The following sections provide context-sensitive help information related to this feature.
General
Use this dialog box to create a new client group or to add and remove clients from the selected group.
Group Name
From Properties, displays the name of the selected client group. From New Group command, specify the name of the group being created.
Description
Enter a description about the client computer group. Choose either TEXT or HTML:
- 
To enter information about the group using text format, click TEXT and then type the information. Text is the default description type. Using text, you can enter more information in the Description box, and it is easier to export client descriptions to other formats such as Microsoft Excel. 
- 
To enter information about the group using HTML format, click HTML and then type the information. Click Insert to add hyperlinks, images, and tables. Click Format to format your text. To work directly with HTML tags, click the lower HTML tab. 
Manual Association
Use this option to manually add client computers to the group.
- 
All clients Displays the clients available within this CommServe. 
- 
Clients in this group Displays clients selected for inclusion in this group. 
Automatic Association
Use this option to automatically add existing or new client computers to a client computer group.
- Client Scope
If you select Clients of User, then the user defined in the scope, must have the following permissions:
- 
The Agent Management permission on the client computers that will be automatically added to the Smart client computer group. 
- 
If the user does not have permission on a client computer, the client computer is not added to the Smart client computer group even if it meets the criteria defined in the rules. For the permissions needed to add client computers to or remove client computers from a client computer group, see User Security Permissions and Permitted Actions by Feature. Rule Group Displays the list of rules used to create a client computer group that adds clients through automatic associations. For descriptions of the available rules, see Rules Available for Smart Client Computer Groups. - 
Match x of the following rule group (Available if multiple rule groups exist) Defines the relationship between multiple rule groups. Valid values are all and any. Use the Add Rule Group button to create a rule group. 
- 
Match x of the following rules (Available if multiple rules exist) Defines the relationship between multiple rules. Valid values are all, any, and not any. Click add new rule  to create a new rule. to create a new rule.
 Operators: This is not a comprehensive list. The operators change as per the selected rules. For example: When you select Client Name, then the following operators appear for selection: - 
Contains This operator searches for a character, string, word or phrase in the client name or operating system name and list those client computers. 
- 
Does Not Contain This operator searches for a character, string, word or phrase in the client name or operating system name, and inverts the result of the comparison. 
- 
Is This operator is used in exact string comparisons with pattern matching. 
- 
Is Not This operator inverts the result of a string comparisons with pattern matching. 
- 
Starts With This operator is used in character, string comparisons with pattern matching. 
- 
Ends With This operator is used in character, string comparisons with pattern matching. 
 Values: The values you can use in the rule change depending on the matching option you chose from the first column. For example, if you chose Client, you can choose types of clients from the values list. 
- 
- 
Preview Displays the client computer groups that will be added to the folder based on the rules that you defined. 
Advanced Settings
Use this dialog box to set up additional advanced settings for the client computer group.
Database Agent Authentication
The options below allow you to provide a valid user account to access the SQL Server to perform all operations, such as backup and restore.
- 
Override Higher Levels Settings Select to override the account settings configured at the Control Panel and Client Group levels for the selected SQL iDataAgent. 
- 
Use Local System Account The Windows account configured to run the Communications Service (GxCVD) service and which is used by the system to perform all operations, including backup, restore and browse. By default, this is the Local System Account. 
- 
Impersonate User Select to enter a user name and password for the Windows User Account that has permission to perform all operations, including backup, restore and browse. The account must already be set up on the client and must have Local administrator privileges and be a member of the SQL sysadmin fixed server role for the instance. 
- 
User Name Use this space to type the name of the Windows user account that will have permission to execute the desired commands. 
- 
Password Use this space to type the corresponding password for the account. 
Web Server
Displays the Web Server computers that you can associate to the client computer group. Search operations of content indexed data will be processed by the selected Web Server.
Enable CvAccounts SSO Login
Use this option to setup single sign-on (SSO) between Web Consoles in the client computer group.
