PowerProtect Data Manager: NAS Protection Engine Data Path and MULTI-LAN Configuration
Summary: This article explains the network traffic flow in PowerProtect Data Manager (PPDM) NAS Protection Engine and provides guidance for multi-LAN configuration to segregate management and data traffic. ...
Symptoms
Data traffic flow in NAS Protection Engine
The NAS Protection Engine uses two primary data paths during backup operations:
- NAS to Protection Engine: The Protection Engine mounts the source share from the NAS array.
- Protection Engine to Data Domain: The File System Agent (FSA) moves data slices to PowerProtect Data.
There is no direct communication between the NAS array and the Data Domain. The Protection Engine acts as the data mover and orchestrates the entire backup operation.
NAS backup workflow
The PPDM NAS backup process follows these steps:
- The NAS Protection Engine mounts the source share from the NAS array.
- The NAS agent creates a snapshot and uses the slicer to create data slices.
- The File System Agent moves the data slices in parallel to the PowerProtect Data Domain.
- The NASDM microservice initiates indexing when the backup completes.
Multi-LAN configuration benefits
When multiple network interfaces are configured on the NAS Protection Engine, traffic types can be segregated:
- Management traffic: PPDM server to Protection Engine for control and orchestration.
- Data traffic: Separate paths for NAS array to Protection Engine and Protection Engine to Data Domain.
This segregation enables better performance optimization and traffic isolation.
Multi-VLAN support
PPDM supports multi-VLAN configuration from version 19.13.
This feature allows configuration of:
- Configure separate networks for management and data transfer operations.
- Select VLAN configuration between the storage array and the proxy for share mounting.
- Configure dedicated VLANs for Protection Engine to Data Domain communication.
- Configure different VLANs for Protection Engine to NAS appliance communication.
Cause
VLAN configuration levels
VLAN configuration can be applied at three levels:
- Asset source level: Configure network settings for all assets under a source.
- Asset level: Assign network interface to individual assets (higher precedence than asset source).
- Policy level: Assign network interface to all assets in a protection policy.
Network types
PPDM uses three network types:
- Data: For data transfer operations.
- Management: For control and orchestration communications.
- Data for Management Components: When a network is added with this option, configure the search engine with the new VLAN.
Performance recommendations
For optimal performance, the following guidelines apply:
- Use a dedicated 10 GbE network interface per NAS Protection Engine.
- Multiple Protection Engines with dedicated 10 GbE networks achieve better aggregated throughput.
- If the entire environment uses 10 GbE networks, the overall throughput is bound by 10 GbE speed.
- If read throughput from the NAS array and write throughput to the Data Domain cause bottlenecks, add more network ports to the NAS array and Data Domain.
Configuration considerations
Important factors must be considered when configuring multi-LAN:
- When a network or VLAN is assigned at an asset, data communication always occurs between the Protection Engine and the Data Domain.
- There is no mechanism to specify the network or VLAN for Protection Engine to array communication.
- Protection Engine to NAS array communication occurs over network interfaces discovered as part of the NAS server.
- If share mounting fails, the system retries mounting over other network interfaces.
- Existing Protection Engines cannot be configured with new VLANs; create new Protection Engines with the newly added VLANs.
- When the Data for Management Components option is used, configure search nodes for the new VLANs.
Resolution
Data traffic in PPDM NAS Protection Engine refers to both the NAS to Protection Engine and Protection Engine to Data Domain communication paths. There is no direct NAS to Data Domain data path. The Protection Engine serves as the intermediary data mover, which enables performance optimization, traffic isolation, and network management capabilities when properly configured with multiple network interfaces and VLANs.