IBM Storage Defender Copy Data Management Support Information
Access release details, supported storage vendors, file systems, database requirements, and Sentinel compatibility for IBM Storage Defender Copy Data Management releases.
Overview
This page provides detailed support information for IBM Storage Defender Copy Data Management releases.
IBM DCDM Release: IBM Storage Defender Copy Data Management version
Storage Vendors and Version: Supported storage vendors and their versions
File System: Supported file systems
Database Requirements: SAP HANA, Oracle, Microsoft SQL Server, and InterSystems requirements
IBM Storage Defender Sentinel Support: Sentinel version compatibility
Usage Instructions
Use dropdown filters in column headers to filter by release, storage vendor, or requirements.
Note: Physical NetApp ONTAP Storage Systems are not supported. It is supported with iSCSI disks attached directly to guest operating system using VMware.
Supports IBM Storage Defender Sentinel 2.3.0 for IBM FlashSystem 8.5.1 and later interim fixes
GA: 2.3.0.0: Available 10 April 2026
GA: 2.3.0.1: Available 30 April 2026
2.3.0
Dell PowerMax Storage
Dell PowerMax 2000/8000 | Unisphere Version 10.3.x
Dell PowerMax 2500/8500 | Unisphere Version 10.3.x
Operating System
Red Hat Enterprise Linux 8.x, 9.x, 10.0
SUSE Linux Enterprise Server 15.x, 16
AIX 7.1, 7.2, 7.3 (up to Version: 7300-04-00)
Windows Server 2019, 2022, 2025
Supported filesystem types
AIX — JFS2
Windows — NTFS, FAT32
Linux — XFS, ext3 and ext4
Models:
Dell PowerMax 2000/8000 (Unisphere 10.3.x)
Dell PowerMax 2500/8500 (Unisphere 10.3.x)
Storage Configuration:
Storage Configuration: Fibre Channel, iSCSI
IRIS Configuration
IRIS 2022 (beginning with CDM Version 2.2.19)
IRIS 2024.1
IRIS 2025.1
IRIS 2025.1.2
Models:
Dell PowerMax 2000/8000 (Unisphere 10.3.x)
Dell PowerMax 2500/8500 (Unisphere 10.3.x)
Storage Configuration:
Storage Configuration: Fibre Channel, iSCSI
Oracle Configuration
Oracle 19c configured as: Standalone/RAC in ASM and non-ASM mode
Oracle 21c configured as: Standalone/RAC in ASM and non-ASM mode
Models:
Dell PowerMax 2000/8000 (Unisphere 10.3.x )
Dell PowerMax 2500/8500 (Unisphere 10.3.x )
Storage Configuration:
Storage Configuration: Fibre Channel, iSCSI
SAP HANA Configuration
SAP HANA 2.0 SPS 07 on SUSE Linux Enterprise Server 15 SP6
SAP HANA 2.0 SPS 07 on RedHat Enterprise Linux 8.10 and 9.4
SAP HANA 2.0 SPS 08 on RedHat Enterprise Linux 9.6
SAP HANA 2.0 SPS 08 on SUSE Linux Enterprise Server 15 SP7
SAP HANA 2.0 SPS 08 on SUSE Linux Enterprise Server 16
Models:
Dell PowerMax 2000/8000 (Unisphere 10.3.x )
Dell PowerMax 2500/8500 (Unisphere 10.3.x)
Storage Configuration:
Storage Configuration: Fibre Channel, iSCSI
Supported platforms
Microsoft SQL Server 2019 on Microsoft Windows Server 2019
Microsoft SQL Server 2022 on Microsoft Windows Server 2019
Microsoft SQL Server 2022 on Microsoft Windows Server 2022
Microsoft SQL Server 2022 on Microsoft Windows Server 2025 (SQL Standalone only)
Microsoft SQL Server 2025 on Microsoft Windows Server 2025 (SQL Standalone and Failover Cluster)
Models:
Dell PowerMax 2000/8000 (Unisphere 10.3.x )
Dell PowerMax 2500/8500 (Unisphere 10.3.x )
Storage Configuration:
Storage Configuration: Fibre Channel, iSCSI
Db2 Configuration
Not Supported
Not Applicable
GA: 2.3.0.0: Available 10 April 2026
GA: 2.3.0.1: Available 30 April 2026
2.3.0
Dell Powerflex Storage
Dell PowerFlex Manager version - 4.6.x, 4.8.x
Operating System
Red Hat Enterprise Linux 8.x, 9.x, 10.0
SUSE Linux Enterprise Server 15.x, 16
AIX 7.1, 7.2, 7.3 (up to Version: 7300-04-00)
Windows Server 2019, 2022, 2025
Supported filesystem types
AIX — JFS2
Windows — NTFS, FAT32
Linux — XFS, ext3 and ext4
Supported Dell Powerflex Versions: 4.6.x and 4.8.x
Storage Configuration: Proprietary SDC protocol
IRIS Configuration
IRIS 2022 (beginning with CDM Version 2.2.19)
IRIS 2024.1
IRIS 2025.1
IRIS 2025.1.2
Supported Dell Powerflex Versions: 4.6.x and 4.8.x
Oracle Configuration
Oracle 19c configured as: Standalone/RAC in ASM and non-ASM mode
Oracle 21c configured as: Standalone/RAC in ASM and non-ASM mode
Supported Dell Powerflex Versions: 4.6.x and 4.8.x
SAP HANA Configuration
SAP HANA 2.0 SPS 07 on SUSE Linux Enterprise Server 15 SP6
SAP HANA 2.0 SPS 07 on RedHat Enterprise Linux 8.10 and 9.4
SAP HANA 2.0 SPS 08 on RedHat Enterprise Linux 9.6
SAP HANA 2.0 SPS 08 on SUSE Linux Enterprise Server 15 SP7
SAP HANA 2.0 SPS 08 on SUSE Linux Enterprise Server 16
Supported Dell Powerflex Versions: 4.6.x and 4.8.x
Supported platforms
Microsoft SQL Server 2019 on Microsoft Windows Server 2019
Microsoft SQL Server 2022 on Microsoft Windows Server 2019
Microsoft SQL Server 2022 on Microsoft Windows Server 2022
Microsoft SQL Server 2022 on Microsoft Windows Server 2025 (SQL Standalone only)
Microsoft SQL Server 2025 on Microsoft Windows Server 2025 (SQL Standalone and Failover Cluster)
Supported Dell Powerflex Versions: 4.6.x and 4.8.x
Db2 Configuration
Not Supported
Not Applicable
GA: 2.3.0.0: Available 10 April 2026
GA: 2.3.0.1: Available 30 April 2026
2.3.0
Netapp ONTAP
Data ONTAP 8.1.x operating in 7-Mode
Data ONTAP 8.2.x operating in 7-Mode
Clustered Data ONTAP 8.1.x
Clustered Data ONTAP 8.2.x
Clustered Data ONTAP 8.3.x
Clustered Data ONTAP 9.4.x
Data ONTAP 9.0.x - 9.10.x
Not Applicable
Not Applicable
Not Applicable
Not Applicable
Not Applicable
Db2 Configuration
Not Supported
Not Applicable
GA: 2.3.0.0: Available 10 April 2026
GA: 2.3.0.1: Available 30 April 2026
2.3.0
Pure/Everpure Storage
FlashArray//c
FlashArray//m
FlashArray//x
FlashArray-4xx series
REST API version 1.0 - 1.19
Purity 5.x (beginning with Purity 5.2.x)
Purity 6.1.x
Purity 6.3.12
Operating System
Red Hat Enterprise Linux 8.x, 9.x, 10.0
SUSE Linux Enterprise Server 15.x, 16
AIX 7.1, 7.2, 7.3 (up to Version: 7300-04-00)
Windows Server 2019, 2022, 2025
Supported filesystem types
AIX — JFS2
Windows — NTFS, FAT32
Linux — XFS, ext3 and ext4
Supported Pure Storage:
FlashArray//c
FlashArray//m
FlashArray//x
FlashArray-4xx series
REST API version 1.0 - 1.19
IRIS Configuration
IRIS 2022 (beginning with CDM Version 2.2.19)
IRIS 2024.1
IRIS 2025.1
IRIS 2025.1.2
Supported Pure Storage:
FlashArray//c
FlashArray//m
FlashArray//x
FlashArray-4xx series
REST API version 1.0 - 1.19
Oracle Configuration
Oracle 19c configured as: Standalone/RAC in ASM and non-ASM mode
Oracle 21c configured as: Standalone/RAC in ASM and non-ASM mode
Supported Pure Storage:
FlashArray//c
FlashArray//m
FlashArray//x
FlashArray-4xx series
REST API version 1.0 - 1.19
SAP HANA Configuration
SAP HANA 2.0 SPS 07 on SUSE Linux Enterprise Server 15 SP6
SAP HANA 2.0 SPS 07 on RedHat Enterprise Linux 8.10 and 9.4
SAP HANA 2.0 SPS 08 on RedHat Enterprise Linux 9.6
SAP HANA 2.0 SPS 08 on SUSE Linux Enterprise Server 15 SP7
SAP HANA 2.0 SPS 08 on SUSE Linux Enterprise Server 16
Supported Pure Storage:
FlashArray//c
FlashArray//m
FlashArray//x
FlashArray-4xx series
REST API version 1.0 - 1.19
Supported platforms
Microsoft SQL Server 2019 on Microsoft Windows Server 2019
Microsoft SQL Server 2022 on Microsoft Windows Server 2019
Microsoft SQL Server 2022 on Microsoft Windows Server 2022
Microsoft SQL Server 2022 on Microsoft Windows Server 2025 (SQL Standalone only)
Microsoft SQL Server 2025 on Microsoft Windows Server 2025 (SQL Standalone and Failover Cluster)
Supported Pure Storage:
FlashArray//c
FlashArray//m
FlashArray//x
FlashArray-4xx series
REST API version 1.0 - 1.19
Db2 Configuration
Not Supported
Not Applicable
GA: 2.3.0.0: Available 10 April 2026
GA: 2.3.0.1: Available 30 April 2026
2.3.0
VMware
vSphere 8.0 and 8.0.x levels
vSphere 8.0.2 and 8.0.3 levels
Operating System
Red Hat Enterprise Linux 8.x, 9.x, 10.0
SUSE Linux Enterprise Server 15.x, 16
AIX 7.1, 7.2, 7.3 (up to Version: 7300-04-00)
Windows Server 2019, 2022, 2025
Supported filesystem types
AIX — JFS2
Windows — NTFS, FAT32
Linux — XFS, ext3 and ext4
IRIS Configuration
IRIS 2022 (beginning with CDM Version 2.2.19)
IRIS 2024.1
IRIS 2025.1
IRIS 2025.1.2
Oracle Configuration
Oracle 19c configured as: Standalone/RAC in ASM and non-ASM mode
Oracle 21c configured as: Standalone/RAC in ASM and non-ASM mode
SAP HANA Configuration
SAP HANA 2.0 SPS 07 on SUSE Linux Enterprise Server 15 SP6
SAP HANA 2.0 SPS 07 on RedHat Enterprise Linux 8.10 and 9.4
SAP HANA 2.0 SPS 08 on RedHat Enterprise Linux 9.6
SAP HANA 2.0 SPS 08 on SUSE Linux Enterprise Server 15 SP7
SAP HANA 2.0 SPS 08 on SUSE Linux Enterprise Server 16
Supported platforms
Microsoft SQL Server 2019 on Microsoft Windows Server 2019
Microsoft SQL Server 2022 on Microsoft Windows Server 2019
Microsoft SQL Server 2022 on Microsoft Windows Server 2022
Microsoft SQL Server 2022 on Microsoft Windows Server 2025 (SQL Standalone only)
Microsoft SQL Server 2025 on Microsoft Windows Server 2025 (SQL Standalone and Failover Cluster)
Db2 Configuration
Not Supported
Not Applicable
GA: 2.3.0.0: Available 10 April 2026
GA: 2.3.0.1: Available 30 April 2026
×
IBM Storage Requirements
IBM Storage Systems run on:
IBM Storage Virtualize 8.7.0.x, 8.7.3.x (8.7.3.2 included)
IBM Storage Virtualize for Snapshot 9.1.x (9.1.0, 9.1.1, 9.1.2, 9.1.3 included)
Supported IBM storages are IBM FlashSystems, IBM SAN Volume Controller.
Warning:
Outdated SAN Volume Controller (SVC) firmware might result in a storage-warm start. SVC firmware needs to be updated to the most current supported version to ensure system reliability.
HyperSwap is supported on IBM FlashSystems for both physical and virtual server types for volumes, virtual machines, and applications.
Only Safeguarded Copy is supported on IBM Storage Systems running on IBM Storage Virtualize software version 8.5.1 or later.
IBM Storage Virtualize for Snapshot is supported on IBM Storage Systems running on IBM Storage Virtualize software version 8.5.4 or later.
IBM Storage Defender Copy Data Management supports PBR for IBM Storage FlashSystem version 8.7.0 and later by using IBM Storage Virtualize Snapshot SLA policies.
IBM Storage Defender Copy Data Management supports PBHA 2-site & PBHA 3-site configuration for IBM Storage FlashSystem version 9.1.0 and later by using IBM Storage Virtualize Snapshot SLA policies.
Note:
IBM providers must be registered by an IBM user with administrator-level privileges.
×
Dell PowerMax Storage Requirements
Dell PowerMax storage system models running on the listed Dell PowerMax versions are supported:
Model
Unisphere Version
Dell PowerMax 2000/8000
10.2.x, 10.3.x, 10.4.x
Dell PowerMax 2500/8500
10.2.x, 10.3.x, 10.4.x
×
Dell PowerFlex Storage Requirements
Dell PowerFlex Storage systems managed by the following versions of PowerFlex Manager are supported:
Dell PowerFlex Manager version — 4.6.x, 4.8.x
Note:
Due to a known limitation in PowerFlex Manager version 4.6.x and 4.8.x, the standard user account with storage admin privileges is insufficient for performing remote snapshot operations. As a workaround, user must be granted super-user privileges.
×
Dell PowerStore Storage Requirements
Dell PowerStore Storage systems managed by the following versions of PowerStore Manager are supported:
Dell PowerStore Manager version — 4.4.0, 4.2.0
Note:
Only Virtual Applications Supported.
×
NetApp ONTAP Requirements
Note:
IBM Storage Defender Copy Data Management does not support new features introduced in ONTAP 9.x. IBM Storage Defender Copy Data Management was tested against Data ONTAP 9.3.
IBM Storage Defender Copy Data Management supports NetApp MetroCluster configurations running on ONTAP 9.x or later. After successful completion of MetroCluster Switchover or Switchback operations, mirror or vault relationships must be reestablished through an IBM Storage Copy Data Management job.
Clustered Data ONTAP providers must be registered with a cluster administrator account. Cluster peering must be enabled. Peer relationships enable communication between SVMs. See NetApp ONTAP's Cluster and Vserver Peering Express Guide.
Note:
Make sure that TLS protocol is enabled on the NetApp storage system by setting the tls.enable option to ON. For TLS to take effect on HTTPS, make sure that the httpd.admin.ssl.enable option is also set to ON. See Enabling or disabling TLS.
NetApp ONTAP File Inventory Job Requirements
IBM Storage Defender Copy Data Management uses SnapDiff in NetApp ONTAP file level jobs to run catalog based on snapshot differences. The following options must be enabled on the volume of the NetApp storage system to catalog:
create_ucode and convert_ucode: These options are turned off by default.
Inode to Pathname: Creates relationships between file names and relative paths. If disabled on a volume, you must enable it, then delete existing snapshots on the volume. When new snapshots are created with Inode to Pathname enabled, the volume can be cataloged.
Internationalization Requirements
The language code must be set and the UTF-8 variant must be specified on the NetApp storage system. For example, en_US.UTF-8. Only the English locale for vol0 for UTF-8 is supported.
The IBM Storage Defender Copy Data Management application and documentation are available in English only. However, cataloging, searching, and reporting functions support international metadata.
×
Pure/Everpure Storage Requirements
Supported Versions
Purity 6.9.3
Note:
IBM Storage Defender Copy Data Management supports only snapshot and replication of volumes in Purity 6.x. Newer features such as vVol, ActiveCluster (pod), SafeMode Snapshot, or CloudSnap are not supported.
×
VMware Requirements
vSphere 8.0 and 8.0.x levels (Beginning with 2.2.21)
vSphere 8.0.2 and 8.0.3 levels (Beginning with 2.2.27)
vSphere 9.1 (Beginning with 2.3.1)
Make sure that the most current version of VMware Tools is installed in your environment.
Note:
Beginning with IBM Spectrum Copy Data Management 2.2.18, VMware VDDK 7.0 is included. This VDDK level does not support vSphere 6.0. See APAR IT42544.
For NetApp ONTAP Storage Systems, a FlexClone license is required to fully use Instant Disk Restore and Instant VM Restore features. If your workflow includes vault and mirror protection, SnapVault and SnapMirror licenses are also required on both source and destination resources. Similarly, if your workflow includes individual file recovery a SnapRestore license is required. Individual file recovery is only supported at the primary site.
IBM Storage Systems
For IBM Storage Systems, Remote Mirroring and FlashCopy licenses are required.
VMware
For VMware, a Storage vMotion license is required.
×
General
IBM Storage Defender Copy Data Management installs an agent on application servers when they are registered. Some anti-virus software might flag or attempt to remove the agent software. If you run anti-malware software on application servers, exclude the installation path of the IBM Storage Defender Copy Data Management agent.
