NSX Manager SFTP Backup

During my last couple of NSX projects the backup of the NSX Manager proved to be some kind of a challenge. Using the NSX manager, it is possible to create backups via the FTP or the SFTP transfer protocol, but because we wanted to adhere the NSX hardening recommendations SFTP is preferred transfer protocol. No biggie you would think, except that most of the customers did not possessed the proper SFTP (don’t confuse with FTPS!!) software to support this.

Why is it so important to create a proper backup of the NSX Manager? Well that’s because the backup contains the following components :

  • NSX configuration
  • NSX Controllers configuration
  • Logical switches configuration
  • Routing configuration
  • Security groups, policies and settings
  • All firewall rules
  • And simply everything else that you configure within the NSX Manager UI or API
  •  
    I think you now understand why you want to have these settings safely stored away.

    So what are our options? On SFTP.net the authors created a list of stand-alone SFTP servers that can be used for this task. For some customers it is difficult to procure these types of software online and rather use “freeware”. Then the next problem arises, some companies won’t use encryption software if it’s not commercial… Yeah I love those discussion with the security guys 🙂 .

    OK so just for the sake of it (and I’m not bound by any security guys looking over my shoulders) I’m just going for the NSX Manager SFTP Backup based on FreeFTPd for Windows.

     

    FreeFTPd

    Download the FreeFTPd software and run the installer :

    NSX Manager SFTP Backup

    Select a path for the installation :

    NSX-Backup-02

    Select “Full Installation” (funny enough there is no other option than this) :

    NSX-Backup-03

    Select the Start folder :

    NSX-Backup-04

    Deselect the “Create a desktop icon” if you don’t want a cluttered desktop :

    NSX-Backup-05

    Review your settings and select “Install” :

    NSX-Backup-06

    Select “Yes” if you want to generate the private keys automaticly :

    NSX-Backup-07

    And select “Yes” if you want to install FreeFTPd as a service :

    NSX-Backup-08

    Select “Finish” to close the installer.

    NSX-Backup-09

    NOTE: Be absolutely sure to run the FreeFTPd configuration utility as a Administrator (right click “Run as an Administrator”) and have the FreeFTPd service stopped! Otherwise your settings won’t work and the SFTP service won’t be started!

    NSX-Backup-10

    In the configuration utility select “Users” and select “Add” :

    NSX-Backup-13

    Select “Password stored as SHA1 hash” at the “Authorization” field and fill in all the fields and configure a strong password (so no Welcome123!) and select “Apply” :

    NSX-Backup-14

    Quit the FreeFTPd configuration utility (also the one running in your systray!), go the Services Management Console start the FreeFTPd service.

    NSX-Backup-12

    Check if the service is running by using the following command line :

    It should return something like this :

    &nsbp;

    NSX Manager SFTP Backup

    The configuration of the NSX Manager Backup is quite easy so I’m going though it quite rapidly :

    Open the NSX Manager and select “Backup & Restore” and select “Change” beside FTP Server Settings :

    NSX-Backup-15

    Fill in the fields according to your configuration, don’t forget to set the “Transfer Protocol” to SFTP, and select “OK” :

    NSX-Backup-16

    Select “Change” beside “Scheduling” and fill in the settings :

    NSX-Backup-17

    If necessary to exclude object from the backup select “Change” beside “Scheduling” and select the object to exclude from the backup :

    NSX-Backup-18

    Select “Backup” and “Start” to test the backup :

    NSX-Backup-19

    If successful it will look like this in the NSX Manager :

    NSX-Backup-20

    And like this in the specified backup directory :

    NSX-Backup-21

    Backup files rotation

    Somehow there is no backup file rotation build in the NSX Manager!?! So if you’re not careful the backup directory can grow quite rapidly and fill up your disk.
    That is why I use a simple script that runs on a task schedule and removes the backup files older than the configured days.

    Change the number 5 in the script above to your own retention specification and NSXBACKUPDIRECTORY to your own NSX Manager Backup directory.

    PS. And of course don’t forget to backup your server where the SFTP server runs on!

    Marco van Baggum

    Marco van Baggum

    Works as a Virtualization Consultant for ITQ. More details can be found on the About page

    Leave a Reply

    Your email address will not be published. Required fields are marked *