Quantum Q-Cloud Backup-as-a-Service Reference Architecture NOTICE This Technology Brief may contain proprietary information protected by copyright. Information in this Technology Brief is subject to change without notice and does not represent a commitment on the part of Quantum. Although using sources deemed to be reliable, Quantum assumes no liability for any inaccuracies that may be contained in this Technology Brief. Quantum makes no commitment to update or keep current the information in this Technology Brief, and reserves the right to make changes to or discontinue this Technology Brief and/or products without notice. No part of this document may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording, or information storage and retrieval systems, for any person other than the purchaser s personal use, without the express written permission of Quantum.
TABLE OF CONTENTS Introduction..........................................................................3 Q-Cloud Reduces Cloud Storage Costs & Increases Speed with Deduplication.................3 Q-Cloud Offers Cloud Storage Options that Others Cannot..................................3 How to Manage Local, Remote, and Cloud DXi.............................................7 Appendix.............................................................................9 2 Quantum Q-Cloud Backup-as-a-Service Reference Architecture
INTRODUCTION Users want to leverage cloud storage because it represents value. Remote offsite storage: The ability to store a backup copy in a remote location reduces the risk of loss. Inexpensive storage: The perception is that cloud storage is inexpensive. Users need to evaluate this thoroughly. With some offerings, the access fees can exceed the storage fees. This is not the case with Q-Cloud. Fast access to offsite storage: Access to cloud storage can be faster than access to traditional offsite storage with vendors such as Iron Mountain. Pricing models shift CapEx expenses into OpEx expenses, making it easier to acquire and retain the service. Immediate access to data and storage from anywhere: You can access cloud storage from anywhere in the world, as long as an Internet service is available. Disaster Recovery (DR) in the cloud: Locating a copy of data in the cloud is the first step towards DR in the cloud. Q-CLOUD REDUCES CLOUD STORAGE COSTS & INCREASES SPEED WITH DEDUPLICATION Cloud storage offerings from Microsoft, Amazon and others charge for the amount of storage used. So does Q-Cloud, but the difference is that Q-Cloud is storing deduplicated data. The others are storing fully hydrated data. It is easy to imagine use cases where deduplication can decrease the amount of storage required by ratios of 15-to-1 or more. The advantage of Quantum deduplication in the cloud is not only evident in how much less storage space is required, but also in how many fewer bytes have to traverse the network link between customer premise and the cloud. Quantum deduplication sends and stores only compressed unique data. This reduces the routine network bandwidth cost required to meet SLAs (Service-Level Agreements). In addition, whereas most cloud storage providers charge by the byte for downloading that fully hydrated data from the cloud, Quantum Q-Cloud does not charge for downloads. Q-CLOUD OFFERS CLOUD STORAGE OPTIONS THAT OTHERS CANNOT If the goal is cloud storage, the question is: How do you get a copy of your data to the cloud? Some cloud users manually copy files and/or directories to the cloud. Others write complex scripts to manage the process. Still others cobble together pieces from several vendors, adding cost and complexity to a solution that they then have to maintain. In contrast, the Q-cloud approach uses your existing data protection framework to move copies of backup data to the cloud. Quantum Q-Cloud Backup-as-a-Service Reference Architecture 3
Figure 1. Q-Cloud Usage Option 1: Local Backup, Replicated to Q-Cloud Customer Premise (Existing or Purchased Separately) DXi in Cloud Data Centers Protected Data Data Mover DXi Quantum vmpro SQL VMs E-mail Protected data (eg-15tb) Or other Backup DXi V1000 or other DXi Appliance Deduplication (eg-1tb*) Replication Deduplicated Data (eg-1tb*) CRM *Assumes an average deduplication ratio of 15:1 Option 1: Local Backup is Replicated to Q-Cloud Back up locally to a Quantum DXi using your traditional backup application and replicate an exact copy to a DXi in the cloud (Figure 1). This has the following advantages: 1. Minimize the backup window by using the throughput available in the local environment. 2. Provide a local copy in the event a restore is required. 3. Replicate only compressed unique data to the cloud, thereby minimizing both network bandwidth and cloud storage space requirements. 4. Assure the availability of an offsite cloud copy that is identical to the original. That cloud copy can be failed back to the original customer premise or anywhere else the end user might need it. 4 Quantum Q-Cloud Backup-as-a-Service Reference Architecture
