Bring your knowledge and expertise while creating blogs and podcasts
Recently active
When running a Veeam backup, you may encounter the following error:One or more errors occurred. (The remote certificate was rejected by the provided RemoteCertificateValidationCallback.)This issue is typically caused by a trust problem between the Veeam Backup & Replication (VBR) server and a managed server or backup component.ResolutionTo resolve the issue:Open the Veeam Backup & Replication console. Navigate to Inventory. Trust allRetry the backup job.Once the certificate trust is restored, the backup should complete successfully.ConclusionIn most cases, this error indicates that the remote certificate is no longer trusted by the VBR server. Re-establishing the certificate trust relationship resolves the problem quickly.
Back in the days...Do you remember the Matrix screensavers from back in the day? Green characters cascading down your screen while your PC idles away. Everyone had one at some point. And somehow — it was just cool.The idea hit me during one of those moments where you should really be doing something else: What if the characters weren't random glyphs, but instead IMMUTABILITY, RANSOMWARE RECOVERY, ZERO-TRUST RESILIENCE and VEEAM DATA CLOUD VAULT?As some of you may know, I have absolutely no clue about coding — but every now and then I get crazy ideas. This one is for you. From One Idea to Almost 100 VersionsWhat started as a small weekend experiment turned into a real project. I had the idea, the direction, the requirements — and with Claude as a coding partner, we built it step by step. Every version tested, verified, adjusted. Comments added, fine-tuning done. Across multiple evenings and iterations.Then, somewhere around version 35, another idea: What if there was also a Star W
@Rick Vanover announced (thanks Rick!) during today’s Weekly Recap the new #EmpowHerVMCE+ Accelerator, and I can’t describe how proud I am. A lot of people worked on this initiative, but special recognition goes to @ertelle1, who first had this idea and whose drive, vision, and collaboration made this happen.I took part in leading the 2023 edition of EmpowHer VMCE+, and I saw firsthand how this program was an opportunity to change trajectories. Participants did not just become better technical professionals, they strengthened their confidence and sense of empowerment. They confidently stepped into the room and proved that they belong in this industry, and that they have a place on the front line.And that is powerful.Some of them changed roles, many progressed in their careers, and some, like @leaha and @brnavarro, became familiar names in the community and are now leading the WA-IT! conversation. The impact they created is significant, they became role models and are inspiring ot
During the upgrade of Veeam Backup & Replication to version 13.2.29, I encountered the following warning during the Configuration Check phase:Trusted hosts hardeningYour remote host trust option is set to Manual. After the upgrade, open a backup console and make sure all your backup infrastructure servers are trusted. At first glance, this message may seem concerning, but it is important to note that it is not a blocking issue and does not prevent the upgrade from completing successfully.Why Does This Warning Appear?Starting with recent Veeam releases, the platform has introduced additional security controls to strengthen communication between backup infrastructure components.In my environment, the Remote Host Trust policy was configured as Manual. This means that Veeam does not automatically trust remote infrastructure servers such as:Backup Repositories Backup Proxies Mount Servers WAN Accelerators Other managed Linux or Windows hostsBecause the trust relationship must be verifie
...don't let them drift apart With Veeam Backup & Replication v13 and the new Veeam Software Appliance (VSA), many of us are enjoying the convenience of components that keep themselves up to date. The VSA is deployed and updates itself automatically — convenient, right? Yes, mostly!But there's a catch that just bit me in my lab environment, and I wanted to share it quickly before it trips someone up in production. The ScenarioImagine you already have one or more Veeam VSA appliances deployed. They update themselves — in this case to 13.0.2. So far so good.But not everything in your environment is an appliance. Your Veeam Backup Enterprise Manager might still be running on a Windows server (it happens). Enterprise Manager was therefore not automatically updated alongside the VSA — and suddenly your backup server shows up as offline in the Enterprise Manager console. Cannot add backup server version 13.0.2.29 to Enterprise Manager server version 13.0.1.2067. Upgrade the Enterprise M