For Linux-based file system and Application servers, you must install the psmisc package. For example, it is required so that the cancellation or cleanup of restore jobs function correctly. If this package is not installed, restore jobs might fail. Installation of psmisc package can be done on RHEL OS using below command. Please identify equivalent command for your OS platform:
yum localinstall psmisc*.rpm
For Microsoft Windows-based systems, such as Microsoft SQL Server, the agent installation directory must be excluded for any anti-virus scans. Add this path to the exclusion list for all anti-virus software that is installed on the application server:
"C:\Program Files\IBM\IBM Storage Defender Copy Data Management"
For Linux-based and AIX-based systems, the agent installation directory must be excluded for any anti-virus software scans. Add this path to the exclusion list for all anti-virus software that is installed on the application server. For Oracle, InterSystems Caché, IRIS and SAP HANA:
/tmp/cdm_guestapps_<username>
Where <username> is the username of the account used to register the application server in IBM Storage Defender Copy Data Management.
IBM Storage Defender Copy Data Management support for third-party operating systems, applications, services, and the hardware depends on their respective vendors. If a third-party product and product's version moves into extended support, self-service support or end-of-life, IBM Storage Defender Copy Data Management supports that product and product's version at the same level as the vendor. See also IBM Support General Guidelines and Limitations - IBM support for software on unsupported operating systems.
For supported VMware vSphere versions, see in System requirements: IBM Storage Defender Copy Data Management 2.3.1.
Select the Physical provider type when you register the provider in IBM Storage Defender Copy Data Management. All data and log files for an instance should be backed by either an iSCSI, FC or in case of PowerFlex' proprietary SDC protocol disk.
Note: NetApp ONTAP Storage Systems are not supported.
Applications registered as Physical on CDM are only supported.
On AIX only Fiber Channel is supported for file system backup and restore.
On IBM Systems Storage, condense is run during maintenance jobs.
For Dell PowerMax Storage: Ensure all the relevant volumes of the File System for that given instance are part of single Storage Group. IBM Storage Copy Data Management supports one parent storage group, and it can contain different child storage group for different file systems. For Instant Restore, Host on Dell PowerMax array must have at least one Masking View created for itself, even if the host is a part of a hostgroup having active Masking View. For remote replication, please create and map the host to the remote array as well and have at least one Masking View created using it.
JFS2 filesystem is only tested and supported for IBM FlashSystem as a storage provider.
RHEL 10, SUSE 16 and SUSE 15 SP07 are currently not supported by Dell PowerFlex SDC driver for version 4.8.x.
CDM currently does not support RDM LUNs configured in VMware.
Applications that are registered as Physical for Dell PowerFlex need to follow the below steps. Since SDC setup is done as root user, binaries like drv_cfg are not accessible for non-root users, which are used in application registration.
For the Windows file system, the following configurations are not supported:
Windows Failover Cluster
Clustered Shared Volumes (CSV)
Linux file system considerations
For the Linux file system, the following configurations are not supported:
Linux HA Cluster
×
Software
The bash and sudo packages must be installed. Sudo must be version 1.8.29 or later. Run sudo -V to check the version.
Python version 3.x (up to 3.9) must be installed.
RHEL 8.x only: Verify the util-linux package is up to date by running:
yum update util-linux
RHEL 8.x or later: A required Perl module, Digest:MD5, is not installed by default. Install the module by running:
yum install perl-Digest-MD5
Linux only: If data stays on LVM volumes, make sure that the LVM version is 2.03.02 or later. To check the LVM version and if necessary to update the package, run:
lvm version
yum update lvm2
×
Connectivity
The SSH service must be running on port 22 on the server and any firewalls must be configured to allow IBM Storage Defender Copy Data Management to connect to the server by using SSH. The SFTP subsystem for SSH must also be enabled.
The server can be registered by using a DNS name or IP address. DNS names must be resolvable by IBM Storage Defender Copy Data Management.
To mount clones or copies of data, IBM Storage Defender Copy Data Management automatically maps and unmaps LUNs to the servers. Each server must be preconfigured to connect to the relevant Storage Systems at that site.
For Fibre Channel, the appropriate zoning must be configured beforehand.
For iSCSI, the servers must be configured beforehand to discover and log in to the targets on the storage servers.
×
Authentication and Privileges
Authentication
The application server must be registered in IBM Storage Defender Copy Data Management by using an operating system user that exists on the server (referred to as "IBM Storage Defender Copy Data Management agent user").
During registration, you must provide either a password or a private SSH key that IBM Storage Defender Copy Data Management uses to log in to the server.
For password-based authentication, make sure that the password is correctly configured and that the user can log in without facing any other prompts, such as prompts to reset the password.
For key-based authentication, verify that the public SSH key is placed in the appropriate authorized_keys file for the IBM Storage Defender Copy Data Management agent user.
Typically, the file is at /home/<username>/.ssh/authorized_keys
Typically, the .ssh directory and all files under it need to have their permissions set to 600.
Privileges
The IBM Storage Defender Copy Data Management agent user needs the following privileges:
Privileges to run commands as root and other users by using sudo. IBM Storage Defender Copy Data Management requires these privileges for various tasks such as discovering storage layouts and mounting and unmounting disks.
The sudoers configuration must allow the IBM Storage Defender Copy Data Management agent user to run commands without a password.
The !requiretty setting must be set.
For examples on creating a new user with the necessary privileges, see Sample Configuration in file system requirements.
×
Restore and Revert
Restore Jobs
If the xfsprogs package version on the destination server is between 3.2.0 and 4.1.9, the restore process might fail when you restore a database or file system from an XFS file system. To resolve the issue, upgrade xfsprogs to version 4.2.0 or later.
Revert Jobs
File system revert jobs are not supported for backups using volume group snapshots.
When you run file system revert jobs, there are considerations that must be met for jobs to successfully complete:
Shut down any application databases on the file system to be reverted before you run the revert operation.
When the revert action completes, take appropriate steps to restore the applications to use the old data that is now contained on one or more file system that were reverted.
×
Sample Configuration
The following commands are examples for creating and configuring an operating system user that IBM Storage Defender Copy Data Management use to log in to the application server. The command syntax might vary depending on your operating system type and version.
Create the user that is designated as the IBM Storage Defender Copy Data Management agent user:
useradd -m cdmagent
If you use password-based authentication, set a password:
passwd cdmagent
If you use key-based authentication, place the public key in /home/cdmagent/.ssh/authorized_keys. Or use the appropriate file depending on your sshd configuration, and verify that the correct ownership and permissions are set, such as:
Place the following lines at the end of your sudoers configuration file, typically /etc/sudoers. If the existing sudoers file is configured to import configuration from another directory (for example /etc/sudoers.d), you can also place the lines in a new file in that directory:
IBM Storage Defender Copy Data Management is installed as a virtual appliance on VMware vSphere. Before you deploy to the host, verify you have the following:
IBM Storage Defender Copy Data Management is distributed as an OVF template, with an OVA file extension.
vSphere 8.0.3, or 9.x.
Either an available static IP address to use or access to DHCP server.
Note:
For later versions of vSphere, the vSphere Web Client might be required to deploy IBM Storage Defender Copy Data Management appliances.
Beginning with IBM Spectrum Copy Data Management 2.2.18, VMware VDDK 7.0 is included. This VDDK level does not support vSphere 6.0. See APAR IT42544.
VM Appliance on Windows Hyper-V
IBM Storage Defender Copy Data Management is installed as a virtual appliance on Windows Hyper-V. Before you deploy to the host, verify you have the following:
IBM Storage Defender Copy Data Management for Hyper-V is distributed as an EXE install binary, packaged as a ZIP file.
Microsoft Windows 2019, 2022, 2025.
Either an available static IP address to use or access to DHCP server.
Hyper-V is currently tested and supported for IBM FlashSystem as a storage provider.
CDM Software on IBM PowerPC
IBM Storage Defender Copy Data Management is installed as native software on IBM PowerPC. Before you deploy to the host, verify you have the following:
IBM Storage Defender Copy Data Management for PowerPC is distributed as an ISO, mountable on RHEL 9.6 ppc64le arch.
PowerPC 10 and 11.
Either an available static IP address to use or access to DHCP server.
CDM on PowerPC is currently tested and supported for IBM FlashSystem as a storage provider.
Common Configuration Requirements
For initial deployment, configure your virtual appliance to meet the following minimum requirements:
Component
Requirement
Processor
64-bit quad-core machine
Memory
48 GB
The appliance has three virtual disks that total 400 GB storage:
50 GB for operating system and application (includes 16 GB swap, 256 MB boot, remainder for root partition)
100 GB for configuration data related to jobs, events, and logs
250 GB for Inventory data
Important:
Use Network Time Protocol (NTP) in your environment for IBM Storage Defender Copy Data Management appliance, storage arrays, hypervisors, and application servers. If the clocks on the various systems are significantly out of sync, you might experience errors during application registration, inventory, backup, or restore jobs. For more information, see Time in virtual machine drifts due to hardware timer drift.
Browser Support
Run IBM Storage Defender Copy Data Management from a computer that has access to the installed virtual appliance. IBM Storage Defender Copy Data Management was tested and certified against the following web browsers. Latest levels are supported.
Google Chrome, Microsoft Edge, Firefox and Safari
Note:
If your resolution is less than 1024 x 768, some items might not fit on the window. Pop-up windows must be enabled in your browser to access the Help system and some IBM Storage Defender Copy Data Management operations.
×
General
Verify that you have the required system configuration and browser to deploy and run IBM Storage Defender Copy Data Management.
IBM Storage Defender Copy Data Management uses the NetworkManager tool nmtui for network configuration.
IBM Storage Defender Copy Data Management uses TLS 1.2 for communication between the host and clients where applicable.
IBM Storage Defender Copy Data Management support for third-party operating systems, applications, services, and hardware depend on the respective vendor. If a third-party product or version moves into extended support, self-service support, or end-of-life, IBM Storage Defender Copy Data Management supports the product or version at the same level as the vendor. See also IBM Support General Guidelines and Limitations.
×
IBM Storage Requirements
IBM Storage Systems run on:
IBM Storage Virtualize 8.7.0.x, 8.7.3.x (8.7.3.2 included)
IBM Storage Virtualize 9.1.x (9.1.0, 9.1.1, 9.1.2 included)
Supported IBM Storages:
IBM FlashSystems, IBM SAN Volume Controller
Important Information:
Outdated SAN Volume Controller (SVC) firmware might result in a storage-warm start. SVC firmware needs to be updated to the most current supported version to make sure the system reliability.
HyperSwap is supported on IBM FlashSystems for both physical and virtual server types for volumes, virtual machines, and applications.
Only Safeguarded Copy is supported on IBM Storage Systems running on IBM Storage Virtualize software version 8.5.1 or later.
IBM Storage Virtualize for Snapshot is supported on IBM Storage Systems that are running on IBM Storage Virtualize software version 8.5.4 or later.
IBM Storage Defender Copy Data Management supports PBR for IBM Storage FlashSystem version 8.7.0 and later by using IBM Storage Virtualize Snapshot SLA policies.
IBM Storage Defender Copy Data Management supports PBHA 2-site & PBHA 3-site configuration for IBM Storage FlashSystem version 9.1.0 and later by using IBM Storage Virtualize Snapshot SLA policies.
Notes:
IBM providers must be registered by an IBM user with administrator-level privileges.
×
Pure Storage Requirements
Note:
IBM Storage Defender Copy Data Management supports only snapshot and replication of volumes in Purity 6.x. Newer features such as vVol, ActiveCluster (pod), SafeMode Snapshot, or CloudSnap are not supported.
×
VMware Requirements
Make sure that the most current version of VMware Tools is installed in your environment.
Note:
Beginning with IBM Spectrum Copy Data Management 2.2.18, VMware VDDK 7.0 is included. This VDDK level does not support vSphere 6.0. See APAR IT42544.
×
Third-Party License Requirements
For NetApp ONTAP Storage Systems: A FlexClone license is required to fully use Instant Disk Restore and Instant VM Restore features. If your workflow includes vault and mirror protection, SnapVault and SnapMirror licenses are also required on both source and destination resources. Similarly, if your workflow includes individual file recovery a SnapRestore license is required. Individual file recovery is only supported at the primary site.
For IBM Storage Systems: Remote Mirroring and FlashCopy licenses are required.
For VMware: A Storage vMotion license is required.
×
General Requirements
IBM Storage Defender Copy Data Management installs an agent on application servers when they are registered. Some anti-virus software might flag or attempt to remove the agent software. If you run anti-malware software application servers, exclude the installation path of the IBM Storage Defender Copy Data Management agent.
For Linux-based file system and Application servers, you must install the psmisc package. For example, it is required so that the cancellation or cleanup of restore jobs function correctly. If this package is not installed, restore jobs might fail. Installation of psmisc package can be done on RHEL OS using below command. Please identify equivalent command for your OS platform yum localinstall psmisc*.rpm
For Microsoft Windows-based systems, such as Microsoft SQL Server, the agent installation directory must be excluded for any anti-virus scans. Add this path to the exclusion list for all anti-virus software that is installed on the application server: "C:\Program Files\IBM\IBM Storage Defender Copy Data Management"
For Linux-based and AIX-based systems, the agent installation directory must be excluded for any anti-virus software scans. Add this path to the exclusion list for all anti-virus software that is installed on the application server. For Oracle, InterSystems Caché, IRIS and SAP HANA: /tmp/cdm_guestapps_<username> Where <username> is the username of the account used to register the application server in IBM Storage Defender Copy Data Management.
IBM Storage Defender Copy Data Management support for third-party operating systems, applications, services, and the hardware depends on their respective vendors. If a third-party product and product's version moves into extended support, self-service support or end-of-life, IBM Storage Defender Copy Data Management supports that product and product's version at the same level as the vendor. See also IBM Support General Guidelines and Limitations - IBM support for software on unsupported operating systems
×
Software Requirements
The bash and sudo packages must be installed. Sudo must be version 1.8.29 or later. Run sudo -V to check the version.
Python version 3.x (upto 3.9) must be installed.
RHEL 8.x only: Verify the util-linux package is up to date by running: yum update util-linux
RHEL 8.x or later: A required Perl module, Digest:MD5, is not installed by default. Install the module by running: yum install perl-Digest-MD5
Linux only: If data stays on LVM volumes, make sure that the LVM version is 2.03.02 or later. To check the LVM version and if necessary to update the package, run: lvm version
yum update lvm2
×
Connectivity Requirements
The SSH service must be running on port 22 on the server and any firewalls must be configured to allow IBM Storage Defender Copy Data Management to connect to the server by using SSH. The SFTP subsystem for SSH must also be enabled.
The server can be registered by using a DNS name or IP address. DNS names must be resolvable by IBM Storage Defender Copy Data Management.
To mount clones or copies of data, IBM Storage Defender Copy Data Management automatically maps and unmaps LUNs to the servers. Each server must be preconfigured to connect to the relevant Storage Systems at that site.
For Fibre Channel, the appropriate zoning must be configured beforehand.
For iSCSI, the servers must be configured beforehand to discover and log in to the targets on the storage servers.
×
Authentication and Privileges Requirements
Authentication
The application server must be registered in IBM Storage Defender Copy Data Management by using an operating system user that exists on the server (referred to as "IBM Storage Defender Copy Data Management agent user" for the rest of this topic).
During registration, you must provide either a password or a private SSH key that IBM Storage Defender Copy Data Management uses to log in to the server.
For password-based authentication, make sure that the password is correctly configured and that the user can log in without facing any other prompts, such as prompts to reset the password.
For key-based authentication, verify that the public SSH key is placed in the appropriate authorized_keys file for the IBM Storage Defender Copy Data Management agent user.
Typically, the file is at /home/<username>/.ssh/authorized_keys
Typically, the .ssh directory and all files under it need to have their permissions set to 600.
Privileges
The IBM Storage Defender Copy Data Management agent user needs the following privileges:
Privileges to run commands as root and other users by using sudo. IBM Storage Defender Copy Data Management requires these privileges for various tasks such as discovering storage layouts and mounting and unmounting disks.
The sudoers configuration must allow the IBM Storage Defender Copy Data Management agent user to run commands without a password.
The !requiretty setting must be set.
For examples on creating a new user with the necessary privileges, see Sample Configuration in file system requirements.
×
Restore and Revert Requirements
Restore Jobs
If the xfsprogs package version on the destination server is between 3.2.0 and 4.1.9, the restore process might fail when you restore a database or file system from an XFS file system. To resolve the issue, upgrade xfsprogs to version 4.2.0 or later.
Revert Jobs
File system revert jobs are not supported for backups using volume group snapshots. When you run file system revert jobs, there are considerations that must be met for jobs to successfully complete:
Shut down any application databases on the file system to be reverted before you run the revert operation.
When the revert action completes, take appropriate steps to restore the applications to use the old data that is now contained on one or more file system that were reverted.
×
Sample Configuration
The following commands are examples for creating and configuring an operating system user that IBM Storage Defender Copy Data Management use to log in to the application server. The command syntax might vary depending on your operating system type and version.
Create the user that is designated as the IBM Storage Defender Copy Data Management agent user: useradd -m cdmagent
If you use password-based authentication, set a password: passwd cdmagent
If you use key-based authentication, place the public key in /home/cdmagent/.ssh/authorized_keys. Or use the appropriate file depend on your sshd configuration, and verify that the correct ownership and permissions are set, such as: chown -R cdmagent:cdmagent /home/cdmagent/.ssh
×
SAP HANA - General Requirements
IBM Storage Defender Copy Data Management installs an agent on application servers when it is registered. Some anti-virus software might flag or attempt to remove the agent software. If you run anti-malware software application servers, exclude the installation path of the IBM Storage Defender Copy Data Management agent.