Figure 2. Q-Cloud Usage Option 2: Symantec OST Backup and Optimized Duplication to the Q-Cloud. The Cloud copy is visible to Symantec. Customer Premise (Existing or Purchased Separately) DXi in Cloud Data Centers Protected Data Data Mover DXi SQL VMs E-mail Protected data (eg-15tb) NetBackup OST Backup Exec OST Backup DXi V1000 or other DXi Appliance Deduplication (eg-1tb*) OST Optimized Deduplication Deduplicated Data (eg-1tb*) CRM Symantec Visibility to the Q-Cloud *Assumes an average deduplication ratio of 15:1 Option 2: Symantec OST Backup with OpDup to Q-Cloud Back up locally to a Quantum DXi using Symantec (NBU and BUE) OST and use Symantec Optimized Duplication (OpDup) to replicate a copy to a DXi in the cloud (Figure 2). This has the following advantages: 1. Minimize the backup window by using the throughput available in the local environment. 2. Provide a local copy in the event a restore is required. 3. Replicate only compressed unique data to the cloud, thereby minimizing both network bandwidth and cloud storage space requirements. 4. Assure the availability of an offsite cloud copy that is identical to the original. That cloud copy can be failed back to the original customer premise or anywhere else the end user might need it. 5. Provide awareness of, and access to, the cloud copy through Symantec. a. Symantec can manage the cloud copy retention differently from the local copies, effectively building an archive in the Q-Cloud. b. Symantec can restore files directly from the Q-Cloud copy even after the local copy has long since expired and been removed. Quantum Q-Cloud Backup-as-a-Service Reference Architecture 5
Figure 3. Q-Cloud Usage Option 3: OST Compressed Deduplicated Backup to Q-Cloud Using DXi Accent. Accent is free. Customer Premise (Existing or Purchased Separately) DXi in Cloud Data Centers Protected Data Data Mover SQL VMs E-mail Protected Data (eg-15tb) NetBackup OST with Quantum Accent Backup Exec OST with Quantum Accent OST compressed deduplicated backup using Quantum Accent (Accent is FREE) Deduplicated Data (eg-1tb*) CRM *Assumes an average deduplication ratio of 15:1 Option 3: OST Compressed Deduplicated Backup Directly to the Cloud Some remote end user locations may not have sufficient data to justify deploying a DXi to them. Those sites could use Symantec OST, together with the free Quantum DXi Accent plugin, to back up directly to the Q-Cloud without requiring a local DXi (Figure 3). Accent will deduplicate the data on the backup server and send only new unique data to the Q-Cloud. This has the following advantages: 1. Remove the cost of on-premise hardware at remote locations. 2. Enable dependable backups that are stored in the cloud. 3. Minimize WAN costs with the use of Accent deduplication and compression. 4. Provide visibility from the backup application to the backup in the cloud, and the capability to restore individual files just as easily as it can restore an entire backup. a. All restores are sent in compressed and deduplicated mode for rehydration by Accent on the remote backup server. 6 Quantum Q-Cloud Backup-as-a-Service Reference Architecture
HOW TO MANAGE LOCAL, REMOTE, AND CLOUD DXi Every DXi and Q-Cloud solution includes DXi Advanced Reporting (DAR) at no additional charge. This tool enables a detailed granular view of what is happening inside the DXi. It can be used to: Measure data reduction of individual backups, OST Optimized Duplications, and OST Accent backups. Measure backup activity such as size of backup and throughput of the backup. Monitor replication for data protection effectiveness. Present up to 6 years of historical data. Show trending for capacity and growth. Figure 4. DXi Advanced Reporting Graph Examples Quantum Q-Cloud Backup-as-a-Service Reference Architecture 7
