CDP_SiteToSite

SonicWALL CDP Site-to-Site Backup and Recovery

 
“SonicWALL CDP Site-to-Site Service Overview” section
 
“Preparing for the SonicWALL CDP Site-to-Site Service” section
 
“Configuring the Downstream CDP Appliance” section
 
“Configuring the Upstream CDP Appliance Quota” section
 
“Removing a Downstream CDP” section
 
“Selecting Files for Offsite Backup” section
 
“Recovering Data From the Upstream CDP Appliance” section
 
“Deleting Data From the Upstream CDP Appliance” section
 
“Replacing the Downstream CDP Appliance” section

SonicWALL CDP Site-to-Site Service Overview

This section provides an introduction to the SonicWALL CDP Site-to-Site Service feature. This section contains the following subsections:

 
“What is the SonicWALL CDP Site-to-Site Service?” section
 
“Benefits of the Site-to-Site Service” section
 
“How Does the SonicWALL CDP Site-to-Site Service Work?” section

What is the SonicWALL CDP Site-to-Site Service?

The SonicWALL CDP Site-to-Site Data Backup Service is an optional offsite backup and recovery solution that stores data in a secure data center, and can be purchased for an additional fee. For more information, see the SonicWALL CDP Offsite Data Backup Service data sheet at: <http://www.sonicwall.com/downloads/DS_CDP_Offsite_US_060507.pdf >.

The CDP Site-to-Site Service feature provides a secure, reliable, and confidential method of backing up and recovering data from one or more local CDP appliances to another local or offsite CDP appliance.

In a typical one-to-one configuration of CDP Site-to-Site, one local CDP appliance, or downstream appliance, is used to backup local workstations. A second CDP appliance, or upstream appliance, is deployed locally or at a remote location and is used to backup the downstream CDP appliance.

 
Note
You must purchase an 8x5 or 24x7 support contract and a 1, 3, 5, or 10 node Offsite license for the upstream CDP appliance.

The one-to-one CDP Site-to-Site configuration can be expanded to include multiple downstream CDP appliances that back up to a single local or offsite upstream CDP appliance. The upstream appliance needs to have sufficient Offsite nodes licensed.

 
Note
Multiple downstream CDP appliances can backup to a single upstream CDP appliance. Upstream CDP appliances can also backup local data to the SonicWALL Offsite Portal or to yet another CDP appliance. However, this third appliance cannot send any data offsite.

In the event that a downstream CDP appliance is rendered unusable, the CDP Site-to-Site feature allows you to recover your data, settings and configurations directly from the upstream CDP appliance. If the data on the upstream CDP appliance is not the most recent, choose the option to only download settings and configurations; the local agents will then back up the most recent data to the downstream CDP appliance which will be sent to the upstream CDP appliance. If the upstream CDP appliance is rendered unusable, it can easily be replaced with a new CDP appliance configured with the same IP address as the original upstream CDP appliance.

Benefits of the Site-to-Site Service

The benefits of the SonicWALL CDP Site-to-Site feature include:

 
Secure, confidential data backup and recovery
 
Additional protection against data loss
 
Easy deployment
 
Quick recovery of settings and configurations or complete recovery of data, settings, and configurations.

How Does the SonicWALL CDP Site-to-Site Service Work?

The CDP Site-to-Site feature requires a minimum of two CDP appliances to be deployed in a one-to-one scenario, in which a single upstream CDP appliance is the backup method for a downstream CDP appliance. The upstream CDP appliance can be deployed locally or offsite using a VPN or WAN connection, as illustrated in Figure 1 and Figure 2 . The downstream CDP appliance must be configured to backup to the IP address of the upstream CDP appliance, and the upstream CDP appliance must be licensed for Offsite and have at least one node available.

Multiple downstream CDP appliances can be configured to backup to a single local or offsite upstream CDP appliance in a many-to-one configuration. Upstream CDP appliances can also be used as a backup method for local agents, and can back up the local agent data to the SonicWALL offsite portal or to another CDP. Data, settings and configuration backed up from the downstream CDP appliance to the upstream CDP appliance are 256-bit encrypted and compressed, and sent using port 2022. All other features, including alerts, policies, and reports, can be configured on the upstream and downstream CDP appliances.

In the event of a disaster, data, settings, and configurations (or just settings and configurations) can be recovered from the upstream CDP appliance to the downstream CDP appliance. If the data on the upstream appliance is outdated, the option to recover only settings and configurations provides the ability to rapidly set up the replacement CDP. The replacement will then recover the latest data directly from its local agents, and then pass this data on to the upstream CDP appliance, thereby reinstating full backup protection.