One of the most common things I notice during Veeam deployments, health checks, training that I deliver and customer workshops is that email notifications, Syslog and SNMP integration are often left unconfigured.The backup jobs work. The repositories are available. The backups complete successfully.But when I ask about notifications or centralized logging, the answer is frequently:"We haven't configured that yet." Why This MattersVeeam provides native integration with email systems, SNMP and Syslog servers, allowing administrators to receive immediate visibility into backup activities, warnings, and failures.These integrations are not just operational conveniences, they are important security controls.When a backup job finishes, Veeam can automatically send a notification email. Likewise, relevant events can be forwarded to a SNMP and Syslog server for centralized monitoring, retention, and correlation with other infrastructure events.This means:Faster detection of backup failures Bett
The ultimate test of cyber resilience: recovering when all you have left are your backup files Most organizations spend significant time and effort protecting their backup data.They implement:Immutable repositories Air-gapped storage Tape archives Object storage with Object Lock The 3-2-1-1-0 or 3-2-1-2-0 ruleAs a result, they feel confident that their data is safe.But let me ask a different question:What if your Veeam Backup & Replication server no longer exists?What if ransomware, a hardware failure, human error, or even a disaster destroys:The Veeam Backup Server The configuration database Enterprise Manager Credentials Documentation Recovery runbooksAnd all that remains are your protected backup copies?Could you still recover your business?If you cannot confidently answer "yes", then you may have discovered the biggest gap in your disaster recovery strategy.Backup Data vs. Recovery CapabilityMany organizations focus on protecting backup files.That is important.However, cyber r
In today’s threat landscape, backup and management platforms have become prime targets for cyberattacks, particularly in multi-tenant service provider environments. Ensuring the security and integrity of these systems is no longer optional—it is a critical operational requirement.Recently, a critical vulnerability (CVE-2026-32998) with a CVSS v3.1 score of 9.4 has been identified in Veeam Service Provider Console (VSPC) version 9 builds. This vulnerability can potentially allow remote code execution (RCE) through specific features such as alarm script execution, exposing service providers to severe risks including unauthorized access, system compromise, and lateral movement across managed infrastructures. [community.veeam.com]All versions prior to VSPC 9.2.1.33875, including 9.0.0.29860, are affected, making it imperative for organizations to take immediate action. [community.veeam.com]This guide is designed to provide a clear and practical walkthrough on how to safely upgrade Veeam Se
When IT professionals discuss availability, business continuity, and data protection, the conversation usually focuses on backup software, immutable storage, disaster recovery plans, and cybersecurity.Those technologies are critical.However, some of the most dangerous Data Center Risks have nothing to do with software, storage arrays, or backup systems.Sometimes, the real threat is much closer than we think.Recently, I was called onsite to investigate an issue involving a tape library. One of the drives had grabbed a tape cartridge and failed to release it properly. The task seemed simple: remove the tape, validate the drive, and confirm everything was operating normally.A routine service call.At least, that's what I thought.What I discovered that day had very little to do with backup infrastructure and everything to do with governance, operational discipline, and the hidden risks that can quietly develop inside critical environments.The First Sign Something Was WrongAs soon as I enter
Recently, a customer asked me:“Hey — is it possible that VMware tag backup isn’t working?”The reason: After a Full VM Restore (Restore to original location), the VM’s VMware tags were suddenly gone. In the restore log it basically said:“These tags were not present at the time of backup — so I’m removing them.” And that’s despite the fact that the tags were definitely set in production (otherwise the customer wouldn’t have been able to pick up the VM in their jobs using tag-based selection in the first place). A test with another VM showed the same behavior. At that point it was clear: this wasn’t a one-off. So how does Veeam get the idea that a VM has “no tags” — even though it does? What is a VMware Tag (and why is it relevant for backups)? VMware tags are metadata in vCenter that can be assigned to objects (for example, VMs). Typical use cases include:Organizational mapping (customer, environment, cost center) Technical classification (OS, SLA, app) Automation (backup scopes, policie
