Configuring EFS on N2WS allows you to determine backup:
Schedule and frequency
Lifecycle policy, including moving backups to cold storage, defining expiration options, and deleting them at end of life.
With AWS Backup, you pay only for the amount of backup storage you use and the amount of backup data you restore in the month. There is no minimum fee and there are no set-up charges.
In the AWS Console, create the EFS in one of the available regions. See section 8 for regions not supported for EFS.
In N2WS, in the Backup Targets tab of a Policy, select Elastic File Systems in the Add Backup Targets menu.
In the Add Elastic File System screen list, select one or more EFS targets and then select Add selected.
In the Backup Targets tab, select an EFS target and then select Configure.
Configure the EFS backup and restore options described in section 8.1.1, and select Apply.
Select Save in the Backup Targets screen to save the configuration to the policy.
Backup Vault – A logical backup container for your recovery points (your EFS snapshots) that allows you to organize your backups.
IAM Role – An IAM identity that has specific permissions for all supported AWS backup services. The following AWS backup permissions should be attached to your IAM role:
AWSBackupServiceRolePolicyForBackup - Create backups on your behalf across AWS services.
AWSBackupServiceRolePolicyForRestores - Perform restores on your behalf across AWS services.
If a default IAM role was not automatically created by AWS, or you require a custom IAM role, see section 8.2. Selecting the preferred IAM role is only required during the EFS policy configuration.
Transition to cold storage– Select the transition lifecycle of a recovery point (your EFS snapshots). The default is Never.
Expire – When does a protected resource expire. The default is Policy Generations.
A default or custom IAM role is necessary for AWS to perform EFS operations on behalf of N2WS.
To create a default IAM Role:
Go to the AWS Backup Service: https://us-east-1.console.aws.amazon.com/backup/
Select Create an on-demand backup.
For Resource type, select EBS.
For Volume ID, select any EBS volume to backup.
Select Default IAM Role.
Select Create on-demand backup. Ignore the error provided by AWS.
Verify that the following role was created on AWS IAM Service:
To create a custom IAM Role:
Go to AWS IAM Service: https://console.aws.amazon.com/iam/home#/roles
Select Create role.
Select AWS Backup and then select Next: Permissions.
Search for BackupService.
Select the following AWS managed policies:
Select Next: Tags and then select Next: Review.
Enter a Role name and select Create role.
EFS can be configured by creating the cpm backup tag. In this case, N2WS will override the EFS configuration with the tag values. See section 14.1.4 for keys and values.