Data Protection Manager offers flexible data backup and restoration for Microsoft shops
endif; ?>Microsoft’s flagship backup and archiving software, Data Protection Manager, has come a long way since we first tested it in 2005.
When we first visited the newly released Data Protection Manager, it was a start towards the goal of enterprise backup and archiving, but barely that. It didn’t run on 64-bit machines, backed up a few Windows applications, but by no means all — not even Microsoft Exchange Server. And restoration of a dead server from bare metal was a gruesome and tedious process.
That’s all changed with Data Protection Manager 2010, has evolved dramatically from the last time we looked. DPM now requires a Windows 2008 (or 2008 R2) 64-bit platform, and includes a handy algorithm concerning both user memory and storage space for the estimated size of DPM storage pools.
DPM delivers plenty of flexibility in terms of network-based backup, archiving and restoration. As with all Microsoft System Center modules, it suffers from a harrowing lack of compatibility with non-Microsoft products. That alone may sway organizations to look elsewhere as heterogeneous operating systems environments are the norm these days.
TEST: Microsoft beefs up System Center with new module | Test methodology
If, however, an organization needs a sophisticated solution that knows Microsoft Exchange and SQL Server somewhat intimately, DPM provides great support for both apps, as well as file servers and client datasets. While we found the documentation useful, much planning must be done to obtain full advantage and integrity that Data Protection Manager provides.
Getting started
DPM requires a running instance of SQL Server 2008 R1 on a separate machine. Supported storage fabrics can consist of concurrent tape and storage-area network (SAN) media pools or approaches that back up from disk to DPM storage pool to tape. We tested with an iSCSI Compellent SAN that was easily understood by DPM.
Under a single Enterprise DPM license, it’s possible to have a secondary, backup DPM server that is a replica of the primary DPM server for availability purposes — a “free” backup of the backup so long as the replica server is in the same domain (or where there are transitive trust relationships between domains).
There are a few small limitations imposed but no real drama in making and deploying an alternate DPM server. One hopes that the bandwidth on the path to the alternate server is high for backup/restoral purposes as prudent practice would put the alternate DPM server in a different locale, which would result in some WAN link latency.
Microsoft claims that a single DPM server, correctly configured with adequate hardware, can support up to 1,000 clients. That’s likely a very top number, for several reasons. Now that Windows XP, Windows 7 and Vista can have client backups, a healthy server with excellent I/O characteristics and blindingly fast drives ought to be able to sustain a lot of user data backups.
If a large number of machines need restoration at once (given a group catastrophe), a single DPM server won’t be able to recover things with finger-snapping speed. As an example, if an infected group of files is accidentally distributed, the recovery time through a DPM server might take quite some time, as even the “healthiest” DPM servers can become I/O bound.
DPM also supports WAN/branch connection speeds of 512Kbps faster. Backup traffic can be somewhat throttled to prevent trashing bandwidth during backups.
Agents on all clients
Basic installation was simple. We brought up an instance of MS SQL Server 2008 SP2 (SP1 is said to work). We used volumes resident on our Compellent iSCSI SAN, but Fibre Channel, other SAN, or directly attached disks (Directly Attached Storage in Microsoft parlance) could work as well.
USB/IEE1394-FireWire storage doesn’t work. If storage media have OEM recovery partitions on them, those partitions must be wiped first.
Each system that’s to be backed up (“protected” in Microsoft parlance) requires a DPM agent to be installed on them. The agent and server listen on Port 135 for communications. Firewalls typically block this port in our experience, so it must be opened across firewall boundaries. The agent is also sensitive to the CPU word-size of the protected machine, meaning there is a 64-bit and a 32-bit agent payload type. Only NTFS partitions of 1GB or larger can be protected; FAT16/32 aren’t supported, and if you use Linux or MacOS or Solaris, go fish.
Client agents must be installed as the machine’s administrator account. As some organizations don’t allow users to know how to become an administrator, a Remote Desktop session must be managed, or better still, the DPM agent should be installed as part of the initial customization payload for user machines — unless organizational security policy says otherwise.
Configuration
The DPM Software offers a gradient of methods of backup, depending on the operating system and/or Microsoft application. A full list of compatible protected clients is located here.