The agent installation directory must be excluded for any anti-virus software scans. Add this path to the exclusion list for all anti-virus software that is installed on the application server. For Oracle, InterSystems Caché and IRIS, and SAP HANA: /tmp/cdm_guestapps_<username> Where <username> of the account used to register the application server in IBM Storage Defender Copy Data Management.
IBM Storage Defender Copy Data Management support for third-party operating systems, applications, services, and hardware depend on the respective vendor. If a third-party product or version moves into extended support, self-service support, or end-of-life, IBM Storage Defender Copy Data Management supports the product or version at the same level as the vendor. See also IBM Support General Guidelines and Limitations - IBM support for software on unsupported operating systems
×
SAP HANA - Prerequisites
The SAP HANA Client must be installed on your SAP HANA machine.
Create a symbolic link to the SAP HANA Client installation directory through the following command: ln -s <installation directory of SAP HANA Client> /opt/hana. For example, if SAP HANA Client is installed in /hana/shared/<SID>/hdbclient, you would enter the following: ln -s /hana/shared/<SID>/hdbclient/ /opt/hana
For SAP HANA, the hdbcli module must be installed. The hdbcli module must be installed only after the complete installation of the SAP HANA client. The module might be extracted from <path to directory>/hdbclient/hdbcli-<version>.tar.gz.
Log backups require that the log backup option is enabled on the SAP HANA system. Additionally, the Universal Destination Directory for log backups must match the directory that is configured on the SAP HANA system when you enable log backups.
Each SAP HANA system has a system ID (SID). It is good practice to have the SID in the path. For example, if /hana/logbackup is the mount point, create these directories: mkdir /hana/logbackup/<SID>
mkdir /hana/logbackup/<SID>/catalog To make sure that database logs can be saved, permissions need to be specified for the created directories: chown --reference=/hana/shared/<SID>/HDB01 /hana/logbackup/<SID>
The bash and sudo packages must be installed. Sudo must be version 1.8.29 or later. Run sudo -V to check the version.
Python version 3.x must be installed. It might be necessary to add your python3 binary file location to the system PATH or to create a symbolic link. For example, if your python3 is installed at /opt/freeware/bin, you need to create a link as follows: ln -s /opt/freeware/bin/python3 /usr/bin/python3 SLES only: Run the following commands before hdbcli installation: python3 -m ensurepip
pip3 install hdbcli Note: The hdbcli module need to be version 2.17 or later.
RHEL 8.x: Verify the util-linux package is up to date by running: yum update util-linux
RHEL 8.x or later: A required Perl module, Digest:MD5, is not installed by default. Install the module by running: yum install perl-Digest-MD5
SLES only: The Python pip package needs to be installed. Follow these steps to install the pip module on SLES: $ sudo zypper addrepo https://download.opensuse.org/repositories/Cloud:Tools/<SLES_verision_SP_level>/Cloud:Tools.repo
$ sudo zypper refresh
$ sudo zypper python-pip Note: The SLES equivalent of yum is zypper.
Linux only: If data stays on LVM volumes, verify that the LVM version is 2.03.02 or later. To check the LVM version and if necessary to update the package, run: lvm version
yum update lvm2
×
SAP HANA - Connectivity Requirements
The SSH service must be running on port 22 on the server and any firewalls must be configured to allow IBM Storage Defender Copy Data Management to connect to the server by using SSH. The SFTP subsystem for SSH must also be enabled.
The server can be registered by using a DNS name or IP address. DNS names must be resolvable by IBM Storage Defender Copy Data Management.
To mount clones or copies of data, IBM Storage Defender Copy Data Management automatically maps and unmaps LUNs to the servers. Each server must be preconfigured to connect to the relevant Storage Systems at that site.
For Fibre Channel, the appropriate zoning must be configured beforehand.
For iSCSI, the servers must be configured beforehand to discover and log in to the targets on the storage servers.
×
SAP HANA - Authentication, Registration and Privileges
Authentication
The application server must be registered in IBM Storage Defender Copy Data Management by using an operating system user that exists on the server (referred to as "IBM Storage Defender Copy Data Management agent user" for the rest of this topic).
During registration, you must provide either a password or a private SSH key that IBM Storage Defender Copy Data Management uses to log in to the server.
For password-based authentication, make sure that the password is correctly configured, and that the user can log in without facing any other prompts, such as prompts to reset the password.
Registration
When you register an SAP HANA provider in IBM Storage Defender Copy Data Management, note the following:
The format for the port number is 3<instance number>15. So, for example, if the instance number is 07, then enter the following port number: 30715.
HANA database user credentials are required to query the database. These credentials are used to log in to the SYSTEMDB and TENANTDB to run restore operations. A "SYSTEM" user or NON-SYSTEM user can be used for database operations. When creating a NON-SYSTEM user specific privilege must be granted to the user, also the username and password must be same in both SYSTEMDB and SXX tenant database.
The NON-SYSTEM database user must have BACKUP ADMIN, CATALOG READ, DATABASE RECOVERY OPERATOR on SYSTEMDB and BACKUP ADMIN, CATALOG READ on the TENANT database (e.g. SXX).
Note: For examples on creating a new user with the necessary privileges, see Sample Configuration in SAP HANA requirements.
Privileges
The IBM Storage Defender Copy Data Management agent user needs the following privileges:
Privileges to run commands as root and other users by using sudo. IBM Storage Defender Copy Data Management requires these privileges for various tasks such as discovering storage layouts and mounting and unmounting disks.
The sudoers configuration must allow the IBM Storage Defender Copy Data Management agent user to run commands without a password.
The !requiretty setting must be set.
For examples on creating a new user with the necessary privileges, see Sample Configuration in SAP HANA requirements.
×
SAP HANA - Restore and Revert
Restore Jobs
If the xfsprogs package version on the destination server is between 3.2.0 and 4.1.9, the restore process might fail when you restore a database or file system from an XFS file system. To resolve the issue, upgrade xfsprogs to version 4.2.0 or later.
Restriction: The Restore (Instant Disk and Instant Database) operations for SAP HANA are not supported on an alternate host. You need to restore it on the same source host.
Revert Jobs
When you run revert jobs on SAP HANA, there are special considerations that must be met for jobs to successfully complete:
SAP HANA data and the operating system (OS) file system must be on separate datastores (Virtual) and on seprate volumes/LUNs (Physical).
Make sure that the databases are on independent storage. The underlying storage volume for the reverted databases must not contain data for other databases. Also, must not contain a datastore that is shared by other virtual machines (VMs) or by other databases not being reverted.
Make sure that the production databases are not on VMDK disks that are part of a VMware VM snapshot.
All VM snapshots need to be removed from the SAP HANA server before you run the revert function.
Production databases are automatically shut down during the revert.
Revert is available only after a restore is completed.
When you create a job, you need to set the default revert action for the job. This behavior is controlled through the Revert Database option during the job creation process:
Enabled – Always revert the database.
Disabled – Never reverts the database.
User Selection – Allows the user to make the determination to revert the database when the job session is pending.
Restriction: The revert function is not supported for HyperSwap environments, see APAR IT42565
×
SAP HANA - Sample Configuration
The following commands are examples for creating and configuring an operating system user that IBM Storage Defender Copy Data Management uses to log in to the application server. The command syntax might vary depending on your operating system type and version.
Create the user that is designated as the IBM Storage Defender Copy Data Management agent user: useradd -m cdmagent
If you use password-based authentication, set a password: passwd cdmagent
Place the following lines at the end of your sudoers configuration file, typically /etc/sudoers. If the existing sudoers file is configured to import configuration from another directory (for example, /etc/sudoers.d), you can also place the lines in a new file in that directory: Defaults:cdmagent !requiretty
cdmagent ALL=(ALL) NOPASSWD:ALL
The following commands are examples for creating and configuring a HANA database with minimum privileges to perform query / backup / restore operations. The prompt $> indicates command to execute from UNIX shell prompt and the prompt => indicates the command to execute on hdbsql prompt.
Create required user with a temporary password and grant privileges
hdbsql SYSTEMDB=> CREATE USER scdm_admin PASSWORD change_on_first_logon_01;
hdbsql SYSTEMDB=> GRANT BACKUP ADMIN, CATALOG READ, DATABASE RECOVERY OPERATOR TO scdm_admin;
Log in to SYSTEMDB with newly created user and change the password
$> hdbsql -j -i 01 -n localhost -u scdm_admin -p change_on_first_logon_01 -d SYSTEMDB
You have to change your password.
Enter new Password: <ENTER_NEW_PASSWORD_HERE>
Confirm new Password: <ENTER_NEW_PASSWORD_HERE>
Connect to SXX tenant database as SYSTEM user (without -d SYSTEMDB)
Create user with same name (as the one created in SYSTEMDB) in tenant database and grant privileges
hdbsql S12=> CREATE USER scdm_admin PASSWORD change_on_first_logon_01;
hdbsql S12=> GRANT BACKUP ADMIN, CATALOG READ TO scdm_admin;
Log into the tenant database with newly created user and change the password
$> hdbsql -j -i 01 -n localhost -u scdm_admin -p change_on_first_logon_01
You have to change your password.
Enter new Password: <ENTER_NEW_PASSWORD_HERE>
Confirm new Password: <ENTER_NEW_PASSWORD_HERE>
Note: The username and password for the database user created in both SYSTEMDB and SXX tenant database must be identical. The privileges for the user differ in the respective databases. The table below lists the privileges.
Standalone databases protected by IBM Storage Defender Copy Data Management can be recovered to the same or alternate standalone server installation. When you recover from standalone to RAC, if the source database uses Automatic Storage Management, then it is successfully recovered to all nodes in the destination cluster. If the source database uses non-ASM storage, the database is mounted only on the first node in the destination RAC.
RAC databases protected by IBM Storage Defender Copy Data Management can be recovered to the same or another RAC installation or to a standalone ASM server. To recover a RAC database to a standalone server, the Grid Infrastructure must be installed on the destination server, and an ASM instance must be running.
Oracle Flex ASM is not supported. Oracle ASM is not supported in virtual mode.
RAC database recoveries are not server pool aware. IBM Storage Defender Copy Data Management can recover databases to a RAC, but not to a specific server pools.
IBM Storage Defender Copy Data Management supports recovering databases from a source physical server to a destination-virtual server by provisioning disks as physical RDMs. Similarly, IBM Storage Defender Copy Data Management can recover databases from a source-virtual server that uses physical RDM to a destination physical server. However, source databases on VMDK virtual disks can be recovered only to another virtual server and not to a physical server.
Oracle data must stay directly on one of the supported Storage Systems listed previously. VADP-based protection of virtual Oracle servers is not supported.
On AIX LPAR/VIO servers, Oracle data must stay on disks attached to the server by using NPIV. Virtual SCSI disks are not supported.
Masking and DevOps recoveries are not supported on virtual servers.
For supported VMware vSphere versions, see in System Requirements: IBM Storage Defender Copy Data Management 2.3.0
Oracle servers registered as Virtual need VMware Tools installed and running.
Data masking is not supported for Oracle in NetApp storage environments. Masking is not supported on source database on NFS (a copy of which cloned and masked) or source databases on replica copies. Instead of the default mirror copy, you must select a snapshot copy as a replication source.
NetApp systems running in 7-Mode are not supported.
Oracle 19c standalone is now supported for AIX 7.3. More requirements:
Oracle database data and the flash recovery area (FRA) must stay on supported Storage Systems. IBM Storage Defender Copy Data Management can back up archived logs to a supported storage system if they are not already on one.
During an Instant Database Restore, there might be failures if the new name specified for the restored database is similar to an existing database differing only by numerical suffix. For clustered instances of Oracle databases, the appliance always uses global database name in the UI. During the inventory and restore processes, individual instances by using the numerical suffixes of the cluster must be correlated to the global database name. This issue appears when, as an example, "Production12" is discovered. Is this "Production12" the instance 12 of the "Production" database, or instance 2 of the "Production1" database, or a database named "Production12."
On all supported storage systems, snapshot condense is run during every maintenance jobs.
Supported platforms: IBM Power Systems and Intel based Systems running supported AIX and Linux OS.
For Dell PowerMax Storage:
Use separate Storage Groups (SG) for different databases for improved performance.
IBM Storage Defender Copy Data Management supports one parent SG, and it can contain different child SG for different databases.
Keep datafiles and log files in separate SG.
When using Parent SG with child SGs, use separate child SGs for data and log.
For Instant Disk Restore, Host on Dell PowerMax array must have at-least one Masking View created for itself, even if the host is a part of a hostgroup having active Masking View.
Oracle 19c RAC configuration is now supported on the DELL PowerMax storage system.
Oracle 21c RAC configuration is not supported on the DELL PowerMax storage system.
For remote replication feature, please create and map the host to the remote array and have at least 1 masking created using it. The portgroup used in the masking view created by the user will be used by the CDM restore job while creating masking view to map the restored volumes to the host on the remote array.
NFS share mapped directly to the VMware guest is not supported.
CDM does not support multiple DBs with same db_name (but different db_unique_name), as it relies on db_name to uniquely identify the Oracle home belonging to the database (instance).
User should make sure that Oracle parameters (texts) do not exceed the recommended size by Oracle. e.g. CDM workflow may fail when the size of '_fix_control' parameter exceeds 255 characters.
In Oracle RAC configuration, the cluster database restore will create only a single instance and the restored instance is not registered as a cluster resource.
When the Prepare scripts, option is chosen the files will be copied to the CDM appliance under /data/log/ecxdeployer/<YYYY-MM-DD>/<random generated string> folder. The actual value can be seen in the Instant disk restore job logs in the line prior to prepare scripts which says ECX log dir = /data/log/ecxdeployer/<YYYY-MM-DD>/<random generated string>. Note: To run these scripts, they need to be copied from this folder of the CDM appliance to any preferred location on the Oracle Server. In order to execute the scripts, follow these steps as an Oracle user: a. Export the Oracle SID as the SID used during recovery.
b. When executing an SQL script, login to SQLPlus using sqlplus / as sysdba. You can then run the script: @<location in oracle server>/Step-<number>_<operation>.sql
c. When executing an RMAN script, login to RMAN using rman target=/. You can then run the script as, @<location in oracle server>/Step-<number>_<operation>.rman.
×
Oracle - Restore and Revert
Restore Jobs
If the xfsprogs package version on the destination server is between 3.2.0 and 4.1.9, the restore process might fail when you restore a database or file system from an XFS file system. To resolve the issue, upgrade xfsprogs to version 4.2.0 or later.
Revert Jobs
Restrictions:
Oracle revert jobs are only supported for backups using the IBM Storage Virtualize for snapshot provider, Dell PowerMax and Dell Powerflex storage providers. Note – With Dell PowerMax and Dell Powerflex storage provider, revert with remote/replicated copy is not supported.
When you run revert jobs on Oracle, there are special considerations that must be met for jobs to successfully complete:
Oracle data, log and the operating system (OS) file system must be on separate datastores/LUNs. Make sure that the databases are on independent storage.
The underlying storage volume for the databases (data and log disks) being reverted should not contain data for other databases and should not contain a datastore that is shared by other VM's or by another database not being reverted.
Make sure that the production databases are not on VMDK disks that are part of a VMware VM snapshot.
All VM snapshots need to be removed from the Oracle server before you run the revert function.
Production databases are automatically shut down during the revert.
Revert is available only after a restore is completed.
Oracle ASM/RAC backups can only be restore on the same host.
When you create a job, you need to set the default revert action for the job. This behavior is controlled through the Revert Database option during the job creation process:
Enabled – Always revert the database.
Disabled – Never reverts the database.
User Selection – Allows the user to make the determination to revert the database when the job session is pending.
Note – 'Make Permanent' option will be disabled when Revert is enabled.
Restriction:
The Revert function is not supported for AIX based Oracle deployments.
The Revert function is not supported for LVM based Oracle deployments.
×
Oracle - Software Requirements
The bash and sudo packages must be installed. Sudo must be version 1.8.29 or later. Run sudo -V to check the version.
Python version 3.x must be installed. It might be necessary to add your python3 binary file location to the system PATH or to create a symbolic link. For example, if your python3 is installed at /opt/freeware/bin, you need to create a link as follows: ln -s /opt/freeware/bin/python3 /usr/bin/python3 On AIX systems, it might be necessary to rerun any AIX inventory jobs.
RHEL 8.x or later: Ensure that the util-linux package is up to date by running: yum update util-linux Depending on your version or distribution, the package might be named util-linux.
RHEL 8.x or later: A required Perl module, Digest:MD5, is not installed by default. Install the module by running: yum install perl-Digest-MD5
Linux only: If data stays on LVM volumes, ensure that the LVM version is 2.03.02 or later. To check the LVM version and if necessary to update the package, run: lvm version
yum update lvm2
×
Oracle - Connectivity Requirements
The SSH service must be running on port 22 on the server and any firewalls must be configured to allow IBM Storage Defender Copy Data Management to connect to the server by using SSH. The SFTP subsystem for SSH must also be enabled.
The server can be registered by using a DNS name or IP address. DNS names must be resolvable by IBM Storage Defender Copy Data Management.
When you register Oracle RAC nodes, register each node by using its physical IP or name. Do not use a virtual name or Single Client Access Name (SCAN).
To mount clones or copies of Oracle data, IBM Storage Defender Copy Data Management automatically maps and unmaps LUNs to the Oracle servers. Each server must be preconfigured to connect to the relevant Storage Systems at that site.
For Fibre Channel, the appropriate zoning must be configured beforehand.
