vCenter Server file-based backup fails to SMB share when digital signing is required
search cancel

vCenter Server file-based backup fails to SMB share when digital signing is required

book

Article ID: 445333

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

vCenter Server file-based backups to an SMB target fail when the NAS or file server enforces SMB digital signing. This typically occurs on specialized storage appliances or hardened Windows file shares.

Environment

  • VMware vCenter Server 7.0 Update 3h and higher
  • VMware vCenter Server 8.x
  • SMB NAS shares (e.g., HPE StoreOnce, Windows Server)

Cause

Since vCenter 7.0 U3h, the backup architecture uses smbclient instead of the cifs kernel module. The smbclient utility may fail to negotiate a connection when the server strictly requires digital signing, particularly in complex network or domain environments.

Resolution

To resolve this issue, perform the following steps:

  1. Log in to the management interface of the NAS or SMB server.
  2. Navigate to the SMB/CIFS share settings for the vCenter backup target.
  3. Modify the SMB Digital Signing (or "Digitally sign communications") setting from Required to Optional (or "Enabled" but not "Enforced").
  4. Ensure the Backup location in the vCenter VAMI (port 5480) uses the Fully Qualified Domain Name (FQDN) of the NAS: smb://nas-server.domain.com/sharename.
  5. Retry the backup from the vCenter VAMI.

Additional Information

For further assistance with SMB configuration, see "NT_STATUS_NOT_FOUND" error for file based backups of vCenter Server using the SMB protocol following update to 8.0U2.

If the issue persists, contact Broadcom Support.