Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

One of the data recovery schemes _ data recovery scheme after infortrend ESDS RAID6 failure

2025-01-20 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Servers >

Share

Shulou(Shulou.com)06/02 Report--

[user unit]

XXX Audio and Video production Co.

[description of data recovery failure]

An infortrend ESDS-S12F-G1440 storage consists of 12 2TB hard drives to form a RAID6. All the space of the whole RAID6 is divided into a LUN and mapped to the WINDOWS system. On the WINDOWS system, a GPT partition is divided, the size is 18.2TB, and the original used space is about 16.5TB.

After using it for a period of time, the manager found that the storage could not be accessed. The administrator checked the storage and found that three hard drives were offline, and then made the storage online by some unconventional means and started rebuild. However, when accessed through the host, it was found that the partition could not be opened and all data could not be accessed. After consulting professional institutions, we learned that this situation indicates that the data has been corrupted. In order to avoid further deterioration of the status, stop rebuild and seek the help of professional data recovery agencies after shutting down the computer.

After the full recovery of the local data recovery company, the final result is that a large amount of data is lost and a large amount of data cannot be opened.

[data recovery Analysis]

RAID6 is a storage redundancy mode that supports two hard drives going offline at the same time, but when more than two disks are offline, RAID6 will not work properly. Usually, the three offline disks of RAID6 fail successively within a period of time. Therefore, in this case, if the disconnected disks (outdated data) are online, the RAID6 algorithm will be synchronized with the online disks (fresh data). As a result, the data will not be able to be read normally.

In this case, it should be the above analysis, but because the rebuild time is short (about a few minutes), about dozens of GB data can be synchronized in a few minutes. In this case, there is a lot of user data file data, and as a material library, the front part of the file system is most likely to store old data, and because of the large number of files, the directories and node indexes of some newer files should be located at the back of the disk. Therefore, synchronization may have little impact on storage, and the damage is inferred to be limited.

[data recovery scheme]

1. In order to avoid fault expansion, first of all, complete sector-level cloning of the failed hard disk is made. If part of the hard disk has a physical failure, the hardware recovery team will solve the hardware failure.

2. Analyze the RAID6 algorithm used in storage, and then do 66 possible combinations of missing 2 disks on 12 hard disks according to this algorithm. Manually or through the program to determine the most correct missing disk is possible.

3. Build a virtual RAID platform through North Asia RAID data recovery software or third-party data recovery software, and attach it according to the analysis of missing disk state, disk order, block size, check direction and RAID6 algorithm.

4. Explain the GPT partition structure of the virtual RAID, and then interpret the file system to determine whether the algorithm is correct. If incorrect, adjust the algorithm until the best structure.

5. Migrate the data to another storage in the way of file or sector to complete the recovery work.

[estimated data recovery time]

Mirroring time: within 8 hours (12 parallel processes are mirrored at the speed of each process 60M/S)

Analysis and verification algorithm: 2-4 hours

Migration data: 15 days (file migration) or 3 days (sector migration, the destination storage must be greater than or equal to the source failure storage, and there is no serious damage to the file system)

[emergency advice]

After the failure occurs, the hard disk should be plugged in and unplugged in the shutdown state, and the original location of the hard disk should be marked at the same time. Do not power up the storage after the hard drive leaves the storage. Make sure that all operations are traceable as far as possible.

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Servers

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report