Gallium inc. EN FR
NASLORD
Documentation

NASLORD 3.0 Installation Guide and Release Notes

Version 3.0.0 2026-07-14 Audience: installers, virtualization administrators, operators

1.Product overview

NASLORD is a multi-tenant management and chargeback appliance for Dell storage platforms. It is distributed as a portable, ready-to-go virtual appliance (OVA) and provides three integrated managers:

NASLORD Multi-Tenant Manager for Dell PowerScale

OneFS, the operating system running on PowerScale clusters, can isolate end-users belonging to different tenants (up to fifty separate tenants per cluster, each with their own subnet, routing, DNS, and security infrastructure). However, OneFS administration remains centralized and cannot delegate per-Access-Zone management.

NASLORD fills this gap: administrators can delegate full Access Zone management to designated “Tenant Administrators”, who get a simple and secure way to manage their own Access Zones — browsing the file system and viewing/creating/editing/deleting Quotas, Snapshot Schedules, NFS exports and SMB shares — across one or multiple clusters.

NASLORD Retention Lock Manager for Dell PowerProtect DD

Retention Lock is a PowerProtect DD (Data Domain) feature that makes files immutable (read-only) until their retention period expires, protecting backup copies even if the backup server is compromised by ransomware. Most backup solutions cannot use Retention Lock, or only support one mode of operations.

NASLORD makes Retention Lock usable with any backup application. It automates the creation of Protected Copies (using the fast, space-efficient fastcopy feature), lets the storage unit apply and enforce Retention Lock for the selected period, and automatically deletes older copies whose retention has expired. Both Governance and Compliance modes are supported.

NASLORD Chargeback Manager for Dell PowerScale and ECS/ObjectScale

ECS and ObjectScale clusters maintain statistics about disk capacity and API utilisation, but offer no built-in system to define rates, calculate charges based on actual usage, or produce meaningful reports. The same applies to PowerScale capacity consumption.

NASLORD provides a comprehensive cost allocation and chargeback solution: it tracks, manages, and allocates the costs associated with usage of Dell ECS/ObjectScale namespaces and buckets and (new in 3.0) Dell PowerScale Access Zones, giving IT administrators and service providers a transparent, detailed view of storage consumption and enabling accurate and fair billing models for multi-tenant and enterprise environments.

2.Release notes — what’s new in 3.0.0

Version 3.0.0 is a major release focused on turning the Chargeback Manager into a complete, automated billing workflow, with first-class Tenant objects, budgets, scheduled report delivery, and major platform improvements around security and operations.

Tenant management

  • Tenants are now first-class objects in NASLORD. Each Tenant carries a name, contact name, phone number, office address, e-mail address, a dedicated report e-mail address, notes, an enabled/disabled flag, and a billing currency (USD, CAD, EUR, GBP, or BRL).
  • Storage components are associated to Tenants: PowerScale Access Zones and ObjectScale Namespaces can each be wired to a Tenant (Buckets inherit the Tenant of their parent Namespace).
  • Per-tenant monthly reports can be enabled individually.

Chargeback for PowerScale

  • Chargeback is no longer limited to ECS/ObjectScale. PowerScale Access Zones can now be charged using dedicated PowerScale Chargeback Profiles, with separate rates (and rate tiers) for data capacity, protection overhead, and snapshot capacity.

Charge reports and dashboards

  • Monthly charge reports per Tenant (report period in YYYYMM format), with charge details and consolidated dashboards for both administrators and tenant users.
  • Reports can be exported in multiple formats: PDF Summary, PDF Complete/Detailed, CSV, JSON, and XML.
  • Reports can be generated in five languages: English, French, Spanish, German, and Portuguese.

Automated report delivery

  • Report Destinations: deliver reports by SMTP (e-mail), SFTP, or HTTP POST (with None/Basic/Bearer/API-Key authentication, custom headers, and TLS verification options).
  • Report Routes: bind a Tenant (or all Tenants, globally) to a Destination, choosing the formats and language; monthly scheduled delivery can be enabled per route, and routes can also be triggered manually on demand.
  • Full delivery tracking: report runs and per-destination delivery attempts are recorded and can be reviewed in the web interface.

Tenant budgets

  • Budgets can be defined per Tenant with monthly and yearly amounts, a configurable fiscal-year start month, a start date, and an optional end date.
  • Budgets can be broken down into components with their own amounts.
  • Alert thresholds are created automatically at 85% (Warning) and 100% (Critical) of the budget, and can be adjusted. Threshold crossings can generate e-mail notifications.
  • A budget dashboard compares budget versus actual charges, and periodic budget snapshots build a browsable history (exportable as JSON).

Authentication and security

  • LDAP authentication: external LDAP providers can be configured, and users can authenticate locally or via LDAP. Tenants can be mapped to an LDAP base OU and an LDAP administrator group DN.
  • Two-factor authentication (TOTP, compatible with standard authenticator apps, with static backup tokens). 2FA can be enabled or disabled system-wide from the admin interface.
  • Login auditing: last authentication timestamp and source IP address are recorded per user.

