com”.

      • Enter the IP address for your primary DNS server in the Primary DNS server text box. You must enter a valid IP address.

      • Enter the IP address for your secondary DNS server in the Secondary DNS server text box (if applicable). You must enter a valid IP address.

    • Static: Address information must be entered manually. Enter the following information:

      • Enter a default gateway address in the Default Gateway text box.

        The gateway address must match a subnet of a defined static network.

      • Enter one or more local search domains in the Search Domain text box, each separated by a space. You must enter valid hostnames.

        You can use search domains to avoid typing the complete address of domains that you use frequently. The search domains that you enter are automatically appended to names that you specify for purposes such as Active Directory configuration, HTTPS proxy, and NTP server. For example, if you specify the search domain “mycompany.com”, then typing “server1” for one of these purposes would connect to “server1.mycompany.com”.

      • Enter the IP address for your primary DNS server in the Primary DNS server text box. You must enter a valid IP address.

      • Enter the IP address for your secondary DNS server in the Secondary DNS server text box (if applicable). You must enter a valid IP address.

  2. To configure a proxy in order to reach HTTPS resources on the Internet, select the Configure A Proxy check box.

Tip: On Azure-based Edge Appliances only, during a recovery procedure, it is necessary to connect with IP address 169.254.169.254 in order to obtain information about the Azure VM instance.
If you have configured an HTTPS proxy, this attempt to connect can cause a delay of several minutes. To avoid this delay, add the IP address 169.254.169.254 to the “Do Not Proxy” section of the HTTPS Proxy configuration.

  1. To proceed, click Continue.

  2. The Review the Network Settings page appears.

    To accept the network settings, click Continue. To return to a previous page to change network settings, click Back.

  3. The Configuring Network Settings page appears.

  4. You are automatically directed to the specified IP address.
    Alternatively, you can click the link “here”.

  5. If there is a more recent software version than the software version that you are attempting to install, the Software Update page appears.

    To apply the suggested update, select “Apply the update” and click Continue. The update is installed.

    Otherwise, make sure that “Apply the update” is not selected, and click Continue.

  6. If you selected “Apply the update”, the Applying Updates page appears.

    The update is installed.

    Tip: The Web-based display might update several times during the installation of the update. Because some Web browsers cache the display, we recommend clearing the browser cache, so that you can tell when the update completes.

    After the update and reboot are complete, you are directed to the next step of the wizard.
    Alternatively, you can click the link “here” to proceed to the next step and wait for the reboot to finish.

  7. If there is no software update available, the Nasuni Filer Software Update page informs you that your NEA version is up to date.

    A verification message indicates the version of your NEA. Click Continue.

4.4 Entering serial number and authorization code

  1. The “Enter your serial number and authorization code” wizard page appears.

  2. Enter the Filer Serial Number and Authorization code, as recorded previously in Downloading the Nasuni Edge Appliance Software.
    Click Continue to proceed.

Important: You must use the same serial number for new NEA as the original Edge Appliance used.

Important: Authorization codes (also called “Auth codes”) are intended for a single use, and are not permanent. Authorization codes change if the associated serial number is used successfully, if the authorization code is refreshed via the NMC (Account Status Serial Numbers, then click Refresh), and if the authorization code is regenerated.
You can regenerate a serial number by using the Serial Numbers page of portal.nasuni.com.

  1. The “Perform Disaster Recovery on existing Filer” page appears.

  2. Verify that the Description and the Serial Number are the same as those of the original source NEA.

4.5 Providing encryption keys

Before proceeding to the next step, you must ensure that you have ALL THE ENCRYPTION KEYS for ALL THE VOLUMES for the Nasuni Edge Appliance. You must have ALL THE ENCRYPTION KEYS for BOTH LOCAL VOLUMES AND REMOTE VOLUMES.

For help with this, see Acquiring encryption keys.

Important: If you do not have the encryption key file for an encryption key that is not escrowed by Nasuni, you might not be able to recover this Edge Appliance. Contact Nasuni Support.

  1. If you have successfully obtained ALL THE ENCRYPTION KEYS for BOTH LOCAL VOLUMES AND REMOTE VOLUMES, enter “Perform Disaster Recovery” in the Confirmation text box, then click Continue to proceed.

    Note: After performing this step, the original source Nasuni Edge Appliance is decommissioned.

  2. The second Perform Disaster Recovery on Existing Filer page appears.

  • If you escrowed any of your encryption keys (including the backup key) with Nasuni, and you intend to use your escrow passphrase to de-escrow your escrowed encryption keys, perform the following steps:

    1. Select “Yes - Escrow Passphrase” from the drop-down list.

      Tip: You can select Yes even if you also have some non-escrowed encryption keys, which you provide separately.

    2. The Escrow Passphrase pane becomes available.

    3. If you do not have an encryption key escrow passphrase available, skip to step a below.
      Alternatively, if you set an encryption key escrow passphrase and you have the escrow passphrase, enter the escrow passphrase.