- 
CvAccounts SSO Login URL Use this option to define the Web Console that is the identity provider (IdP). When you access Web Consoles that are part of the single sign-on (SSO) client group and you are not logged on, you are redirected to the IdP Web Console to log on. After you log on, you are returned to the Web Console you first accessed, and you can access any Web Console that is part of the SSO client group without logging on again. 
Key Performance Indicators (KPIs)
This section allows you to configure options for reports.
SLA
These options allow you to configure the time range for the SLA (Service Level Agreement) percentage that appears in dashboards and reports. The formula used to calculate SLA is: Number of Clients that Met SLA / Total Number of Clients. A client meets SLA when all of its subclients and databases are protected by at least one successful full, incremental, differential, or log backup job during the specified time range. A client misses SLA when there are no successful jobs run during the specified time range.
- 
Use CommCell level settings Allows you to specify that the CommCell level setting will be used. This is the default setting. 
- 
SLA for last N Days Allows you to specify the time range for calculating SLA for the clients in this client group. 
- 
Exclude from SLA Allows you to exclude all of the clients in this client group from SLA calculations in dashboards and reports. 
Copy Redundancy
Allows you to specify the minimum number of copies required to meet the copy redundancy SLA that is calculated in the Copy Redundancy SLA Report.
Maximum Allowed Auxiliary Copy Fallen Behind
The maximum time interval that auxiliary copy can fall behind before it goes into Warning/Critical status in the Fallen Behind Secondary Copies tile in the Health Report.
Recovery Point Objective (RPO)
Enter the number of days, hours, and minutes that make up the RPO. The RPO is the maximum number of hours that data can be lost during a service disruption. These settings will be used to calculate the data that appears in the Recovery Point and Time Report.
Recovery Time Objective (RTO)
Enter the number of days, hours, and minutes that make up the RTO. The RTO is the maximum amount of time allowed to restore after a service disruption. These settings will be used to calculate the data that appears in the Recovery Point and Time Report.
Quota Limit
Set a quota in gigabytes to limit the size of data that is backed up for a client computer group. When the quota is exceeded, backup jobs are placed in a waiting state and are tagged with an error code and error description: Client group capacity quota is exceeded.
Download software from Internet
Allows software updates to be downloaded from the internet (that is, from Akamai), instead of from the CommServe computer or remote cache.
Note
- 
If a download from the internet fails, the client will download the software from the CommServe computer or remote cache on the next attempt. 
- 
This setting is overridden by the Client can download the software from internet setting at the client level. For more information, see Client Computer Online Help - Version. 
Activity Control
Data Management and Recovery Activity
Use this section to enable or disable data management and data recovery operations on selected client computer group.
- 
Enable Backup Specifies whether Backups will occur from this client computer group. 
- 
Enable Restore Specifies whether Restores will occur from this client computer group. 
Administration Activity
Use this section to enable or disable data aging operations on selected client computer group.
- 
Enable Data Aging When selected, data aging operations are allowed on the Client or Client Group. When cleared, data aging operations are skipped on a client or client group, and: - The Enable after a Delay button is displayed next to this operation activity. Use the button to specify the date and time when data-aging operations on a client or client group can begin on the CommCell.
 
Allow Jobs to Run Past Operation Window
The option to allow running jobs to continue to run when the operation window starts. Without this option, running jobs are put in a "waiting" state when the operation window starts. For information on operations windows, see Operation Window Overview.
Network Route Configuration
Use this dialog box to configure network route settings for the selected CommCell entity, which can be a CommServe, MediaAgent, client computer or client group.
Configure Network Route Settings
Select this option to configure network route settings on the client or client group that you selected.
If you configure network routes on a client group, all the clients that are associated with the client group will inherit the configurations that you set on the group. The clients that are part of the client group will display a note indicating that network route settings are inherited from the client group.
Remember: If a client is inheriting the network route settings from a client group, you do not need to select the Configure Network Route Settings check box. However, you can select the option if you want to configure additional (or different) network route settings on the client.