Platform and operations

  • E-mail (SMTP) settings are configurable in the web interface, including a “send test e-mail” function.
  • Timezone configuration from the web interface.
  • Scheduled jobs viewer with execution logs.
  • Database management: export/import of the configuration database, plus backup download, restore, and deletion from the web interface.
  • In-app upgrade: upload a NASLORD upgrade package and apply it from the web interface. Reboot and shutdown of the appliance can also be performed from the web interface.
  • License management page for viewing the installed license and installing new license keys.

3.Upgrade notes

  • Upgrading from 2.x: use the in-app upgrade (see section 10) or deploy a fresh 3.0.0 OVA and re-add your Clusters, Appliances and VDCs.
  • Back up first. Before upgrading, export the configuration database: Admin page → Database Management → Export Database. Download the backup file and store it outside the appliance.
  • License compatibility: NASLORD validates the license against the product’s major version. A license issued for version 2.x is not valid on 3.0.0 (unless the license was issued for “any” version). Contact Gallium to obtain an updated license before upgrading a production system.
  • New 3.0 features that send e-mail (report delivery by SMTP, budget threshold notifications, monthly tenant reports) require SMTP settings to be configured after the upgrade (Admin page → Email Settings).

4.Known behaviours and limitations

  • A valid license is required for charge reports. If the license is missing, expired, or does not cover the relevant products, charge reports are generated empty (all amounts show as zero). If reports unexpectedly show $0, verify the license first (Admin page → License).
  • Demo license limits: one (1) PowerScale Cluster with up to three (3) enabled Access Zones; one (1) PowerProtect DD Appliance with up to three (3) Primary MTrees; one (1) ECS/ObjectScale VDC with up to three (3) enabled Namespaces. The demo license is valid for 90 days. Production licenses have no such limits.
  • Monthly report timing: the report for the current month covers the period up to yesterday, and is not available on the 1st day of the month (no data yet). Reports cannot be generated for future periods.
  • Capacity charge rounding: ObjectScale capacity is billed per day (the monthly rate divided by the number of days in the month), and each daily charge is rounded to the cent. Monthly capacity totals may therefore differ from a simple (capacity × rate) calculation by a few cents.
  • The “Default” chargeback profile ships preconfigured, can be modified, but cannot be deleted. Components without an explicitly assigned profile use the Default profile.
  • PowerScale Access Zones are discovered automatically when a cluster is added, but are disabled by default; they must be enabled before they appear anywhere (including in charge reports).
  • After creating MTrees or changing Retention Lock parameters on the PowerProtect DD, use “Refresh Cache”; if MTrees appear in the “Missing MTrees” column, use “Synchronize MTrees”.
  • Chargeback profiles applied to a Tenant’s components must all use the Tenant’s currency; NASLORD blocks mismatched assignments.

5.Requirements

NASLORD is distributed as a portable, ready-to-go appliance.

Virtual machine requirements

The NASLORD OVA requires:

  • VMware ESXi 6.5 or newer — Gallium recommends ESXi 8.0 or newer
  • 4 GB RAM
  • 16 GB hard disk
  • 1 virtual network adapter

Network requirements

All connections are initiated from NASLORD to the various components, except for NASLORD’s web interface (inbound HTTPS on port 443).

Network flows used by the NASLORD appliance.
TrafficPort / protocolDirection
Web interface (super-users and tenant administrators)TCP/443Inbound
DNS (every configured DNS server)UDP/53Outbound
PowerScale nodes (API)TCP/8080 (default)Outbound
PowerProtect DD appliances (SSH)TCP/22 (default)Outbound
PowerProtect DD appliances (API)TCP/3009 (default)Outbound
ECS/ObjectScale nodes (API)TCP/4443 (default)Outbound

Optional services (only if the corresponding feature is used)

  • SMTP server port (commonly TCP/25, TCP/465 or TCP/587, outbound) for e-mail delivery of reports and notifications
  • TCP/22 (outbound) to SFTP servers used as report destinations
  • TCP/443 or TCP/80 (outbound) to HTTP POST report destinations
  • LDAP TCP/389 or LDAPS TCP/636 (outbound) to LDAP authentication servers

6.Installation — deploying the OVA

The NASLORD OVA can be downloaded from the NASLORD download centre.

  1. From vCenter, choose “Deploy OVF Template”.
  2. Choose the previously downloaded OVA file, enter the VM name and select the destination folder.
  3. Select the compute resource.
  4. Select the destination storage.
  5. Select the destination network for the virtual network adapter.
  6. Click Next, review the settings, and click Finish.
  7. Wait for the deployment to complete, then power on the virtual machine.