For iSCSI, the Oracle servers must be configured beforehand to discover and log in to the targets on the storage servers.
×
Oracle - Authentication and Privileges
Authentication
The Oracle server must be registered in IBM Storage Defender Copy Data Management by using an operating system user that exists on the Oracle server (referred to as "IBM Storage Defender Copy Data Management agent user" for the rest of this topic).
During registration, you must provide either a password or a private SSH key that IBM Storage Defender Copy Data Management use to log in to the server.
For password-based authentication, ensure that the password is correctly configured and that the user can log in without facing any other prompts, such as prompts to reset the password.
For key-based authentication, ensure that the public SSH key is placed in the appropriate authorized_keys file for the IBM Storage Defender Copy Data Management agent user.
Typically, the file is at /home/<username>/.ssh/authorized_keys
Typically, the .ssh directory and all files under it need their permissions set to 600.
Privileges
The IBM Storage Defender Copy Data Management agent user needs the following privileges:
Privileges to run commands as root and other users by using sudo. IBM Storage Defender Copy Data Management requires these privileges for various tasks such as discovering storage layouts and mounting and unmounting disks.
The sudoers configuration must allow the IBM Storage Defender Copy Data Management agent user to run commands without a password.
The !requiretty setting must be set.
The ENV_KEEP setting must allow the ORACLE_HOME and ORACLE_SID environment variables to be retained.
Privileges to read the Oracle inventory. IBM Storage Defender Copy Data Management requires those privileges to discover and collect information about Oracle homes and databases. To achieve discovery and collection of information, the IBM Storage Defender Copy Data Management agent user must belong to the Oracle inventory group, typically named oinstall.
SYSDBA privileges for database instances. IBM Storage Defender Copy Data Management needs to run database tasks like querying instance details, hot backup, RMAN cataloging, and starting and stopping instances during recovery.
To achieve database tasks, the IBM Storage Defender Copy Data Management agent user must belong to the OSDBA operating system group, typically named dba.
If multiple Oracle homes each with a different OSDBA group, the IBM Storage Defender Copy Data Management agent user must belong to each group.
SYSASM privileges, if Automatic Storage Management (ASM) is installed. IBM Storage Defender Copy Data Management needs to run storage tasks like querying ASM disk information, and renaming, mounting, and unmounting diskgroups.
To achieve storage tasks, the IBM Storage Defender Copy Data Management agent user must belong to the OSASM operating system group, typically named asmadmin.
Shell user limits for the IBM Storage Defender Copy Data Management agent user must be the same as those limits for the user that owns the Oracle home, typically named oracle. Refer to Oracle documentation for requirements and instructions on setting shell limits. Run ulimit -a as both the oracle user and the IBM Storage Defender Copy Data Management agent user and ensure that their settings are identical.
For examples on creating a new user with the necessary privileges, see Sample Configuration in Oracle requirements.
×
Oracle - Discovery
Oracle Home Discovery for Symbolic Links
IBM Storage Defender Copy Data Management discovers Oracle installations and databases by looking through the files /etc/oraInst.loc and /etc/oratab, we well as the list of running Oracle processes. When you connect to a database instance to discover its properties, IBM Storage Defender Copy Data Management connects by setting the ORACLE_HOME environment variable based on the path that was auto discovered.
In some cases, when Oracle databases are used in combination with SAP software for instance, a symbolic link to the Oracle Home path might be created. This link path can then be used by the database administrator to connect to the database.
Consider the following example where the real Oracle Home path can be /u01/app/oracle/product/19c/dbhome_1, while the symbolic link that points to it is /oracle/PRODDB/19c.
When IBM Storage Defender Copy Data Management connects to the instance by using the real, auto-discovered path, queries against the database can fail due to the ORACLE_HOME environment variable being incorrectly set. To override the auto-discovered path and force IBM Storage Defender Copy Data Management to use the correct symbolic link path, a configuration file must be defined on each Oracle server where symbolic links are in use. Create or edit if it exists a file named /etc/guestapps_oraHomes.conf. Insert into this file these entries:
# Define one entry per line.
# Each entry must be in the form: <instanceName> = <oraHomePath>
# Lines beginning with the '#' character are ignored.
PRODDB = /oracle/PRODDB/19c
TESTDB = /oracle/TESTDB/19c
To ensure that the configuration file is readable by the agent user, run the following command:
chmod 644 /etc/guestapps_oraHomes.conf
Database Discovery
IBM Storage Defender Copy Data Management discovers Oracle installations and databases by looking through the files /etc/oraInst.loc and /etc/oratab, and the list of running Oracle processes. If the files are not present in their default location, the "locate" utility must be installed on the system so that IBM Storage Defender Copy Data Management can search for alternative locations of these files. IBM Storage Defender Copy Data Management discovers databases and their storage layouts by connecting to running instances and querying the locations of their data files, log files, and other files. In order for IBM Storage Defender Copy Data Management to correctly discover databases during cataloging and copy operations, databases must be in "MOUNTED," "READ ONLY," or "READ/WRITE" mode. IBM Storage Defender Copy Data Management cannot discover or protect database instances that are shut down. Databases must be used a server parameter file (spfile). IBM Storage Defender Copy Data Management does not support copy operations for databases that are used a text-based parameter file (pfile).
ASM Disk Discovery
When IBM Storage Defender Copy Data Management mounts snapshots or clones of ASM disks, it configures the disks to set the appropriate permissions required to make them discoverable by ASM:
The disk owner and group are set to the owner of the Grid installation and the OSASM group, which are typically grid and asmadmin. IBM Storage Defender Copy Data Management automatically discovers the appropriate owner and group information on each server.
The disk permissions are set to 660.
IBM Storage Defender Copy Data Management creates aliases or symbolic links with names that follow a consistent pattern. Ensure that ASM is able to discover the disks mapped by IBM Storage Defender Copy Data Management and update the ASM_DISKSTRING parameter to add this pattern. Linux: IBM Storage Defender Copy Data Management creates udev rules for each disk to set the appropriate ownership and permissions. The udev rules also create symbolic links of the form /dev/ecx-asmdisk/<diskId> that point to the appropriate device under /dev. To ensure that the disks are discoverable by ASM, add the following pattern to your existing ASM_DISKSTRING: /dev/ecx-asmdisk/* AIX: IBM Storage Defender Copy Data Management creates a device node (by using mknod) of the form /dev/ecx_asm<diskId> that points to the appropriate hdisk under /dev. IBM Storage Defender Copy Data Management also sets the appropriate ownership and permissions for this new device. To ensure that the disks are discoverable by ASM, add the following pattern to your existing ASM_DISKSTRING: /dev/ecx_asm* Notes:
If the existing value of the ASM_DISKSTRING is empty, you might have to first set it to an appropriate value that matches all existing disks, then append the previous value.
If the existing value of the ASM_DISKSTRING is broad enough to discover all disks (for example: /dev/*), you might not need to update it.
Refer to Oracle documentation for details about retrieving and modifying the ASM_DISKSTRING parameter.
×
Oracle - Sample Configuration
The following commands are examples for creating and configuring an operating system user that IBM Storage Defender Copy Data Management use to log in to the Oracle server. The command syntax might vary depending on your operating system type and version.
Create the user that is designated as the IBM Storage Defender Copy Data Management agent user: useradd -m cdmagent
If you use password-based authentication, set a password: passwd cdmagent
If you use key-based authentication, place the public key in /home/cdmagent/.ssh/authorized_keys, or the appropriate file depending on your sshd configuration, and ensure that the correct ownership and permissions are set, such as: chown -R cdmagent:cdmagent /home/cdmagent/.ssh
chmod 700 /home/cdmagent/.ssh
chmod 600 /home/cdmagent/.ssh/authorized_keys
Add the user to the Oracle installation and OSDBA group: usermod -a -G oinstall,dba cdmagent
If ASM is in use, also add the user to the OSASM group: usermod -a -G asmadmin cdmagent
Note: If on AIX, the append argument (-a) needs to be omitted when you use the usermod command.
Place the following lines at the end of your sudoers configuration file, typically /etc/sudoers. If the existing sudoers file is configured to import configuration from another directory (for example, /etc/sudoers.d), you can also place the lines in a new file in that directory: Defaults:cdmagent !requiretty
Defaults:cdmagent env_keep+="ORACLE_HOME"
Defaults:cdmagent env_keep+="ORACLE_SID"
cdmagent ALL=(ALL) NOPASSWD:ALL
×
More Information
iSCSI disks attached directly to guest operating system [4]
pRDM [4]
vRDM [5]
VMDK [6]
Microsoft SQL Servers staying on any storage can also be protected to supported storage systems through VM Replication jobs.
For both physical and virtual SQL environments, point-in-time recoveries beyond the last snapshot taken are incompatible with workflows by using more than one Site. In a virtual environment, the Microsoft SQL Server, associated vCenter, and storage must be registered to the same site. In a physical environment, the Microsoft SQL Server and storage must be registered to the same site.
Microsoft SQL Server - In-Memory OLTP Requirements and Limitations
In-Memory OLTP is a memory-optimized database engine used to improve database application performance, supported in Microsoft SQL Server 2019 and above. IBM Storage Defender Copy Data Management requirements and limitations for In-Memory OLTP usage:
The maximum restore file path must be fewer than 256 characters, which is an SQL requirement. If the original path exceeds this length, consider using a customized restore file path to reduce the length.
The metadata that can be restored is subject to VSS and SQL restore capabilities.
×
Microsoft SQL Server - Revert Considerations and Limitations
Considerations and Limitations for databases in an Availability Group
CDM restores copies of primary databases only.
Revert is at the LUN level and must be reverted back to the source LUN that was used to create the snapshot.
A database cannot be reverted if it is part of an Availability Group. CDM removes the database from the Availability Group as part of the revert process.
CDM does not put the database back in the Availability Group.
After CDM recovers the database, manually perform the following steps:
Restore any log backups that are required and recover the database by using RESTORE DATABASE <database name> WITH RECOVERY; command.
Delete the secondary database.
Add the primary database back into the availability group using the SQL Server Management Studio:
Connect to the server instance hosting the primary replica.
Expand the Always On High Availability node and the Availability Groups node.
Right-click the Availability Group and select Add Database to launch the Add Database to Availability Group wizard.
Select the database on the Select Databases page. If a database does not meet all the prerequisites, the Status hyperlink provides a brief explanation of why the database is not eligible.
Select the data synchronization preference on the Select Initial Data Synchronization page.
Connect to the secondary SQL Server instances on the next page and click Next.
If the validation is successful, click Next, else correct the problem, and click Re-run Validation.
Review the summary and click Finish.
×
Microsoft SQL Server - General
IBM Storage Defender Copy Data Management installs an agent on application servers when they are registered. Some anti-virus software might flag or attempt to remove the agent software. If you run anti-malware software on application servers, exclude the installation path of the IBM Storage Defender Copy Data Management agent.
For Microsoft Windows-based systems, such as Microsoft SQL Server, the agent installation directory must be excluded for any anti-virus scans. Add this path to the exclusion list for all anti-virus software that is installed on the application server: "C:\Program Files\IBM\IBM Storage Defender Copy Data Management"
IBM Storage Defender Copy Data Management support for third-party operating systems, applications, services, and hardware depend on the respective vendor. If a third-party product or version moves into extended support, self-service support, or end-of-life, IBM Storage Defender Copy Data Management supports the product or version at the same level as the vendor. See also IBM Support General Guidelines and Limitations - IBM support for software on unsupported operating systems
×
Microsoft SQL Server - Notes
Windows Remote Shell (WinRM) must be enabled.
Clustered Shared Volumes (CSV) are not supported.
For supported VMware vSphere versions, see in System Requirements: IBM Storage Defender Copy Data Management 2.3.0
Select the physical provider type when you register the provider in IBM Storage Defender Copy Data Management. Recoveries require direct access to storage. NetApp ONTAP Storage Systems are not supported.
vRDMs are supported through VM Replication jobs.
VMware VM Independent disks associated to SQL VM registered as virtual in CDM are supported for snapshot and recovery with IBM and Dell storages starting CDM release 2.3.0.1 onwards.
When you register physical Microsoft SQL Servers, register them through the DNS server. The IBM Storage Defender Copy Data Management appliance must be resolvable and routeable by the DNS server. The physical Microsoft SQL Server communicates back to IBM Storage Defender Copy Data Management through DNS.
Recovery for target servers registered as Physical provider types requires direct access to storage.
Any Windows node with iSCSI or Fibre Channel access to the storage can be selected as a proxy server, if the node is not part of the original cluster. Select a stand-alone virtual or physical Windows node as a proxy server.
For physical Microsoft SQL Servers you must allow outgoing connections to port 8443 on the IBM Storage Defender Copy Data Management appliance from the Microsoft SQL Server.
Dynamic disks are not supported.
On all supported storage systems, snapshot condense is run during every maintenance jobs.
×
Microsoft SQL Server - VMware Support
UUID must be enabled to run Microsoft SQL-based backup functions. To enable:
Power off the guest virtual machine through the vSphere client.
Then, select the guest and click Edit Settings. Select Options,
Then General under the Advanced section.
Select Configuration Parameters..., then find the disk.EnableUUID parameter.
If set to FALSE, change the value to TRUE.
If the parameter is not available, add it by clicking Add Row, set the value to TRUE, then power on the guest.
The virtual machine must use SCSI disks only. MS SQL databases mounted on NTFS created using dynamic disks are not supported. The most current VMware Tools must be installed on the virtual machine node.
In-Memory OLTP requirements and limitations
In-Memory OLTP is a memory-optimized database engine used to improve database application performance, supported in Microsoft SQL Server 2019 and above. IBM Storage Defender Copy Data Management requirements and limitations for In-Memory OLTP usage:
The maximum restore file path must be fewer than 256 characters, which is an SQL requirement. If the original path exceeds this length, consider by using a customized restore file path to reduce the length.
The metadata that can be restored is subject to VSS and SQL restore capabilities.
Revert Considerations and Limitation
Considerations and Limitations for databases in an Availability Group:
CDM restores copies of primary databases only.
Revert is at the LUN level and must be reverted back to the source LUN that was used to create the snapshot.
A database cannot be reverted if it is part of an Availability Group. CDM removes the database from the Availability Group as part of the revert process.
CDM does not put the database back in the Availability Group.
After CDM recovers the database, manually perform the following steps:
Restore any log backups that are required and recover the database by using RESTORE DATABASE WITH RECOVERY; command.
Delete the secondary database.
Add the primary database back into the availability group using the SQL Server Management Studio.
Connect to the server instance hosting the primary replica.
Expand the Always On High Availability node and the Availability Groups node.
Right-click the Availability Group and select Add Database to launch the Add Database to Availability Group wizard.
Select the database on the Select Databases page. If a database does not meet all the prerequisites, the Status hyperlink provides a brief explanation of why the database is not eligible.
Select the data synchronization preference on the Select Initial Data Synchronization page.
Connect to the secondary SQL Server instances on the next page and click Next.
If the validation is successful, click Next, else correct the problem, and click Re-run Validation.
Review the summary and click Finish.
×
Microsoft SQL Server - Instant Seeding Prerequisites and Limitations
The goal of seeding is to restore a secondary database by taking advantage of snapshot technology and minimize the data movement between primary and secondary replicas.
Seeding of both virtual and physical Microsoft SQL Servers is supported. The seeding destination replica must be an instance of a secondary role and must be created or configured with a working mirroring endpoint before the seeding process. The seeding process restores by using the original database only, and only the most current backup snapshot is supported.
Source databases must be backed up under the full recovery model, which is configured though the SQL Management Console. The full recovery model provides a granular transaction restore.
The transaction log can grow indefinitely unless the logs are backed up, which automatically initiates log truncation. The database administrator must run maintenance to free space if necessary.
Before the seeding process, primary databases and log backups are required to make sure the LSN gap between the primary and secondary databases is acceptable by the SQL AAG framework.
The data file and log file paths on all replicas of an availability group must be the same. IBM Storage Defender Copy Data Management requires that the original volume mount points are available on the target SQL node for seeding process. If the original volume was mounted on a volume mount point, such as a folder, the root drive letter of the mount point must exist before the restore begins.
When you create an Instant Seeding restore job definition, the destination must be a non-system drive. The SQL database and log files must be on nonsystem drives.
A network share for Always On log backups must be accessible from the secondary node. The seeding restore restores log backups directly from the original log backup target instead of the temporary snapshot.
×
Microsoft SQL Server - Authentication, Registration, and Privileges
Authentication and registration
Register each Microsoft SQL Server as a provider in IBM Storage Defender Copy Data Management by name or IP address. When you register an SQL Cluster (AlwaysOn) node, register each node by name or IP address.
Note: The IP addresses must be public-facing and listening on port 5985. The fully qualified domain name and virtual machine node DNS name must be resolvable and route-able from the IBM Storage Defender Copy Data Management appliance. The user identity needs sufficient rights to install and start the IBM Storage Defender Copy Data Management Tools Service on the node. The sufficient rights also include "Log on as a service" rights. For more information, see Add the Log on as a service right to an account
The default security policy uses the Windows NTLM protocol, and the user identity format follows the default domain\Name format. You must manually create a directory to store VSS provider logs when you run IBM Spectrum Copy Data Management 2.2.6 and earlier. Create the following directory structure on the Microsoft SQL Server: c:\temp\CDM\logs
Privileges
On the Microsoft SQL Server, the system login credentials need public, and sysadmin permissions enabled, plus permission to access cluster resources in an SQL AlwaysOn environment. If one user account is used for all SQL functions, a Windows login must be enabled for the Microsoft SQL Server, with public and sysadmin permissions enabled.
