AirGap for Dell
Introduction
Superna AirGap is a feature of Superna Ransomware Defender that creates and manages a secure, isolated ("air-gapped") copy of your critical data on a dedicated vault cluster. It combines fast, incremental SyncIQ replication with automated network isolation and user-behavior-aware controls so that a clean copy of your data is always available for recovery, even if your production environment is compromised.
This page introduces the concepts behind AirGap: what problem it solves, how it fits alongside Data Security and Disaster Recovery, and the core ideas — a location-independent vault, data immutability, and rapid recovery — that shape how AirGap is designed and deployed.
Superna recommends Ransomware Defender as the primary product for ransomware and unauthorized-access protection, since it covers detection, prevention, and recovery. AirGap is the Ransomware Defender feature that adds the isolated vault copy and integrates user-behavior detection to suspend vault updates until an administrator has acted on active alarms.
What AirGap Provides
AirGap protects data by replicating it to a third, dedicated cluster (the vault) that is normally disconnected from the network, and by locking that data as read-only/immutable using SyncIQ. Unlike a typical backup target, the vault:
- Is not reachable from the network except during a scheduled, narrow replication window (when "the AirGap opens").
- Cannot have its data deleted or modified, even by the root user, because SyncIQ locks the replicated copy in a read-only state.
- Integrates with Ransomware Defender's real-time user-behavior detection ("AirGap"), so that if suspicious activity is detected on the source cluster, the scheduled sync to the vault is automatically suspended until an administrator resolves the alarm.
- Supports split, role-based administration, so day-to-day monitoring of the source cluster and control of the AirGap/vault itself can be assigned to different teams or individuals.
Key Features
For the full list of AirGap capabilities — including AirGap behavior-based sync suspension, split roles, fast incremental replication, and Cloud Pool Vaulting — see AirGap Features.
How AirGap Fits with Data Security and Disaster Recovery
AirGap is one of three complementary layers of protection in the Superna Cyberstorage portfolio for Dell:
- Data Security proactively detects and isolates threats (suspicious user behavior, ransomware activity) at the source, before they can reach a backup or vault copy.
- Disaster Recovery protects against site failure by replicating data to a DR cluster on a short interval (for example, every 5 minutes) so operations can fail over quickly.
- AirGap protects the last-resort, immutable copy of data from an on-site cyber threat by isolating a third cluster (the vault) behind a much longer replication interval and a firewalled/disconnected network.
These layers are deliberately different, because they solve different problems: a DR cluster must always be reachable and current, whereas a vault must be isolated and updated slowly enough to allow time to detect a compromise before it is replicated. Do not use your DR cluster as your AirGap vault — see Design Guide for the reasoning and for guidance on where to place the vault.
Core Concepts
Location-independent vault
The vault cluster does not need to be located anywhere specific relative to the source cluster. SyncIQ replication allows the vault PowerScale to be placed on-site next to the source cluster (recommended, for fastest recovery) or at a remote location (supported, but with a longer recovery-time trade-off). Because AirGap is not a DR copy, Superna's general recommendation is to keep the vault on-site, since DR is what protects against site failure, and the vault is what protects against an on-site threat.
Immutability
Data replicated into the vault is locked as read-only by SyncIQ and cannot be modified or deleted, regardless of the permissions applied to it or the privileges of the account attempting the change (including root). Replication can be scoped to the entire source cluster or to specific paths, by creating one or more SyncIQ policies for the paths that need vault protection.
Rapid recovery (RPO/RTO framing)
AirGap is designed around two different recovery needs:
- Recovery point (data currency): the vault is updated on a much longer interval than a DR copy (for example, daily) — this delay is intentional, giving time to detect a compromise before it is replicated into the vault.
- Recovery time: because the vault cluster can itself serve data (over SMB/NFS) rather than requiring a lengthy restore, AirGap is designed to support bringing data back online within a few hours. See Use Cases for the detailed recovery scenarios (partial recovery, complete recovery, and rapid recovery/Emergency Operations Mode).
High change rate vs. low change rate data
Data sets with different change rates need different protection strategies (for example, different SyncIQ scheduling and retention choices) to balance vault storage cost against recovery granularity. See Design Guide for deployment-level guidance on planning for high-change-rate data.
AirGap Documentation
This documentation helps you plan, deploy, configure, and operate Superna AirGap in your Dell environment (PowerScale or ECS).
What's New
Prerequisites
This section covers the concepts and design decisions behind an AirGap deployment: platform and system requirements, and deployment topology, hardening, and sizing guidance.
Installation
Configuration
This section covers day-to-day configuration: creating and scheduling AirGap Jobs, Vault-controlled scheduling, AirGap for ECS, integrations with Ransomware Defender/Golden Copy/Easy Auditor/Dell APEX Metering, and CLI/API management.
Features
User Help
This section covers day-to-day use cases (ransomware recovery, partial and full restores, Emergency Operations Mode) and troubleshooting/FAQ.
Reference
Frequently Asked Questions
These questions are commonly asked when evaluating AirGap as part of a cyber vault strategy.
Is vault data protected and immutable? Yes. The vault is a third PowerScale cluster, and SyncIQ locks the replicated data in a read-only state. The data cannot be deleted or modified even by the root user on the cluster. Replication can cover the entire source cluster or specific paths.
Can I use my DR cluster as the AirGap vault? No — Superna recommends a dedicated third cluster. A DR copy needs to replicate as fast as possible (for example, every 5 minutes) to protect against site failure, whereas an AirGap copy should replicate more slowly (for example, every 24 hours) to allow time to detect compromised data before it reaches the vault. In addition, an AirGap vault needs to be firewalled and secured, while a DR cluster needs to stay reachable for a DR event — these are opposing requirements.
Can the AirGap be opened and closed from inside the vault? Yes. Ransomware Defender supports two modes: an outside-the-vault (Virtual AirGap) automation model, and an inside-the-vault automation model (Enterprise AirGap) that requires additional resources (an agent VM) deployed inside the vault. See Design Guide for details on both modes.
Is there any dependency on NTP or other network services? No. The vault cluster's clock can free-run independently; NTP and DNS servers are typically pre-configured on the vault (for use during a rapid recovery event) but do not need to be reachable during normal operation.
Is there visibility in production that a copy is being sent to the vault? Yes. AirGap provides full 24-hour, 30-day, and 60-day reporting on all copy jobs, including success/failure counts, throughput, and average AirGap-open time (the time the network connection to the vault is open, which the solution aims to minimize). Reports can be reviewed on demand or received daily by email.
Airgap Virtual Clean Room
Superna also offers an Airgap Virtual Clean Room capability, including an OnDemand Operations mode, as a related but distinct feature from the core AirGap solution described in this guide. Detailed documentation for Virtual Clean Room (overview, key values, requirements, configuration, and OnDemand Operations) is not yet published in this portal. Contact your Superna representative for current information on this capability.