7.Initial configuration

Step 1 — Configure the basic VM settings (console)

  1. In vCenter, click on the NASLORD virtual machine.
  2. Select the “Summary” tab.
  3. Open the VM console.
  4. Log in as: root
  5. Use the default password: changeme
  6. Execute the following command: configure
  7. The first prompt asks if you want to change the root password. Answer: y — do not keep or reuse the default root password.
  8. Enter the new root password (twice).
  9. The next prompt asks if you want to change the network configuration. Answer: y
  10. You will be asked if you want to use DHCP. Answer y or n — for production use, Gallium recommends against using DHCP.
  11. If you answered no (static configuration), answer the prompts: hostname (FQDN), IP address, netmask bits (e.g. 24), default gateway, DNS servers (space-separated list).
  12. After changing the network settings, rebooting the VM is mandatory. Execute the following command: reboot
  13. Close the VM console.

Step 2 — First login to the web interface

  1. Open a browser and access NASLORD using its hostname or IP address (HTTPS, port 443).
  2. Log in as user admin. The default password is: changeme
  3. Click on Change Password to set a new password immediately.

Step 3 — Recommended post-install configuration

In the Admin page, review the following before adding storage systems:

  • Timezone: set the appliance timezone.
  • Email Settings: configure the SMTP server and send a test e-mail (required for report delivery by e-mail and budget notifications).
  • License: verify the license status (see section 8).
  • Two-Factor Authentication: enable system-wide 2FA if desired.
  • LDAP: configure an LDAP provider if users will authenticate against a directory (see the LDAP Configuration Guide).

The appliance is now ready. Refer to the NASLORD 3.0.0 Administration Guide to add PowerScale Clusters, PowerProtect DD Appliances and ECS/ObjectScale VDCs, create Tenants and users, and configure chargeback.

8.Licensing

  • A demo license is active after installation. The demo license is valid for 90 days, after which you need to request a production license.
  • Demo license limits:
    • One (1) PowerScale Cluster, up to three (3) enabled Access Zones
    • One (1) PowerProtect DD Appliance, up to three (3) Primary MTrees
    • One (1) ECS/ObjectScale VDC, up to three (3) enabled Namespaces
  • Production licenses can be obtained without any Access Zone, Primary MTree or Namespace limit.
  • To view the installed license or install a new license key: Admin page → License.
  • Important: charge reports are generated empty when the license is missing, expired, or does not cover the product concerned.
  • To obtain a production license, contact Gallium (see section 12).

9.Creating additional super-user accounts (optional)

  1. Navigate to Admin page → User Management → + Create Local User.
  2. Enter the desired username, first name, last name, email and password.
  3. Enable the “Super-user” checkbox.
  4. Save the user.
Note. Super-users do not need to be explicitly granted access to any specific Access Zones, MTrees or Namespaces. They automatically have access to all active Access Zones, MTrees and Namespaces, across all Clusters, Appliances and VDCs configured in NASLORD.

10.Upgrading NASLORD from the web interface

NASLORD 3.0 supports in-app upgrades:

  1. Export the configuration database first (Admin page → Database Management → Export Database) and download the backup.
  2. Obtain the NASLORD upgrade package from Gallium.
  3. Navigate to Admin page → Upgrade NASLORD and upload the package.
  4. Review the confirmation screen, then apply the upgrade.
  5. The appliance restarts its services; a reboot needs to be triggered from the web interface.

If anything goes wrong, the exported database can be re-imported on a freshly deployed appliance (Admin page → Database Management → Import Database).

11.Virtual machine reconfiguration

How to change the root password or network settings after installation:

  1. Log on to the vCenter web UI.
  2. Click on the NASLORD virtual machine.
  3. Select the “Summary” tab.
  4. Open the VM console.
  5. Log in as root.
  6. Execute the following command: configure
  7. The first prompt asks if you want to change the root password. Answer y or n; if you answered yes, enter the new root password (twice).
  8. The next prompt asks if you want to change the network configuration. Answer y or n.
  9. If you answered yes, you will be asked if you want to use DHCP. Answer y or n — for production use, Gallium recommends against using DHCP.
  10. If you answered no (static configuration), answer the prompts: hostname (FQDN), IP address, netmask bits (e.g. 24), default gateway, DNS servers (space-separated list).
  11. If you changed the network settings, reboot the VM: execute reboot.
  12. If you only changed the root password, log out from the terminal: execute exit.
  13. Close the VM console.

12.How to contact Gallium

To inquire about NASLORD or to obtain a quote for a licensed version, please contact us directly:

Gallium inc.
2200-1250 René-Lévesque W. Montréal (Québec) Canada H3B 4W8
sales@gallium-it.com
Tel.: +1 877 564-0888

Legal

Use of NASLORD is subject to the End-User License Agreement (EULA) included with the product. The Software is owned by Gallium inc. and is protected by national copyright laws and international copyright treaties. All Rights Reserved. Copyright © Gallium, Inc.

Back to top

Book a Demo 90-Day Trial