Create an AWS recovery target for Active Directory forest recovery to recover domain controllers to an AWS account.
Start the Add Amazon Target wizard
-
From the Command Center navigation pane, go to Protect > Active Directory.
The Overview page appears.
-
Click the Forests tab, and then click the forest.
The forest page appears.
-
Click the Runbook tab, and then click the runbook.
The runbook page appears.
-
Click the Runbook settings tab, and then click View recovery targets.
The Recovery targets dialog box appears.
-
Click Add recovery target.
The Select target dialog box appears.
-
Select Amazon Web Services.
-
Click Select Target.
The Add Amazon Target wizard appears.
Configure the General settings
-
Enter a name for the recovery target.
-
To register a new AWS account, beside Destination, click Add.
The Add hypervisor dialog box appears.
-
Download the Active Directory Forest access node package.
-
Install the access node package on the server to use as the access node.
Important access node requirements
-
Deploy the access node as a VM in the AWS EC2 region that the domain controllers will be restored to.
-
When you install the access node package, select a drive with 10 GB or more of free disk space.
-
For adequate restore performance, configure the access node with 16 GB or more of memory.
-
-
Wait for the installation to complete successfully.
-
In the Add hypervisor dialog box, refresh the Access nodes list, and then select the host that you installed the access node package on.
-
Enter a name for the hypervisor.
-
Under Advanced options, select AWS STS AssumeRole.
-
For Credential, select existing credentials or add new credentials.
Steps to add new credentials
AWS STS AssumeRole is the recommended credential method. Follow the steps to create the
CommvaultAdminRolein your AWS account.-
From the Command Center navigation pane, go to Protect > Virtual machines.
The Overview page appears.
-
Click Add hypervisor.
The Configure hypervisor page appears.
-
Select Amazon Web Services, and then click Next.
The Configure Amazon Web Services Account wizard appears.
-
Select the Use your access nodes for backups option.
-
For Authentication method, select AWS STS AssumeRole (recommended).
-
Under Launch CloudFormation Template, click Copy Link.
-
Paste the link into a new browser window.
Some steps are completed in the AWS CloudFormation portal and might change. The Quick create stack page appears.
-
Review the stack settings, select the I acknowledge that AWS CloudFormation might create IAM resources with custom names option, and then click Create stack.
-
Go to the
CommvaultAdminRolerole that you created. -
From the Add permissions menu, select Attach policies.
-
Select the
AmazonS3FullAccessandAmazonSSMManagedInstanceCorepolicies, and then click Add permissions. -
Copy the full ARN value for the role.
Example:
arn:aws:iam:[tenant_id]:role/Commvault/CommvaultAdminRole -
Return to the Add hypervisor dialog box, and then do the following:
-
For Account type, select Cloud Account.
-
For Vendor type, select Amazon Web Services.
-
Enter a name for the credential.
-
Under ARN, paste the ARN value that you copied from the AWS portal.
-
Click Save.
Note
The IAM role that you create in the AWS account must be assigned to the EC2 instance that the access node runs on.
-
-
In the Add hypervisor dialog box, click Save.
-
For Destination, select the AWS recovery target that you created.
-
For Access node, select the server that you installed the access node package on.
-
For Security, select the roles that need access to the AWS recovery target.
-
Click Next.
Configure Destination options
-
For Availability zone, select the availability zone that the access node belongs to.
-
For Instance type, select an instance type with at least 16 GB of RAM.
Example:
t3.large -
For IAM role for Amazon EC2, select the IAM role that you created earlier.
-
For Network, expand the virtual network, and then select New Network Interface.
-
Click Next.
Configure Repave options
On this page, you can specify a clean image to use for restored domain controllers. If you do not specify an image, a Commvault-hosted image is used.
To specify your own Windows Server image, follow these steps:
- To add your VM template, click Add.
The Custom image page appears.
-
For Operating system, select Windows.
-
Select an image from the Amazon Machine Image (AMI) list.
-
Click Save.
If you specify your own image, follow these steps to specify a software cache:
-
For OS Type, select Windows.
-
Under Software cache, select the server where the software cache is configured.
-
Click Next.
Recommended location for the software cache
Place the software cache on the access node that has connectivity to your recovered domain controllers.
Steps to configure a new software cache
-
From the Command Center navigation pane, go to Explore > Companies.
-
Click the Software caches tab, and then click Add to create a software cache and specify the server and details to host the cache.
-
After creating the software cache, from the actions list, select Sync to ensure that the cache is up to date.
Configure Advanced options
-
To specify a server group, enable the Enable association to a server group toggle key.
-
For Associate destination server to this server group, select the server group to associate recovered domain controllers with.