Solved

Enabling Loopback Mode on Clients and Client Groups ?

  • 31 January 2022
  • 3 replies
  • 136 views

Userlevel 3
Badge +11

Hi Community , 

Is there any advantage of enabling “Enabling Loopback Mode on Clients and Client Groups” . Just want to understand in which scenario this setting will be useful and what is the impact on backups and recovery jobs if we enabled this ?

https://documentation.commvault.com/11.24/expert/125171_enabling_loopback_mode_on_clients_and_client_groups.html

Regards, Mohit

icon

Best answer by Alireza B 2 February 2022, 22:58

View original

If you have a question or comment, please create a topic

3 replies

Userlevel 4
Badge +9

Hey Mohit,

There is no specific advantage. It's more for security reasons. By default CV services will listen on all interfaces on any client meaning from outside you will see Client IP(s) is listening on 8400 etc.

In case you want to make sure services are not listening on Client IPs you can use this feature. Please note some services will still listen on IPs to facilate the communications like CVFWD which is responsible for comms.

 

Cheers,

Ali

Userlevel 3
Badge +11

@Alireza B :

Thank you . Can you please give a practical scenario or possible type of security threat where this feature would be useful .

Regards, Mohit

Userlevel 4
Badge +9

Generally speaking the less listening ports on IPs the better. More ports available on a server means more doors (even locked).This is important for critical servers that are exposed to external users. For servers sitting all in internal network this won't matter much but again it's something you need to check with your security team. Web shells and other tools that an attacker usually use leverage listening ports for gaining access. Please note, ports are not the only concern, you can have firewall rules to control these traffic direction, protocols etc to make them more secure.