All-Demo Session & Installable ISO for Veeam Hardened Repository

All-Demo Session & Installable ISO for Veeam Hardened Repository

Show first post
This topic has been closed for comments

199 comments

Userlevel 7
Badge +10

@Rick Vanover @HannesK -- Trying to do another deployment after two successful ones but this time I am seeing the following message after a complete setup of the VM with the ISO file but cannot connect to it from VCC server - get the below error.  Any suggestions?  The VCC server can reach the VM via ping.

 

Are any ports blocked, @Chris.Childerhose - as the transport service would need to communicate. Also - I had something like this happen in DHCP labs where on next book a new IP was taken in, so I started ensuring DNS names were used.

Userlevel 7
Badge +20

@Rick Vanover @HannesK -- Trying to do another deployment after two successful ones but this time I am seeing the following message after a complete setup of the VM with the ISO file but cannot connect to it from VCC server - get the below error.  Any suggestions?  The VCC server can reach the VM via ping.

 

Are any ports blocked, @Chris.Childerhose - as the transport service would need to communicate. Also - I had something like this happen in DHCP labs where on next book a new IP was taken in, so I started ensuring DNS names were used.

Yeah, no ports are blocked as this is in our MGMT stack of VMs and VLANs.  I am using Static IP addresses also not DHCP, so I specify the details.  I also ensured that the DNS is updated but going to try something else now that you mention that.

Userlevel 7
Badge +20

Well, my theory did not work so I am stuck on this one DC for deploying these.  Need to do some thinking but if anything, else comes to mind do share.

Userlevel 7
Badge +20

Well, my theory did not work so I am stuck on this one DC for deploying these.  Need to do some thinking but if anything, else comes to mind do share.

Interesting - one random idea Chris….  A) Reboot the VHR and B) do an infrastructure rescan after it is back online.

I will give that a try and see.  I even compared this DC and VMware settings to ones that have worked and they are identical. I even ensured EFI and Secure Boot turned on.  Let me see what this does and update here.

Userlevel 7
Badge +20

Duplicate MAC? If still on a VM...

Shouldn't be as I even deleted the VM from disk to recreate it from scratch and use the previous June 5th ISO too.

OK makes sense. I am not sure why it can’t see it. Any VLAN stuff? That’s about only next thing to think of.

Yeah, the VDS that I am connected to the port group has a VLAN, so I add that to the network config when setting up the ISO VHR.  I did the same thing in other DCs where it worked so not sure about this one and why it is not working.

Userlevel 7
Badge +20

I have the feeling, that this has nothing to do with the ISO itself. So my suggestion would be to ask support, because it’s regular Ubuntu 20.04 which is supported.

Thanks @HannesK.  I will see what else I can come up with and go from there.  Will ask Support if needed.

Userlevel 7
Badge +20

Or something environmental/equipment-related.

That was my next thought as the storage is the same but the hosts are on Cisco UCS whereas the other DCs were HPE C7000 Blade chassis.  I will check everything over as there is something off and will find it.  😁

Userlevel 7
Badge +20

Seeing these messages fairly frequently and can eventually get the installer to work.

 

 

Userlevel 7
Badge +20

Another AHA! moment.  I took a look at the file structure (lsblk) and found that the deployment ended up on the internal SD Card (ISDM).  It really was out of space.  I had to go in to the BIOS and disable the ISDM.  Reinstalled and now I’m able to add the Repository.

Glad to hear you figured it out and that they have noted it as a bug in doing so.

Userlevel 7
Badge +20

I wanted to ask if there was any thought for this project about automation - mainly for the screens that you do have to enter information or just click done can that we in an answer file or something that we can feed into the ISO deployment?

I am trying to think of ways to automate this for my Veeam team to make things easier.  It is not much to do with the current deployment but simplifying it would help me not get as many questions.  😁

Userlevel 7
Badge +20

I wanted to ask if there was any thought for this project about automation - mainly for the screens that you do have to enter information or just click done can that we in an answer file or something that we can feed into the ISO deployment?

I am trying to think of ways to automate this for my Veeam team to make things easier.  It is not much to do with the current deployment but simplifying it would help me not get as many questions.  😁

That’s a good point Chris. I have discussed with one organization about a remote build/remote deploy type of use case. Something like that may be of interest. I’ll relay this and bring up. No promises.

Thanks Rick.  Just a thought to make things easier and hopefully it comes to fruition.  I am still working on that one site that is not allowing me to deploy things sadly.  😢

Userlevel 7
Badge +20

@HannesK - do you know if the ISO supports Cisco UCS?  In particular these models in the screenshot.  This is the one that does not allow me to fully deploy things or I get it deployed then it errors on adding the VHR to the Veeam Console.

 

Userlevel 7
Badge +10

That’s interesting @Chris.Childerhose → especially as a VM if it isn’t working.

Badge

If you enter the ‘normal’ command, the system reboots again. Right after pressing enter after typing the normal command press ESC multiple times until you see the grub menu.

see here:

https://askubuntu.com/questions/381613/how-to-return-from-grub-prompt-to-the-grub-menu

Got it, thanks!

Userlevel 7
Badge +20

For those that have tested on physical servers have you tried it with multiple networks - not bonding?  I need to possibly test this with two different networks possibly where the repo is segregated from our typical VLANs.

