Bring your knowledge and expertise while creating blogs and podcasts
Recently active
I recently had an issue after updating both my VBR v12 Servers to the latest patch v12.3.2.4465. As most of you know, Veeam released a Vulnerability KB back on 12 March. See below:https://www.veeam.com/kb4830From this page, there is a link to direct you to VDP v12.3 Release information:https://www.veeam.com/kb4696 , which provides the download to the latest VDP v12 Patch. A few weeks ago, I downloaded the small patch and updated both my VBR servers. All good. But, with this patch, there is a bug. And let me be more specific here, a non-functional disruption bug. (i.e. more cosmetic than anything; Jobs are unaffected)IssueThe bug is on how VBR detects the latest update/release information. Even after I installed the Patch, upon logging into the VBR Console, I was prompted to get the latest VBR Update. I checked the Help > About section, as well as the notification bar on the bottom of the Console, and both show I’m on the latest VBR v12 Build. So why would the Console prompt me to up
Hi thereTime to update the Lab, this time, easy monitoring for VMs, Services and Webs.UPTIME - KUMAIm going to show you how to easily deploy an instance inside Proxmox, containerized, ready to go.First, go to this website and search the community script to deploy it:https://community-scripts.org/?q=uptimeCopy the command, as shown in the pictureGo to your Proxmox Host, open a terminal, and paste the commandHit EnterLets follow the script steps, as always, with screenshots:Default is okStorage for template, in my case, NFS, for future HAContainer Storage, same thing, NFS for future HAScript running, great looking.update found, lets apply it and continuecontinue...Done!Now you can see the Ip from our DHCP were Uptime Kuma is running.Open up in a browser, and follow the initial wizard,I selected SQLite.language and credentials.Done!Next entry, initial config, notifications and initial monitors.cheers.
How to change name and what to watch out for and what to consider if you have unmanaged plugins. My Name is „Bond“ – „Repository, Bond“ – Display-Name vs. FQDN – Licensed to Rename Sometimes, in the backup universe, you simply want to bring order to chaos, fix a mistake, or the naming structure has just changed. So a repository is supposed to get a new, nicer name. Or the server behind it needs to be renamed because a domain migration is coming up, naming conventions have changed, or a rebranding is being rolled out. Basically: “We’re cleaning everything up now.” And this is exactly where you need to: “Change the name”. I know it sounds harmless at first — but it rarely is. Especially in IT, names often have… well… everything attached to them. And while it’s totally understandable that you don’t want to redeploy everything just because of a name, it’s worth popping the hood. That way you’ll know what impact a name change really has — and how to implement it cleanly. Important: In Veea
When you're standing up a Hyper-V cluster and adding it to Veeam Backup & Replication, the proxy placement question comes up. The documentation says you can use on-host or off-host backup mode, and both work. What it doesn't tell you is what the data path looks like. Or what infrastructure each mode requires. Or what happens when VBR makes a decision you didn't expect.This post covers what I've observed running on-host backup across a Hyper-V cluster and what the docs say about off-host mode.How Veeam Sees a Hyper-V ProxyVeeam's proxy for Hyper-V is not the same component as a VMware backup proxy. For Hyper-V, the role is fulfilled by the Veeam Data Mover. In on-host mode, every Hyper-V host you add to VBR gets the on-host proxy role automatically. You don't install it yourself. The VBR pushes the Data Mover to each host when you add it to the infrastructure.In off-host mode, the Data Mover runs on a separate machine outside the cluster. That machine has specific infrastructure re