    4. Click Continue. Continue with step 3.

      Important: If you have previously escrowed your encryption keys with Nasuni, and you use these escrowed encryption keys as part of the recovery process, you MUST re-escrow those encryption keys with Nasuni if you want those encryption keys to continue to be escrowed with Nasuni. After the recovery is complete, the Nasuni Edge Appliance treats all encryption keys as if they were not created by this Nasuni Edge Appliance.

  • If you escrowed any of your encryption keys (including the backup key) with Nasuni, and you do not intend to use the escrow passphrase, but you do intend to request a recovery key to de-escrow your escrowed encryption keys, perform the following steps:

    1. Select Yes - Recovery Key from the drop-down list.

      Tip: You can select Yes even if you also have non-escrowed encryption keys, which you provide separately.

    2. The Recovery Key pane becomes available.

    3. Contact Nasuni Support to verify your identity and obtain your one-time-use recovery key.

    4. Then enter the Recovery Key.

    5. Click Continue. Continue with step 3

      Important: If you have previously escrowed your encryption keys with Nasuni, and you use these escrowed encryption keys as part of the recovery process, you MUST re-escrow those encryption keys with Nasuni if you want those encryption keys to continue to be escrowed with Nasuni. After the recovery is complete, the Nasuni Edge Appliance treats all encryption keys as if they were not created by this Nasuni Edge Appliance.

  • Otherwise, select No from the drop-down list, then click Continue.

This means that either you do not have any encryption keys escrowed with Nasuni at all, or you do have encryption keys escrowed with Nasuni, but you intend to provide your escrowed encryption keys yourself.

  1. If you selected No, the Upload Encryption Keys page appears.

    1. Click Choose File to navigate to one of your encryption key files. This is a .pgp file that you saved in Acquiring encryption keys.

      Important: The maximum length of a file name is 255 bytes.

      In addition, the length of a path, including the file name, must be less than 4,000 bytes.

      Since the UTF-8 representation of characters from some character sets can occupy several bytes, the maximum number of characters that a file path or a file name might contain can vary.

      If a particular client has other limits, the smaller of the two limits applies.

    2. Enter the Key Passphrase, if necessary, then click Upload Key(s). The selected encryption keys are uploaded. (For security reasons, encryption keys that you upload cannot be downloaded from the system.)

      All uploaded encryption keys must be at least 2048 bits long.

  2. If several encryption key files are necessary, the Upload Encryption Keys page could appear several times.

5 Completing setup of the NEA

This section completes the setup of the new NEA.

5.1 Finishing the Recovery wizard

  1. The “Ready to perform disaster recovery!” page appears.

  2. Click Continue. Recovery of the Nasuni Edge Appliance begins.

  3. After recovery, the Filer Recovery Complete page appears.

  4. Click Continue.

  5. The Accept the Terms of Service and License Agreement page appears.

  6. You can print or download a copy of the Terms of Service and License Agreement by clicking the appropriate icon.

  7. Select “I accept the Terms of Service”, then click Continue.

5.2 Creating the administrator account

  1. The “Enter a username and password for Administration of this Filer” page appears.

  2. Set up an administrator for the Nasuni Edge Appliance by creating a Username (case-sensitive) and a Password (case-sensitive). An indicator of password strength appears. Although password strength is not enforced, you should use strong passwords. The newly defined user is automatically a member of the Filer Administrators permission group for this Nasuni Edge Appliance.

    1. Note: If the appliance is managed by the NMC, the entered username and password might be overwritten by credentials from the NMC.

  3. Click Continue.

  4. The Recovery process is complete. The Configuration Complete page appears.

  5. The Nasuni Edge Appliance reboots. You can wait for this to happen, or click the link “here” to proceed directly to the Login page.

Note: When a reboot is requested, a notification is logged that the reboot was requested and by whom the reboot was requested.

5.3 Logging in to the recovered NEA

You are now ready to log in to the recovered NEA.

  1. The recovered Nasuni Edge Appliance becomes available in a few moments. The Login page appears.

  2. Enter the Username (case-sensitive) and Password (case-sensitive) that you specified in Creating the administrator account.

Tip: If this username and password do not work, try using the credentials for the local NMC administrative account.

  1. Click Log in.

With the new instance of the Nasuni Edge Appliance running, as soon as you rejoin the new appliance to Active Directory or LDAP,  you can access volumes and data using the CIFS shares, NFS exports, or FTP directories that you created before the recovery. Folders and files are available.

5.4 Reconfiguring the recovered NEA

While many settings are automatically retained by the recovered NEA, some settings must be reconfigured after the recovered NEA is running.

  1. If the previous Nasuni Edge Appliance was in Active Directory mode, you must re-join Active Directory to maintain ACL support. Before rejoining the Edge Appliance to the Active Directory domain, delete the original Active Directory computer object for the Edge Appliance. For details, see Joining a Nasuni Edge Appliance to a domain.

    Similarly, if the previous Nasuni Edge Appliance was in LDAP mode, you must re-join LDAP. For details, see Directory Services.

  2. Your new destination system might require bonding of NICs to complete network configuration. Usually, this is only required for hardware appliances. Details for this appear in the Initial Configuration Guide.

