LINUXOR.SK ... open source notes ...

Balabit - Backup policies (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Backup, archive and retention

noteThe design's chapter 4.5.1 lists, for the same three data backups, encryption with SCB-AUDIT-ENCRYPT, timestamping and signing with SCB-AUDIT-SIGN. The backup policy page has no such fields: those rows describe the audit policy that encrypts the audit trails when they are written, not the backup.

The four backup policies of the site 1 cluster: one for the system (configuration) backup and one per company for the audit trails of its connections. Each copies to its own NFS export on the NetApp SVM DC1-S-VCVSM001, every night, one hour apart.

ItemValue
WhereSCB web interface, Policies > Backup & Archive/Cleanup, section Backup policies
Clusterdc1-s-xblb001, the site 1 HA pair dc1-a-ablb001 and dc1-b-ablb001
Firmware at the time5 LTS (5.0.3), per chapter 7.2 of the same document
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapter 7.4.2, "configuration from real implementation realized in production environment"
Used bySYSTEM-BACKUP by Basic Settings > Management > System backup (Management, site 1); the others by the connections (RDP connections, SSH connections)
Not in itSchedule details beyond the start time (days, retries), the NFS options, a backup policy for partner 3

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.4.2

Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / NAME = SYSTEM-BACKUP
Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / START TIME = 00:00
Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / TARGET SETTINGS = NFS
Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / TARGET SERVER = 10.11.18.236 (Netapp)
Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / EXPORT = DC1_S_VCVSM001_data/scb_system_backup
Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / SEND NOTIFICATION ON ERRORS ONLY = Yes

Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / NAME = ORG-BACKUP
Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / START TIME = 01:00
Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / TARGET SETTINGS = NFS
Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / TARGET SERVER = 10.11.18.236 (Netapp)
Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / EXPORT = DC1_S_VCVSM001_data/scb_org_backup
Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / SEND NOTIFICATION ON ERRORS ONLY = Yes

Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / NAME = PARTNER1-BACKUP
Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / START TIME = 02:00
Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / TARGET SETTINGS = NFS
Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / TARGET SERVER = 10.11.18.236 (Netapp)
Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / EXPORT = DC1_S_VCVSM001_data/scb_partner1_backup
Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / SEND NOTIFICATION ON ERRORS ONLY = Yes

Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / NAME = PARTNER2-BACKUP
Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / START TIME = 03:00
Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / TARGET SETTINGS = NFS
Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / TARGET SERVER = 10.11.18.236 (Netapp)
Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / EXPORT = DC1_S_VCVSM001_data/scb_partner2_backup
Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / SEND NOTIFICATION ON ERRORS ONLY = Yes
FieldWhat it means
START TIMEThe time of day the policy runs. The design's chapter 4.5.1 adds "PERIODICITY Daily"; the as-built table shows only the time
TARGET SETTINGS = NFSThe protocol. The conceptual and logical design still say CIFS; why it changed is told in SVMs and NFS
TARGET SERVERThe NFS data LIF of the SVM DC1-S-VCVSM001, in the same backup/archive network 10.11.18.224/28 (VLAN 1020) as the SCB's address 10.11.18.225
EXPORTVolume and qtree on the SVM, written without a leading slash. The export rule allows only 10.11.18.225
SEND NOTIFICATION ON ERRORS ONLYAs I understand it, a mail goes out only when a run fails; the recipients are those of Basic Settings > Management > Mail settings

SYSTEM-BACKUP alone does nothing until the system backup page selects it; that page also switches on encryption of the configuration with the GPG public key SCB-BACKUP. The other three are selected per connection, so every connection names the backup policy of the company it belongs to. The NetApp side has qtrees scb_partner3_backup and scb_partner3_archive too, but no PARTNER3-BACKUP policy is in this table: the partner 3 connections are not in the design, and which policies they used is not recorded.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
Balabit SCB 5 LTS, 5.0.xDiscontinued since 2020-05-28; the product is now One Identity Safeguard for Privileged Sessions (SPS), newest documents 9.0 of September 2026
Backup over NFS after SMB failedSPS 9.0 still offers Rsync, SMB/CIFS and NFS. The NFS version is detected automatically, up to NFS version 4; files are owned by root with no_root_squash, by nobody otherwise
Exports and qtrees created on the NetApp in advanceStill required: backup and archive policies only work with existing shares and subdirectories
Target given as an IPv4 addressBackup targets must still be IPv4 addresses
SYSTEM-BACKUP with GPG encryptionUnchanged feature. Only the configuration file is encrypted, and system backups do not contain audit-trail data; an encrypted configuration has to be decrypted locally before it can be imported

The settings in the table are still documented in SPS 9.0; whether the policies survive the upgrade chain or a data migration is not stated. The appliance underneath would not survive it: SPS 8.0 and later are not supported on T-Series hardware.

← solutionz