Every SQL instance can use a specific user account to access the resources of that particular SQL instance.
To run log backups, the SQL user registered with IBM Storage Defender Copy Data Management must enable the sysadmin permission to manage Microsoft SQL Server agent jobs. If the Microsoft SQL Server agent service user is the default NT user, the agent uses that account to enable and access log backup jobs.
×
Microsoft SQL Server - ODBC Versions 18 and Above
For CDM to work with ODBC versions 18 and above, user needs to ensure below and should be usually present in production environments. Note that it is a SQL ODBC driver pre-requisite, and not a CDM pre-requisite.
Install a valid SSL certificate on the SQL Server (windows host)
Configure SQL Server to use the certificate
Ensure the certificate is trusted by the client machine
In case above requirement cannot be met for whatever reason, user can manually uninstall ODBC 18 and above versions from the MS SQL setup and keep only ODBC 17.
×
InterSystems Database - General
On the IBM Storage Defender Copy Data Management environment, InterSystems Caché and InterSystems IRIS are collectively referred to as InterSystems Database.
IBM Storage Defender Copy Data Management installs an agent on application servers when they are registered. Some anti-virus software might flag or attempt to remove the agent software. If you run anti-malware software application servers, exclude the installation path of the IBM Storage Defender Copy Data Management agent.
For Linux-based and AIX-based systems, the agent installation directory must be excluded for any anti-virus software scans. Add this path to the exclusion list for all anti-virus software that is installed on the application server. For Oracle (Linux and AIX/Power), Caché and IRIS (on Linux and AIX/Power), and SAP HANA (on Linux and Power): /tmp/cdm_guestapps_ Where is the username of the account used to register the application server in IBM Storage Defender Copy Data Management.
IBM Storage Defender Copy Data Management support for third-party operating systems, applications, services, and hardware depend on the respective vendor. If a third-party product or version moves into extended support, self-service support, or end-of-life, IBM Storage Defender Copy Data Management supports the product or version at the same level as the vendor. See also IBM Support General Guidelines and Limitations - IBM support for software on unsupported operating systems
×
InterSystems Database - Notes
IBM Storage Defender Copy Data Management tested against IRIS 2022, IRIS 2024.1 and IRIS 2025.1, IRIS 2025.1.2.
For supported VMware vSphere versions, see in System Requirements: IBM Storage Defender Copy Data Management 2.3.0
Select the provider type (Virtual/Physical) when you register the InterSystems Database provider in IBM Storage Defender Copy Data Management. All data and log files for an instance should be backed by either an iSCSI, FC or in case of PowerFlex' proprietary SDC protocol disk. Note: NetApp ONTAP Storage Systems are not supported.
InterSystems Database servers registered as virtual must have the most recent version of VMware Tools installed.
Supported platforms: IBM Power Systems, Intel based Systems running supported Linux OS.
On all supported storage systems, snapshot condense is run during every maintenance jobs.
Pure storage supports InterSystems Caché.
InterSystems IRIS is tested on AIX 7.1, AIX 7.2 and AIX 7.3.
Select the Physical provider type when you register the provider in IBM Storage Defender Copy Data Management.
×
InterSystems Database - Software Requirements
The bash and sudo packages must be installed. Sudo must be version 1.8.29 or later. Run sudo -V to check the version.
Python version 3.x must be installed.
RHEL 8.x only: Verify the util-linux package is up to date by running: yum update util-linux
RHEL 8.x or later: A required Perl module, Digest:MD5, is not installed by default. Install the module by running: yum install perl-Digest-MD5
Linux only: If data stays on LVM volumes, make sure that the LVM version is 2.03.02 or later. To check the LVM version and if necessary to update the package, run: lvm version
yum update lvm2
×
InterSystems Database - Connectivity Requirements
The SSH service must be running on port 22 on the server and any firewalls must be configured to allow IBM Storage Defender Copy Data Management to connect to the server by using SSH. The SFTP subsystem for SSH must also be enabled.
The server can be registered by using a DNS name or IP address. DNS names must be resolvable by IBM Storage Defender Copy Data Management.
To mount clones or copies of data, IBM Storage Defender Copy Data Management automatically maps and unmaps LUNs to the servers. Each server must be preconfigured to connect to the relevant Storage Systems at that site.
For Fibre Channel, the appropriate zoning must be configured beforehand.
For iSCSI, the servers must be configured beforehand to discover and log in to the targets on the storage servers.
×
InterSystems Database - Authentication and Privileges
Authentication
The application server must be registered in IBM Storage Defender Copy Data Management by using an operating system user that exists on the server (referred to as "IBM Storage Defender Copy Data Management agent user" for the rest of this topic).
During registration, you must provide either a password or a private SSH key that IBM Storage Defender Copy Data Management uses to log in to the server.
For password-based authentication, make sure that the password is correctly configured, and that the user can log in without facing any other prompts, such as prompts to reset the password.
For key-based authentication, verify that the public SSH key is placed in the appropriate authorized_keys file for the IBM Storage Defender Copy Data Management agent user.
Typically, the file is at: /home//.ssh/authorized_keys
Typically, the .ssh directory and all files under it need their permissions set to 600.
OS-level authentication must be enabled on the InterSystems Database server.
For InterSystems IRIS interface:
Go to: System Administration > Security > System Security > Authentication/Web Session Options.
Then, select: Allow Operating System authentication.
The user identity associated with IBM Storage Defender Copy Data Management registration needs sufficient privileges to start some system commands. For example, system commands used to find disk information for InterSystem IRIS', "iris session" command without asking for a database username and password. To enable this feature, use the InterSystems Database instance owner user after you add the user to sudoers file.
Privileges
The IBM Storage Defender Copy Data Management agent user needs the following privileges:
Privileges to run commands as root and other users by using sudo. IBM Storage Defender Copy Data Management requires these privileges for various tasks such as discovering storage layouts and mounting and unmounting disks.
The sudoers configuration must allow the IBM Storage Defender Copy Data Management agent user to run commands without a password.
The !requiretty setting must be set.
For examples on creating a new user with the necessary privileges, see Sample Configuration in InterSystems Database requirements.
×
InterSystems Database - Backup and Restore
Backup Jobs
InterSystems IRIS Database backup jobs occur at the instance level. Multiple instances can be added to a single backup job definition, and all instances on a host are automatically discovered. It is possible to scan an InterSystems Database backup failover member instance or an async member instance and run snapshots against the mirror copy instead of the primary failover member. Virtual instances can be selected for backup, however it is better to select database instances explicitly. If virtual instances are selected, the associated job definition must be adjusted when the database instances are upgraded to later versions.
Restore Jobs
If the xfsprogs package version on the destination server is between 3.2.0 and 4.1.9, the restore process might fail when you restore a database or file system from an XFS file system. To resolve the issue, upgrade xfsprogs to version 4.2.0 or later. InterSystems IRIS software is not required on the target host. However, the target host needs to have similar specifications to the source host, including operating system and processor. That the following users and groups must be created on the target host: instance owner, effective user for InterSystems Database superserver and its jobs, effective group for InterSystems Database processes, and a group that has permissions to start and stop InterSystems Database instances. The user and group IDs need to match with the user and group IDs on the source host. The instance is brought up by using the same mount points as those mount points found on the source machine. Make sure that these mounts are not in use on the target. When you restore to a target with running InterSystems Database instances, the instances display as valid targets. That IBM Storage Defender Copy Data Management does not interact with these instances but instead start a new instance by using mapped mount points. When you restore to a target with no prior InterSystems Database instances, IBM Storage Defender Copy Data Management creates a placeholder that acts as a restore target. Single InterSystems Databases can be restored through an Instant Disk Restore job, which mounts physical volumes on the target machine. Granular recovery can then be run through InterSystems commands.
Instant Database restore for InterSystems Databases
When you run an instant database restore to another compatible Linux system, you must first register that system in IBM Storage Defender Copy Data Management as an InterSystems database to which the existing database can be restored. Make sure that no existing mounts exist on the new system that might conflict with mounts that are restored. For example, /IRISHealth/db and /IRISHealth/log/ for InterSystems IRIS. The database is started automatically. If it is not, start the database instance manually.
$ cd /IRISHealth/db/bin
$ iris start
When you run an instant database restore to the same InterSystems database system or another system runs an InterSystems database, the source and destination mount points must be different for /IRISHealth/db and /IRISHealth/log/ for InterSystems IRIS. InterSystems IRIS Databases can be only restored to another InterSystems IRIS system. Additionally, the destination database must be stopped because the port used to run the database can be used only by one database at a time. To stop the database from running, issue the following command:
$ iris stop
×
InterSystems Database - Sample Configuration
The following commands are examples for creating and configuring an operating system user that IBM Storage Defender Copy Data Management use to log in to the application server. The command syntax might vary depending on your operating system type and version.
Create the user that is designated as the IBM Storage Defender Copy Data Management agent user: useradd -m cdmagent
If you use password-based authentication, set a password: passwd cdmagent
Add the user to the dbusr group: usermod -g dbusr username
If you use key-based authentication, place the public key in /home/cdmagent/.ssh/authorized_keys. Or place the appropriate file, depends on your sshd configuration. And verify that the correct ownership and permissions are set, such as: chown -R cdmagent:cdmagent /home/cdmagent/.ssh
chmod 700 /home/cdmagent/.ssh
chmod 600 /home/cdmagent/.ssh/authorized_keys
Place the following lines at the end of your sudoers configuration file, typically /etc/sudoers. If the existing sudoers file is configured to import configuration from another directory (for example, /etc/sudoers.d), you can also place the lines in a new file in that directory: Defaults:cdmagent !requiretty
cdmagent ALL=(ALL) NOPASSWD:ALL
×
Download Information - Fix Central
To get the most current features and enhancements, it is required to update IBM Storage Defender Copy Data Management from a previous version; 2.2.28. Maintenance packages (fix packs) and interim fixes are delivered on Fix Central.
Fix Central is a secure website that requires you to log in using your IBMid. You can acquire an IBMid at Sign up to IBMid. You can locate the packages on the Fix Central online website by using the product name, version, and platform as the search query. For example, use the "IBM Storage Defender Copy Data Management". The HTTPS link in the download list directs to the Fix Central online website.
However, these maintenance packages and interim fixes available through Fix Central do not contain the required license enablement files. For initial installation of IBM Storage Protect Copy Data Management, you must obtain your package, with the associated license enablement files, from the Passport Advantage Online website
Available Files for Download
The following files are available for download of IBM Storage Defender Copy Data Management 2.3.0:
Image Name
Installation Environment
Description
DefenderCDM_2.3.0.0.iso
Linux
Updates to IBM Storage Defender Copy Data Management. 2.3.0 for VMware
DefenderCDM_2.3.0.1.iso
Linux
Updates to IBM Storage Defender Copy Data Management. 2.3.0.1 for VMware
DefenderCDM_2.3.0.0_UsersGuide.pdf
--
Installation and User's Guide
DefenderCDM_2.3.0.0_REST_API_Guide.pdf
--
This document provides information for the IBM Storage Defender Copy Data Management API based on the RESTful framework.
DefenderCDM_2.3.0.0_Whats_New.pdf
--
This document provides information for the IBM Storage Defender Copy Data Management new features.
×
Download Information - Passport Advantage Online
The Passport Advantage Online website offers complete images of IBM Storage Defender Copy Data Management for download. The packages available through Passport Advantage are the base level packages.
The Passport Advantage Online website is a secure website that requires an account ID and password. It has all IBM Storage Defender Copy Data Management packages available for download. The HTTPS link in the download list directs to the Passport Advantage Online website.
Download Steps
To download and assemble the installation parts for IBM Storage Defender Copy Data Management, complete the following steps:
Go to the Passport Advantage Online website, click Customer sign in, and sign in by using your IBMid and password.
In the Software and services online page, click Software download & media access.
Use one of the search options under Browse your entitled software to find the link for the wanted IBM Storage Protect product. The fulfilled program number for IBM Storage Defender Copy Data Management is 5737-B34.
On the product download page, verify that the Required checkbox is selected, and then click Download. The table in section "Images on Passport Advantage Online" contains the descriptions and part numbers of the parts for IBM Storage Defender Copy Data Management.
When the download is finished, extract the IBM Storage Defender Copy Data Management OVA template file into a single dedicated directory.
To install the product as a virtual appliance, follow the instructions in the IBM Storage Defender Copy Data Management User's Guide.
Note: Downloading any files indicates acceptance of the terms and conditions detailed in the IBM Program license agreement.
Available Images
The following images are available for download of IBM Storage Defender Copy Data Management:
Description
Part number
File name with file extension
IBM Storage Defender Copy Data Management 2.3.0 eAssembly
G0HP6EN
--
IBM Storage Defender Copy Data Management. 2.3.0.0 English for VMware
M11FREN
M0Y5LEN.ova
IBM Storage Defender Copy Data Management. - Enablement Key for Upgrade from Trial to Full Version English
M11FSEN
M0Y5MEN.lic
IBM Storage Defender Copy Data Management. 2.3.0.0 English for Hyper-V
M11FTEN
M11FTEN.zip
IBM Storage Defender Copy Data Management. 2.3.0.0 English for PowerPC
For hardware and software requirements on other components and other levels, see Requirements Documents: IBM Storage Defender Copy Data Management.
For featured technical support documents, see Featured Documents: IBM Storage Defender Copy Data Management.
×
Download Information - Installation Instructions
To access technical information and various technical resources for this product, go to the IBM Storage Defender Copy Data Management documentation.
For the most recent product information, go to the IBM Storage Defender Copy Data Management 2.3.0 documentation.
Detailed installation instructions are available in the Installation and User's Guide for IBM Storage Defender Copy Data Management. For more information IBM Storage Defender Copy Data Management - Installation and setup.
Security Bulletin: Vulnerabilities in Jetty, Eclipse Jetty, minimatch, url-regex, jsdiff, golang, qs and Apache Tomcat might affect IBM Storage Defender Copy Data Management https://www.ibm.com/support/pages/node/7268263
2.3.0.0
Linux
Security Bulletin: Vulnerabilities in hoek, Bouncy Castle Inc, Spring Framework, golang, Apache Commons, semver and Google Guava might affect IBM Storage Defender Copy Data Management https://www.ibm.com/support/pages/node/7268264
2.3.0.0
Linux
Security Bulletin: Vulnerabilities in Jetty, Eclipse Jetty,Spring Cloud Netflix Zuul,Spring Framework,Spring Security,NPM package,glob-parent package,jQuery,Braces, go-redis,qs,LZ4,js-yaml might affect IBM Storage Defender Copy Data Management https://www.ibm.com/support/pages/node/7268265
The following table provides a list of APARs fixed in this level on IBM Storage Defender Copy Data Management:
APAR
Fixed Level
Abstract
N/A
N/A
N/A
×
Dell PowerFlex Storage Requirements
Dell PowerFlex Storage systems managed by below versions of PowerFlex Manager are supported:
Dell PowerFlex Manager version - 4.6.x, 4.8.x
Note:
Due to a known limitation in PowerFlex Manager version 4.6.x and 4.8.x, the standard user account with storage admin privileges is insufficient for performing remote snapshot operations, as a workaround user must be granted super-user privileges.
×
NetApp ONTAP Requirements
Note:
IBM Storage Defender Copy Data Management does not support new features introduced in ONTAP 9.x. IBM Storage Defender Copy Data Management was tested against Data ONTAP 9.3.
IBM Storage Defender Copy Data Management supports NetApp MetroCluster configurations that are running on ONTAP 9.x or later. After successful completion of MetroCluster Switchover or Switchback operations, mirror or vault relationships must be reestablished through an IBM Storage Copy Data Management job. See Create a Backup Job Definition -NetApp ONTAP in the IBM Storage Defender Copy Data Management User's Guide.
Clustered Data ONTAP providers must be registered with a cluster administrator account. Cluster peering must be enabled. Peer relationships enable communication between SVMs. See on NetApp's Support site: NetApp ONTAP's Cluster and Vserver Peering Express Guide
Note:
Make sure that TLS protocol is enabled on the NetApp storage system by setting the tls.enable option to ON. For TLS to take effect on HTTPS, make sure that the httpd.admin.ssl.enable option is also set to ON. See on NetApp's Support site: Enabling or disabling TLS
NetApp ONTAP File Inventory Job requirements:
IBM Storage Defender Copy Data Management uses SnapDiff in the NetApp ONTAP file level jobs to run catalog based on snapshot differences. SnapDiff cataloging is supported on storage system models that are running the following versions of Data ONTAP:
The following options must be enabled on the volume of the NetApp storage system to catalog:
create_ucode and convert_ucode: These options are turned off by default.
Inode to Pathname: The Inode to Pathname function creates relationships between file names and relative paths. If Inode to Pathname is disabled on a volume, you must enable it, then delete existing snapshots on the volume. When new snapshots are created with Inode to Pathname enabled, the volume can be cataloged.
Internationalization requirements:
The language code must be set and the UTF-8 variant must be specified on the NetApp storage system. For example, en_US.UTF-8. Only the English locale for vol0 for UTF-8 is supported.
The IBM Storage Defender Copy Data Management application and documentation are available in English only. However, cataloging, searching, and reporting functions support international metadata.
×
Download Information - Fix Central
To get the most current features and enhancements, it is required to update IBM Storage Defender Copy Data Management from a previous version; 2.2.28. Maintenance packages (fix packs) and interim fixes are delivered on Fix Central.
Fix Central is a secure website that requires you to log in using your IBMid. You can acquire an IBMid at Sign up to IBMid. You can locate the packages on the Fix Central online website by using the product name, version, and platform as the search query. For example, use the "IBM Storage Defender Copy Data Management". The HTTPS link in the download list directs to the Fix Central online website.
