Bring your knowledge and expertise while creating blogs and podcasts
Recently active
Hello Community, As part of my ongoing work with Veeam Backup for Google Cloud (VBGC), I’ve come across an important yet sometimes overlooked component in its architecture, the Worker Profile. Worker profiles play a critical role in the performance and reliability of your backup and archiving operations in the Google Cloud Platform (GCP). In this article, I’ll explain what worker profiles are, how they are used, why GCP quota limits matter, and how to plan your configurations to avoid common pitfalls. What Are Worker Profiles? In Veeam Backup for Google Cloud, worker instances are temporary compute instances deployed automatically by the VBGC appliance to handle backup, restore, and archiving tasks. These instances are configured via Worker Profiles, which you manage from the Web UI under:Configuration ➝ Workers ➝ ProfilesEach profile defines:The machine type The region The use case (e.g., regular backup vs. archiving) Default Worker Profiles and Their Purpose: - Primary profile (e2-hi
Late last year Microsoft released Azure Data Box Next Gen, and, for US, EU, UK, Canada and US Gov, this version has fully replaced the old generation. Other region roll-out is still in progress. Using Azure Data Box Next Gen is supported with Veeam and is significantly faster than the previous generation.We often get questions about seeding data with Veeam Backup and Replication. So, I wanted to cover briefly how that works.1. Ordering Azure Data BoxOrder your Azure Data Box with ‘Import to Azure’. Selecting the appropriate subscription and resource group. Select source country, associated with the address this Data Box will be delivered to, select the destination Azure region, and choose from the Data Box 120 or Data Box 525 as they have the same form factor. Pricing of course will be different. There is a service fee, shipping fee and fees for extra days over the built-in 10 or 20 days depending on the Data Box capacity. Give your order a name, select a brand-new storage account a
On May 28th of this year, I had the incredible opportunity to join Rick Vanover and Emilee Tellez at Security Field Day 13 in San Jose, California! I was able to tag along and help them facilitate their smashing Security Field Day presentation, centered around Veeam’s latest innovations in security. If you are unfamiliar with what Security Field Day is, it’s a live streamed presentation that includes an in-person roundtable of security thought leaders and experts to weigh in and drive the conversation about what really matters in the current security landscape. I wanted to take this opportunity to break down the five-part presentation and share my feedback on the most impactful and interesting moments. Have You Seen Veeam Lately?This section was a great starting point to give a fresh update on Veeam. Highlighting our pillars of Data Backup, Recovery, Portability, Security, and Intelligence made many realize just how much Veeam has evolved. When it comes to Veeam’s data security, it’s a
A common request from customers with large AWS environments has been how best to set up IAM roles for Veeam Backup for AWS. Customers with dozens or hundreds of accounts had to configure templates or scripts to create roles in each of their accounts and then add them to Veeam. This can be a time-consuming endeavor at scale, and I created a solution that uses native AWS services to automate the process. Thankfully, that solution only applies to previous versions of Veeam Backup for AWS now.Veeam Backup for AWS v9 now has built-in support for AWS Organizations, allowing you to easily protect all of your AWS resources regardless of the size or complexity of your organization. Let’s take a look at this new feature and how it works. Laying the foundationBefore you can leverage this feature, you must have AWS Organizations enabled, and you need to be familiar with AWS CloudFormation and StackSets and how these services work together. AWS Organizations and CloudFormation are de facto standard
Certificate improvementAbout more news features on new “VMware(R) Cloud Foundation 9” I think one of all need mension is the unified certificate management within VCF Operations.This feature facilitates smooth, non-disruptive certificate updates, automatic renewals with multiple Certificate Authorities, and the ability to import externally signed certificates.Consequently, it resolves operational difficulties, enhances security measures, and ensures greater compliance. Certificate Alerts Tab Do you remember when your vCenter’s certificate expired resulting in a Veeam backup crash and related panic?Now with this long-awaited and long-requested feature, this will no longer be a problem we have to face !