I have seen repeated conversations around leveraging SSO in Veeam v13, particularly concerns about joining the backup server to a production domain. This has also come up multiple times in my discussions with partners.Based on that, I put together this exercise to explore a few possible ways of addressing those concerns. It may be more than what some environments need, but sharing it here to get thoughts and opinions from the wider community.The challenge: Central identity Vs domain isolationVeeam Software Appliance v13 brings a SAML SSO experience into Veeam Backup & Replication. Organization want to integrate with Microsoft Entra ID forSingle Sign-on Unified Identity management Central auditingBased on my recent engagements with users, I have heard an interesting challenge: connecting Veeam to a production Entra domain. It has long been considered a best practice to avoid joining backup infrastructure to the production domain to achieve a Zero-trust architecture. So the question
Hello Community, There’s something every backup admin will relate to.You arrive, open the Veeam console, filter jobs by status, start clicking through failures, make a note of error codes, maybe open a browser tab to Google it or check the Veeam Community, cross-reference it, and slowly form a picture of what your morning actually looks like.By the time you know what needs fixing, it's already been half an hour. I’ve done this for years. We all have. A few days back, I came across a post talking about Veeam introduced feature called Data Resilience Daily, also known as the Morning Coffee Report.The concept is straightforward. Before you open any console, the report lands in your inbox and tells you exactly what happened overnight, which jobs have issues, which workloads are affected, and what you should probably do about it.When I first heard about it, my reaction was simple. Another summary email? We've had those before.But what makes this different is the last partwhat you should p
Veeam 12In v12 is not so sensitive via WMI/DCOM connection Veeam 13Upgrade to v13 was successful.All services are runningPS C:\Users\user01> Get-Service | Where-Object { $_.Name -like "Veeam*" }Status Name DisplayName ------ ---- -----------Running VeeamAHVSvc Veeam AHV ServiceRunning VeeamAWSSvc Veeam AWS ServiceRunning VeeamAzureSvc Veeam Azure ServiceRunning VeeamBackupCdpSvc Veeam CDP Coordinator ServiceRunning VeeamBackupRESTSvc Veeam Backup Server RESTful API Ser…Running VeeamBackupSvc Veeam Backup ServiceRunning VeeamBackupUpda… Veeam Backup Update ServiceRunning VeeamBrokerSvc Veeam Broker ServiceRunning VeeamCatalogSvc Veeam Guest Catalog ServiceRunning VeeamCloudSvc Veeam Cloud Connect ServiceRunning VeeamDataAnalyz… Veeam Data Analyzer ServiceRunning VeeamDeploySvc Veeam Installer ServiceRunning VeeamDistributi… Veeam Distribution ServiceRunning VeeamEnterprise… Veeam Backup Enterprise ManagerRunning VeeamExplorersR… Veeam Explorers Recovery ServiceRunning VeeamFilesysVss
Hi Folks,Next week we will be launching our new Fleet Manager and we have a true star joining us! See if you can guess who that is 😁! There will also be some other cool folks present. If you have time please join us. https://objectfirst.com/fleet-manager-launch-event/
I am not sure if this has been posted somewhere before but I thought I would post my experience of setting up Linux proxies for our VMware backups and the one issue I ran into. I deployed a couple of Ubuntu 22.04 VMs, as I will be using hot-add for the VM backups. I added them to the VBR server and created a test backup of one VM. First backup attempt and I got this error:Error: Cannot get service content. Soap fault. Temporary failure in name resolution Detail: 'getaddrinfo failed in tcp_connect()', endpoint: 'https://vc.domain.local:443/sdk' SOAP connection is not available. Connection ID: [vc.domain.local]. Failed to create NFC download stream. NFC path: [nfc://conn:vc.domaint.local,nfchost:host-1310340,stg:datastore-1310378@TEST/TEST.vmx]. --tr:Unable to open source file [nfc://conn:vc.domain.local,nfchost:host-1310340,stg: So the key to the problem is “failure in name resolution”. Specifically name resolution from my new Linux proxies. I have run into this kind of problem before f
Ansible + Veeam + AI + Monitoring and Observability Tools = AIOps Everything starts with a signal.A sudden spike detected by Dynatrace.Suspicious behavior flagged by CrowdStrike.A failed backup showing up in Splunk.Before, this meant just another ticket.Someone had to notice it.Someone had to analyze it.Someone had to act.Time lost.Today, the flow is different.Observability detects.AI evaluates.The system decides.And that’s where everything changes.👉 Ansible Automation Platform executes automatically:isolates the workload adjusts the infrastructure triggers remediation workflowsMeanwhile…👉 Veeam ensures there is always a clean recovery point:immutable backups validated restores reliable recovery👉 The Ansible automation platform executes the remediation.👉 Veeam ensures data protection and recovery. Veeam Integrations with Monitoring & Observability Tools Use Cases 📊 SplunkIntegration:Veeam sends logs and events to SplunkUse Cases:Detect backup failures in real time Correlate ba
