Infinidat InfiniBox Data Recovery
InfiniBox is Infinidat's high-capacity block and file array, built around triple-active controller nodes and a proprietary declustered RAID scheme called InfiniRaid. Enterprises typically deploy it for large-scale primary storage and backup targets, so recovery cases usually involve either multiple concurrent drive faults inside a section or logical damage to volumes and file systems presented from the array.
Platform Lineage and Naming
Infinidat launched the original InfiniBox in 2015, followed by the F-series (F2000/F4000/F6000) hybrid platforms and later the InfiniBox SSA and SSA II all-flash lines. The G4 generation refreshed controller hardware and networking while keeping the same InfiniRaid data layout and management software.
InfiniGuard, previously marketed as DDE (Data Domain Extended, later Infinidat's own dedupe backup appliance), reuses the InfiniBox storage engine underneath a purpose-built deduplication and backup-target layer, so its recovery characteristics track the base platform closely.
- InfiniBox F-series (F2000, F4000, F6000)
- InfiniBox SSA and SSA II all-flash
- InfiniBox G4 generation
- InfiniGuard (formerly known internally as DDE)
- InfiniSafe immutable snapshot technology
- InfiniRaid declustered RAID engine
Generations and Models We Evaluate
| Generation / family | Models |
|---|---|
| Hybrid | InfiniBox F2000, F4000, F6000 |
| All-flash | InfiniBox SSA, SSA II, G4 all-flash configurations |
| Backup target | InfiniGuard appliances built on the InfiniBox engine |
Architecture and Data Layout
InfiniBox nodes run in a triple-active configuration, meaning three controller nodes can each service I/O simultaneously, with data mirrored in cache across all three before being committed to persistent media. This gives the array resilience against a single node failure without an interruption in service, but it also means the state of all three nodes matters when reconstructing a system after a serious fault.
Data is distributed across drives in large sections using InfiniRaid, a declustered parity scheme that spreads both data and parity widely rather than using fixed RAID groups, which shortens rebuild exposure after a single drive loss but complicates manual reconstruction if multiple drives are lost close together.
InfiniSafe provides immutable, air-gapped-style snapshots intended for ransomware recovery; where these snapshots exist and have not been deleted or expired, they are usually the fastest route back to a known-good state ahead of any deeper recovery engagement.
Protocols and formats: Fibre Channel, iSCSI, NFS, SMB, VMware VAAI, InfiniSafe snapshot API
- InfiniRaid declusters data and parity across a section of drives rather than fixed-width RAID groups, which affects how many concurrent drive losses a section can tolerate.
- Triple mirroring of write cache across controller nodes protects in-flight writes but requires all relevant node states to be preserved together after a serious fault.
Failure Scenarios
Logical failures
- Volume or file system deletion, including presented NFS/SMB shares
- InfiniSafe or standard snapshot expiry or deliberate removal
- Failed firmware or software upgrade across controller nodes
- Storage pool or section metadata corruption
- Host-side file system or database corruption inside presented volumes
- Misconfigured replication or migration overwriting live data
Hardware failures
- Multiple drive failures within a declustered section exceeding tolerance
- Controller node failure combined with cache inconsistency across the remaining nodes
- Backplane, enclosure or interconnect faults
- Power-loss events affecting more than one node simultaneously
- InfiniGuard appliance faults affecting the underlying dedupe store
Encryption and credentials
InfiniBox supports data-at-rest encryption with array-managed keys. Preserve controller configuration alongside drives, since encrypted sections cannot be reconstructed from media alone.
What Not To Do Before an Evaluation
- Do not run rebuilds, reconstructions or re-initialisations against an array that has already lost more drives than its protection level allows.
- Do not recreate pools, aggregates, disk groups, storage pools or clusters — these operations write new metadata over the structures a recovery needs.
- Do not swap drives between slots, and do not reorder shelves. Record the original slot and shelf positions before removing anything.
- Do not run file-system repair tools against production volumes before the underlying storage layer has been evaluated.
- Do not restore a backup or replication set over the affected volumes until the recovery scope has been assessed.
- Do not eradicate deleted volumes or empty recycle/destroyed states on platforms that hold deleted data for a retention window.
Our Evaluation and Recovery Process
- Intake and platform identification — array model, generation, firmware, protection layout and the sequence of events that led to the failure.
- Read-only evaluation of the media and array structures, including assessment of drive health and the extent of any physical damage.
- Forensic imaging of all contributing media, with cleanroom work where drives require it. Originals are preserved unaltered.
- Reconstruction of the storage layer — pools, aggregates, parity groups, chunklets, extent groups or objects — from the images.
- Extraction of the layers above: file systems, virtual machines, databases, mailboxes and shares.
- Verification against a file list and customer-nominated critical data, followed by secure return on encrypted media.
Frequently Asked Questions
Does InfiniSafe guarantee we can undo a ransomware event?
InfiniSafe snapshots are immutable while retained, but they must exist and be within their retention window at the time of the incident — expired or never-configured snapshots leave no built-in undo path.
Can InfiniRaid sections be rebuilt like a normal RAID array?
Not with generic RAID tools. InfiniRaid declusters data and parity across many drives in a pattern specific to Infinidat's software, so reconstruction needs an approach tailored to that layout.
Is InfiniGuard recovery different from InfiniBox recovery?
InfiniGuard is built on the same InfiniRaid engine, so the underlying storage recovery approach is similar, though the deduplication and backup-catalogue layer on top needs separate handling.