<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Create custom Role for Veeam backup integration in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Create-custom-Role-for-Veeam-backup-integration/m-p/442804#M41969</link>
    <description>&lt;P&gt;I want to backup my SMB/CIFS share on my FAS2750.&lt;/P&gt;&lt;P&gt;Need to add the filer as a storage object in Veeam 11.&lt;/P&gt;&lt;P&gt;Authentication fails when adding the filer into Veeam using a local user assigned the built in NetApp role called "backup".&lt;/P&gt;&lt;P&gt;I can successfully add the filer into Veeam if I specify the filer admin account. I don't want to use the admin account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a support case with Veeam and they said I need to specify additional permissions per this guide.&lt;/P&gt;&lt;P&gt;&lt;A href="https://helpcenter.veeam.com/archive/backup/110/vsphere/required_permissions.html#netapp-data-ontap-lenovo-thinksystem-dm-permissions" target="_blank" rel="noopener"&gt;https://helpcenter.veeam.com/archive/backup/110/vsphere/required_permissions.html#netapp-data-ontap-lenovo-thinksystem-dm-permissions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The section titled&lt;STRONG&gt; CDOT&lt;/STRONG&gt; &lt;STRONG&gt;(NAS Backup Integration)&lt;/STRONG&gt;&amp;nbsp;The specified permissions are not found in OnTap 9.12.1&lt;/P&gt;&lt;P&gt;For example need to grant &lt;STRONG&gt;DEFAULT&lt;/STRONG&gt; the "readonly" permission.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TroyPayne_0-1679947200995.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/25397i79C14AFD497B1ACF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TroyPayne_0-1679947200995.png" alt="TroyPayne_0-1679947200995.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DEFAULT is not available. Merely a long list of /api/blahblahblah&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TroyPayne_1-1679947287451.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/25398i995769E3ED46E918/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TroyPayne_1-1679947287451.png" alt="TroyPayne_1-1679947287451.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yet there it is. Plain as day on the admin role.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TroyPayne_2-1679947381430.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/25399iAE42C005704D8F8F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TroyPayne_2-1679947381430.png" alt="TroyPayne_2-1679947381430.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I missing?&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 09:51:23 GMT</pubDate>
    <dc:creator>TroyPayne</dc:creator>
    <dc:date>2025-06-04T09:51:23Z</dc:date>
    <item>
      <title>Create custom Role for Veeam backup integration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Create-custom-Role-for-Veeam-backup-integration/m-p/442804#M41969</link>
      <description>&lt;P&gt;I want to backup my SMB/CIFS share on my FAS2750.&lt;/P&gt;&lt;P&gt;Need to add the filer as a storage object in Veeam 11.&lt;/P&gt;&lt;P&gt;Authentication fails when adding the filer into Veeam using a local user assigned the built in NetApp role called "backup".&lt;/P&gt;&lt;P&gt;I can successfully add the filer into Veeam if I specify the filer admin account. I don't want to use the admin account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a support case with Veeam and they said I need to specify additional permissions per this guide.&lt;/P&gt;&lt;P&gt;&lt;A href="https://helpcenter.veeam.com/archive/backup/110/vsphere/required_permissions.html#netapp-data-ontap-lenovo-thinksystem-dm-permissions" target="_blank" rel="noopener"&gt;https://helpcenter.veeam.com/archive/backup/110/vsphere/required_permissions.html#netapp-data-ontap-lenovo-thinksystem-dm-permissions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The section titled&lt;STRONG&gt; CDOT&lt;/STRONG&gt; &lt;STRONG&gt;(NAS Backup Integration)&lt;/STRONG&gt;&amp;nbsp;The specified permissions are not found in OnTap 9.12.1&lt;/P&gt;&lt;P&gt;For example need to grant &lt;STRONG&gt;DEFAULT&lt;/STRONG&gt; the "readonly" permission.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TroyPayne_0-1679947200995.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/25397i79C14AFD497B1ACF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TroyPayne_0-1679947200995.png" alt="TroyPayne_0-1679947200995.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DEFAULT is not available. Merely a long list of /api/blahblahblah&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TroyPayne_1-1679947287451.