So Andy you did Magic tricks some time ago right? Can you tell me how security and ransomeware scanning is done by veeam with a card trick? Im a little rusty with it, but sure Challenge accepted, I will give it a try… Can you tell me how security and ransomware scanning is done by veeam?SureSo lets do an abstraction. So we’ve got your files. Let’s think about 52 files inside a card deck.Each card in this deck, represents your workload, your database, your VMs, your server, your fileservers, your hardware servers.Each card is one of them and of course they all have a lot of data inside of them.Now one of your files, one of your file servers is getting corrupted. So let’s – I don’t know – suggest this one here. So the eight of um spades is getting corrupted. So your data looks normal and of course you have got in your environment in your environment you have got a lot of scanning tools. So you’ve got your XDR, you’ve got a SOC and SIEM and different solutions. EDR and you scan the wh
Given the complexity and critical nature of this transition, I have created Part 2 of this guide to focus specifically on updating WinPE boot images to support the Windows UEFI CA 2023 Secure Boot certificates.The previous guide was published nine months ago and continues to generate significant traffic. This follow-up article addresses the missing component: updating WinPE boot images to ensure compatibility with Windows Deployment and the Windows UEFI CA 2023 Secure Boot trust chain.The complete Part 1 guide is available here, followed by Part 2 covering “Update WinPE Boot Images with Windows UEFI CA Certificates”WinPE boot media relies on the same Secure Boot trust chain as full Windows. That trust is validated against the UEFI db (allowed certificates) and dbx (revoked certificates) stored in firmware.Microsoft recommends enabling automatic management of Windows Updates to ensure timely delivery of these updates. In addition, Microsoft is working closely with original equipment ma
It was a technical milestone last week for me in the lab after successfully migrating my Veeam v13.0.1 backup server from Windows to a Linux VSA. The purpose of this migration was to improve system efficiency and showcase the v13 product enhancements to my customers. This was a joint effort with Veeam support and the Partner team. Below are the steps I followed during the migration. The first step was obtaining approval from Veeam support and having a dedicated engineer available if any issues arose. All the migration steps are below Step 1 - engage Veeam support and open a migration ticketStep 2 - follow the pre-requisites from Veeam supportConfirm the latest P1 is installed Remove all the storage integrations from the Veeam server Remove the google plugin from the installation Collect and send the VMC log to support for verificationStep 3 - engage with support and provide the following detailsUpload a log bundle to the support case Ensure and confirm a VSA is installed and ready wit
TL,DRAfter upgrading to Veeam Backup and Replication v13, in one of our customer environments SAP HANA application backups started failing because the plug in tried to reach the repository on TCP 6162 first, timed out, and did not automatically fall back to the classic 2500 to 3300 range in our scenario as it should have done according to documentation.Opening 6162 fixed the connectivity requirement as confirmed by Veeam Support. Our issueBackups that had been stable on v12 suddenly failed right after moving to v13, specifically SAP HANA application backups using the Veeam Enterprise plug in for SAP HANA. SymptomOur HANA jobs spent a long time “trying to connect” and then died with a timeout. In the logs it was obvious that the plug in was repeatedly attempting to connect to the repository IP on port 6162 and eventually timing out. [27.03.2026 13:17:37.846] <139893376276160> plugin_co| IP endpoints: [10.211.102.158:6162; 10.211.102.158:2501].[27.03.2026 13:17:37.