Hello everyone, I'm continuing my exploration of Veeam v13. Today, I'm sharing with you a presentation of the Web UI and the thick client. In this first section, we will cover:Configuring a component via the WebUI Configuring a component via the thick client Configuring a backup job from the WebUI Performing a restore from the WebUIEnjoy the read!Find my previous article here : 1. Veeam Software Appliance WEB UI / Console⚠️ Reminder: We are testing a beta version here. Some features are still missing, incomplete, or may not be included in the final release.Deployment: In this Beta version, to deploy V13 as a virtual machine, the following prerequisites are required:Two hard drives of at least 256 GB each are mandatory. I have allocated 4 vCPUs and 16 GB of vRAM. Rocky Linux is used as the OS type, as this is what Veeam uses here. A paravirtualized SCSI adapter will be used by default.Additional Information:The design of the WebUI interface is 80% complete. The thick client interface i
As promised in Part XV, today we will be looking at common environment architecture topics. These are very important parts of planning and operating a secure backup environment.Of course, the backup environment cannot be viewed in isolation from the rest of the IT landscape. Everything interacts and influences each other. There are specific requirements for backup, but most of the considerations in this text also apply to the production environment. However, I will still refer to the backup environment in this text.But – as always – it is not an aspect that alone leads to a secure environment. Therefore, in this context we will also look at some side aspects in general.Designing an effective backup environment architecture is pivotal for maintaining data integrity, availability, and security in today's data-centric world. What are the main threats to backup data?Wrong placement of backup environment components Hardware damage to backup systems Power outages or disasters at one location
If Oracle backup provided over backup job with application aware processing, has limitation with restore i regards of number of channels. Restore via gui is possible over Veeam Enterprise and via Veeam Oracle Explorer:Veeam Enterprise Manager is restore possible only via 1 channel Veeam Oracle Explorer by default has set 1 channel To change number of channels for Veeam Enterprise manager is not possible, but is possible to change number of channels via Veeam Oracle Explorer via config.xml file: %programdata%\Veeam\Backup\OracleExplorer\Config.xml Content example: <Veeam> <OracleExplorer> <Oracle RmanCopyJobChannelsCount="4" /> <Oracle RmanCopyJobChannelsByDatafilesCount="true" /> </OracleExplorer></Veeam> Our tests speed:>> - 1 channel: - 115 GB, 18 mins 109 MByte/sec>> - 4 channels: - 115 GB, 15 mins 130 Mbyte/sec>> - 12 channels: - 115 GB, 14 mins 135 Mbyte/sec The speed could not be much difference, but in case of TB of
Hello Veeam Community, I want to share a recent experience I encountered with the Linux-based Veeam Backup Appliance (used via plug-in to protect GCP workloads). This is part of our growing environment where we use Veeam Backup for Google Cloud. Issue Summary:Yesterday, I ran into a serious issue where the backup appliance became unresponsive. Here’s what happened: Problem Description:Appliance DB disk was full this caused log files to pile up. Logs were not auto-deleting, consuming critical DB disk storage space. The appliance showed the following errors below: "Failed to get server IP address" "Backup Appliance is unavailable"The Veeam plug-in was unable to communicate with the appliance, and no backups could proceed at that point. Root Cause:The database disk inside the appliance reached full capacity. ( Above Screenshot ) Logs under the appliance’s backup storage directory were accumulating over time. The appliance could not boot its services properly due to no free space, which