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/25398i995769E3ED46E918/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TroyPayne_1-1679947287451.png" alt="TroyPayne_1-1679947287451.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yet there it is. Plain as day on the admin role.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TroyPayne_2-1679947381430.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/25399iAE42C005704D8F8F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TroyPayne_2-1679947381430.png" alt="TroyPayne_2-1679947381430.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I missing?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:51:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Create-custom-Role-for-Veeam-backup-integration/m-p/442804#M41969</guid>
      <dc:creator>TroyPayne</dc:creator>
      <dc:date>2025-06-04T09:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Create custom Role for Veeam backup integration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Create-custom-Role-for-Veeam-backup-integration/m-p/442811#M41970</link>
      <description>&lt;P&gt;I guess by default, pre-defined (built-role) role such as "backup" is set to NONE for DEFAULT command/directory and cannot be modified. However, you can create a custom role and assign it to the user as necessary.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example- According to the "section titled CDOT (NAS Backup Integration) for Veeam you shared", it requires following capabilities.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create a custom role:&lt;BR /&gt;::&amp;gt; security login role create -role backup_veeam -cmddirname DEFAULT -access readonly -query ""&lt;BR /&gt;::&amp;gt;security login role create -role backup_veeam -cmddirname security -access readonly -query ""&lt;BR /&gt;::&amp;gt;security login role create -role backup_veeam -cmddirname "security login" -access readonly -query ""&lt;BR /&gt;::&amp;gt; security login role create -role backup_veeam -cmddirname "volume snapshot" -access all -query ""&lt;BR /&gt;::&amp;gt; security login role create -role backup_veeam -cmddirname vserver -access all -query ""&lt;BR /&gt;::&amp;gt; security login role create -role backup_veeam -cmddirname "vserver nfs" -access all -query ""&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;You can verify added capabilities:&lt;BR /&gt;::&amp;gt; security login role show -role backup_veeam&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create a user or assign the existing user the above role:&lt;BR /&gt;::&amp;gt; security login create -user-or-group-name netapp_veeam -application ontapi -role backup_veeam -authmethod &amp;lt;password/doman&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know if this will help resolve it, but give it a try.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Definitions:&lt;/P&gt;&lt;P&gt;Command directory = Refers to a directory in the CLI.&lt;BR /&gt;Role = Refers to a collection of capabilities or privileges.&lt;BR /&gt;Access control = The capability is specified as an ‘access control’ on a ‘command directory’ or a ‘command’.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Related:&lt;BR /&gt;What is this DEFAULT rule and why is it getting created?&lt;BR /&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/FAQ%3A__Custom_roles_for_administration_of_ONTAP#What_is_this_DEFAULT_rule_and_why_is_it_getting_created.3F" target="_blank" rel="noopener"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/FAQ%3A__Custom_roles_for_administration_of_ONTAP#What_is_this_DEFAULT_rule_and_why_is_it_getting_created.3F&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 22:58:00 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Create-custom-Role-for-Veeam-backup-integration/m-p/442811#M41970</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-03-27T22:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Create custom Role for Veeam backup integration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Create-custom-Role-for-Veeam-backup-integration/m-p/442818#M41973</link>
      <description>&lt;P&gt;Amazing!&lt;/P&gt;&lt;P&gt;Thank you very much &lt;STRONG&gt;Ontapforrum&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Your explanation makes perfect sense.&lt;/P&gt;&lt;P&gt;The commands provided worked like a charm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So refreshing to get a straight, accurate answer.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 16:04:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Create-custom-Role-for-Veeam-backup-integration/m-p/442818#M41973</guid>
      <dc:creator>TroyPayne</dc:creator>
      <dc:date>2023-03-28T16:04:14Z</dc:date>
    </item>
  </channel>
</rss>

