If you want to migrate data between Apsara File Storage NAS file systems, you must allow Data Online Migration to access the source and destination NAS file systems. In this case, the source and destination NAS file systems must reside in the same virtual private cloud (VPC).

Precautions

If the source and destination NAS file systems belong to different Alibaba Cloud accounts, we recommend that you log on to the Data Transport console by using the account that owns the source NAS file system.

Preparations for two NAS file systems that do not reside in VPCs

If the source and destination NAS file systems do not reside in Alibaba Cloud VPCs, connect the two file systems to a VPC. This way, the two file systems can be accessed within the same VPC.

  • Apsara File Storage NAS
    • Mount the source and destination NAS file systems to a VPC. For more information, see Usage notes.
    • If you configure permission groups for the source and destination NAS file systems, you must authorize all IP addresses in the VPC to access the NAS file systems. For more information, see Manage a permission group.
  • Third-party NAS services
    • You can use one of the following methods to mount the source and destination NAS file systems to a VPC:
      • To allow access to an NAS file system from all IP addresses in a VPC, you can mount the NAS file system to the VPC by using an Express Connect circuit. For more information, contact Alibaba Cloud technical support.
      • To allow access to an NAS file system from all IP addresses in a VPC, you can mount the NAS file system to the VPC over a VPN network.
    • If you configure permission groups for the source and destination NAS file systems, you must authorize all IP addresses in the VPC to access the NAS file systems.

Preparations for two NAS file systems that reside in the same VPC

If the source and destination NAS file systems reside in the same VPC, communication between the file systems is enabled by default. If you configure permission groups for the source and destination NAS file systems, you must authorize all IP addresses in the VPC to access the NAS file systems.

Preparations for two NAS file systems that reside in different VPCs

Create and authorize a RAM user

  1. Log on to the Resource Access Management (RAM) console.
  2. In the left-side navigation pane, choose Identities > Users.
  3. On the Users page, click Create User.
  4. On the Create User page, specify Logon Name and Display Name in the User Account Information section.
  5. In the Access Mode section, select Console Access or Open API Access. Save the generated logon name, password, AccessKey ID, and AccessKey secret.
    • Console Access: If you select this option, you must configure the console password, password reset settings, and multi-factor authentication settings.
    • Open API Access: If you select this option, an AccessKey pair is automatically created for the RAM user. The RAM user can call API operations or use other development tools to access Alibaba Cloud resources.
  6. After the RAM user is created, return to the Users page. Find the RAM user and click Add Permissions in the Actions column. In the panel that appears, select the AliyunNASFullAccess and AliyunMGWFullAccess policies and click OK. This way, the RAM user is granted the permissions to read and write files from Apsara File Storage NAS and perform online data migrations.
  7. In the left-side navigation pane, click Overview.
  8. On the page that appears, navigate to the Account Management section and click the link under RAM user logon. On the page that appears, enter the logon name and password of the RAM user to log on to the Alibaba Cloud Management Console.