Hello, everyoneIn this article, we will explore Veeam Universal CDP (Continuous Data Protection), an advanced disaster recovery technology designed to provide critical levels of protection with minimal data loss.Unlike traditional backups, which run every few hours, Universal CDP operates continuously, enabling companies to protect their most critical applications with a Recovery Point Objective (RPO) of just a few seconds.What makes it “Universal” is its versatility. While Veeam's standard CDP is typically limited to virtual machines within VMware vSphere environments, Universal CDP extends this capability to protect a variety of workloads (such as physical servers or different platforms) and replicate them directly to a VMware vSphere infrastructure at a disaster recovery site. Backup infrastructure for Universal CDP The following backup infrastructure components are required to use Universal CDP:Backup server Source workloads CDP proxies Target host or clusterHow it works Unlike tra
Hi everyone,I’ve just published the February edition in the “Regkey of the Month series” This month’s focus is on the EnableSameHostHotaddMode registry setting in Veeam Backup & Replication.What it does ?Forces Veeam to preferentially use a proxy on the same ESXi host as the VM being backed up — helping to localize backup traffic and reduce performance issues like VM stun and cross-host data transfer.Why this can be interesting for you ?This can be especially useful in complex infrastructures (e.g., HCI or NFS-based storage) where network and snapshot performance matter.If you’re curious how this setting works and when to implement it, check out the full post here:👉 https://integriservices.blogspot.com/2026/02/regkey-of-month-february.htmlI would love to hear your thoughts or real-world use cases!
Many of my customers (luckily) are using Sure Backups. Some of the subnets are also quite small (i.e., smaller than /24). When configuring the network settings in the Virtual Lab wizard, there is a little problem which can easily be handled. Veeam automatically inserts the appropriate letters for masking in the masquerading network.For example, if you configure a /24 network, the wizard inserts a “D” in the fourth octet. This is correct and must be done this way. The situation is different if the subnet is smaller. For example, if you have a /25 network and enter it in the wizard, the fourth octet of the masquerading network no longer displays a letter, but the number of the subnet mask. To avoid this, simply click on the fourth octet of the masquerading network and enter a “0”. Then confirm with OK. If you now reopen the configured network in the wizard via “Edit”, the “D” will now also appear here and the network can be used in the Virtual Lab.Original post on my blog:Veeam: Virtual
ContextWe have been using the vCloud Director Self-Service Plugin to allow our tenants to initiate their own restores. Essentially how it works is to provide them with limited access to Enterprise Manager, scoped to just their vCloud Organization. The ProblemRecently however, all file restores and downloads started to fail for them, as well as files restores performed by me directly on the Enterprise Manager server. Those restore failed with the following error(s):Error occurred during the FLR job executionSerialization for transport spec is not implementedUpdating FLR session historyUnable to prepare files for download. TroubleshootingTo resolve this, I searched high and low for a resolution, including:Confirming that the restore worked on the B&R console; it did However I found that when initiating from Enterprise manager, the FLR session opened up, but it didn’t log any attempt to restore a file, indicating that it never got that far in the process Recreating the Enterprise Man
V13 upgrades cleanly when the VBR server is already cleaned up first. Most delays come from legacy backup-copy jobs, old agent deployments, nested repositories, removed job settings, or unsupported infrastructure that was still tolerated before the upgrade. Check the starting build first, clear blockers before mounting the ISO, and validate backup plus restore behavior afterward. 1. Supported starting pointDirect to v13.0.1 only from:v12.3.1 build 12.3.1.1139 or later v12.3.2If the server is on an earlier v12.3.x build:patch to v12.3.1 build 1139 firstIf the server is on v12.2.x or older:stage through v12.3.1 first2. Installer blockers to clear before the ISO is mountedThese stop the upgrade:backup metadata not upgraded to v12 format legacy backup-copy jobs Veeam Agent for Windows before v6 using LocalDB nested repository paths UNC path still configured in Export VBK File Copy jobs targeting the backup server jobs still using "Transform previous chains into rollbacks"Do not wait for t