If the downstream CDP appliance is rendered unusable, it is necessary to obtain a new downstream CDP appliance to replace it. The upstream CDP appliance must be notified of the change and the new box must be configured to backup to it prior to recovering data from the upstream CDP appliance.

Sample Setup Cases

The diagram in Figure 1 provides an example of a one-to-one CDP Site-to-Site deployment. Multiple agents are configured to backup to the downstream CDP appliance (IP address 10.0.0.1). The downstream CDP appliance is configured to backup to the local upstream CDP appliance (IP address 10.0.0.2).

Figure 1
CDP Site-to-Site: One to One Local Configuration

The diagram in Figure 2 provides an example of a one-to-one offsite CDP Site-to-Site deployment. Multiple agents are configured to backup to the downstream CDP appliance (IP address 10.0.0.1). The downstream CDP appliance is configured to backup to the offsite upstream CDP appliance (IP address 10.1.1.2) using a VPN or WAN connection.

Figure 2
CDP Site-to-Site: One to One Offsite Configuration

 
Warning
An upstream appliance cannot be backed up on a downstream appliance.

Figure 3 provides an example of a many-to-one CDP Offsite deployment with multiple CDP appliances (IP addresses 10.0.0.1 and 10.0.0.3) configured to backup to a single upstream CDP appliance (IP address 10.1.1.2). The upstream CDP appliance can be used to backup local clients and backup this data either to the offsite portal or to a final CDP.

 
Note
Only data being backed up by the upstream CDP’s local clients will be sent to the offsite portal. If the data is sent to another CDP, this final CDP cannot send any data offsite.
Figure 3
CDP Offsite: Many to One Configuration; Single Destination Backup

Preparing for the SonicWALL CDP Site-to-Site Service

This section contains the following sub-sections:

 
“SonicWALL CDP Site-to-Site Service Best Practices” section
 
“Administrator Prerequisites” section
 
“Purchasing Licenses and Support” section

SonicWALL CDP Site-to-Site Service Best Practices

For best performance, SonicWALL recommends you follow these practices:

 
Seed data to a second local CDP when dealing with large data sets.
 
Consider having a dedicated Internet connection for many-to-one backup scenarios.
 
Separate out data being uploaded: Do not seed all machines at once. Do not seed all files from a single large machine at one time.
 
No circular references of data. An upstream appliance cannot back up to one of its downstream appliances.

Administrator Prerequisites

The following deployment prerequisites are required to use the CDP Site-to-Site feature:

 
Two or more CDP appliances running 6.0 or higher firmware
 
8x5 or 24x7 support contract for the upstream CDP Appliance
 
Offsite license for the upstream CDP appliance to accept downstream CDP appliance connections
 
IP address or Fully Qualified Domain Name for the Upstream CDP Appliance
 
In the case of an offsite Upstream Appliance, port 2022 must be open to receive incoming traffic within firewall rules.
 
Note
You must purchase an 8x5 or 24x7 support contract and a 1, 3, 5, or 10 node Offsite license for the upstream CDP appliance.

Purchasing Licenses and Support

 
Note
Your SonicWALL CDP appliances must be registered before they can be deployed for Site- to-Site. Refer to the SonicWALL CDP Getting Started Guide for further information on registering your appliances.

You must purchase an 8x5 or 24x7 support contract and a 1, 3, 5, or 10 node Offsite license for the upstream CDP appliance. This can be done directly through mysonicwall.com or through your reseller.

To configure the upstream CDP appliance to accept backup data from the downstream CDP appliance, perform the following steps:

Step 1
Open a Web browser on the computer you are using to manage the SonicWALL  SSL VPN.
Step 2
Enter http://www.mysonicwall.com in the location or address field.

The mySonicWALL.com login page is displayed.

Step 3
Enter your mySonicWALL.com account username and password in the appropriate fields and click the submit button.
Step 4
Navigate to My Products in the left-hand navigation bar

 

Step 5
Select the CDP appliance you wish to use as the Upstream backup.
Step 6
Register for a Dynamic Support license.

Step 7
Register for an Offsite Node Support license.
 
Note
Offsite Node licenses do not expire. You may add additional Node Licenses by purchasing them from the mysonicwall.com Website.
Step 8
Login to your upstream CDP appliance’s Web management interface.
Step 9
Navigate to the Licenses page in the left-hand navigation bar.
Step 10
Click the Refresh button to have the CDP appliance update its license.

The appliance should now show the correct number of nodes licensed and is ready to backup a downstream CDP appliance.

Configuring the Downstream CDP Appliance

To configure the downstream CDP appliance to back up to the SonicWALL CDP Portal or to an upstream CDP appliance, perform the following steps:

Step 1
Login to the downstream CDP appliance using the Web Management Interface.
Step 2
Navigate to the System > Settings page and select the Offsite tab.

Step 3
To use the SonicWALL Portal as the upstream destination, leave the Enable SonicWALL Portal checkbox selected and leave PORTAL in the Upstream Appliance Name/IP Address field.
Step 4
To use another SonicWALL CDP appliance as the upstream destination, clear the checkbox next to Enable SonicWALL Portal and type the IP address or the FQDN (Fully Qualified Domain Name) of the upstream CDP appliance in the Upstream Appliance Name/IP Address field.
 
Note
It is important that the upstream and downstream appliances have different IP addresses. Refer to the SonicWALL CDP Getting Started Guide for further information on configuring an appliance’s IP address and domain name.
Step 5
Set the desired number of minutes in the Synchronization Interval field. The default, and minimum, is 15 minutes. To save bandwidth, you can set the interval to a larger number for less frequent synchronization between the downstream and upstream appliances..
Step 6
The Encryption Key is set automatically, and cannot be changed. If you switch between the Portal and another upstream destination, you will see a different key in this field. You can copy the key to your computer clipboard and save it in a text file for secure storage offsite.
Step 7
To specify the maximum bandwidth used during synchronization with the upstream destination, select the Enable Bandwidth Management checkbox, enter the desired numerical value in the field below it, and select kbps , Mbps , or Gbps as the units.
Step 8
To enforce a schedule for synchronization with the upstream destination, select the Enable Bandwidth Management checkbox and then select the desired schedule from the Schedule drop-down list. You can configure an appropriate schedule on the Policy > Schedules page.
Step 9
Click Apply .

Configuring the Upstream CDP Appliance Quota

The SonicWALL CDP Site-to-Site Data Backup provides different services, ranging from 5 to 100 GB of quota. The quota is the maximum amount of data that can be backed up. You need to make sure that the total size of all of your backups does not exceed the quota limit. If quota is exceeded, a subsequent backup will fail, the Quota Exceeded Error message will be displayed, and the status for the last backup will change to Quota Exceeded . You will receive an email notification informing you of the failed backup attempt. You can free up your storage space by removing some of the old backups, or you can purchase additional quota.

For information about editing the default policy quota or creating a custom policy with a custom quota, refer to the “Creating a Global Policy” section .

To apply a quota for the amount of data the upstream CDP appliance will accept from the downstream CDP appliance, perform the following steps:

Step 1
Login to the upstream CDP appliance using the Web Management Interface.
Step 2
Navigate to the Agents > Manage page.
Step 3
Click the Policy tab.
Step 4
In the left pane, under the SonicWALL CDP Agents list, select the downstream CDP appliance.
Step 5
Click the Edit icon for the downstream CDP appliance.
Step 6
From the Select Admin Policy drop-down list, select the Default Policy , or, if you have configured one, a custom policy with a specific quota defined.
Step 7
Click OK .

Removing a Downstream CDP

Removing a downstream CDP will delete all the relevant backup data from the upstream CDP appliance. To remove a downstream CDP and free up an upstream node, perform the following steps:

Step 1
Login to the downstream CDP appliance using the Web Management Interface.
Step 2
Navigate to the System > Settings page and select the Offsite tab.
Step 3
Clear the Upstream Appliance Name/IP Address field.
Step 4
Click Apply .
Step 5
Login to the upstream CDP appliance using the Web Management Interface
Step 6
Navigate to the Agents > Manage page.
Step 7
Click the Configure tab.
Step 8
Click the Delete icon for the downstream CDP appliance.
Step 9
An alert displays. Click Yes .

Selecting Files for Offsite Backup

Once properly configured, SonicWALL CDP Offsite Backup is as simple to use as the basic CDP backup.

Step 1
Login to the SonicWALL CDP Agent User Interface.
Step 2
Click the Policies tab.
Step 3
To backup files designated in a CDP Files and Folders object to the offsite appliance, click the Edit icon for the object, click on the desired folder in the Backup Folders list, and then select the Offsite Backup checkbox.
Step 4
To backup files designated in a Files and Folders or Applications object to the offsite appliance, edit the Backup Task for the object and select the Send all files offsite option in the Offsite drop-down list.
Step 5
Click OK .

Viewing Backed Up Files on the Offsite Appliance

You can view the files that are backed up offsite in one of the following ways:

 
Connect the SonicWALL CDP Agent User Interface to the Offsite appliance, and use the Administrator File Browser to view and manage the offsite files. See “Administrative Use of the Agent User Interface” for more information.
 
In the Web Management Interface of the downstream appliance, navigate to the Agents > Browse Agent Files page and select Offsite. See “Browsing Agents Files” for more information.

Recovering Data From the Upstream CDP Appliance

To restore data and policy information from the upstream appliance to the downstream appliance, perform the following steps:

Step 1
Login to the downstream CDP appliance using the Web Management Interface.
Step 2
Navigate to the System > Settings page and click the Restore from Offsite tab.

Step 3
If a new downstream appliance is set up, verify that the correct key is in the key field.
Step 4
To restore data, select the Data checkbox.
Step 5
To restore settings and configurations, select the Policy checkbox.
 
Note
Once the old appliance’s settings and configurations are downloaded after selecting the Policy checkbox, the new appliance will begin backing up the local agents immediately. It may not be necessary to download the old data from the upstream appliance.
Step 6
Click Restore from Offsite .
Step 7
A warning message displays. Click Yes to continue.
 
Note
The data on the downstream appliance will be replaced with the data from the upstream appliance.
Step 8
A second warning message displays. Click Yes to continue.
 
Note
The data restore process cannot be canceled once it has started.

The restore progress displays. Click Close to close the progress page.

Deleting Data From the Upstream CDP Appliance

To delete data and policy information from the upstream appliance, perform the following steps:

Step 1
Login to the downstream CDP appliance using the Web Management Interface.
Step 2
Navigate to the System > Settings page and click the Restore from Offsite tab.

Step 3
To delete data, select the Data checkbox.
Step 4
To delete settings and configurations, select the Policy checkbox.
Step 5
Click Wipe Offsite Data .
Step 6
A warning message displays. Click Yes to continue.

Replacing the Downstream CDP Appliance

If the downstream CDP is no longer accessible, a new CDP can take its place and recover data from the upstream appliance. The following information is required before you begin:

 
Old CDP’s registration code (to identify the original CDP)
Old CDP’s encryption key
New CDP’s registration code

To recover data from the upstream CDP appliance, you must first configure the upstream appliance to allow the new downstream appliance access to the old appliance’s data. Then the new appliance must be setup to connect to the upstream CDP appliance.

 
Note
The data on the downstream appliance will be replaced with the data from the upstream appliance. The data restore process cannot be canceled once it has started.

To update the upstream appliance with a different downstream appliance, perform the following steps:

Step 1
Login to the upstream CDP appliance using the Web Management Interface.
Step 2
Navigate to the Agents > Manage page.
Step 3
On the Configure tab, click the Edit icon for the old CDP that is being replaced.
Step 4
In the Agent Name and Friendly Name fields, replace the old CDP’s IP address or FQDN with the new one and click OK .

You must now configure the new downstream appliance to backup to the upstream CDP appliance. Follow the directions in “Configuring the Downstream CDP Appliance” section before recovering data from the upstream CDP appliance.

Disaster Recovery Using the Offsite Service

SonicWALL CDP Offsite Service allows the administrator to perform a disaster recovery when local data have been rendered unrecoverable. This means that the local SonicWALL CDP appliance is unusable and must be replaced. Data can be recovered from the Offsite Service in the event that a disaster renders local data corrupted, destroyed or otherwise unrecoverable.

 
Note
Data cannot be recovered from the Offsite Service without the Encryption Key, even by SonicWALL technical support engineers. It is advised that you store your encryption key in a secure location, such as a safe or bank. Your encryption key may be viewed by selecting the Offsite tab on the System > Settings page of the Web Management Interface. For more information, refer to the “Configuring the Downstream CDP Appliance” section .

To recover data from the Offsite Service after the original local SonicWALL CDP appliance has become unusable, perform the following steps:

Step 1
Locate your encryption key, which should be stored in a safe location, such as a vault or bank.
Step 2
Verify that your SonicWALL CDP appliance is under warranty or extended warranty. If it is not under warranty, it will be necessary to purchase a replacement SonicWALL CDP appliance with enough storage to contain the data recovered from the Offsite Service. Contact your SonicWALL Technical Support representative for your replacement appliance.
Step 3
Configure the replacement SonicWALL CDP appliance to match the settings of the original appliance.
Step 4
Replace the encryption key of the replacement appliance with the encryption key of the original appliance.
Step 5
When the replacement appliance is properly configured with the encryption key from the original appliance, it will automatically recover data from the Offsite Service.