I had the chance to spend some of my evenings on adding some more functionality to my little pet project… or as I have been referring to it, the RVtools for your Cloud and Kubernetes environments and platforms. We already had the ability to grab details on your Kubernetes, AWS and Azure resources, I also did add some Veeam Backup & Replication inventory as well. With this 0.0.3 release we added Google Cloud Platform (GCP) and Terraform State File inventory. But probably the biggest feature has been around the user experience. The concept of the tool was to be able to use either the CLI or browser and this remains the same but the UI now can be used with a lot more flexibility. I did a full on demo session of the state of the project and would love to get your feedback. What should I add next? What are we missing? What doesn’t work? Project can be found here - https://github.com/MichaelCade/kollect
Recién integrándome al grupo, me llamó la atención el sistema de insignias (badges) en el perfil de muchos usuarios. Esa curiosidad me llevó a investigar más sobre cada una, y aquí te comparto lo que descubrí 👇En la Comunidad Veeam, tu participación no pasa desapercibida. Cuanto más compartes, ayudas o lideras... más visibilidad y reconocimiento puedes ganar. Desde certificaciones hasta hackathons, hay una insignia para cada perfil.🧑🤝🧑 Comunidad y Reconocimiento🏅 Medalla 🎯 ¿Cómo la consigues? 🐼 Veeam Legend Ser constante, activo y colaborativo en el Hub 🛡️ Veeam Vanguard Postularte con aportes técnicos relevantes (blog, labs, presentaciones) 🧠 Top Contributor Publicar y responder con contenido útil y validado por la comunidad 👑 Top Panda (1000+) Acumular karma por tus contribuciones valiosas 🎓 Certificación y Especialización🏅 Medalla 🎯 ¿Cómo la consigues? 📘 VMCE Aprobar el examen de Veeam Certified Engineer 🌟 VMCA Obtener la certificación como V
Over the last few years, the time to execute ransomware attacks dropped 94%; now, criminals take, on average, just 3.85 days to deploy a ransomware attack.On the other side, according to the “Veeam Ransomware Trends – 2023 Global Report”, recovering the affected environment after a ransomware incident takes an average of 3.3 weeks of work, equivalent to 136 business hours of business downtime.Here is the link for this Veeam’s report:https://go.veeam.com/ransomware-trends-report-2023Along with exploiting application vulnerabilities, hackers heavily utilize client-side compromise techniques to deploy ransomware.In each attack, criminals must take well-known steps to reach their targets. Based on this, models were created to identify and prevent cyber intrusion activity. One of the most famous is the Cyber Kill Chain, developed by Lockheed Martin.For this purpose, we will focus on four stages of a client-side attack: delivery of exploitation, installation, command-and-control, propag
In part I of this series we have seen how to move a tape library with all data to another VBR server which has already data on it.https://community.veeam.com/blogs-and-podcasts-57/veeam-and-tape-i-moving-a-tape-library-with-data-from-one-vbr-server-to-another-1654 The open question was, how do I get my tapes with data to the correct media pools without losing my data…When you select to move a tape to a media pool the following message appears:So, the tapes are marked free, and the data is lost when a tape is moved? A quick check of the helpcenter and the forums says exactly this…https://helpcenter.veeam.com/docs/backup/vsphere/moving_tapes_to_custom_pool.html?ver=110But is this correct?Fortunately, it is not. The tape is marked free when it is moved, but the data on the tape is not lost. Its metadata is deleted from the Veeam database – and this can be recreated. All the tapes from the new library are assigned to the pool “Imported” Move the tapes to their corresponding media pools.
Scenario:Very recently a customer asked me if Veeam could leverage Data Domain mtree replica for DR purposes.Of course, the answer is YES! While this idea is not new, I thought it would be a good reminder of Veeam’s backup import capabilities. Steps:You must use Data Domain repository on the source site. It most likely will be declared as a DDboost share. The mtree should be replicated to the DR site. Note that the mtree replica will be Read Only! The mtree replica needs to be exposed as a share over your protocol of choice (CIFS, DDboost), so it can be defined in the DR VBR server. In this example, I chose DDboost.Note again that this DDboost share is Read Only! The last step is to declare that DR DDboost share and import backups You should now be able to access these backups from the “Disk (Imported)” section. Remember that you will have to manually rescan that repository in order to refresh new “mtree replicated” restore points.