Yesterday, I published an article on #CloudCity about my FinOps journey.Check here: FinOps in Practice: Optimizing Cloud Value with AWS, CloudCheckr, and VeeamI'd like to highlight some key initiatives that helped my team strengthen data protection while improving cost control and reducing expenses associated with backup infrastructure assets. Resilience, Backup & High Availability - by CLOUDCHECKRCloudCheckr identifies risks related to data protection and business continuity, ensuring workloads are prepared for failures, accidental deletions, and downtime.Examples of recommendations:• EBS volumes without snapshots (direct data loss risk)• EBS volumes without recent snapshots (outdated backup)• EC2 instances without termination protection enabled• Environments without multi-AZ deployment• Lack of automated backup and retention strategy• Critical resources without defined recovery (DR) policies• Low maturity in business continuity (BCP)• Workloads not prepared for availability zone
I recently worked on another project with a major customer where we unfortunately reached the limits of Veeam Backup & Replication’s out-of-the-box features for Scale-Out-Repositories and had to find a workaround. Our ChallengeOur challenge: The customer has over 100 scale-out repositories, each with different permissions depending on the application and operating system. We had to migrate the VBR server to a new Windows Server. However, this also meant that the users created locally on the old server were no longer available. In principle, this wasn’t a problem—we simply recreated the same users on the new server.However, this is where the problem comes in. The SOBR permissions include the old user as “OLDSERVERNAME\USERNAME,” which we then have to replace with “NEWSERVERNAME\USERNAME.” If we didn’t replace these, our Enterprise Plugins would no longer have permissions to write their backups.Unfortunately, there is no function to change permission settings across multiple reposito
Some days your job is just plain fun! No ifs or buts!This morning I had the immense pleasure to talk with 3 pillars of the Veeam Community, Senior Community Manager Nikola Pejkova @NikolaPejkova , Mr. Community himself Rick Vanover @Rick Vanover and of course Vanguard/Legend/Object First Ace, author of Mastering Veeam Backup & Replication Chris Childerhose @Chris.Childerhose !This is a conversation that could have lasted all morning, never a dull moment.Also courtesy of a fresh of the press Rickatron quote a potentially fantastic new title for a DR horror movie! I can see it now: coming soon to a theater near you: “Agents gone wild”! Tune in to find out what it is like to write a book and the fun these three folks had collaborating together on this new edition! https://www.buzzsprout.com/2545760/episodes/19293879 The Book is out, don’t you miss out!
I finally had some time to wire in the Veeam Ports MCP server into GPT. It works but has a number of steps in the process. If you are like me you watch the token burn in Claude for projects like these. This started with EdxH’s post on the Veeam Ports MCP server introducing the project & GitHub repo.The repo is @ https://github.com/shapedthought/veeam-ports-mcp. I wanted to see what it took to make that same idea work /w GPT.Claude Desktop can launch a local MCP server /w STDIO. The Veeam Ports MCP repo already shows that path well. GPT expects an MCP endpoint instead. On my end that meant I had to put a bridge and a tunnel in the middle before GPT could make use of the tool correctly.Once that was running, I could describe a VBR v13 layout in plain language and get back firewall rules, topology output, and a Magic Ports import file (yea).The painful part was useful as well. I learned that a topology JSON and a Magic Ports import JSON are not the same thing. They look close enough
Throughout this tape series, I explored installation, troubleshooting, tape cleaning procedures, advanced diagnostics, and real-world operational scenarios involving Veeam tape environments.But there is another side of tape infrastructure that usually only receives attention when something starts going wrong: tape library administration.And many times, the problem is not directly related to the backup job itself.Issues often appear around: media movement firmware inconsistencies robotics communication tape-out operations media rotation hardware lifecycle operational mistakes In enterprise environments, tape infrastructure eventually becomes much more than just a backup target.It becomes an operational platform that requires maintenance, organization, validation, and process consistency. Understanding Control Path and Data PathOne of the first important concepts in enterprise tape environments is understanding the difference between control path and data path.The control pat
