[ Applies to ] StorageGuard / Everpure FlashBlade / AI Storage & Parallel File Storage
This article lists the recommended baseline checks for Everpure FlashBlade. Core6 updates the list periodically as new StorageGuard checks become available.
In this article
Overview
Everpure (formerly Pure Storage) FlashBlade is an all-flash, scale-out platform for unified fast file and object storage. Its massively parallel architecture delivers the throughput and metadata performance that AI and machine learning pipelines, analytics and large unstructured data sets require.
Why hardening Everpure FlashBlade matters
FlashBlade often stores AI training data, analytics results and intellectual property. Role-based access, encryption in transit and at rest, SafeMode snapshots and complete audit logging are essential to protect that data, and any gap can disrupt AI workflows and business continuity.
Recommended baseline checks
The baseline below contains 59 checks, listed alphabetically.
| ID | Configuration check |
|---|---|
| SG-F1493T200V01 | Alert watcher status |
| SG-F9516T200V01 | Approved Access style for multi-protocol file systems |
| SG-F1017T200V01 | Approved alert watcher |
| SG-F5895T200V01 | Approved DNS search domain |
| SG-F5392T200V01 | Approved DNS servers |
| SG-C0435T200V01 | Approved LDAP servers |
| SG-F4778T200V01 | Approved MultiProtocol filesystem |
| SG-F3286T200V01 | Approved NFS export policy |
| SG-C0013T200V01 | Approved NTP servers |
| SG-F4023T200V01 | Approved object replication remote credentials |
| SG-F3764T200V01 | Approved Object store account user |
| SG-F8164T200V01 | Approved rule based NFS export |
| SG-F8063T200V01 | Browsable file shares (Multi-protocol) |
| SG-F6512T200V01 | Bucket retention lock mode |
| SG-F4596T200V01 | CIFS SMB ACL mode |
| SG-F1658T200V01 | CIFS SMB anonymous user access restriction |
| SG-F2476T200V01 | CIFS SMB enabled |
| SG-F9747T200V01 | CIFS SMB encryption (policy) |
| SG-C0065T200V01 | Data at-rest encryption |
| SG-C0056T200V01 | Default passwords |
| SG-F9200T200V01 | DNS search domain status |
| SG-C0243T200V01 | DNS server configuration |
| SG-C0060T200V01 | DNS server redundancy |
| SG-C0245T200V01 | Domain name configuration |
| SG-C0600T200V01 | End of support |
| SG-F5378T200V01 | Event types enabled for audit logging (Alert watcher) |
| SG-C0162T200V01 | Expired SSL certificate |
| SG-C0600T200V02 | Future end of support |
| SG-C0209T200V01 | Idle session timeout |
| SG-F5897T200V01 | LDAP server configuration |
| SG-C0025T200V01 | LDAP server redundancy |
| SG-C0427T200V01 | Login banner message |
| SG-C0426T200V01 | Login banner status |
| SG-F7052T200V01 | Management network separation |
| SG-F3651T200V01 | NFS browsable exports (Rule based) |
| SG-F9217T200V01 | NFS enabled |
| SG-F9761T200V01 | NFS export ACL status |
| SG-F9305T200V01 | NFS export allowed access list (Policy based) |
| SG-F2502T200V01 | NFS root squash status |
| SG-C0230T200V01 | Non-default local admin |
| SG-C0171T200V01 | NTP server configuration |
| SG-C0251T200V01 | Object versioning protection |
| SG-C0102T200V01 | Object-lock status |
| SG-C0138T200V01 | Remote support status |
| SG-F2356T200V01 | Required DNS servers |
| SG-C0439T200V01 | Required LDAP servers |
| SG-C0014T200V01 | Required NTP servers |
| SG-C0349T200V01 | Required SNMP trap hosts |
| SG-F1401T200V01 | Safeguard ACL status |
| SG-C0447T200V01 | Self-signed certificate |
| SG-C0058T200V0 | SNMP community default string |
| SG-C0347T200V01 | SNMP trap host configuration |
| SG-C0422T200V01 | SNMPv3 privacy encryption algorithm |
| SG-C0419T200V01 | SNMPv3 user authentication protocol |
| SG-C0019T200V01 | Target OS version |
| SG-C0005T200V01 | TLS audit logging |
| SG-C0448T200V01 | Trusted certificate-authority (CA) |
| SG-C0116T200V01 | Unapproved admin users |
| SG-C0213T200V01 | Use of secure LDAP |
Related components
A complete baseline also covers the components that manage, connect to or protect Everpure FlashBlade. Review the configuration of:
- Pure1 and Pure1 Manage
- FlashArray systems replicating to or from FlashBlade
- Object replication targets and S3 clients
Run checks with StorageGuard
[ Still need help? ]
Our support team is here to help. Submit a request.
Comments
0 comments
Please sign in to leave a comment.