VM networking was much simpler. In VMware, there is a lot of planning when managing the network. You create virtual switches per host and assign properties like MTU size, VLAN, etc and pair those with physical NICs. You setup VMkernel NICs with specific roles to control host traffic. With Scale computing, you set a native VLAN on the physical switches and use standard VLAN Trunking to the host. You assign an IP on the management network which uses the default VLAN and then tag VMs on their virtual NICs directly, skipping all the complex concepts of a vSwitch. A separate Linux bridge with different physical NICs or a subinterface with a VLAN is used for the cluster backplane used for storage and inter-node cluster communication depending on how many NICs the host has. If a VM needs to be on multiple networks, you can assign one NIC with a certain VLAN, and another NIC with a different VLAN. You can also choose not to tag at the port and let the guest OS setup VLAN tagging, similar to as
In some situations/scenarios it is absolutely necessary to move the Veeam Configuration Database (PostgreSQL) to another hard disk of the Backup & Replication Server (e.g. if the C: partition is too small). After installation, the Postgres databases are located under: C:\Program Files\PostgreSQL\xx\data (Unfortunately, the path cannot be changed during the Veeam installation).Moving the PostgreSQL database is actually quite simple and can be done with pgAdmin. Before you start the migration, you should create a VMware snapshot and/or a Veeam Configuration Backup.Download pgAdmin from their website (pgAdmin – PostgreSQL Tools) and install it on the Veeam Backup & Replication Server.Add a second hard disk to the VBR server and create a folder for the database in it.Because the PostgreSQL service runs under the “Network service” account, the folder must be correctly authorized. To do this, add the “Network service” user with “Full control” to the folder under “Security”.Stop the V
We've been a certified Scality ARTESCA partner for almost six months. In addition to my lab installations, I've already deployed four productive ARTESCA systems for our customers, both single-node and three-node cluster systems.Since the beginning of June, version 3.1.1 has been available for Scality ARTESCA. Documentation & Release NotesThe corresponding documentation and release notes can be found at https://documentation.scality.com/ . Access is via OneLogin with an existing Scality account. To upgrade from version 3.1.0 or 3.0.X to the latest version, follow the steps described here: https://documentation.scality.com/Artesca/3.1.1/upgrade.html . Or check out the step-by-step process in the corresponding blog post here 😉. ARTESCA UIAfter successfully logging into the ARTESCA UI with the appropriate authorization… …we are greeted by a notification that a new ARTESCA version is available.The update components can be downloaded via the ARTESCA UI, as in this scenario, with the
Using S3 Object Lock’s Governance mode with Veeam Backup & Replication v12.1 Veeam Backup & Replication (VBR) v12.1, which was launched in December of 2023, has many great features and new capabilities. One of those features is the ability to use S3 Object Lock’s Governance mode when you setup an object storage repository to be immutable. The purpose of this blog is to introduce you to the Governance mode and how to use it within VBR 12.1.So, what is Governance mode? To answer that I first need to briefly explain S3 Object Lock. It is a feature of S3 and S3 Compatible object storage to prevent objects from being deleted or modified until the object lock retention has been met and the lock expires. There are two modes for the object lock retentionCompliance GovernanceCompliance mode has been used by Veeam Backup & Replication since v10 of VBR was released in February of 2020. Compliance mode locks the objects with a high level of strictness. This strictness includes: p
One of the standout features in Veeam’s arsenal is the ability to verify backups in an isolated VMWare and / or Hyper-V environment using SureBackup and DataLabs. These tools allow organizations to automatically spin up virtual machine and agent-based backups in a secure, sandboxed network…. often referred to as a “Clean room”, where Veeam can (but not limited to):Ensure the backup does not contain any malware / ransomware / virus’ Check for file system consistency Verify application services start as expected Perform custom script checks to validate functionalityWhile these capabilities shine in an on-premises VMware and Hyper-V environment, verifying backups in Azure brings a different set of technical challenges:No vSwitch / vRouter control in Azure Lack of deep VM network customization No ability to intercept or NAT Traffic Azure resource constraints and API GapsWhile Azure presents challenges, the importance of verified, clean backups remain critical. Even with these challenges, w
For those with IBM Flash System Storage, you will have noticed a surprise at the end of your 12.2 upgrade. It will ask you to install the plug-in on your Veeam server at the end of the process. It will also tell you that backup jobs may not work properly until you do. The first take away is don’t start this upgrade at 3PM on a Friday thinking you have plenty of time to upgrade your entire Veeam infrastructure before the end of the day. This extra step didn’t take too long but still added some extra time to the process. As with anything, check the release notes, and compatibility with all hardware, software, and firmware before doing installs on production servers. This is a very simple install that requires hitting next a few times and waiting. Setup In this test, I’m using both backup from storage snapshots, as well as snapshot only jobs. Snapshot jobs are easy to configure as seen below.For the backup repository, choose snapshot only. If you configure a secondary destination, you