According to Microsoft, DPM offers protection for file data, at the level of volumes, folders and shares on file servers running Windows 2003+, file data on workstations running Windows XP SP2+ (except Home versions), MS SQL Server 2000 SP4+/2005 SP1+ data at the level of databases, Windows SharePoint Services 3.0 and Office SharePoint Server 2007 at the level of farms, Microsoft Exchange 2003 SP2+/2007+ at the level of storage groups, Microsoft Virtual Server 2005 R2 SP1+ .
When protection is performed by file members in a protected group, the Volume Shadow Services/VSS can remember 64 recovery points for the snapshot object of files. For specifically protected applications (SQL Server), there are 512 available recovery points. This in turn, specifies the time that data is retained and organizational policy may come into play about how long data must be retained — therefore dictating policy. The life of a backup may be on disk, then disk to tape depending on organizational needs, to further store backups over time.
We added clients first, then servers into the DPM administrative console. Clients aren’t allowed to have bare metal recovery possibilities, but servers are. We’re not as concerned about client bare metal, because most clients are simply replaced with ready application payloads, needing only user-data and configuration information.
Clients can be specified by client or client group membership to have folders backed up; common folders like Documents or folders that don’t fit the default hierarchy of typical Windows user machines are backed up as an object/group. Servers can also be backed up this way if desired, or can be backed up by system state (including server role application components), application, or for bare metal recovery including system state, which increases the backup displacement as it has everything.
Each type of protection method has its own backup payload, and advantage in terms of time to restore in case of a failure. Applications restore most quickly, system state after that, and bare metal takes longest, as application recovery takes place after system state. Bare metal recovery (BMR) is a separate object from applications and reserves an automatic 30GB of space for the BMR object.
To perform a system state protection, the agent on the target server must first dump the system state to disk, then transfer the state object, which can be typically 15GB says Microsoft, although ours was at 9GB, significantly smaller. The states between BMR and Systems State protection can be changed.
Backup in Motion: Beep Beep Beep
Backups and LAN/WAN traffic are important considerations in placing DPM servers that will have a high duty cycle — meaning frequently polled high-volume data backup objects/duties. Although much is done to not duplicate individually protected machines, as only changes are sent by the VSS services during backup, data de-duplication across machines is not done by DPM. The first backup of any type is usually the fullest.
Connected machines we tested fell into two groups, servers with Microsoft Exchange and SQL Server, and Windows clients.
To test restores, we backed up the running instances of SQL Server used in System Center: Service Manager first. Restoration went smoothly and quickly on our Gigabit Ethernet-based network. Our database and table sizes were comparatively small, however and it’s difficult to extrapolate how long the restoration time might have been over high latency, low speed networks, or very large databases.
Many machines being polled frequently will tube available bandwidth, so polling frequencies need to be decided, even though only changed data information is sent.
Bare metal restoration is a bit more tricky. DPM must first be used to create a restoration object for a dead server, then we had to share the object for network access purposes.
If you’re in the hands of new hardware or merely must wipe the server, one boots with an operating system (Windows 2003-2008/R2) and uses the initially presented repair selections to find the restore object, point it to desired boot media, and commence the download process. Having a server that can boot from a fat USB stick would likely be faster than the DVD-style process we used. The documents don’t describe the process well, and we used information from a Microsoft DPM blog to perfect the process.
There’s an extra tool for SQL Server users that allows them to recover databases without bothering administrators, called the Self Service Recovery Tool/SSRT. After installation (warning, requires administrator account credentials), users can restore protected databases.
Windows clients have an icon in their system tray for DPM. Clicking it allows users to choose recovery points, which are objects consisting of files and folders that had (hopefully) been backed up during a DPM protection session. Previous versions are available, and the number of versions available are a function of the aforementioned policies used to determine polling frequency for jobs, availability of the computer to have had backups (when the machine was last on the network or connected through a VPN).
One highlight is the desired dataset/restore point/files/folders and DPM whirs, pushing the files to the client. We found no fuss or muss in the process. Users can also force a sync that pushes the backup cycle to DPM, a likely must for mobile users about to depart the building.
Fans of the powershell commands scripting power will find dozens of new powershell commandlets that can be used to do things like query tape drives, find datasets and DPM objects. While we didn’t do any testing of these, we were happy to find many of these and could envision scripts built with them to do low-level jobs.
Henderson is a researcher for ExtremeLabs. He can be reached at kitchen-sink@extremelabs.com.