When working with tape environments in Veeam Backup for Tape, cleaning is often treated as a routine task.However, in practice, it plays a much bigger role than most people expect.Over time, I’ve seen stable environments suddenly start presenting errors, performance degradation, or unexpected behavior — and in many of these cases, the root cause was simply a lack of proper tape drive cleaning.In this post, I’ll share how tape drive cleaning actually works in practice, what is often overlooked, and why this small maintenance task can have a major impact on reliability. What Is a Cleaning TapeAt first glance, a cleaning tape looks just like a regular data cartridge.It follows the same physical format but uses a specific label, typically CLN or CLNU, depending on the vendor.The difference is internal.Instead of storing data, the cartridge contains a specialized cleaning material — typically a controlled, non-abrasive fabric — designed to safely interact with the drive’s read/write heads.F
Managed BCDR with Veeam Delivering Resilient Business Continuity & Disaster Recovery as a Managed ServiceProviding Business Continuity and Disaster Recovery (BCDR) as a managed service requires far more than “running backups.”Customers expect guaranteed recovery outcomes, predictable recovery times, and protection even when the backup infrastructure itself is compromised.This article walks through a real‑world MSP architecture for delivering Managed BCDR with Veeam using:Active/Standby Veeam Backup & Replication (VBR) Veeam Cloud Connect Veeam Data Cloud Vault (immutable object storage) Microsoft Azure as the disaster recovery execution platformWe’ll cover the business problem, architecture decisions, operational flows, DR activation, and practical configuration guidance, concluding with clear pros, cons, and limitations.The Business Problem MSPs Must SolveModern customers don’t buy backups — they buy recovery confidence.They require:Predictable RPO and RTO Protection against r
As a follow-up to my last article, “Lab View: How to Air-Gap Veeam without breaking operation,” in this article, I will discuss common mistakes with Air-Gap and how they break you Air-gapping your backups is one of the smartest moves you can make.Done right, it protects you from:Ransomware Insider threats Accidental deletion Catastrophic failureBut here’s the reality:Most air-gap strategies fail—not because they don’t exist, but because they’re implemented wrong.I’ve seen environments with “air-gapped backups” that looked secure on paper…and completely fell apart during recovery.Let’s break down the most common mistakes—and why they matter. 1. “We Have Immutability—We’re Good”This is the #1 misunderstanding.Immutability is powerful.But it’s not the same as an air gap.The mistake:Relying solely on immutable storage Assuming it covers all attack scenariosThe problem:Credentials can still be compromised Access paths still exist Attackers can still disrupt operationsThe fix:Combine immutab
Dear all, this is just a quick guide, but maybe helpful for some of you!I had this behaviour with the latest release from yesterdays ISO, to patch to the latest release… After mounting the ISO and click on Setup.exe I received the following error:Unable to run the installer because files from this ISO are blocked for security reasons. Use the “Unblock” option in the file properties to proceed. It’s an easy step, but keep in mind, this you have to do on the ISO file itself, not on the Setup.exe file 😉So right-click on the ISO, and choose Unblock under Security. Hit OK/Apply and have fun, while applying your urgent updates! Take care, stay up2date and have a great weekend!
I hear it all the time: my customers are looking for a backup solution they can set and forget, basically run itself. This article will focus on that - every backup solution needs to be monitored and troubleshoot issues. “Set it and forget it.”It sounds like the dream.You deploy your backup platform, configure your jobs, see everything turn green… and move on to the next project.No noise.No issues.No need to touch it.Until something goes wrong. The Illusion of “Everything Is Fine”In a lot of environments, backups quietly run in the background.Jobs complete Reports look clean Storage is filling (as expected… mostly)So naturally, attention shifts elsewhere.That’s the trap.Because backup environments don’t usually fail loudly at first.They drift. What “Set It and Forget It” Actually Looks Like Over TimeIt doesn’t break on Day 1.It slowly turns into:Jobs that run longer than they used to Warnings that get ignored (“it’s just a warning”) Storage growing faster than expected New workloads ad
When working with tape environments, tape backup troubleshooting in Veeam is often more complex than it initially appears. Many professionals associate errors directly with faulty media. However, in real-world scenarios, issues often originate from hardware behavior, environmental conditions, or subtle physical problems.In this article, I will share real troubleshooting cases and, more importantly, explain the reasoning behind each analysis. The goal is to demonstrate how to identify the root cause instead of relying only on error messages. Case 1 – Mechanical obstruction during tape movementScenarioBackup jobs started failing during tape movement operations between slots and drives.Observed symptomsFailures during load and unload operations Errors affecting a specific range of slots Intermittent behavior that initially appeared randomExample error:Unexpected slider block, cartridge is not pushed far enough into the slot(ROB_SLIDER_UNEXPECTED_BLOCK_DURING_INSERT) TroubleshootingManual
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.