Use the following options to establish connectivity to and from CommCell entities separated by network routes or tunnels.
Note
By default, the network route properties at the CommCell level only display the Advanced options.
Basic
Select this option to quickly configure direct tunnel connection or proxy connection between the selected CommCell component and the CommServe or MediaAgent.
Use the following tabs to specify the type of network route configuration:
Advanced
Select this option to configure any type of connection route between the CommCell components (entities) to establish connectivity across the network.
Use the following tabs to provide the network route configuration details:
CommServe Connectivity
Visible when Configure Network Route Settings is set to Basic. Use this tab to select the type of network configuration between the selected CommCell component and the CommServe.
This Computer is
Specifies whether this computer is in the same network as the CommServe.
- 
Always in the same network as CommServe Click to specify that this computer connects directly to the CommServe (no network routes between them). CommCell services of this computer and the CommServe can directly communicate. 
- 
Always outside of CommServe network Click to specify that this computer will always connect to the CommServe from a remote site. This option allows you to configure direct tunnel connections and proxy connections. 
- 
May travel outside of CommServe network Click to specify that this computer will occasionally connect to the CommServe from a remote site. This option is recommended for laptops and other mobile devices that routinely move in and out of the network. Note When connecting to the CommServe, this option will first attempt to establish a direct connection (same CommServe network scenario). If it fails, the direct tunnel connection or proxy will be used. 
When connecting from outside
Available when This Computer is is set to Always outside of CommServe network or May travel outside of CommServe network. Sets the type of configuration that this computer will use to connect to the CommServe.
- 
Open tunnel directly to CommServe Click to enable this computer to connect to the CommServe through a direct tunnel connection. By default, the CommServe will use port 8403 to receive connections from the computer. 
- 
Use remote proxy Click to enable this computer to connect to the CommServe using a proxy. 
MediaAgent Connectivity
Visible when Configure Network Route Settings is set to Basic. Use this tab to select the type of network route configuration between the selected CommCell component and its associated MediaAgent.
This Computer is
Indicates whether this computer is in the same network as the MediaAgent.
- 
Always in the same network as MediaAgent Click to specify that this computer connects directly to the MediaAgent (no network routes between them). CommCell services of this computer and the MediaAgent can directly communicate. 
- 
Always outside of MediaAgent network Click to specify that this computer will always connect to the MediaAgent from a remote site. This option allows you to configure direct tunnel connections and proxy connections. 
- 
May travel outside of MediaAgent network Click to specify that this computer can connect to the MediaAgent from a remote site. This option is recommended for laptops and other mobile devices that routinely move in and out of the network. Note When connecting to the MediaAgent, this option will first attempt to establish a direct connection (same CommServe network scenario). If it fails, the direct tunnel connection or proxy will be used. 
When connecting from outside
Available when This Computer is is set to Always outside of MediaAgent network or May travel outside of MediaAgent network. Indicates the type of network route configuration that this computer will use to connect to the MediaAgent.
- 
Open tunnel directly to MediaAgent Click to enable this computer to connect to the MediaAgent through a direct tunnel connection. 
- 
Use remote proxy Click to enable this computer to connect to the MediaAgent using a proxy. 
Incoming Connections
Visible when Configure Network Route Settings is set to Advanced. Use this tab to add or modify the connection status of remote clients or client groups that cannot open direct connections to this CommCell component.
Entity
Displays the list of clients or client groups (entities) that cannot open direct connections or can open connections only on restricted ports to this CommCell component (see Restricting or Blocking Connections).
State
Indicates the type of connection from the client or client group.
Actions
- 
Add Click Add to add a client or client group. This opens the Connections to dialog box. 
- 
Edit Select a client or client group, then click Edit to change the details. 
- 
Delete Select a client or client group, then click Delete to remove it from the list. 