In addition to DXi Advanced Reporting, Quantum also offers Quantum Vision, a tool that monitors all Quantum products including DXi, Scalar tape libraries, and vmpro backup utility for VMware. It can be used to: Monitor replication to provide data that can be audited to show that data protection policies are achieved. to provide an alert in the event that replication fails. Figure 5. Vision Replication Alert Example Manage your existing capacity as well as plan for capacity upgrades. Generate reports to maximize performance and reduce cost. Reports can be scheduled to run automatically and to be automatically emailed to a list of addressees. Can include CSV data and/or graphic summaries. Send proactive notification of change in system status. Send proactive progressive notifications as capacity is consumed due to annual growth or unplanned changes in the backup. This provides time to react by purchasing a capacity upgrade or trimming the data stored. View topology, replication relationships, replication status in a single graph. Figure 6. Vision Topology Example 8 Quantum Q-Cloud Backup-as-a-Service Reference Architecture
APPENDIX Connectivity Details Figure 7 shows the connectivity and data path corresponding to Option 1: Local Backup is Replicated to Q-Cloud, described in the previous section. It identifies the potential use of Network Address Translator (NAT) servers and lists the firewall ports that must be open for replication to function properly. Figure 7. Connectivity Diagram when Using Any ISV Backup Application with Standard DXi Replication to the Q-Cloud Backup Server Internal IP 10.xx.xx.70 Backup using any ISV NAT IP 146.xx.xx.71 NAT IP 13.xx.xx.xx NAT server DXi Replication NAT server Local DXi Internal IP 10.xx.xx.71 Cloud DXi Internal IP 10.xx.xx.xx Firewall Open TCP Ports 80,1062 Firewall Open TCP Ports 80,1062 Quantum Q-Cloud Backup-as-a-Service Reference Architecture 9
Figure 8 shows the connectivity and data path corresponding to Option 2: Symantec OST Backup with OpDup to Q-Cloud, described in the previous section. It identifies the potential use of Network Address Translator (NAT) servers and lists the firewall ports that must be open for OST Optimized Duplication to function properly. Figure 8. Connectivity Diagram for OST Backup and Optimized Duplication Copy to Q-Cloud OST Management Backup Server Internal IP 10.xx.xx.70 NAT IP 146.xx.xx.70 Route B OST Backup and OpDup NAT server Route A Management NAT IP 146.xx.xx.71 Local DXi Internal IP 10.xx.xx.71 Route B OpDup NAT server NAT IP 13.xx.xx.xx Cloud DXi Internal IP 10.xx.xx.xx Firewall Open TCP Ports 80,1062,3095-3102, 10001,10002 Firewall Open TCP Ports 80,1062,3095-3102, 10001,10002 The setup requirements for OST backup to local DXi with OpDup to the cloud are: 1. Obtain a NAT address for your backup server (the backup server must be able to see the remote DXi in order to manage the entire OpDup lifecycle). 2. Obtain a NAT address for your local DXi. 3. Confirm that the ports in the local firewall are open. a. You need TCP ports 80, 1062, 3095-3102, 10001, 10002. 4. Obtain from Quantum Q-Cloud: a. The NAT address for the cloud DXi. Be sure and add this NAT address as an allowed IP to your firewall rule. b. The OST storage server and LSU names that you will be writing to. 5. Provide Quantum Q-Cloud both of your NAT IP address so they can add them to their firewall rule. 6. Configure an OST storage server and LSU on your local DXi. 7. Configure your backup server(s) to use OST to backup to the local LSU. 8. Create the backup policy and the Storage Lifecycle Policy for copying the backup to the cloud. 9. You or Quantum Q-Cloud must issue an opduptranslate command to the remote DXi via its CLI. a. [In a single-tenant DXi hosting configuration, you will most likely be able to do this yourself. In a multi-tenant DXi hosting configuration, the Q-Cloud will have to do this for you.] Quantum Q-Cloud Backup-as-a-Service Reference Architecture 10
b. Consider that the backup server knows the cloud DXi by its NAT IP address and knows the local DXi by its local IP address. The cloud DXi does not know the local DXi s local IP address. It only knows the local DXi by its NAT IP address. So the remote DXi needs to be told that, when the backup server contacts it with a reference to the local DXi, using the local IP address, then the cloud DXi should translate that to the NAT address. c. Command format bash-3.2$ syscli --add opduptranslate --replicationip <NAT IP> --dataip <local IP> d. Other related syscli commands are listed below. Replication IP is the same as NAT IP and data ip is the same as local ip. Also, if you make a mistake when entering the opduptranslate command, you will have to delete the erroneous entry and make a new entry. That is, opduptranslate commands to not overwrite or replace previous commands for that local IP. Verify that you have the correct entry by reviewing the output of the list command. bash-3.2$ syscli --help opduptranslate syscli --add opduptranslate --replicationip <replication_ip> --dataip <data_ip> Allows to map OST target ip address to a replication ip address. syscli --del opduptranslate --dataip <data_ip> Allows to delete the mapping of OST