Storage System Integration
The account used to connect to NetApp ONTAP, Fujitsu ETERNUS HX/AX, Lenovo ThinkSystem DM/DG storage system must have permissions described in this section. The commands are provided for the console, UI names may differ.
Required permissions depend on what you add to the storage infrastructure. If you add a whole cluster, use the permissions listed for the cluster. If you add a storage virtual machine (SVM), use the permissions listed for the SVM.
Cluster (VMware Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
DEFAULT |
readonly |
|
cluster |
readonly |
|
metrocluster |
readonly |
|
vserver fcp |
readonly |
|
volume file |
readonly |
|
lun igroup |
all |
|
vserver iscsi |
all |
|
network |
readonly |
|
system node |
readonly |
|
security |
readonly |
|
security login |
readonly |
|
set |
readonly |
|
snapmirror |
all |
|
system |
readonly |
|
version |
readonly |
|
volume qtree |
readonly |
|
lun |
all |
|
vserver nfs |
all |
|
volume snapshot |
all |
|
volume |
all |
|
vserver |
all |
SVM (VMware Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
DEFAULT |
none |
|
lun |
all |
|
lun igroup |
all |
|
network |
readonly |
|
security |
readonly |
|
security login |
readonly |
|
snapmirror |
all |
|
system |
readonly |
|
version |
readonly |
|
volume |
all |
|
volume file |
readonly |
|
volume qtree |
all |
|
volume snapshot |
all |
|
vserver |
all |
|
vserver fcp |
all |
|
vserver iscsi |
all |
|
vserver nfs |
all |
Cluster (NAS Backup Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
DEFAULT |
readonly |
|
security |
readonly |
|
security login |
readonly |
|
volume snapshot |
all |
|
vserver |
all |
|
vserver nfs |
all |
|
snapdiff |
all Note: Required if Use native changed files tracking is enabled. |
SVM (NAS Backup Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
DEFAULT |
none |
|
lun |
readonly |
|
network |
readonly |
|
security |
readonly |
|
security login |
readonly |
|
snapmirror |
readonly |
|
version |
readonly |
|
volume |
readonly |
|
volume snapshot |
all |
|
vserver |
all |
|
snapdiff |
all Note: Required if Use native changed files tracking is enabled. |
Cluster (Veeam Agent Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
cluster |
readonly |
|
lun |
all |
|
metrocluster |
readonly |
|
network |
readonly |
|
system license |
readonly |
|
system node |
readonly |
|
version |
readonly |
|
volume |
all |
|
volume snapshot |
all |
|
vserver |
all |
SVM (Veeam Agent Integration)
|
Command/Directory |
Access/Query Level |
|---|---|
|
lun |
all |
|
network |
readonly |
|
version |
readonly |
|
volume |
all |
|
volume snapshot |
all |
|
vserver |
all |
NetApp US API Storage Systems
The account used to connect to NetApp FAS/AFF/ASA/ASA r2 storage system must have permissions described in this section. The commands are provided for the console, UI names may differ.
Basic Permissions
The following permissions are required for all integration types. These permissions are required for backup, restore, replication and snapshot workflows on both AFF/unified and ASA r2 systems. Permissions can be provided on the SVM or cluster level; otherwise it is stated in the table.
|
API Endpoint |
Access Level |
|---|---|
|
/api/cluster |
readonly |
|
/api/cluster/jobs |
readonly |
|
/api/cluster/licensing/access-tokens |
read_create |
|
/api/cluster/licensing/licenses |
readonly (cluster level only) |
|
/api/cluster/metrocluster |
readonly (cluster level only) |
|
/api/cluster/nodes |
readonly (cluster level only) |
|
/api/cluster/peers |
read_create |
|
/api/network/ip/interfaces |
readonly |
|
/api/protocols/nfs/export-policies |
all |
|
/api/protocols/nfs/services |
readonly |
|
/api/protocols/san/fcp/services |
readonly |
|
/api/protocols/san/igroups |
all |
|
/api/protocols/san/iscsi/services |
readonly |
|
/api/protocols/san/lun-maps |
all |
|
/api/snapmirror/relationships |
all |
|
/api/storage/aggregates |
readonly (cluster level only) |
|
/api/storage/luns |
all |
|
/api/storage/qtrees |
all |
|
/api/storage/snaplock/compliance-clocks |
readonly |
|
/api/storage/volumes |
all |
|
/api/svm/svms |
readonly |
ASA r2-Only Permissions
These permissions are required only for ASA r2 systems.
|
API Endpoint |
Access Level |
|---|---|
|
/api/application/consistency-groups |
all |
|
/api/storage/storage-units |
all |
Other Universal Storage API Integrated Systems
The account used to connect to a Universal Storage API integrated system must be assigned a necessary role in the storage system console and have a set of necessary permissions.
- For DataCore, the account must have the following permissions:
- General
- Port
- Host
- Virtual disk
- Snapshot
- Physical disk
- For Dell PowerMax, the account must be assigned the Storage Administrator role.
- For Dell PowerStore, the account must be assigned one of the following roles:
- Administrator
- Storage Administrator
- Storage Operator
- For Fsas ETERNUS EP300, the account must be assigned the following roles:
- Storage Administrator (View Only)
- Storage Administrator (Provisioning)
- Storage Administrator (Local Copy)
- For Fsas ETERNUS AF and DX series, the account must be assigned the Software role.
- For Hitachi VSP/VSP One Block, the account must be assigned the following roles:
- Storage Administrator (View Only)
- Storage Administrator (Provisioning)
- Storage Administrator (Local Copy)
- For HPE XP, the account must be assigned the following roles:
- Storage Administrator (View Only)
- Storage Administrator (Provisioning)
- Storage Administrator (Local Copy)
- For NEC Storage M Series, the account must be assigned the Administrator role.
- For NEC Storage V Series, the account must be assigned the following roles:
- Storage Administrator (View Only)
- Storage Administrator (Provisioning)
- Storage Administrator (Local Copy)
- For NetApp FAS/AFF/ASA/ASA r2 permissions, see NetApp ONTAP, Fujitsu ETERNUS HX/AX, Lenovo ThinkSystem DM/DG Permissions.
- For NetApp SolidFire/HCI, the account must have the following permissions:
- Volumes
- Cluster Admins
- For Tintri IntelliFlash (formerly Western Digital IntelliFlash, Tegile), the account must be assigned the Veeam Admin Role.
For privileges required to integrate the unstructured data backup feature with Dell PowerScale (formerly Isilon), see Integration with Dell PowerScale in the Unstructured Data Backup section.
For storage systems not mentioned above, the account must have Administrator role.