Incoming Ports
Visible when Configure Network Route Settings is set to Advanced. Use this tab to specify the port numbers for incoming communication. Network TCP Port Requirements provides a list of incoming ports.
Tunnel HTTP/HTTPS Port
- 
Override default tunnel port The port for incoming tunnel connections. The default port is the Commvault Communications (CVD) service port plus 3, for example, 8403. 
Additional Open Ports
- 
Additional incoming ports may be open for faster data transport Specify additional ports or a range of ports that are open for incoming connections to facilitate faster data transport. 
- 
From The starting number in the range of ports that are open. 
- 
To The ending number in the range of ports that are open. 
- 
Add Click Add to include the additional ports. 
- 
Delete Select a port or range of ports, then click this button to remove them from the list. 
Outgoing Routes
Visible when Configure Network Route Settings is set to Advanced. Use this tab to define the connectivity type and port numbers that are open for outgoing communication from this CommCell component.
Remote Entity
Displays the list of remote clients or client groups that are only reachable through a network routes.
Route Settings
Displays the outgoing route to reach the remote client or client group.
- 
Add Click Add to add outgoing route to reach a remote client or client group. Provide the details in the Route Settings dialog box. 
- 
Edit Select a remote client or client group and click Edit to change the route settings. 
- 
Delete Select a remote client or client group and click Delete to remove it from the list. 
Options
Visible when Configure Network Route Settings is set to Advanced. Use this tab to configure additional network route options.
Keep-alive Interval, seconds
The interval for sending keep-alive packets, to maintain the session if backup traffic has an extended pause.
Note
To avoid idle session timeouts on cloud-based clients, set the keep-alive interval to 200 seconds (or less).
Tunnel Init Interval, seconds
The interval at which tunnel initialization must be attempted.
Default Outgoing Tunnel Protocol
When installing software components on a client for which there is no tunnel protocol defined on the Outgoing Routes tab, this option sets the outgoing tunnel protocol for any route that uses a proxy to communicate with a locked-down CommServe host.
Force SSL authentication in incoming tunnel connections
Select this option to force all incoming tunnel connections to use HTTPS protocol. Communication between other CommCell components will be authenticated through Secure Socket Layer (SSL).
Bind all services to open ports only
Select this option to bind all services to the list of incoming ports configured for the client using TCP/IP filtering.
This computer is in DMZ and will work as a proxy
Select this option to designate this computer as a proxy computer for CommCell communications through firewall.
Force per-client certificate based authentication
Visible only when This computer is in DMZ and will work as a proxy is selected. Selecting this option prevents clients that do not have certificates from communicating with a locked-down CommServe host through this computer when it is acting as a proxy. If this option is selected, you will have to generate a temporary authentication certificate to install new clients through the proxy. For more information, see Renew a Revoked Certificate in a Locked Down CommCell.
Roaming client
Select this option to designate a client computer as roaming client. The roaming feature intelligently determines the best route for the client to communicate with the CommServe computer. This is useful for clients that constantly change their geographical location, such as laptop clients.
When the option is selected, the client will try to reach the CommServe computer directly, without the use of firewall routes (outgoing routes are bypassed). If the CommServe computer cannot be reached, the client will continue to use the configured firewall routes.
Network Proxy Settings
These settings are visible when configuring a CommCell. They allow you to configure port-forwarding gateways.
- 
Access GUI Server (EvMgrS) via following proxy Select this option to enable port 8401 on the CommServe computer. - 
Remote Proxy lists the proxy computers that you can use to access the CommServe. 
- 
Port Number specifies a local port used by the proxy computer which will be mapped to port 8401. 
 
- 
- 
Access Web Server via following proxy Select this option to enable port 81 on the computer where the Web Server is installed. - 
Remote Proxy lists the proxy computers that you can use to access the Web Server. 
- 
Port Number specifies a local port used by the proxy computer which will be mapped to a dynamic IIS port. 
 
- 
- 
Access Reports via following proxy Select this option to enable port 80 on the CommServe computer. - 
Remote Proxy lists the proxy computers that you can use to access the Report database. 