TL;DROn May 14, 2026, the PostgreSQL Global Development Group released security updates for all supported branches (18.4, 17.10, 16.14, 15.18, 14.23), fixing 11 CVEs, several rated CVSS 8.8. If you run VBR on Windows with PostgreSQL as your configuration database, you are affected. Veeam does not auto-update PostgreSQL. You have to do it yourself! Here is what you need to know and what to do about it. Why this matters for VBRSince VBR v12, PostgreSQL has been the default (and recommended) configuration database. VBR v13 GA ships with PostgreSQL 17.6, and the latest cumulative update (13.0.1.2067) bumps it to 17.9.1. Both versions are below the patched 17.10 and therefore vulnerable to all 11 CVEs disclosed on May 14 (PostgreSQL release announcement).If you are still on VBR v12.x, your PostgreSQL 15.x is equally affected and needs to be updated to at least 15.18 (PostgreSQL release announcement).The key takeaway: Veeam does not update the PostgreSQL instance between VBR cumulative updat
In my latest blog article part 2 of Integration Veeam with CrowStrike, I'll walk through the steps of a recent implementation & integration of CrowdStrike with Veeam backup servers. Cyberattacks continue to target backup infrastructure because attackers know backups are often the last line of defense. Traditional antivirus solutions are no longer enough to protect modern backup environments, especially when ransomware actors specifically target backup repositories, backup servers, and privileged accounts.That’s where integrating CrowdStrike with Veeam Software can significantly improve your security posture.By combining Veeam’s ransomware detection and secure recovery capabilities with CrowdStrike Falcon’s endpoint protection and threat intelligence, organizations can better detect, contain, and recover from cyber incidents.In this lab guide, I’ll walk through the steps to implement and configure CrowdStrike integration with Veeam and explain how the two platforms complement each
Hi all,I had a customer who needed a way to obtain Veeam Software Appliance (VAS) updates within a closed OT/dark site/closed environment.However, the challenge was that they lacked Linux experience and would prefer to do everything in native Windows, without using WSL (Windows Subsystem for Linux). If you have no idea what I am talking about, read this section of the Veeam help center: https://helpcenter.veeam.com/docs/vbr/userguide/update_appliance_configure_updates.html?ver=13#setting-up-custom-update-configurationSo my idea was to build/configure two components:1) A PowerShell script that can be run in Windows to download the necessary files from repository.veeam.com to a computer with internet access and then zip the files into a single large Zip file. 2) Create an IIS server website with all update files needed for the VSA. Then we can easily hand-carry the Zip files from the internet-connected Windows computer to the IIS server in the OT/dark site/closed environment with you pre
Every now and then you get customer requests that initially knock you off your feet — because you can tell right away: this isn’t described anywhere in the documentation. Then it’s time to truly understand the problem, clarify the requirements properly (does the problem even exist in that form, or can it be solved differently?), research internally, potentially review a feature request including the use case — and finally think about how to help the customer pragmatically in the short term: the good old “workaround” or “self-fix.”That was the case here as well. A customer is using the standalone Veeam Plug-in for Oracle RMAN and wants to install the Veeam plug-in — however, in the customer’s environment it is intentionally used as unmanaged. At the same time, the rollout should be automated, and no one should have to type or “expose” a password.Die Veeam documentation refers to the option of copying the “configuration file” to other servers; however, you then have to reset the passwor
Veeam Backup & Replication 13.0.2 dropped yesterday — and if you manage a smaller environment where a single Windows Server hosts all the things (Proxy, Mount Service, vPowerNFS, Guest Interaction Proxy, you name it), you may have hit an annoying moment when tried to open the console after upgrading the VBR server. You open up the Veeam Backup & Replication console, enter your server's name, click Connect — and instead of the familiar dashboard, you get this: Failed to connect to the backup server: the connection has been established but client update is required, however this machine is hosting other roles. Make sure these following roles are not in use and uninstall them … The message is accurate: the console client is older than the freshly updated server, and the in-place update mechanism wants you to remove other roles before it allows the console to update itself. In a larger, role-separated architecture that is fine — but in a compact single-server se
