Integration Guide for AirGap for Dell
Introduction
AirGap is a feature of Ransomware Defender and integrates with several other Superna products to extend how and when the vault copy is protected and updated. This guide summarizes the current documented integration points between AirGap and Golden Copy, Easy Auditor, and Ransomware Defender role-based administration.
Ransomware Defender Integration
AirGap is delivered as part of Ransomware Defender and relies on it for user-behavior detection. Ransomware Defender's real-time detection of suspicious user behavior on the source production cluster can suspend AirGap data updates to the vault copy until an administrator reviews and acts on the alarms (AirGap).
Superna recommends splitting administration responsibilities across roles so that day-to-day monitoring is separate from AirGap administration:
- Ransomware Defender Role – assigned to the infosec team, for day-to-day configuration and management of real-time monitoring.
- Easy Auditor Role – assigned to the infosec team, for day-to-day auditing configuration.
- AirGap Role – assigned to a CSO or senior management, for access to the AirGap configuration.
Read-only variants of the Ransomware Defender and Easy Auditor roles are also available so the NAS team can have visibility without the ability to make changes.
Superna recommends restricting the AirGap role to CSO or senior security management personnel, kept separate from the personnel who hold the Ransomware Defender role.
Golden Copy File-to-Object Integration
Golden Copy Advanced can copy files to object storage locations off-site (for example, Amazon S3 or Azure).
Future integration with Golden Copy Advanced is planned, allowing Golden Copy to pause copy/sync operations to off-site object targets when an active threat is detected on the source cluster, based on Ransomware Defender user-behavior monitoring. Contact your Superna representative for current Golden Copy licensing information.
Easy Auditor Integration
Customers who own the Easy Auditor platform can extend the vault auto-close and replication criteria using Easy Auditor active auditing. This uses Easy Auditor's built-in triggers — Data Loss Prevention (DLP), mass-delete detection, or custom triggers — to control when vault replication is allowed to run.
- This lets security teams apply user-aware, network-aware policies that stop AirGap replication whenever there is an active event in Easy Auditor.
- If Easy Auditor is installed, any active DLP, mass-delete, or custom trigger event blocks replication to the vault cluster until the event is cleared or resolved in Easy Auditor.
For more on configuring Easy Auditor active auditing criteria, see Active Auditor in the Data Security documentation.
Dell APEX Metering Integration
Customers using Dell APEX can integrate APEX metering software with an Enterprise AirGap vault, securely transporting billing/metering data out of the vault via a UCC Edge VM and SFTP, without requiring a data diode or other out-of-band management path.
See Also
- AirGap Jobs – Configure the "Pause data replication when active ransomware events detected" option that enforces AirGap and Easy Auditor integration behavior.
- Prerequisites – Confirm licensing and platform requirements before enabling integrations.