However, these maintenance packages and interim fixes available through Fix Central do not contain the required license enablement files. For initial installation of IBM Storage Defender Copy Data Management, you must obtain your package, with the associated license enablement files, from the Passport Advantage Online website.
Available Files for Download
The following files are available for download of IBM Storage Defender Copy Data Management 2.3.1:
Image Name
Installation Environment
Description
DefenderCDM_2.3.1.0.iso
Linux
Updates to IBM Storage Defender Copy Data Management 2.3.1 for VMware
DefenderCDM_2.3.1.0_UsersGuide.pdf
--
Installation and User's Guide
DefenderCDM_2.3.1.0_REST_API_Guide.pdf
--
This document provides information for the IBM Storage Defender Copy Data Management API based on the RESTful framework.
DefenderCDM_2.3.1.0_Whats_New.pdf
--
This document provides information for the IBM Storage Defender Copy Data Management new features.
The Passport Advantage Online website offers complete images of IBM Storage Defender Copy Data Management for download. The packages available through Passport Advantage are the base level packages.
The Passport Advantage Online website is a secure website that requires an account ID and password. It has all IBM Storage Defender Copy Data Management packages available for download. The HTTPS link in the download list directs to the Passport Advantage Online website.
Download Steps
To download and assemble the installation parts for IBM Storage Defender Copy Data Management, complete the following steps:
Go to the Passport Advantage Online website, click Customer sign in, and sign in by using your IBMid and password.
In the Software and services online page, click Software download & media access.
Use one of the search options under Browse your entitled software to find the link for the wanted IBM Storage Protect product. The fulfilled program number for IBM Storage Defender Copy Data Management is 5737-B34.
On the product download page, verify that the Required checkbox is selected, and then click Download. The table in section "Images on Passport Advantage Online" contains the descriptions and part numbers of the parts for IBM Storage Defender Copy Data Management.
When the download is finished, extract the IBM Storage Defender Copy Data Management OVA template file into a single dedicated directory.
To install the product as a virtual appliance, follow the instructions in the IBM Storage Defender Copy Data Management User's Guide.
Note: Downloading any files indicates acceptance of the terms and conditions detailed in the IBM Program license agreement.
Available Images
The following images are available for download of IBM Storage Defender Copy Data Management:
Description
Part number
File name with file extension
IBM Storage Defender Copy Data Management 2.3.1 eAssembly
M138PEN
IBM Storage Defender Copy Data Management 2.3.1.0 English for VMware
M138PEN
M138PEN.ova
IBM Storage Defender Copy Data Management — Enablement Key for Upgrade from Trial to Full Version English
M138QEN
M138QEN.lic
IBM Storage Defender Copy Data Management 2.3.1.0 English for Hyper-V
M138REN
M138REN.zip
IBM Storage Defender Copy Data Management 2.3.1.0 English for PowerPC
The following vulnerabilities are fixed in this level:
IBM Storage Defender Copy Data Management
Fixing Level
Platform
Bulletin Title and Link
2.3.1
Linux
Security Bulletin: Vulnerabilities in Spring Security, Handlebars, Apache MINA and Apache Tomcat might affect IBM Storage Defender Copy Data Management https://www.ibm.com/support/pages/node/7277815
Security Bulletin: Vulnerabilities in Spring Security, Apache Tomcat, Netty, Lodash, Spring Framework and Node.js might affect IBM Storage Defender Copy Data Management https://www.ibm.com/support/pages/node/7277164
On the IBM Storage Defender Copy Data Management environment, InterSystems Caché and InterSystems IRIS are collectively referred to as InterSystems Database.
IBM Storage Defender Copy Data Management installs an agent on application servers when they are registered. Some anti-virus software might flag or attempt to remove the agent software. If you run anti-malware software on application servers, exclude the installation path of the IBM Storage Defender Copy Data Management agent.
For Linux-based and AIX-based systems, the agent installation directory must be excluded for any anti-virus software scans. Add this path to the exclusion list for all anti-virus software that is installed on the application server. For Oracle (Linux and AIX/Power), Caché and IRIS (on Linux and AIX/Power), and SAP HANA (on Linux and Power):
/tmp/cdm_guestapps_<username>
Where <username> is the username of the account used to register the application server in IBM Storage Defender Copy Data Management.
IBM Storage Defender Copy Data Management support for third-party operating systems, applications, services, and hardware depend on the respective vendor. If a third-party product or version moves into extended support, self-service support, or end-of-life, IBM Storage Defender Copy Data Management supports the product or version at the same level as the vendor. See also IBM Support General Guidelines and Limitations - IBM support for software on unsupported operating systems.
×
Server Types
Operating Systems
Storage Configuration
Physical AIX 7.1 [5][8] AIX 7.2 [5][8] (beginning with 2.2.19) AIX 7.3 (Version: 7300-04-00) [5][8] RedHat Enterprise Linux 8.x, 9.x, 10.x [11] SUSE Linux Enterprise Server 15.x, 16 [11]
Note: For RHEL 10, the default python version is 3.12.x. However, CDM requires python version 3.9.x, which needs to be installed and set as default python path.
Fibre Channel iSCSI
Virtual (VMware)[2, 4] RedHat Enterprise Linux 8.x, 9.x, 10.x SUSE Linux Enterprise Server 15.x, 16
Note: For RHEL 10, the default python version is 3.12.x. However, CDM requires python version 3.9.x, which needs to be installed and set as default python path.
Physical RDM backed by Fibre Channel or iSCSI disks attached to ESXi [3] VMDK (dependent and independent disks) on VMFS datastores backed by Fibre Channel or iSCSI disks attached to ESXi iSCSI disks directly attached to guest operating system [9]
×
InterSystems Database Requirements — Notes
IBM Storage Defender Copy Data Management tested against IRIS 2022, IRIS 2024.1 and IRIS 2025.1, IRIS 2025.1.2.
For supported VMware vSphere versions, see in System Requirements: IBM Storage Defender Copy Data Management 2.3.1.
Select the provider type (Virtual/Physical) when you register the InterSystems Database provider in IBM Storage Defender Copy Data Management. If using Physical RDM disks on VMware, select Virtual as the provider type.
Note: NetApp ONTAP Storage Systems are not supported.
InterSystems Database servers registered as virtual must have the most recent version of VMware Tools installed.
Supported platforms: IBM Power Systems, Intel based Systems running supported Linux OS.
On all supported storage systems, snapshot condense is run during every maintenance job.
Pure storage supports InterSystems Caché.
InterSystems IRIS is tested on AIX 7.1, AIX 7.2 and AIX 7.3.
Select the Physical provider type when you register the provider in IBM Storage Defender Copy Data Management.
For Dell PowerMax Storage:
Use separate Storage Groups for different databases for improved performance.
IBM Storage Defender Copy Data Management supports one parent Storage Group, and it can contain different child Storage Groups for different databases.
Keep datafiles and log files in separate Storage Groups.
When using Parent Storage Group with child Storage Group, use separate child Storage Groups for data and log.
For Instant Restore, Host on Dell PowerMax array must have at least one Masking View created for itself, even if the host is a part of a hostgroup having active Masking View.
For remote replication, create and map the host to the remote array as well and have at least one Masking View created using it. The port group used in the Masking View created will be used by the CDM restore job while creating Masking View to map the restored volumes to the host on the remote array.
For Dell PowerFlex Storage:
RHEL 10, SUSE 16 and SUSE 15 SP07 are currently not supported by Dell PowerFlex SDC driver for version 4.8.x.
Ensure that the VMware ESXi hostnames registered in Dell PowerFlex Storage exactly match the hostnames configured on the VMware vSphere environment.
Ensure that the Dell PowerFlex SDC component is installed and running on ESXi hosts where the application VMs are hosted.
Applications that are registered as Physical for Dell PowerFlex need to follow the below steps. Since SDC setup is done as root user, binaries like drv_cfg are owned by root with special permissions. In order for a non-root user to be able to run these binaries, the following steps must be performed:
InterSystems Database support for VMware virtual machines
For virtual machines, the Disk UUID option must be enabled. To enable:
Power off the guest machine through the vSphere client.
Select the guest and click Edit Settings.
Select VM Options.
Edit Configuration under the Advanced section and add a row:
Name: disk.enableUUID
Value: TRUE
Virtual disks and pRDM are supported for VMware configurations. Data and log files for an instance need to stay on either pRDMs or virtual disks. One instance cannot use both disk types.
×
InterSystems Database Requirements — Software
The bash and sudo packages must be installed. Sudo must be version 1.8.29 or later. Run sudo -V to check the version.
Python version 3.x must be installed.
RHEL 8.x only: Verify the util-linux package is up to date by running:
yum update util-linux
RHEL 8.x or later: A required Perl module, Digest::MD5, is not installed by default. Install the module by running:
yum install perl-Digest-MD5
Linux only: If data stays on LVM volumes, make sure that the LVM version is 2.03.02 or later. To check the LVM version and if necessary to update the package, run:
lvm version
yum update lvm2
×
InterSystems Database Requirements — Connectivity
The SSH service must be running on port 22 on the server and any firewalls must be configured to allow IBM Storage Defender Copy Data Management to connect to the server by using SSH. The SFTP subsystem for SSH must also be enabled.
The server can be registered by using a DNS name or IP address. DNS names must be resolvable by IBM Storage Defender Copy Data Management.
To mount clones or copies of data, IBM Storage Defender Copy Data Management automatically maps and unmaps LUNs to the servers. Each server must be preconfigured to connect to the relevant Storage Systems at that site.
For Fibre Channel, the appropriate zoning must be configured beforehand.
For iSCSI, the servers must be configured beforehand to discover and log in to the targets on the storage servers.
×
InterSystems Database Requirements — Authentication and Privileges
Authentication
The application server must be registered in IBM Storage Defender Copy Data Management by using an operating system user that exists on the server (referred to as "IBM Storage Defender Copy Data Management agent user" for the rest of this topic).
During registration, you must provide either a password or a private SSH key that IBM Storage Defender Copy Data Management uses to log in to the server.
For password-based authentication, make sure that the password is correctly configured, and that the user can log in without facing any other prompts, such as prompts to reset the password.
For key-based authentication, verify that the public SSH key is placed in the appropriate authorized_keys file for the IBM Storage Defender Copy Data Management agent user.
Typically, the file is at: /home/<username>/.ssh/authorized_keys
Typically, the .ssh directory and all files under it need their permissions set to 600.
OS-level authentication must be enabled on the InterSystems Database server.
For InterSystems IRIS interface:
Go to: System Administration > Security > System Security > Authentication/Web Session Options.
Then, select: Allow Operating System authentication.
The user identity associated with IBM Storage Defender Copy Data Management registration needs sufficient privileges to start some system commands (for example, "iris session" command without asking for a database username and password). To enable this feature, use the InterSystems Database instance owner user after you add the user to sudoers file.
Privileges
The IBM Storage Defender Copy Data Management agent user needs the following privileges:
Privileges to run commands as root and other users by using sudo. IBM Storage Defender Copy Data Management requires these privileges for various tasks such as discovering storage layouts and mounting and unmounting disks.
The sudoers configuration must allow the IBM Storage Defender Copy Data Management agent user to run commands without a password.
The !requiretty setting must be set.
For examples on creating a new user with the necessary privileges, see Sample Configuration in InterSystems Database requirements.
×
InterSystems Database Requirements — Backup and Restore
Backup Jobs
InterSystems IRIS Database backup jobs occur at the instance level. Multiple instances can be added to a single backup job definition, and all instances on a host are automatically discovered.
It is possible to scan an InterSystems Database backup failover member instance or an async member instance and run snapshots against the mirror copy instead of the primary failover member.
Virtual instances can be selected for backup, however it is better to select database instances explicitly. If virtual instances are selected, the associated job definition must be adjusted when the database instances are upgraded to later versions.
Restore Jobs
If the xfsprogs package version on the destination server is between 3.2.0 and 4.1.9, the restore process might fail when you restore a database or file system from an XFS file system. To resolve the issue, upgrade xfsprogs to version 4.2.0 or later.
InterSystems IRIS software is not required on the target host. However, the target host needs to have similar specifications to the source host, including operating system and processor.
The following users and groups must be created on the target host: instance owner, effective user for InterSystems Database superserver and its jobs, effective group for InterSystems Database processes, and a group that has permissions to start and stop InterSystems Database instances. The user and group IDs need to match with those on the source host.
When you restore to a target with running InterSystems Database instances, the instances display as valid targets. IBM Storage Defender Copy Data Management does not interact with these instances but instead starts a new instance by using mapped mount points. When you restore to a target with no prior InterSystems Database instances, IBM Storage Defender Copy Data Management creates a placeholder that acts as a restore target.
Single InterSystems Databases can be restored through an Instant Disk Restore job, which mounts physical volumes on the target machine. Granular recovery can then be run through InterSystems commands.
Instant Database Restore for InterSystems Databases
When you run an instant database restore to another compatible Linux system, you must first register that system in IBM Storage Defender Copy Data Management as an InterSystems database to which the existing database can be restored. Make sure that no existing mounts exist on the new system that might conflict with mounts that are restored (for example, /IRISHealth/db and /IRISHealth/log/ for InterSystems IRIS). The database is started automatically. If it is not, start the database instance manually:
$ cd /IRISHealth/db/bin
$ iris start <name_of_instance>
When you run an instant database restore to the same InterSystems database system or another system running an InterSystems database, the source and destination mount points must be different for /IRISHealth/db and /IRISHealth/log/. InterSystems IRIS Databases can be only restored to another InterSystems IRIS system. Additionally, the destination database must be stopped because the port used to run the database can be used only by one database at a time. To stop the database:
The following commands are examples for creating and configuring an operating system user that IBM Storage Defender Copy Data Management uses to log in to the application server. The command syntax might vary depending on your operating system type and version.
Create the user that is designated as the IBM Storage Defender Copy Data Management agent user:
useradd -m cdmagent
If you use password-based authentication, set a password:
passwd cdmagent
Add the user to the dbusr group:
usermod -g dbusr username
If you use key-based authentication, place the public key in /home/cdmagent/.ssh/authorized_keys (or the appropriate file per your sshd configuration). Verify that the correct ownership and permissions are set:
Place the following lines at the end of your sudoers configuration file (typically /etc/sudoers). If the existing sudoers file imports configuration from another directory (for example, /etc/sudoers.d), you can also place the lines in a new file in that directory:
IBM Storage Defender Copy Data Management installs an agent on application servers when they are registered. Some anti-virus software might flag or attempt to remove the agent software. If you run anti-malware software on application servers, exclude the installation path of the IBM Storage Defender Copy Data Management agent.
For Linux-based and AIX-based systems, the agent installation directory must be excluded for any anti-virus software scans. Add this path to the exclusion list for all anti-virus software that is installed on the application server. For Oracle, InterSystems Caché and IRIS, and SAP HANA:
/tmp/cdm_guestapps_<username>
Where <username> is the username of the account used to register the application server in IBM Storage Defender Copy Data Management.
IBM Storage Defender Copy Data Management support for third-party operating systems, applications, services, and hardware depend on the respective vendor. If a third-party product or version moves into extended support, self-service support, or end-of-life, IBM Storage Defender Copy Data Management supports the product or version at the same level as the vendor. See also IBM Support General Guidelines and Limitations - IBM support for software on unsupported operating systems.
×
Server Types
Operating Systems
Storage Configuration
Physical AIX 7.1 AIX 7.2 AIX 7.3 (Version: 7300-04-00) Red Hat Enterprise Linux 8.x, 9.x SUSE Linux Enterprise Server 15.x
Fibre Channel iSCSI NFS
Virtual Red Hat Enterprise Linux 8.x and 9.x SUSE Linux Enterprise Server 15.x
Physical RDM backed by Fibre Channel or iSCSI disks attached to ESXi VMDK (dependent and independent disks) on VMFS datastores (Fibre Channel or iSCSI) or NFS datastores iSCSI disks directly attached to guest operating system NFS share mapped directly to the guest
×
Oracle Requirements — Notes
Standalone databases protected by IBM Storage Defender Copy Data Management can be recovered to the same or alternate standalone server installation. When you recover from standalone to RAC, if the source database uses Automatic Storage Management, then it is successfully recovered to all nodes in the destination cluster. If the source database uses non-ASM storage, the database is mounted only on the first node in the destination RAC.
RAC databases protected by IBM Storage Defender Copy Data Management can be recovered to the same or another RAC installation or to a standalone ASM server. To recover a RAC database to a standalone server, the Grid Infrastructure must be installed on the destination server, and an ASM instance must be running.
Oracle Flex ASM is not supported. Oracle ASM is not supported in virtual mode.
RAC database recoveries are not server pool aware. IBM Storage Defender Copy Data Management can recover databases to a RAC, but not to a specific server pools.
IBM Storage Defender Copy Data Management supports recovering databases from a source physical server to a destination-virtual server by provisioning disks as physical RDMs. Similarly, IBM Storage Defender Copy Data Management can recover databases from a source-virtual server that uses physical RDM to a destination physical server. However, source databases on VMDK virtual disks can be recovered only to another virtual server and not to a physical server.
Oracle data must stay directly on one of the supported Storage Systems listed previously. VADP-based protection of virtual Oracle servers is not supported.
On AIX LPAR/VIO servers, Oracle data must stay on disks attached to the server by using NPIV. Virtual SCSI disks are not supported.
Masking and DevOps recoveries are not supported on virtual servers.
