All-Demo Session & Installable ISO for Veeam Hardened Repository

All-Demo Session & Installable ISO for Veeam Hardened Repository

Show first post
This topic has been closed for comments

199 comments

Userlevel 7
Badge +14

@mrizzi2 I’m also no longer able to deploy the new ISO on a physical server. “sorry, there was a problem completing the installation”

@Rick Vanover@HannesK I’m not getting much out of the installer log/report. Can you reproduce the issue or can we provide you anything useful from the installer? 

@Assalihin I used a VM and 2 disks for a POC peice of work we are doing. 100GB boot drive and 500GB data drive and the install took care of everything

Thanks.

Userlevel 2

Hello Community and good day,

I am trying to deploy a test Veeam VHR VM in the lab. Although this test VM boots up just fine using the vanilla Ubuntu .ISO (ubuntu-20.04.6-live-server-amd64.iso), unfortunately there is no way for me to boot it from the most recent Veeam VHR 05 June ISO. UEFI secure boot is enabled.

I reproduced the same issue on a couple of VMs in the lab running on both ESXi 8.0 U1a as well as 6.7.

Has anyone experienced such a thing ?

Thanks and Regards,

Massimiliano

Userlevel 7
Badge +6

@Assalihin I used a VM and 2 disks for a POC peice of work we are doing. 100GB boot drive and 500GB data drive and the install took care of everything

Userlevel 1
Badge

Will sure try this out. But many of my customers use RedHat as their preferred Distibution.
So maybe it will make sense to do the same things with a RedHat .ISO ?:-)

 

We’ll see how this one goes before we engage with other Distros :)

THX. Sounds fair enough :-). I recently had to deal with a bit of RH 8.6 and 9 installs for hardened Repos. RH automatically brings in security profiles for different security standards. I miss that on UBUNTU.

 

 

 

Userlevel 1
Badge

Will sure try this out. But many of my customers use RedHat as their preferred Distibution.
So maybe it will make sense to do the same things with a RedHat .ISO ?:-)

 

We’ll see how this one goes before we engage with other Distros :)

THX. Sounds fair enough :-). I recently had to dela with a bit of RH 8.6 and 9 installs for hardenend Repo. And RH automatically brings in security profiles for different security standards. I miss that on UBUNTU.

 

 

Userlevel 1
Badge

Will sure try this out. But many of my customers use RedHat as their preferred Distibution.
So maybe it will make sense to do the same things with a RedHat .ISO ?:-)

 

We’ll see how this one goes before we engage with other Distros :)
 

THX. Sounds fair enough :-). I recently had to deal with a bit of RH 8.6 and 9 installs for hardened Repos. RH automatically brings in security profiles for different security standards. I miss that on UBUNTU.

 

I used a VM & was successful in installing it….I just had to remember to change the BIOS section to EFI in the VM Options tab.

Did you create the vm with 2 disks or just one? One for Os and the other for data or the iso took care of partitioning?

Thanks,

Said

Userlevel 7
Badge +10

Will sure try this out. But many of my customers use RedHat as their preferred Distibution.
So maybe it will make sense to do the same things with a RedHat .ISO ?:-)

 

We’ll see how this one goes before we engage with other Distros :)

Userlevel 1
Badge

Will sure try this out. But many of my customers use RedHat as their preferred Distibution.
So maybe it will make sense to do the same things with a RedHat .ISO ?:-)

 

Userlevel 7
Badge +22

Very interesting. As someone said this could lead to mass usage. The only danger I see here is that it could get “windows only” admins to install this without them making an effort to learn at least some linux. I have run into situations with customers when say the Linux person left the company and the poor people left behind are like stranded on a desert island. The dreaded words that I have heard a few times on the service provider side of things is “would you mind taking a quick peak at this server, something does not look right and it has no GUI” :( 

Userlevel 7
Badge +14

@wolff.mateus Take a look at the following article: https://www.veeam.com/blog/backup-repository-security-disa-stig-ubuntu-step-by-step-guide.html

Userlevel 7
Badge +17

Ah, I see. Yeah...I just scanned through the script a bit. It’s pretty long. I’ve learned quite a bit of BASH this yr, but there’s quite a bit in it I’m not familiar with 😬

Userlevel 7
Badge +11

I missed this session in MIA, but am about to re-watch. I deployed the LHR server; just need to add the server to VBR to deploy the role on the server. Can’t wait to watch the actual recorded session. Thanks for your efforts Rick!

@wolff.mateus - the script probably contains similar cmds as Paolo uses from his VHR post here...at least, that’s my guess. 😊

No, the hardening script is here, however it does not have a resume what it exactly does on the system.

I’m not an expert in shell script, but I’m going to try ’’read’’ this.

 

Userlevel 7
Badge +11

I presume that you are running on a BIOS machine. Try the same on EFI like @coolsport00 said.

Userlevel 7
Badge +17

I used a VM & was successful in installing it….I just had to remember to change the BIOS section to EFI in the VM Options tab.

Userlevel 7
Badge +17

Hi @Assalihin - do you have (Legacy) BIOS enabled by chance? The install won’t work except for EFI-enabled machines, beit physical or VM.

HI, I tried the iso of the hardened linux install and run into an error on physical and virtual test machines. See snip. Did anyone run into the same error and if yes, how did you get around it?

 

Thanks,

 

Userlevel 7
Badge +17

I missed this session in MIA, but am about to re-watch. I deployed the LHR server; just need to add the server to VBR to deploy the role on the server. Can’t wait to watch the actual recorded session. Thanks for your efforts Rick!

@wolff.mateus - the script probably contains similar cmds as Paolo uses from his VHR post here...at least, that’s my guess. 😊

Userlevel 7
Badge +11

This session rocks!

I deploy VHR on my homelab right now.

Just a question:

What are the steps that hardening script does on the system?

I didn't find this on the github.

Userlevel 7
Badge +14

The pre-configured hardened ISO will be a gamechanger. Although the manual setup hasn't been so complicated, Microsoft only shops with limited Linux skills will now likelier deploy the VHR. And so we will see a higher adoption rate and less successful ransomware attacks. 👏

Userlevel 7
Badge +10

Great session. I followed the link but I didn’t see the customized Linux iso install used at the end of the demo. Thanks for sharing.

Said

Senior Network Admin

I fixed the link! Thanks.

Great session. I followed the link but I didn’t see the customized Linux iso install used at the end of the demo. Thanks for sharing.

Said

Senior Network Admin

Userlevel 7
Badge +20

This was an amazing session. Great things coming from Veeam.