- 
Port Number specifies a local port used by the proxy computer, which will be mapped to a dynamic IIS port. 
 
- 
- 
Access Custom Reports Engine via following proxy Select this option to specify the proxy through which this Web Console instance communicates with the Custom Reports Engine. - 
Remote Proxy lists the proxy computers that provide access to the Custom Reports Engine service. 
- 
Port Number specifies the port the Web Console will use to access the Custom Reports Engine (commonly running on the Web Server). This is a local port on the computer hosting the Web Console that is mapped to the Web Server. 
 
- 
Summary
This tab displays a summary of the network route configurations created using the other tabs. This tab is not available at the client group level.
Network Throttle
Enable Network Throttling
Select this option to enable network throttling.
Remote Clients or Client Group
Here you select the entities (groups and clients) whose traffic will be throttled when communicating with the group or client you are configuring.
All clients share allocated bandwidth
Select this option to enable all clients in this client group to share allocated bandwidth.
Throttling Schedule
Displays the scheduled job for network throttling.
- 
Add Click to create a new schedule. 
- 
Modify Click to modify the schedule. 
- 
Delete Click to delete the schedule. 
Additional Settings
Use this dialog box to set additional settings for the selected component. Additional settings are advanced options that can be used to perform troubleshooting and other environment specific configurations. Additional Settings can be added to the following CommCell entities:
- 
CommServe 
- 
MediaAgent 
- 
Clients 
- 
Client Groups 
- 
Companies 
- 
Users (CommServDB.Console settings only) 
- 
User Groups (CommServDB.Console settings only) 
- 
Domains (CommServDB.Console settings only) 
Additional settings created for this component are displayed in this dialog box.
- 
Name Displays the name of the additional setting. 
- 
Category Displays the relative location of the additional setting in the instance (from the registry key tree). 
- 
Type Displays the additional setting value type. For example, the value can be an integer or a string. 
- 
Value Displays the value of the additional setting. Depending on the type, could be numerical, a character string or a boolean value. 
- 
Enable Displays whether the additional setting is currently enabled or not. 
- 
Defined in Lists the CommCell entity where the additional setting is defined. 
Add
Click to add a new additional setting.
Edit
Select an additional setting and click Edit to modify it.
Delete
Select an additional setting and click Delete to remove it.
User Preferences (Client Computer Group Filter)
Use this dialog box to set your viewing preferences for the Client Computer Group node in the CommCell Browser.
Show Unlicensed with software (Restore only Clients)
Displays Restore-only clients in the CommCell.
Show Unlicensed without software
Displays those clients that have been deconfigured in the CommCell.
Show Virtual Server Discovered Clients
Displays Virtual Server Discovered clients in the CommCell.
Show EDC Discovered Clients
Displays EDC Discovered clients in the CommCell.
Storage Device
Use this dialog box to configure a storage policy for the Client Computer Group.
Storage Policy
Click to view and select a storage policy from the available list of storage policies.
Create Storage Policy
Click to trigger the wizard to create a new storage policy.
Filters
Applies to: Windows File System, UNIX File System
Use this dialog box to add Windows and UNIX filters (also called exceptions) to exclude files and folders from backups at the client group level.
Use group filters on all subclients
Click to apply the filters to all of the subclients in the client group. For more information about filter patterns and wildcard support, see the following topics:
Windows
Add
Click to manually add an entry to be included in, or excluded from, data protection operations for all of the subclients in the client group.
Edit
Click to manually edit an entry to be included in, or excluded from, data protection operations for all of the subclients in the client group.
Delete
Click to delete a selected filter entry.
UNIX
Add
Click to manually add an entry to be included in, or excluded from, data protection operations for all of the subclients in the client group.
Edit
Click to manually edit an entry to be included in, or excluded from, data protection operations for all of the subclients in the client group.
Delete
Click to delete a selected filter entry.