Skip to main content
Solved

HyperScale X (Reference Architecture) not hardened by default?


Patrick Dijkgraaf
Commvault Certified Expert
Forum|alt.badge.img+9

Hi!

 

We recently deployed 2 HyperScale X Reference Architecture clusters at a customer, and found out that:

 

  1. Ransomware Protection is not enabled by default
  2. Linux Firewall is not enabled by default

 

In my opinion, in current times, it is strange that by default the solution is so insecure.

Why are the firewall and ransomware protection not enabled by default? And will that be addressed in a future release?

Best answer by R Anwar

Hi @Patrick Dijkgraaf 

Ransomware protection by default for HSX is being worked on and should be available in future releases.

For enabling firewalld, you can add the regkey sHSEnableFirewall Y in /etc/CommvaultRegistry/Galaxy/Instance001/MediaAgent/.properties

It will enable firewalld by default from next boot. Ensure you meet the firewall requirements.

https://documentation.commvault.com/11.24/expert/132961_firewall_port_requirements_for_hyperscale_x_reference_architecture.html

View original
Did this answer your question?

7 replies

R Anwar
Vaulter
Forum|alt.badge.img+10
  • Vaulter
  • 104 replies
  • Answer
  • January 18, 2022

Hi @Patrick Dijkgraaf 

Ransomware protection by default for HSX is being worked on and should be available in future releases.

For enabling firewalld, you can add the regkey sHSEnableFirewall Y in /etc/CommvaultRegistry/Galaxy/Instance001/MediaAgent/.properties

It will enable firewalld by default from next boot. Ensure you meet the firewall requirements.

https://documentation.commvault.com/11.24/expert/132961_firewall_port_requirements_for_hyperscale_x_reference_architecture.html


Patrick Dijkgraaf
Commvault Certified Expert
Forum|alt.badge.img+9
  • Author
  • Commvault Certified Expert
  • 52 replies
  • January 18, 2022

Hi @R Anwar 

Thanks for the fast response! Good to know this is being worked on!

Regarding the firewall requirements, I see that for Commvault Distributed Storage (CDS), a HUGE amounts of ports are required…! This is probably only required on the Storage network, right? And not on the Data Protection network?

 


Patrick Dijkgraaf
Commvault Certified Expert
Forum|alt.badge.img+9
  • Author
  • Commvault Certified Expert
  • 52 replies
  • January 20, 2022

Anyone able to confirm? Thanks!


Mike Struening
Vaulter
Forum|alt.badge.img+23

@R Anwar , can you confirm?  I’ll reach out to some other people internally to see if I can confirm for you @Patrick Dijkgraaf !


R Anwar
Vaulter
Forum|alt.badge.img+10
  • Vaulter
  • 104 replies
  • January 21, 2022

Hi @Patrick Dijkgraaf 

Yes, these port requirements for CDS is on the Storage Pool network.

 


Nikos.Kyrm
Byte
Forum|alt.badge.img+13
  • Byte
  • 197 replies
  • August 16, 2024

Hello @Mike Struening , @R Anwar  and @Patrick Dijkgraaf ,


In our case, Hyperscale X Reference, 3 Nodes from HPE, In Health report, I see the following NEEDS ATTENTION about Platform Hardening.

Does anyone have an idea what is this?

Thank you in advance,
Nikos


Nikos.Kyrm
Byte
Forum|alt.badge.img+13
  • Byte
  • 197 replies
  • September 2, 2024
Nikos.Kyrm wrote:

Hello @Mike Struening , @R Anwar  and @Patrick Dijkgraaf ,


In our case, Hyperscale X Reference, 3 Nodes from HPE, In Health report, I see the following NEEDS ATTENTION about Platform Hardening.

Does anyone have an idea what is this?

Thank you in advance,
Nikos


 

I sent a follow-up response.

Performance hardening fixed by disabling root access!

 

Best regards,
Nikos


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings