Skip to main content
Question

proxy between media agents for axu copy

  • January 13, 2025
  • 3 replies
  • 30 views

mgambetti
Bit
Forum|alt.badge.img+1

good evening,

 i am studying about proxy and i am quite confused about proxy vs vsa proxy vs network gateway, which are the use cases?

i am configuring a local storage pool made of 3 different media agents with local discs, and like to add another REMOTE storage pool for aux copy, someone suggests me to put in front of media agents a proxy for limiting and controlling access, but i quite confused, is better proxy, vsa, or gateway?

 

thank you.

3 replies

Alex Deaconu
Vaulter
Forum|alt.badge.img+4

We use the term ‘Proxy’ for a lot of objects in Commvault. Proxy can be an NFS/CIFS Access Node, used to back up Network Storages, or an IntelliSnap dedicated Backup Client, used to back up a client’s file system, avoiding system resource utilization on production hosts, or a Network Gateway, used to enable communications between hosts in different restricted subnets, or a particular host that acts as a communication/control node for IntelliSnap Arrays.

 

There is more usage of the Proxy term, like MySql Standby Backup client, or Cloud/RDS DB Access Node, or VSA FREL, and maybe more that I cannot remember off the top of my head.
 
Without the context of what was suggested, I cannot tell you what the setup would be. Given that there is a reference to ‘limiting and controlling access’, I believe that is a reference to the Network Gateway. This is a client that acts as a middleman, to facilitate communications in restricted networks.
https://documentation.commvault.com/v11/essential/setting_up_network_gateway_connection_using_predefined_network_topology_client_type_is_servers.html
 
One such example is if you have clients in a network DMZ, and you need to protect them. You can add a Network Gateway in a network in between the DMZ and the internal network. Clients in the DMZ connect to the Network Gateway, the CommServe and Media Agents from the internal network connect to the Network Gateway, and the gateway acts as an intermediary. Obviously, the firewall must still permit traffic from the two networks to the Network Gateway, but this would be a more limited setup, where you would have a dedicated host that is tightly locked down, and all it does is redirect traffic.
 
If you have any questions on the above, or if you have additional context, let us know.


mgambetti
Bit
Forum|alt.badge.img+1
  • Author
  • Bit
  • 2 replies
  • January 14, 2025

this is the main idea, two sites, connected using PRIVATE network, site A keeps primary copies, site B aux copies, i think using network proxy as a more modular solution THAN DIRECTLY configure lib01 to “see on layer3” the lib02, or am i wrong?

 


Forum|alt.badge.img+11
  • Vaulter
  • 241 replies
  • January 14, 2025

That looks indeed like a Network Proxy.

The documentation provided by my colleague Alex should help here = https://documentation.commvault.com/v11/essential/setting_up_network_gateway_connection_using_predefined_network_topology_client_type_is_servers.html


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings