Balabit - Backup policies (site 1)
Balabit SCB Solution · Config document · referenced from Backup, archive and retention
SCB-AUDIT-ENCRYPT, timestamping and signing with SCB-AUDIT-SIGN. The backup policy page has no such fields: those rows describe the audit policy that encrypts the audit trails when they are written, not the backup.The four backup policies of the site 1 cluster: one for the system (configuration) backup and one per company for the audit trails of its connections. Each copies to its own NFS export on the NetApp SVM DC1-S-VCVSM001, every night, one hour apart.
| Item | Value |
|---|---|
| Where | SCB web interface, Policies > Backup & Archive/Cleanup, section Backup policies |
| Cluster | dc1-s-xblb001, the site 1 HA pair dc1-a-ablb001 and dc1-b-ablb001 |
| Firmware at the time | 5 LTS (5.0.3), per chapter 7.2 of the same document |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapter 7.4.2, "configuration from real implementation realized in production environment" |
| Used by | SYSTEM-BACKUP by Basic Settings > Management > System backup (Management, site 1); the others by the connections (RDP connections, SSH connections) |
| Not in it | Schedule details beyond the start time (days, retries), the NFS options, a backup policy for partner 3 |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.4.2 Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / NAME = SYSTEM-BACKUP Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / START TIME = 00:00 Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / TARGET SETTINGS = NFS Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / TARGET SERVER = 10.11.18.236 (Netapp) Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / EXPORT = DC1_S_VCVSM001_data/scb_system_backup Policies > Backup & Archive/Cleanup > Backup policies > SYSTEM-BACKUP / SEND NOTIFICATION ON ERRORS ONLY = Yes Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / NAME = ORG-BACKUP Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / START TIME = 01:00 Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / TARGET SETTINGS = NFS Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / TARGET SERVER = 10.11.18.236 (Netapp) Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / EXPORT = DC1_S_VCVSM001_data/scb_org_backup Policies > Backup & Archive/Cleanup > Backup policies > ORG-BACKUP / SEND NOTIFICATION ON ERRORS ONLY = Yes Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / NAME = PARTNER1-BACKUP Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / START TIME = 02:00 Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / TARGET SETTINGS = NFS Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / TARGET SERVER = 10.11.18.236 (Netapp) Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / EXPORT = DC1_S_VCVSM001_data/scb_partner1_backup Policies > Backup & Archive/Cleanup > Backup policies > PARTNER1-BACKUP / SEND NOTIFICATION ON ERRORS ONLY = Yes Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / NAME = PARTNER2-BACKUP Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / START TIME = 03:00 Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / TARGET SETTINGS = NFS Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / TARGET SERVER = 10.11.18.236 (Netapp) Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / EXPORT = DC1_S_VCVSM001_data/scb_partner2_backup Policies > Backup & Archive/Cleanup > Backup policies > PARTNER2-BACKUP / SEND NOTIFICATION ON ERRORS ONLY = Yes
| Field | What it means |
|---|---|
| START TIME | The time of day the policy runs. The design's chapter 4.5.1 adds "PERIODICITY Daily"; the as-built table shows only the time |
| TARGET SETTINGS = NFS | The protocol. The conceptual and logical design still say CIFS; why it changed is told in SVMs and NFS |
| TARGET SERVER | The NFS data LIF of the SVM DC1-S-VCVSM001, in the same backup/archive network 10.11.18.224/28 (VLAN 1020) as the SCB's address 10.11.18.225 |
| EXPORT | Volume and qtree on the SVM, written without a leading slash. The export rule allows only 10.11.18.225 |
| SEND NOTIFICATION ON ERRORS ONLY | As I understand it, a mail goes out only when a run fails; the recipients are those of Basic Settings > Management > Mail settings |
SYSTEM-BACKUP alone does nothing until the system backup page selects it; that page also switches on encryption of the configuration with the GPG public key SCB-BACKUP. The other three are selected per connection, so every connection names the backup policy of the company it belongs to. The NetApp side has qtrees scb_partner3_backup and scb_partner3_archive too, but no PARTNER3-BACKUP policy is in this table: the partner 3 connections are not in the design, and which policies they used is not recorded.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| Balabit SCB 5 LTS, 5.0.x | Discontinued since 2020-05-28; the product is now One Identity Safeguard for Privileged Sessions (SPS), newest documents 9.0 of September 2026 |
| Backup over NFS after SMB failed | SPS 9.0 still offers Rsync, SMB/CIFS and NFS. The NFS version is detected automatically, up to NFS version 4; files are owned by root with no_root_squash, by nobody otherwise |
| Exports and qtrees created on the NetApp in advance | Still required: backup and archive policies only work with existing shares and subdirectories |
| Target given as an IPv4 address | Backup targets must still be IPv4 addresses |
SYSTEM-BACKUP with GPG encryption | Unchanged feature. Only the configuration file is encrypted, and system backups do not contain audit-trail data; an encrypted configuration has to be decrypted locally before it can be imported |
The settings in the table are still documented in SPS 9.0; whether the policies survive the upgrade chain or a data migration is not stated. The appliance underneath would not survive it: SPS 8.0 and later are not supported on T-Series hardware.