  3. If any of this Nasuni Edge Appliance's owned volumes had "custom" Remote Access permissions configured for other Nasuni Edge Appliances on your account, set the correct custom Remote Access permissions for the owned volumes of the newly recovered appliance.

    You can reconfigure the “custom” Remote Access Permissions for the Edge Appliance by using the NMC.

    For remote volumes with Remote Access Permissions of Read/Write or Read-Only for all appliances, the remote volumes re-connect automatically.

  4. If this Nasuni Edge Appliance previously accessed a volume with custom permissions for Remote Access, you must explicitly set the permissions of that volume for this Nasuni Edge Appliance. You recorded this information in Recording system and volume details.

  5. If you have previously escrowed your encryption keys with Nasuni, and you used these escrowed encryption keys as part of the Recovery process, you MUST re- escrow those encryption keys with Nasuni if you want those encryption keys to continue to be escrowed with Nasuni. (For security reasons, after the recovery is complete, the Nasuni Edge Appliance treats all encryption keys as if they were not created by this Nasuni Edge Appliance.)
    For details, see Escrowing Encryption Keys with Nasuni.

  6. If this Nasuni Edge Appliance was under the control of the Nasuni Management Console, return it to the control of the Nasuni Management Console. The version of the Nasuni Management Console must be equal to or greater than the version of the Nasuni Edge Appliance that the Nasuni Management Console is to manage.

    Click Services, then select Nasuni Management Console from the list. From the “NMC Management is” drop-down list, select enabled, then click Save.

  7. For any volume that was either Pending Delete or Pending Delete Approval before the recovery, those pending deletions might be canceled after the volume's Nasuni Edge Appliance is recovered. You should verify the status of any such pending deletions.

  8. The following settings, if configured, are not retained after the Recovery procedure. You recorded these settings in Recording system and volume details. You should reconfigure these settings.

  • Escrow passphrase.

  • Automatic Software Updates.

  • Time Zone settings.

  • NTP Time Server settings.

  1. If you have Web Access enabled, see Web Access Recovery for post-recovery steps.

6. Side Load and Recovery

The Recovery process enables you to recover the NEA after a true disaster, such as the loss of a data center. However, customers often perform the Recovery process simply in order to change from one platform to another.

In such a situation, there is already an operational original NEA that might contain active data in its cache. Performing the Recovery process results in a new NEA that has an empty cache. The customer must then manually re-populate the new cache with data, which could require considerable inbound bandwidth from the cloud, and which could take days, weeks, or even months to complete.

The Side Load feature enables you to transfer cache data directly from the original source decommissioned NEA to the new destination NEA. For more details, see Performing the Side Load process.

Tip: While the Side Load process typically reduces the time necessary to populate the cache of a NEA, this is not always the case. For example, situations that involve many small files might not experience significant time savings, due to the overhead of handling the metadata for each file.

Tip: Only the Administrative user can perform the Side Load process.

Tip: To perform the Side Load procedure, the original source NEA must be:

  • Running.

  • Decommissioned.

For details about performing the Side Load procedure, see Side Load.

7 Verifying all volumes and access

After completing the recovery procedure, you can verify the volumes on the new destination Nasuni Edge Appliance. This compares the names and other information of current volumes with the names and other information of volumes previously recorded in Recording system and volume details.

To verify the volumes, follow these steps:

  1. Check the Remote Access configuration of each of the volumes, using the Volume Remote Access Setting page on the NMC.

  2. If the Remote Access setting of any volume is “Disabled”, change the Remote Access setting to “Enabled” and the Permissions setting to either “Read/Write” or “Read Only”. For details, see Remote Access.

  3. For the new destination Nasuni Edge Appliance, click Volumes on the NMC. The Volumes page appears.

  4. In the Volumes List, compare the names and other information of all volumes with those previously recorded.

8 Shutting down the source NEA permanently

When you are satisfied that the original source Nasuni Edge Appliance is no longer necessary, you can shut down the original source Nasuni Edge Appliance, if it has not been shut down already.

To shut down the original source Nasuni Edge Appliance, follow these steps:

  1. Ensure that all data has been protected in object storage, either by performing snapshots or by running the Side Load procedure.

  2. On the navigation bar at the top of the page, click Power. The Shutdown Filer dialog box appears.

  3. Enter a Username (case-sensitive) and Password (case-sensitive) that has permission to perform this operation.

  4. Select Shut down immediately. Since all data has already been protected in object storage, it is not necessary to perform a Nasuni snapshot. Also, since this Nasuni Edge Appliance is no longer necessary, rebooting is not needed.

  5. Click Shutdown.
    The message “The system is shutting down. Click here to cancel the shutdown.” appears at the top of the Home page.

  6. To stop the shutdown, click the hyperlink marked “here”. You have 60 seconds to cancel the shutdown.
    The message “Shutdown cancelled at user request.” appears at the top of the Home page. The shutdown stops.

  7. If you do not stop the shutdown, after 60 seconds, the original source Nasuni Edge Appliance shuts down, and the original source Nasuni Edge Appliance user interface is no longer accessible.

This completes the Recovery process.