When I logged on to my Object First Appliance again, I saw that an update was available once more.Honestly, it’s almost too simple to write a blog post about, but why not ;-) Updating your Object First (Ootbi) appliance is super easy and quick (and much faster than it took to write this post).Updates roll out security patches, bug fixes, performance improvements, and new features — and the best part is that the whole thing is driven from a easy Web UI with only some clicks.In this post, I’ll walk you through updating your Ootbi cluster end to end: the online method (for internet-connected appliances), the offline method (for air-gapped or security-restricted environments), and the pre- and post-update checks I always recommend before calling the job done.Good to know: Ootbi updates are applied at the cluster level, not node by node. When you trigger an update, it’s automatically pushed across every node in the cluster, so all your nodes stay on the same version without any extra effort
Enhancement of NFS repository NFS repository is rely on NFS protocol, which is not built for heavy loads and using it should be used only, if another setup of repository is not possible.In my usecase is the only option, how to avoid connection of guests to repositories. NFS repository does not support fast cloning, so consumption is much higher like on repository with direct attached storage or object storage.Synthetic backup is taking very, very long for big VMs especially. How synthetic backup works with NFS repositoryDuring process gateway server needs to take files on gateway, where is data mover, create synthetic full backup and send it backup on nfs storage. How NFS repository works: they are mounting during backup/restore process in one threat and unmounted after backup/restore is done: Such configuration is very safe and is not visible nfs export during non-runtime. Based on my test one threat can run backups around 21MBps on 1Gbps line.In this case was distance was 50km and s
Today marks a big milestone as my fourth book was published - Mastering Veeam Backup & Replication v13. I wrote a blog about it when you can read in the link below, and I have put the links to Packt/Amazon where you can find it if interested. 😎This one was great to write, and I especially enjoyed the chapter on Veeam ONE that I put in this book. I would truly like to thank @Rick Vanover for his chapter contribution about the Console (Chapter 4) and also @NikolaPejkova for her inspiring Foreword that she wrote, it was very touching, and I am grateful.Blog - Mastering Veeam Backup & Replication v13 - BlogBook LinksPackt - Mastering Veeam Backup & Replication v13 - PacktAmazon - Mastering Veeam Backup & Replication v13 - Amazon
Ever wanted to chage your managed server from an IP Adress or DNS (shortname) to FQDN. Then you will find this article very useful. Since the move to version Veeam Backup & Replication (VBR) v13, we have seen that FQDN works more reliably in VBR/VSA due to strict reverse DNS requirements for certificate authentication, SSH, and agent deployment on Linux. IPs skip PTR lookups and often fail validation as demonstrated in this guide “Building VIHR: Ransomware-Proof Repository with Veeam JeOS“. In this article, we shall discuss how to “Switch from IP to DNS names for Backup Infrastructure in VBR cleanly”Managed Server Object RenamePrior to running the commands below you need to identify the IP\DNS (shortname) utilized by your Managed Server currently. Since I am currently using the hostname as Techda01 for example, and this could even be an IP address in your vase, this would need to be changed very shortly to a Fully Qualified Domain Name (FQDN). Note: Until now, this change cannot b
Reflections from my MC2MC Rocket Talk – 21 May 2026 On 21 May 2026, I had the opportunity and privilege to speak at the MC2MC Community event, proudly sponsored by my company ORBID. During my rocket talk, I shared insights into a topic that is becoming increasingly critical for organizations operating in the cloud:How can we move beyond native Azure backup capabilities to achieve true data resilience?As more businesses migrate workloads to Microsoft Azure, protecting data is no longer just about creating backups—it is about ensuring business continuity, cyber resilience, and recovery flexibility. Why Data Protection Matters More Than EverThe session started with a reality check.Today's organizations face a growing number of threats and challenges:89% of ransomware attacks explicitly target backups. 33% of production workloads experienced unexpected outages last year. 82% of organizations cannot recover fast enough to meet business requirements. 82% cite a skills shortage as their num
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.