For supported VMware vSphere versions, see in System Requirements: IBM Storage Defender Copy Data Management 2.3.1.
Oracle servers registered as Virtual need VMware Tools installed and running.
Data masking is not supported for Oracle in NetApp storage environments. Masking is not supported on source database on NFS (a copy of which cloned and masked) or source databases on replica copies. Instead of the default mirror copy, you must select a snapshot copy as a replication source.
NetApp systems running in 7-Mode are not supported.
Oracle 19c standalone is now supported for AIX 7.3. More requirements:
Oracle database data and the flash recovery area (FRA) must stay on supported Storage Systems. IBM Storage Defender Copy Data Management can back up archived logs to a supported storage system if they are not already on one.
During an Instant Database Restore, there might be failures if the new name specified for the restored database is similar to an existing database differing only by numerical suffix. For clustered instances of Oracle databases, the appliance always uses global database name in the UI.
On all supported storage systems, snapshot condense is run during every maintenance jobs.
Supported platforms: IBM Power Systems and Intel based Systems running supported AIX and Linux OS.
For Dell PowerMax Storage:
Use separate Storage Groups (SG) for different databases for improved performance.
IBM Storage Defender Copy Data Management supports one parent SG, and it can contain different child SG for different databases.
Keep datafiles and log files in separate SG.
When using Parent SG with child SGs, use separate child SGs for data and log.
For Instant Disk Restore, Host on Dell PowerMax array must have at least one Masking View created for itself, even if the host is a part of a hostgroup having active Masking View.
Oracle 19c RAC configuration is now supported on the DELL PowerMax storage system.
Oracle 21c RAC configuration is not supported on the DELL PowerMax storage system.
For remote replication feature, create and map the host to the remote array and have at least 1 masking view created using it. The portgroup used in the masking view created by the user will be used by the CDM restore job while creating masking view to map the restored volumes to the host on the remote array.
CDM does not support multiple DBs with same db_name (but different db_unique_name), as it relies on db_name to uniquely identify the Oracle home belonging to the database (instance).
User should make sure that Oracle parameters (texts) do not exceed the recommended size by Oracle. e.g. CDM workflow may fail when the size of '_fix_control' parameter exceeds 255 characters.
In Oracle RAC configuration, the cluster database restore will create only a single instance and the restored instance is not registered as a cluster resource.
When the Prepare scripts option is chosen, the files will be copied to the CDM appliance under /data/log/ecxdeployer/<YYYY-MM-DD>/<random generated string> folder.
Note: To run these scripts, they need to be copied from this folder of the CDM appliance to any preferred location on the Oracle Server.
In order to execute the scripts, follow these steps as an Oracle user:
Export the Oracle SID as the SID used during recovery.
When executing an SQL script, login to SQLPlus using sqlplus / as sysdba. You can then run the script: @<location in oracle server>/Step-<number>_<operation>.sql
When executing an RMAN script, login to RMAN using rman target=/. You can then run the script as: @<location in oracle server>/Step-<number>_<operation>.rman
For Dell PowerFlex Storage:
Ensure that the VMware ESXi hostnames registered in Dell PowerFlex Storage exactly match the hostnames configured on the VMware vSphere environment.
Ensure that the Dell PowerFlex SDC component is installed and running on ESXi hosts where the application VMs are hosted.
Applications that are registered as Physical for Dell PowerFlex need to follow the below steps. Since SDC setup is done as root user, binaries like drv_cfg are not accessible for non-root users:
For Oracle servers running as VMware virtual machines, UUID must be enabled to run Oracle-based backup functions. To enable: power off the guest machine through the vSphere client, then select the guest and click Edit Settings. Select Options, then General under the Advanced section. Select Configuration Parameters..., then find the disk.EnableUUID parameter. If set to FALSE, change the value to TRUE. If the parameter is not available, add it by clicking Add Row, set the value to TRUE, then power on the guest.
Oracle support for VMware virtual machines requires Oracle data and logs to be stored on VMDK virtual disks or physical RDMs. Virtual RDM disks are not supported. The VMDKs must stay on a datastore created on LUNs from supported Storage Systems. Similarly, the physical RDMs must be backed by LUNs from supported Storage Systems.
Note: For Oracle RAC clustered nodes running vSphere 6.5 or later, if an existing shared SCSI controller is not found, IBM Storage Defender Copy Data Management automatically enables the "multi-writer" sharing option for each shared virtual disk.
Restore Jobs
If the xfsprogs package version on the destination server is between 3.2.0 and 4.1.9, the restore process might fail when you restore a database or file system from an XFS file system. To resolve the issue, upgrade xfsprogs to version 4.2.0 or later.
Revert Jobs
Restrictions: Oracle revert jobs are only supported for backups using the IBM Storage Virtualize for snapshot provider, Dell PowerMax and Dell PowerFlex storage providers.
Note: With Dell PowerMax and Dell PowerFlex storage provider, revert with remote/replicated copy is not supported.
When you run revert jobs on Oracle, there are special considerations that must be met for jobs to successfully complete.
Oracle data, log and the operating system (OS) file system must be on separate datastores/LUNs. Make sure that the databases are on independent storage.
The underlying storage volume for the databases (data and log disks) being reverted should not contain data for other databases and should not contain a datastore that is shared by other VMs or by another database not being reverted.
Make sure that the production databases are not on VMDK disks that are part of a VMware VM snapshot.
All VM snapshots need to be removed from the Oracle server before you run the revert function.
Production databases are automatically shut down during the revert.
Revert is available only after a restore is completed.
Oracle ASM/RAC backups can only be restored on the same host.
When you create a job, you need to set the default revert action for the job. This behavior is controlled through the Revert Database option during the job creation process:
Enabled – Always revert the database.
Disabled – Never reverts the database.
User Selection – Allows the user to make the determination to revert the database when the job session is pending.
Note: 'Make Permanent' option will be disabled when Revert is enabled.
Restrictions:
The Revert function is not supported for AIX based Oracle deployments.
The Revert function is not supported for LVM based Oracle deployments.
×
Oracle Requirements — Software
The bash and sudo packages must be installed. Sudo must be version 1.8.29 or later. Run sudo -V to check the version.
Python version 3.x must be installed. It might be necessary to add your python3 binary file location to the system PATH or to create a symbolic link. For example, if your python3 is installed at /opt/freeware/bin, you need to create a link as follows:
ln -s /opt/freeware/bin/python3 /usr/bin/python3
On AIX systems, it might be necessary to rerun any AIX inventory jobs.
RHEL 8.x or later: Ensure that the util-linux package is up to date by running:
yum update util-linux
Depending on your version or distribution, the package might be named util-linux.
RHEL 8.x or later: A required Perl module, Digest::MD5, is not installed by default. Install the module by running:
yum install perl-Digest-MD5
Linux only: If data stays on LVM volumes, ensure that the LVM version is 2.03.02 or later. To check the LVM version and if necessary to update the package, run:
lvm version
yum update lvm2
×
Oracle Requirements — Connectivity
The SSH service must be running on port 22 on the server and any firewalls must be configured to allow IBM Storage Defender Copy Data Management to connect to the server by using SSH. The SFTP subsystem for SSH must also be enabled.
The server can be registered by using a DNS name or IP address. DNS names must be resolvable by IBM Storage Defender Copy Data Management.
When you register Oracle RAC nodes, register each node by using its physical IP or name. Do not use a virtual name or Single Client Access Name (SCAN).
To mount clones or copies of Oracle data, IBM Storage Defender Copy Data Management automatically maps and unmaps LUNs to the Oracle servers. Each server must be preconfigured to connect to the relevant Storage Systems at that site.
For Fibre Channel, the appropriate zoning must be configured beforehand.
For iSCSI, the Oracle servers must be configured beforehand to discover and log in to the targets on the storage servers.
×
Oracle Requirements — Authentication and Privileges
Authentication
The Oracle server must be registered in IBM Storage Defender Copy Data Management by using an operating system user that exists on the Oracle server (referred to as "IBM Storage Defender Copy Data Management agent user" for the rest of this topic).
During registration, you must provide either a password or a private SSH key that IBM Storage Defender Copy Data Management uses to log in to the server.
For password-based authentication, ensure that the password is correctly configured and that the user can log in without facing any other prompts, such as prompts to reset the password.
For key-based authentication, ensure that the public SSH key is placed in the appropriate authorized_keys file for the IBM Storage Defender Copy Data Management agent user.
Typically, the file is at /home/<username>/.ssh/authorized_keys
Typically, the .ssh directory and all files under it need their permissions set to 600.
Privileges
The IBM Storage Defender Copy Data Management agent user needs the following privileges:
Privileges to run commands as root and other users by using sudo. IBM Storage Defender Copy Data Management requires these privileges for various tasks such as discovering storage layouts and mounting and unmounting disks.
The sudoers configuration must allow the IBM Storage Defender Copy Data Management agent user to run commands without a password.
The !requiretty setting must be set.
The ENV_KEEP setting must allow the ORACLE_HOME and ORACLE_SID environment variables to be retained.
Privileges to read the Oracle inventory. IBM Storage Defender Copy Data Management requires those privileges to discover and collect information about Oracle homes and databases. To achieve discovery and collection of information, the IBM Storage Defender Copy Data Management agent user must belong to the Oracle inventory group, typically named oinstall.
SYSDBA privileges for database instances. IBM Storage Defender Copy Data Management needs to run database tasks like querying instance details, hot backup, RMAN cataloging, and starting and stopping instances during recovery.
To achieve database tasks, the IBM Storage Defender Copy Data Management agent user must belong to the OSDBA operating system group, typically named dba.
If multiple Oracle homes each with a different OSDBA group, the IBM Storage Defender Copy Data Management agent user must belong to each group.
SYSASM privileges, if Automatic Storage Management (ASM) is installed. IBM Storage Defender Copy Data Management needs to run storage tasks like querying ASM disk information, and renaming, mounting, and unmounting diskgroups.
To achieve storage tasks, the IBM Storage Defender Copy Data Management agent user must belong to the OSASM operating system group, typically named asmadmin.
Shell user limits for the IBM Storage Defender Copy Data Management agent user must be the same as those limits for the user that owns the Oracle home, typically named oracle. Run ulimit -a as both the oracle user and the IBM Storage Defender Copy Data Management agent user and ensure that their settings are identical.
For examples on creating a new user with the necessary privileges, see Sample Configuration in Oracle requirements.
×
Oracle Requirements — Discovery
Oracle Home Discovery for Symbolic Links
IBM Storage Defender Copy Data Management discovers Oracle installations and databases by looking through the files /etc/oraInst.loc and /etc/oratab, as well as the list of running Oracle processes. When you connect to a database instance to discover its properties, IBM Storage Defender Copy Data Management connects by setting the ORACLE_HOME environment variable based on the path that was auto discovered.
In some cases, when Oracle databases are used in combination with SAP software for instance, a symbolic link to the Oracle Home path might be created. This link path can then be used by the database administrator to connect to the database.
Consider the following example where the real Oracle Home path can be /u01/app/oracle/product/19c/dbhome_1, while the symbolic link that points to it is /oracle/PRODDB/19c.
When IBM Storage Defender Copy Data Management connects to the instance by using the real, auto-discovered path, queries against the database can fail due to the ORACLE_HOME environment variable being incorrectly set. To override the auto-discovered path, a configuration file must be defined on each Oracle server where symbolic links are in use.
Create or edit the file /etc/guestapps_oraHomes.conf. Insert these entries:
# Define one entry per line.
# Each entry must be in the form: <instanceName> = <oraHomePath>
# Lines beginning with the '#' character are ignored.
PRODDB = /oracle/PRODDB/19c
TESTDB = /oracle/TESTDB/19c
To ensure that the configuration file is readable by the agent user, run:
chmod 644 /etc/guestapps_oraHomes.conf
Database Discovery
IBM Storage Defender Copy Data Management discovers Oracle installations and databases by looking through the files /etc/oraInst.loc and /etc/oratab, and the list of running Oracle processes. If the files are not present in their default location, the "locate" utility must be installed on the system so that IBM Storage Defender Copy Data Management can search for alternative locations of these files.
IBM Storage Defender Copy Data Management discovers databases and their storage layouts by connecting to running instances and querying the locations of their data files, log files, and other files. In order for IBM Storage Defender Copy Data Management to correctly discover databases during cataloging and copy operations, databases must be in "MOUNTED," "READ ONLY," or "READ/WRITE" mode. IBM Storage Defender Copy Data Management cannot discover or protect database instances that are shut down.
Databases must use a server parameter file (spfile). IBM Storage Defender Copy Data Management does not support copy operations for databases that use a text-based parameter file (pfile).
ASM Disk Discovery
When IBM Storage Defender Copy Data Management mounts snapshots or clones of ASM disks, it configures the disks to set the appropriate permissions required to make them discoverable by ASM:
The disk owner and group are set to the owner of the Grid installation and the OSASM group, which are typically grid and asmadmin. IBM Storage Defender Copy Data Management automatically discovers the appropriate owner and group information on each server.
The disk permissions are set to 660.
IBM Storage Defender Copy Data Management creates aliases or symbolic links with names that follow a consistent pattern. Ensure that ASM is able to discover the disks mapped by IBM Storage Defender Copy Data Management and update the ASM_DISKSTRING parameter to add this pattern.
Linux: IBM Storage Defender Copy Data Management creates udev rules for each disk to set the appropriate ownership and permissions. The udev rules also create symbolic links of the form /dev/ecx-asmdisk/<diskId> that point to the appropriate device under /dev.
To ensure that the disks are discoverable by ASM, add the following pattern to your existing ASM_DISKSTRING: /dev/ecx-asmdisk/*
AIX: IBM Storage Defender Copy Data Management creates a device node (by using mknod) of the form /dev/ecx_asm<diskId> that points to the appropriate hdisk under /dev. IBM Storage Defender Copy Data Management also sets the appropriate ownership and permissions for this new device.
To ensure that the disks are discoverable by ASM, add the following pattern to your existing ASM_DISKSTRING: /dev/ecx_asm*
Notes:
If the existing value of the ASM_DISKSTRING is empty, you might have to first set it to an appropriate value that matches all existing disks, then append the previous value.
If the existing value of the ASM_DISKSTRING is broad enough to discover all disks (for example: /dev/*), you might not need to update it.
Refer to Oracle documentation for details about retrieving and modifying the ASM_DISKSTRING parameter.
×
Oracle Requirements — Sample Configuration
The following commands are examples for creating and configuring an operating system user that IBM Storage Defender Copy Data Management uses to log in to the Oracle server. The command syntax might vary depending on your operating system type and version.
Create the user that is designated as the IBM Storage Defender Copy Data Management agent user:
useradd -m cdmagent
If you use password-based authentication, set a password:
passwd cdmagent
If you use key-based authentication, place the public key in /home/cdmagent/.ssh/authorized_keys, or the appropriate file depending on your sshd configuration, and ensure that the correct ownership and permissions are set:
Add the user to the Oracle installation and OSDBA group:
usermod -a -G oinstall,dba cdmagent
If ASM is in use, also add the user to the OSASM group:
usermod -a -G asmadmin cdmagent
Note: If on AIX, the append argument (-a) needs to be omitted when you use the usermod command.
Place the following lines at the end of your sudoers configuration file, typically /etc/sudoers. If the existing sudoers file is configured to import configuration from another directory (for example, /etc/sudoers.d), you can also place the lines in a new file in that directory:
IBM Storage Defender Copy Data Management installs an agent on application servers when it is registered. Some anti-virus software might flag or attempt to remove the agent software. If you run anti-malware software on application servers, exclude the installation path of the IBM Storage Defender Copy Data Management agent.
The agent installation directory must be excluded for any anti-virus software scans. Add this path to the exclusion list for all anti-virus software that is installed on the application server. For Oracle, InterSystems Caché and IRIS, and SAP HANA:
/tmp/cdm_guestapps_<username>
Where <username> is the username of the account used to register the application server in IBM Storage Defender Copy Data Management.
IBM Storage Defender Copy Data Management support for third-party operating systems, applications, services, and hardware depend on the respective vendor. If a third-party product or version moves into extended support, self-service support, or end-of-life, IBM Storage Defender Copy Data Management supports the product or version at the same level as the vendor. See also IBM Support General Guidelines and Limitations - IBM support for software on unsupported operating systems.
×
Server Types
Operating Systems
Storage Configuration
Physical[4, 10] RedHat Enterprise Linux 8.0 (beginning with 2.2.18) RedHat Enterprise Linux 9.x (beginning with 2.2.27) RedHat Enterprise Linux 9.x on Power (beginning with 2.2.27) SUSE Linux Enterprise Server 15 SP5, SP6, SP7 [12] SUSE Linux Enterprise Server 16 (beginning with 2.3.0) [12] SUSE Linux Enterprise Server 15 SP7 on IBM Power
Fibre Channel iSCSI SDC
Virtual (VMware)[1, 3, 4] RedHat Enterprise Linux 8.0 (beginning with 2.2.18) RedHat Enterprise Linux 9.x (beginning with 2.2.27) SUSE Linux Enterprise Server 15 SP5, SP6, SP7 [12] SUSE Linux Enterprise Server 16 [12]
Physical RDM backed by Fibre Channel or iSCSI disks attached to ESXi [2] VMDK (dependent and independent disks) on VMFS datastores backed by Fibre Channel or iSCSI disks attached to ESXi iSCSI disks directly attached to guest operating system [2]
×
SAP HANA Requirements — Notes
For supported VMware vSphere versions, see System Requirements: IBM Storage Defender Copy Data Management 2.3.1.
Select the Physical provider type when you register the provider in IBM Storage Defender Copy Data Management. NetApp ONTAP Storage Systems are not supported.