Userlevel 7
Badge +20

For those that have tested on physical servers have you tried it with multiple networks - not bonding?  I need to possibly test this with two different networks possibly where the repo is segregated from our typical VLANs.

I have not @Chris.Childerhose  → But curious how this goes as it is the standard Ubuntu network configuration at this point, too risky to make assumptions there with the installer.

Agreed. I am going to test with a VM since I don't have a physical box just yet 

Userlevel 7
Badge +20

For those that have tested on physical servers have you tried it with multiple networks - not bonding?  I need to possibly test this with two different networks possibly where the repo is segregated from our typical VLANs.

what do you mean with “multiple networks”? Multiple network cards in different networks? Meaning you would create a way around firewalls? We won’t support that for sure (bad design)

No one for management and then the other on a secure VLAN for data transfer would be the design.  We want to have the VHR on its own VLAN separate from what we use for Veeam.

Userlevel 7
Badge +20

that’s what I mean… the Hardened Repository in your case has access to two networks without any firewall in between. Why would you want to separate a few kbit/s management traffic if you have 10gbit/s+ anyway for data traffic? 

SSH is disabled, so that cannot be the reason.

Ah I got you. That makes sense. So no need to test just ensure it is on the separate VLAN we are going to use and ensure comms between that and VBR.  Thanks Hannes.

Userlevel 7
Badge +20

Hello,

I’ve just deployed a test repo, and now I’m starting to play with it. Once rebooted, I’ve realized that it’s impossible to run sudo to change disk layout, for example I wan to modify a LVM instance, or extend a filesystem and I can’t see how to do this…..

Any idea?

 

I believe you need to log in as root or enable the login again after the deployment since the hardening of the server removes this.  Once you have the system running why would you want to change it though?  The OS drive is set up with the ISO and the larger drive becomes the backup.  Just curious on the use case to make changes.

I believe the other way to make changes is during the deployment of the ISO as you can manually set up the disk layout.

***UPDATE - Hannes beat me to it LOL ***

Userlevel 1

Hello,

I’ve just deployed a test repo, and now I’m starting to play with it. Once rebooted, I’ve realized that it’s impossible to run sudo to change disk layout, for example I wan to modify a LVM instance, or extend a filesystem and I can’t see how to do this…..

Any idea?

 

I believe you need to log in as root or enable the login again after the deployment since the hardening of the server removes this.  Once you have the system running why would you want to change it though?  The OS drive is set up with the ISO and the larger drive becomes the backup.  Just curious on the use case to make changes.

I believe the other way to make changes is during the deployment of the ISO as you can manually set up the disk layout.

***UPDATE - Hannes beat me to it LOL ***

What if your backup drive needs to be extended?…..sometimes data grows, or even grows a lot….. We run our production backup in a physical self deployed repo server with hardening tips from Gostev, and others, and I’ve had to extend the repo filesystem because of this… I was just wondering if this ISO was a better option for us

Userlevel 7
Badge +20

Hello,

I’ve just deployed a test repo, and now I’m starting to play with it. Once rebooted, I’ve realized that it’s impossible to run sudo to change disk layout, for example I wan to modify a LVM instance, or extend a filesystem and I can’t see how to do this…..

Any idea?

 

I believe you need to log in as root or enable the login again after the deployment since the hardening of the server removes this.  Once you have the system running why would you want to change it though?  The OS drive is set up with the ISO and the larger drive becomes the backup.  Just curious on the use case to make changes.

I believe the other way to make changes is during the deployment of the ISO as you can manually set up the disk layout.

***UPDATE - Hannes beat me to it LOL ***

What if your backup drive needs to be extended?…..sometimes data grows, or even grows a lot….. We run our production backup in a physical self deployed repo server with hardening tips from Gostev, and others, and I’ve had to extend the repo filesystem because of this… I was just wondering if this ISO was a better option for us

Ok.  That makes sense then as I was just curious.  Then you will need to follow what Hannes said about single-user mode and the URL he posted to do this.

Userlevel 7
Badge +20

What would cause the ISO to fail before it even gets to the network configuration screen? The Network config screen pops up then disappears immediately and says there was an error. while behind that popup there is this line “subiquity/Drivers/_list_driver/wait_apt” with a spinning bar after it. 

This is on a Dell R730XD with UEFI on, Secureboot Enabled, a Raid1 OS array, and a Raid 6 backup array both configured in the Bios before attempting install. I have attempted install without any arrays configured and i get the failure at the same point. 

I have attempted once with an IP configured before the install to see if not seeing internet initially is the cause and that did not change anything.

I am interested in the outcome of this as I am going to be testing a similar setup but on HPE DL380 G9 server but similar RAID configs, etc.

Userlevel 7
Badge +20

FYI Christoph and Hannes have issued a new version of the .ISO. Updated in the main post.

Sweet!  Is there a changelog for it @Rick Vanover ?

Userlevel 7
Badge +20

the new feature is: it works offline. No other changes :-)

Very cool. Thanks Hannes. Will be testing this one now for my documentation as we plan to use this moving forward to make deploying XFS Hardened Repos for all our backups.  😎