I had the discussion two times last week, so I think it is worth sharing here.You may have noticed, VMware deprecated image level backup of its vCenter Appliance (VCSA) with vSphere 7. What does this mean? Basically, it is still supported to do image level backup and restore with VCSA 7.0. But it will not be supported in future releases. Notice that U1 and U2 are still 7.0 versions. With 7.n, with n>0, VMware will not support image restore of VCSA any more. From my perspective, this step was taken because problems arise when restoring this Linux appliance. I have seen many appliances requiring a filesystem check after restore or crash. When you are lucky, everything works fine afterwards. If not, you have to file a support ticket.To avoid this, VMware offers a new way for VCSA backup. Since 6.5 it is possible to run file-based backups and restore of VCSA. Since 6.7 this can be scheduled. With this, new protocols are supported as well: FTP, FTPS, HTTP, HTTPS, SFTP, NFS, or SMB. Pleas
If you have usecase to change location (disk) of PostgreSQL binaries with databases, where is not an option by Veeam wizard and change user, and if you need to change from default postgres user to different one. Or only one of the option.My usecase is to change from D:\ to E:\ drive and change back from non-standard user veeam to postgres due custom installation of PostgreSQL.Changing user of databases is possible, but not for templates, so easy. This usecase is for administrators with minimal knowledge, so via easiest way :) Stop Veeam Services After Veeam application is down, change on PostgreSQL could be provided.First is needed to create postgres user as is missing due custom installation (not via Veeam wizard). This could be done for existing role.Change postgres back as roleSet user as owner of databases - VBR and EM. Changing from veeam user to postgres userVBR DatabaseEnterprise Manager DatabaseChecking of ownership via psql.OwnersLocal backup of all This Dump will be
When discussing Azure App Registrations backup and recovery, one question that often comes up is, “How does Veeam handle secrets and certificates that are embedded within these registrations?”. It is a great question and I wanted to take the opportunity to double click on this.Client Secrets:Client secrets in App Registrations are treated similarly to passwords. Once a secret is created, its value is only displayed once and is never retrievable again. This behaviour is by design, enforced by Azure and Microsoft Graph to maintain strong security hygiene.It is because of this that:Veeam does not back up or restore the actual secret values as that data is not exposed by the Microsoft Graph API. Veeam does capture metadata such as secret names, creation dates, expiration dates, and key identifiers. The secret value itself must be stored securely elsewhere, such as in Azure Key Vault, at the time of creation. Here is a great post from @johan.h which shares how to leverage Veeam to protect
Hi Folks, My name is Geoff Burke. I am Community Manager at Object First. I am a Veeam Vanguard and Veeam Legend. I was asked to write something about the Veeam Community and do a short video for the Spotlight series. Being part of the Veeam 100 Community has been truly a transformative experience for me. I was accepted into the Veeam Community as a member of the inaugural Veeam Legends in 2021. Since then I have been lucky enough to renewed numerous times and was also accepted into the Veeam Vanguards.Make no mistake, the Veeam Community is not about you or me, it is about us! The people you engage with in these communities are top professionals and are very generous when sharing their knowledge. They help you become a better data protection expert and grow. You make friends around the globe and these relationships really to enrich your life.Most importantly the Veeam 100 community is fun! The yearly summits in either Prague or Berlin are the highlight of the year, where you not only
Out-of-the-Box Immutability (Ootbi) is a purpose-built backup storage appliance developed by the founders of Veeam, specifically for Veeam!OOTBI delivers secure, simple, and powerful on-premises backup storage without requiring any security expertise. It will interest you to know that we have discussed extensively the steps to set up, configure and integrate OOTBI with Veeam. Please refer to the following links on the steps to set up and configure a physical appliance.If you're unable to test or purchase the physical appliance, you can still explore OOTBI using the virtual Storage Appliance (vSA) in a virtual environment, as demonstrated in this guide. If you have access to a vSphere environment, follow the steps below to set it up in your labIn this guide, I’ll show you how to deploy the VSA in a Proxmox VE environment. Additionally, here’s a complementary resource showcasing Veeam Hardened Repository (VHR) installed and configured on Proxmox VE.Note: Because you cannot run a Type 2 h
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.