SAP HANA servers registered as virtual need VMware Tools installed.
Supported platforms: Intel based x86, IBM Power Systems on supported Linux platform.
Single tenant configurations can be automatically protected by using storage snapshots.
Only the XFS file system is supported for SAP HANA data and log locations.
On all supported storage systems, snapshot condense is run during every maintenance jobs.
IBM Storage Defender Copy Data Management supports protection and recovery of multi-tenant databases on SAP HANA.
Only non-scale-out SAP HANA configurations are supported.
Supported platforms: IBM Power Systems.
For Dell PowerMax Storage:
Use separate Storage Groups (SG) for different databases for improved performance.
IBM Storage Defender Copy Data Management supports one parent SG, and it can contain different child SG for different databases.
Keep datafiles and log files in separate SG.
When using Parent SG with child SGs, use separate child SGs for data and log.
For Instant Disk Restore, Host on Dell PowerMax array must have at least one Masking View created for itself, even if the host is a part of a hostgroup having active Masking View.
Physical servers listed in table above are not supported.
For Dell PowerFlex Storage:
Ensure that the VMware ESXi hostnames registered in Dell PowerFlex Storage exactly match the hostnames configured on the VMware vSphere environment.
Ensure that the Dell PowerFlex SDC component is installed and running on ESXi hosts where the application VMs are hosted.
RHEL 10, SUSE 16 and SUSE 15 SP07 are currently not supported by Dell PowerFlex SDC driver for version 4.8.x.
Applications that are registered as Physical for Dell PowerFlex need to follow the below steps. Since SDC setup is done as root user binaries like drv_cfg are not accessible for non-root users:
The SAP HANA Client must be installed on your SAP HANA machine.
Create a symbolic link to the SAP HANA Client installation directory through the following command:
ln -s <installation directory of SAP HANA Client> /opt/hana
For example, if SAP HANA Client is installed in /hana/shared/<SID>/hdbclient, you would enter the following:
ln -s /hana/shared/<SID>/hdbclient/ /opt/hana
For SAP HANA, the hdbcli module must be installed. The hdbcli module must be installed only after the complete installation of the SAP HANA client. The module might be extracted from <path to directory>/hdbclient/hdbcli-<version>.tar.gz.
Log backups require that the log backup option is enabled on the SAP HANA system. Additionally, the Universal Destination Directory for log backups must match the directory that is configured on the SAP HANA system when you enable log backups.
Each SAP HANA system has a system ID (SID). It is good practice to have the SID in the path. For example, if /hana/logbackup is the mount point, create these directories:
The bash and sudo packages must be installed. Sudo must be version 1.8.29 or later. Run sudo -V to check the version.
Python version 3.x must be installed. It might be necessary to add your python3 binary file location to the system PATH or to create a symbolic link. For example, if your python3 is installed at /opt/freeware/bin, you need to create a link as follows:
ln -s /opt/freeware/bin/python3 /usr/bin/python3
SLES only: Run the following commands before hdbcli installation:
python3 -m ensurepip
pip3 install hdbcli
Note: The hdbcli module needs to be version 2.17 or later.
RHEL 8.x: Verify the util-linux package is up to date by running:
yum update util-linux
RHEL 8.x or later: A required Perl module, Digest::MD5, is not installed by default. Install the module by running:
yum install perl-Digest-MD5
SLES only: The Python pip package needs to be installed. Follow these steps to install the pip module on SLES:
Linux only: If data stays on LVM volumes, verify that the LVM version is 2.03.02 or later. To check the LVM version and if necessary to update the package, run:
lvm version
yum update lvm2
×
SAP HANA Requirements — Connectivity
The SSH service must be running on port 22 on the server and any firewalls must be configured to allow IBM Storage Defender Copy Data Management to connect to the server by using SSH. The SFTP subsystem for SSH must also be enabled.
The server can be registered by using a DNS name or IP address. DNS names must be resolvable by IBM Storage Defender Copy Data Management.
To mount clones or copies of data, IBM Storage Defender Copy Data Management automatically maps and unmaps LUNs to the servers. Each server must be preconfigured to connect to the relevant Storage Systems at that site.
For Fibre Channel, the appropriate zoning must be configured beforehand.
For iSCSI, the servers must be configured beforehand to discover and log in to the targets on the storage servers.
×
SAP HANA Requirements — Authentication, Registration, and Privileges
Authentication
The application server must be registered in IBM Storage Defender Copy Data Management by using an operating system user that exists on the server (referred to as "IBM Storage Defender Copy Data Management agent user" for the rest of this topic).
During registration, you must provide either a password or a private SSH key that IBM Storage Defender Copy Data Management uses to log in to the server.
For password-based authentication, make sure that the password is correctly configured, and that the user can log in without facing any other prompts, such as prompts to reset the password.
Registration
When you register an SAP HANA provider in IBM Storage Defender Copy Data Management, note the following:
The format for the port number is 3<instance number>15. So, for example, if the instance number is 07, then enter the following port number: 30715.
HANA database user credentials are required to query the database. These credentials are used to log in to the SYSTEMDB and TENANTDB to run restore operations. A "SYSTEM" user or NON-SYSTEM user can be used for database operations. When creating a NON-SYSTEM user specific privilege must be granted to the user, also the username and password must be same in both SYSTEMDB and SXX tenant database.
The NON-SYSTEM database user must have BACKUP ADMIN, CATALOG READ, DATABASE RECOVERY OPERATOR on SYSTEMDB and BACKUP ADMIN, CATALOG READ on the TENANT database (e.g. SXX).
Note: For examples on creating a new user with the necessary privileges, see Sample Configuration in SAP HANA requirements.
Privileges
The IBM Storage Defender Copy Data Management agent user needs the following privileges:
Privileges to run commands as root and other users by using sudo. IBM Storage Defender Copy Data Management requires these privileges for various tasks such as discovering storage layouts and mounting and unmounting disks.
The sudoers configuration must allow the IBM Storage Defender Copy Data Management agent user to run commands without a password.
The !requiretty setting must be set.
For examples on creating a new user with the necessary privileges, see Sample Configuration in SAP HANA requirements.
×
SAP HANA Requirements — Restore and Revert
Restore Jobs
If the xfsprogs package version on the destination server is between 3.2.0 and 4.1.9, the restore process might fail when you restore a database or file system from an XFS file system. To resolve the issue, upgrade xfsprogs to version 4.2.0 or later.
Restriction: The Restore (Instant Disk and Instant Database) operations for SAP HANA are not supported on an alternate host. You need to restore it on the same source host.
Revert Jobs
When you run revert jobs on SAP HANA, there are special considerations that must be met for jobs to successfully complete:
SAP HANA data and the operating system (OS) file system must be on separate datastores (Virtual) and on separate volumes/LUNs (Physical).
Make sure that the databases are on independent storage. The underlying storage volume for the reverted databases must not contain data for other databases. Also, must not contain a datastore that is shared by other virtual machines (VMs) or by other databases not being reverted.
Make sure that the production databases are not on VMDK disks that are part of a VMware VM snapshot.
All VM snapshots need to be removed from the SAP HANA server before you run the revert function.
Production databases are automatically shut down during the revert.
Revert is available only after a restore is completed.
When you create a job, you need to set the default revert action for the job. This behavior is controlled through the Revert Database option during the job creation process:
Enabled – Always revert the database.
Disabled – Never reverts the database.
User Selection – Allows the user to make the determination to revert the database when the job session is pending.
Restriction: The revert function is not supported for HyperSwap environments, see APAR IT42565.
×
SAP HANA Requirements — Sample Configuration
The following commands are examples for creating and configuring an operating system user that IBM Storage Defender Copy Data Management uses to log in to the application server. The command syntax might vary depending on your operating system type and version.
Create the user that is designated as the IBM Storage Defender Copy Data Management agent user:
useradd -m cdmagent
If you use password-based authentication, set a password:
passwd cdmagent
Place the following lines at the end of your sudoers configuration file, typically /etc/sudoers. If the existing sudoers file is configured to import configuration from another directory (for example, /etc/sudoers.d), you can also place the lines in a new file in that directory:
The following commands are examples for creating and configuring a HANA database with minimum privileges to perform query / backup / restore operations. The prompt $> indicates command to execute from UNIX shell prompt and the prompt => indicates the command to execute on hdbsql prompt.
Create required user with a temporary password and grant privileges:
hdbsql SYSTEMDB=> CREATE USER scdm_admin PASSWORD change_on_first_logon_01;
hdbsql SYSTEMDB=> GRANT BACKUP ADMIN, CATALOG READ, DATABASE RECOVERY OPERATOR TO scdm_admin;
Log in to SYSTEMDB with newly created user and change the password:
$> hdbsql -j -i 01 -n localhost -u scdm_admin -p change_on_first_logon_01 -d SYSTEMDB
You have to change your password.
Enter new Password: <ENTER_NEW_PASSWORD_HERE>
Confirm new Password: <ENTER_NEW_PASSWORD_HERE>
Create user with same name in tenant database and grant privileges:
hdbsql S12=> CREATE USER scdm_admin PASSWORD change_on_first_logon_01;
hdbsql S12=> GRANT BACKUP ADMIN, CATALOG READ TO scdm_admin;
Log into the tenant database with newly created user and change the password:
$> hdbsql -j -i 01 -n localhost -u scdm_admin -p change_on_first_logon_01
You have to change your password.
Enter new Password: <ENTER_NEW_PASSWORD_HERE>
Confirm new Password: <ENTER_NEW_PASSWORD_HERE>
Note: The username and password for the database user created in both SYSTEMDB and SXX tenant database must be identical. The privileges for the user differ in the respective databases. The table below lists the privileges.
Supported IBM storages are IBM FlashSystems, IBM SAN Volume Controller.
Warning: Outdated SAN Volume Controller (SVC) firmware might result in a storage-warm start. SVC firmware needs to be updated to the most current supported version to ensure system reliability.
HyperSwap is supported on IBM FlashSystems for both physical and virtual server types for volumes, virtual machines, and applications.
Only Safeguarded Copy is supported on IBM Storage Systems running on IBM Storage Virtualize software version 8.5.1 or later.
IBM Storage Virtualize for Snapshot is supported on IBM Storage Systems running on IBM Storage Virtualize software version 8.5.4 or later.
IBM Storage Defender Copy Data Management supports PBR for IBM Storage FlashSystem version 8.7.0 and later by using IBM Storage Virtualize Snapshot SLA policies.
IBM Storage Defender Copy Data Management supports PBHA 2-site & PBHA 3-site configuration for IBM Storage FlashSystem version 9.1.0 and later by using IBM Storage Virtualize Snapshot SLA policies.
Note: IBM providers must be registered by an IBM user with administrator-level privileges.
×
Db2 Database Requirements — General
IBM Storage Defender Copy Data Management installs an agent on application servers when they are registered. Some anti-virus software might flag or attempt to remove the agent software. If you run anti-malware software on application servers, exclude the installation path of the IBM Storage Defender Copy Data Management agent.
For AIX-based systems, the agent installation directory must be excluded for any anti-virus software scans. Add this path to the exclusion list for all anti-virus software that is installed on the application server:
/tmp/cdm_guestapps_<username>
Where <username> is the username of the account used to register the application server in IBM Storage Defender Copy Data Management.
IBM Storage Defender Copy Data Management support for third-party operating systems, applications, services, and hardware depend on the respective vendor. If a third-party product or version moves into extended support, self-service support, or end-of-life, IBM Storage Defender Copy Data Management supports the product or version at the same level as the vendor. See also IBM Support General Guidelines and Limitations — IBM support for software on unsupported operating systems.
Server Types
Operating Systems
Storage Configuration
Physical
AIX 7.2 (beginning with 2.3.1)
AIX 7.3 (Version: 7300-04-00)
Fibre Channel
Notes
With CDM 2.3.1 release, Db2 database standalone configurations are supported only.
Cluster Db2 solutions are not supported.
Virtual mode of configuration/registration is not supported for Db2.
Only snapshots of the storage provider type 'IBM Storage Virtualize for Snapshot' are supported.
Db2 archive log mode is not supported. It is recommended to configure Db2 in no archive log mode at present.
Instant database restore for Db2 is not supported for this release.
PIT restore is not supported.
Database Revert is not supported for Db2.
Replication mode is not supported. It includes policy-based replication.
×
Db2 Database Requirements — Connectivity
The SSH service must be running on port 22 on the server and any firewalls must be configured to allow IBM Storage Defender Copy Data Management to connect to the server by using SSH. The SFTP subsystem for SSH must also be enabled.
The server can be registered by using a DNS name or IP address. DNS names must be resolvable by IBM Storage Defender Copy Data Management.
To mount clones or copies of data, IBM Storage Defender Copy Data Management automatically maps and un-maps LUNs to the servers. Each server must be preconfigured to connect to the relevant Storage Systems at that site.
For Fibre Channel, the appropriate zoning must be configured beforehand.
×
Db2 Database Requirements — Prerequisites
On DB2 Server
1. DB2 Installation
DB2 must be installed and configured.
DB2 instance(s) must be created.
DB2 instance must be started before discovery/backup operations.
Start DB2 instance.
Verify instance is running:
sudo -u db2inst1 db2 get instance
2. Environment Variables
The DB2DIR environment variable must be set (e.g., /opt/ibm/db2/V12.1), where V12.1 is the DB2 version.
The DB2DIR environment variable should point to the DB2 installation directory. For DB2 12.1, set it as follows and add to the system-wide profile:
db2 command must be in PATH or accessible via instance profile.
db2ilist command must be available for instance discovery.
Database manager must be started (see requirement 1 above).
6. File System Permissions
Read access to DB2 instance home directories (e.g., /home/db2inst1).
Read access to DB2 configuration files.
Read access to database storage paths.
×
Instant Disk Restore — Db2 Clone Runbook
Overview
This runbook describes the end-to-end automation steps required to clone a Db2 database from an instant disk snapshot mount point. This process isolates the clone so it can run alongside an existing live database on the same instance without causing conflicts or data corruption.
Architectural Rules & Assumptions
Rule
Detail
Database Instance User
db2inst1 (Modify according to your specific environment)
Db2 Naming Limit
The target database clone name must not exceed 8 characters (e.g., PRODCLN)
Transaction Log Isolation
Transaction logs are explicitly rerouted to an isolated local directory (/tmp/PRODCLN) to completely prevent overwriting or locking production log footprints
Catalog Protection
If the source database already exists on the target instance, the relocation utility will temporarily overwrite its registry entry. This runbook includes immediate safety steps to restore the original catalog pointer
Part 1: Provisioning & Initialization
Step 0: Verify Storage Mount Availability
Ensure the instant disk restore job has been successfully executed from your storage copy management software and that the snapshot is presented to the target server.
Log in to the server as root (or use sudo). Establish the isolated transaction log landing path and physically align the data directories to match our new 8-character database name.
# 1. Create the isolated transaction log path and apply rigid instance ownership
mkdir -p /tmp/PRODCLN
chown -R db2inst1:db2iadm1 /tmp/PRODCLN
chmod -R 770 /tmp/PRODCLN
# 2. Rename the snapshot physical database folder to match the new target name
mv /data_1779858852006/db2inst1/NODE0000/PRODDB /data_1779858852006/db2inst1/NODE0000/PRODCLN
Step 2: Generate the Db2 Relocation Configuration File
Create the mapping configuration file used by the relocation engine to perform low-level binary data path alterations.
Because the storage clone was carved out of a live, running snapshot, it remains flagged in an unbuffered "crash" state. Run crash recovery while simultaneously lifting the snapshot write-lock flag.
# 1. Flush the database backend registry one more time
db2 terminate
# 2. Re-initialize the engine internals, roll back uncommitted work, and resume writes
db2 "RESTART DATABASE PRODCLN WRITE RESUME"
Part 3: Validation & Cleanup
Step 5: Verification Routine
# 1. Attempt connection to the clone
db2 connect to PRODCLN
# 2. Verify that the active transaction logs are running out of the isolated /tmp directory
db2 get db cfg for PRODCLN | grep -i "Path to log files"
# 3. Test catalog queries to confirm physical stability
db2 list tables
Part 4: Decommissioning & Cleanup Procedures
Step 1: Drop Database Registries (Instance Level)
As the db2inst1 user:
# 1. Terminate any stray or hanging connection handles to the clone
db2 "FORCE APPLICATION ALL"
db2 terminate
# 2. Deactivate the clone to purge active bufferpools from RAM
db2 "DEACTIVATE DATABASE PRODCLN"
# 3. Drop the database from the local instance filesystem and uncatalog it
Step 2: Clear Ephemeral Logs and Storage Mounts (OS Level)
Switch to the root account or use sudo to release the physical server footprints:
# 1. Purge the isolated log files from the /tmp directory structure
rm -rf /tmp/PRODCLN
# 2. Remove the empty directory mount point anchor
rmdir /data_1779858852006
Step 3: Storage UI Confirmation
Return to your Copy Data Management (CDM) user interface. Formally terminate the Instant Disk Restore session to tear down the virtual storage allocation and release SAN/NAS resources.
×
Dell PowerFlex — Note
Note: Due to a known limitation in PowerFlex Manager version 4.6.x and 4.8.x, the standard user account with storage admin privileges is insufficient for performing remote snapshot operations. As a workaround, user must be granted super-user privileges.
×
VMware — More Info
Make sure that the most current version of VMware Tools is installed in your environment.
Note: Beginning with IBM Spectrum Copy Data Management 2.2.18, VMware VDDK 7.0 is included. This VDDK level does not support vSphere 6.0. See APAR IT42544.