ExaGrid-Security Reliability and Redundancy DS
ExaGrid-Security Reliability and Redundancy DS
ExaGrid assumes the hackers will take control of the backup application or the backup storage
and will issue delete commands for all backups. ExaGrid has the only non-network-facing tiered
backup storage solution (a tiered air gap) with delayed deletes and immutable deduplication
objects. This unique approach ensures when a ransomware attack occurs, data can be easily
recovered or VMs booted from the ExaGrid Tiered Backup Storage system. Not only can the
primary storage be restored, but all retained backups remain intact.
For a more in-depth look at the Retention Time-Lock feature, please download the
“ExaGrid Retention Time-Lock for Ransomware Recovery” data sheet at exagrid.com
Because there are two parity disks, each ExaGrid appliance can tolerate the simultaneous
loss of up to two disk drives. The first lost disk drive will automatically initiate a parity rebuild
operation using the global hot spare. Administrators and (optionally) ExaGrid customer support
are informed of the failure. A replacement disk drive is dispatched quickly, typically allowing
replacement of the failed disk the next business day. Loss of the second disk does not result in loss
of data since the remaining parity disk allows for data regeneration; providing more time for the
important task of replacing the failed disk(s).
Flash-Backed RAID Cache
The industry-leading PCIe RAID controller has an onboard volatile memory writeback cache that is backed up to flash memory
when system power is lost or interrupted. The RAID controller’s super-capacitor provides ample power to allow all writeback
cache data to be transferred to flash until system power is restored.
ExaGrid Specifications
y Uses FIPS 140-2 Validated Self-Encrypting Drives (SEDs) to ensure that data at rest is always efficiently encrypted with
256-bit AES and is never in the clear on the disk storage. All data, configuration settings, etc. are encrypted.
y Drive theft protection – The drives cannot be read outside of the host system where encryption was enabled.
y System theft protection – System booting and access to data can be restricted with a password. This can be enabled as
an option (no extra charge).
y
Operating System Patches
Current ExaGrid server platform software is based on the CentOS Linux distribution. We release critical and relevant OS
security patches as a part our regular ExaGrid software releases. Relevant CVEs will be included at least quarterly, with critical
fixes included more quickly.
ExaGrid Software
Management Interfaces
y ExaGrid software is managed through a web interface and will, by default, accept connections from a web
browser on both ports 80 (HTTP) and 443 (HTTPS). ExaGrid software supports disabling HTTP for environments
that require HTTPS (secure) only. When using HTTPS, ExaGrid’s certificate can be added to web browsers, or a
user’s certificates can be installed onto ExaGrid servers via the the web interface or provided by a SCEP server.
y Windows Active Directory (AD) domain credentials can be used to control access to the ExaGrid management
interface, providing authentication and authorization to the web GUI.
y Two-factor Authentication (2FA) can be required for any user (local or Active Directory) using any industry-
standard OAUTH-TOTP application.
y Role-Based Access Control using local or Active Directory credentials.
y Backup operator role for day-to-day operations has limitations such as no deletion of shares
y Admin role is like Linux super-user – allowed to do any administrative operation – limited users given this role
y Security Officer role required to approve any changes to the Retention Time-Lock policy
y Automatic user interface logout after a period of inactivity.
y Although access via SSH is not necessary for user functions, some support operations can only be provided
over SSH. ExaGrid secures SSH by allowing it to be disabled, allowing access via randomly generated
passwords, or customer-supplied passwords, or only SSH key pairs.
y Security checklist for quick and easy implementation of best practices.
y Each ExaGrid server runs a proper firewall and a customized Linux distribution that opens just the ports and
runs just the services necessary for receiving backups, web-based GUI, and ExaGrid-to-ExaGrid replication.
Share Access
y Common Internet File System (CIFS) – SMBv2, SMBv3
y Network File System (NFS) – Versions 3 and 4
y Veeam Data Mover – SSH for command and control and Veeam-specific protocol for data movement over TCP
y Veritas OpenStorage Technology protocol (OST) – ExaGrid specific protocol over TCP
y Oracle RMAN channels using CIFS or NFS
For CIFS and Veeam Data Mover, AD integration allows using domain credentials for share and management GUI access
control (authentication and authorization). For CIFS, additional access control is provided via an IP whitelist. For NFS, and OST
protocols, access control to backup data is controlled by an IP whitelist. For each share, at least one IP address/mask pair is
provided, with either multiple pairs or subnet mask used to broaden access. It is recommended that only the backup servers
that regularly access a share are placed in a share’s IP whitelist.
For Veeam shares using the Veeam Data Mover, access control is provided by username and password credentials entered into
both the Veeam and ExaGrid configuration. These can be AD credentials, or local users configured on the ExaGrid site. The
Veeam Data Mover is automatically installed from the Veeam server onto the ExaGrid server over SSH. The Veeam Data Mover
runs in an isolated environment on the ExaGrid server which limits system access, has no root privileges, and runs only when
activated by Veeam operations.
Logging Filesystem
Backup data is kept in the ExaGrid internal storage on an industry-standard logging filesystem where file activity is logged for
integrity and quick repair after an unclean shutdown.
United States
United Kingdom
350 Campus Drive / Marlborough, MA 01752 / (800) 868-6985
200 Brook Drive / Green Park, Reading, Berkshire RG2 6UB / +44 (0) 1189 497 051 exagrid.com
Singapore 1 Raffles Place, #20-61 / One Raffles Place Tower 2 / 048616 / +65 6808 5574
ExaGrid reserves the right to change specifications or other product information without notice. ExaGrid and the ExaGrid logo are trademarks
of ExaGrid Systems, Inc. All other trademarks are the property of their respective holders. ©2021 ExaGrid Systems, Inc. All rights reserved.