A NAS estate of NetApp filers must be protected to the new Data Domain. Security rules forbid installing backup agents on the filers, and monitoring shows filer CPU already peaks high in business hours, so management wants no file-level backup reads consuming filer resources. How should this backup connectivity be set up?
Select an answer to reveal the explanation.
Short Explanation
Filer backup has its own dedicated lane, and it's called NDMP. It's the one protocol where the storage system talks appliance-to-appliance and the backup server just conducts the traffic, no agents, no file-by-file crawl that would cook your filer's CPU. Reaching for a generic mount or a tape device here just recreates the exact problem you're trying to avoid.
Full Explanation
NDMP exists precisely for this shape of scenario. The filer's own data-management process streams its backup over the NDMP path straight to the target appliance, while the backup application orchestrates scheduling and cataloging; nothing is installed into the filer's general environment, and the media-server double-hop of file-level reads is avoided, which is what protects both filer CPU and the LAN. On the Data Domain side the work is small but real: enable the NDMP service, create a dedicated NDMP access user bound to a dedicated MTree, and register matching NDMP paths in the backup application. The NFS-copy proposal misstates the protocol, since NDMP requires no such agent, while pulling every file across a mount is exactly the file-level load the requirement excludes. Virtual tape presents emulated SCSI drives aimed at applications that write tape; filers do not orchestrate their own direct-to-tape backups in this pattern, and no NDMP or catalog semantics appear. The Boost-on-filers proposal violates the security rule by construction and misunderstands Boost, which is a backup-application integration loaded by media agents and clients running supported applications, not a filer-resident agent. Exam caveat: verify NDMP versions and transport security compatibility between filer model and backup application. Operational check: run a test NDMP backup to the dedicated MTree and watch filer CPU and the direct filer-to-appliance path during the run.