target ip address for a replication ip address. syscli --get opduptranslate --dataip <data_ip> Gets the replication ip address for a translated OST target ip address. syscli --edit opduptranslate --replicationip <replication_ip> --dataip <data_ip> Allows to edit the existing map of OST target ip address to a replication ip address. syscli --list opduptranslate Lists all mappings of OST target ip address to a replication ip address Figure 9 shows the connectivity and data path corresponding to Option 3: OST Compressed Deduplicated Backup Directly to the Cloud, described in the previous section. It identifies the potential use of Network Address Translator (NAT) servers and lists the firewall ports that must be open for OST with Accent to function properly. Figure 9. Connectivity Diagram for OST with Accent OST Accent Backup Server Internal IP 10.xx.xx.70 NAT IP 146.xx.xx.70 NAT server NAT server NAT IP 13.xx.xx.xx Cloud DXi Internal IP 10.xx.xx.xx Firewall Open TCP Ports Firewall Open TCP Ports Quantum Q-Cloud Backup-as-a-Service Reference Architecture 11
DXi Accent is a no-cost feature included with every DXi and Q-Cloud service. Accent will deduplicate the backup data on the backup server and send only compressed unique data to the cloud. This has the potential of (1) reducing network load, and (2) reducing the backup window if network loading and/or propagation times were extending the backup window. DXi Accent is not all-or-none, but can be configured for individual backup servers. DXi Accent requires DXi OST plugin v2.6 or newer. The setup requirements for Accent backups directly to the cloud are: 1. Obtain a NAT address for your backup server. 2. Confirm that the ports in the local firewall are open (80, 1062, 3095-3102, 10001, 10002). 3. Obtain from Quantum Q-Cloud: a. The NAT address for the cloud DXi from your cloud service provider. Be sure and add this NAT address as an allowed IP to your firewall rule. b. The OST storage server and LSU names that you will be writing to. 4. Provide Quantum Q-Cloud your NAT IP address so they can add it to their firewall rule. 5. Configure your backup server(s) to use OST to backup to the cloud LSU. 6. Consult the respective documentation and turn on Accent on the cloud DXi as well as the backup server plugin. Both must be ON in order to utilize Accent on that connection. Quantum Q-Cloud Backup-as-a-Service Reference Architecture 12
DXi Q-Cloud Compatibility Table 1. DXi Q-Cloud Replication and Accent Support DXi FW 1.x (Includes DXi7500 and some 8500 & 6700) to Q-Cloud Yes DXi FX 2.x Yes Yes Accent Backup Yes NA OST OpDup to Q-Cloud Yes Table 2. Q-Cloud Support Details DXi FW 1.x (Includes DXi7500 and some 8500 & 670x) to Q-Cloud that is DXi 2.1 to Q-Cloud that is DXi 2.2 to Q-Cloud that is DXi 2.2.1 Yes (1) Yes Yes Yes (2) DXi FW 2.1 Yes (1) Yes (1) Yes (1) Yes DXi FW 2.2 Yes (1,3) Yes (3,4) Yes (3,4) Yes DXi FW 2.2.1 Yes (1) Yes (4) Yes Yes Accent Backup Yes Yes Yes NA OST OpDup to Q-Cloud 1. FW 2.1 requires manually editing replication.conf to add target IP due to source-target authentication checking that is incompatible with the use of NAT servers. Fixed in 2.2.1. 2. Requires DXi command opduptranslate on cloud target, which is not available in FW 1.x, so cloud target must always be FW 2.x or higher. 3. FW 2.2 has a replication bug that generates some Invalid Packet Size (IPS) packets. Some firewalls, including Quantum IT, block IPS packets so replication cannot occur across those firewalls. This is fixed in FW 2.2.1. 4. FW 2.2 introduces new replication authentication protocol that doesn t work when NAT servers are involved. The workaround is to manually edit replication.conf. This will be fixed in FW 2.3. ABOUT QUANTUM Quantum is a proven global expert in Data Protection and Big Data management, providing specialized storage solutions for physical, virtual and cloud environments. From small businesses to major enterprises, more than 50,000 customers trust Quantum to help maximize the value of their data by protecting and preserving it over its entire lifecycle. With Quantum, customers can Be Certain they re able to adapt in a changing world keeping more data longer, bridging from today to tomorrow, and reducing costs. See how at www.quantum.com/becertain. www.quantum.com 866-809-5230 2012 Quantum Corporation. All rights reserved. Quantum, the Quantum logo, DXi, Q-Cloud, Scalar and Vision are either registered Quantum trademarks or Q-Cloud trademarks Backup-as-a-Service of Quantum Corporation and Reference its affiliates Architecture in the United States and/or other countries. All other trademarks are the property of their respective owners. TB00020A-v02 13 Nov 2012