Skip to main content

Veeam v11 - Hardened Repository aka Immutable backups


Show first post

88 comments

vNote42
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 1246 comments
  • February 27, 2021
osonder wrote:

Thank you.! Is there a step-by-step guide somewhere? I planning to upgrade to V11, and want to set up this hardening as soon as possible

I would recommend to start here: https://helpcenter.veeam.com/docs/backup/vsphere/hardened_repository.html?ver=110

There you find the section: Deployment of Hardened Repository.

I am sure more detailed information and best practices for Linux repositories will come soon.


vNote42
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 1246 comments
  • April 14, 2021

[Update]

Veeam Hardened Repository passes independent compliance assessment

When properly configured, the Hardened Repository meets the requirements for non-rewritable, non-erasable storage as specified by SEC 17a-4(f), FINRA 4511(c) and CFTC 1.31(c)-(d) regulations.

https://www.veeam.com/blog/hardened-repository-passes-compliance.html

 


vNote42
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 1246 comments
  • April 14, 2021

Check out the new Whitepaper from Veeam ( @HannesK  ): 

Protect against Ransomware with Immutable Backups: a Veeam Guide


@vNote42 have you been able to post anything on How to setup Linux as repository server?

 


vNote42
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 1246 comments
  • May 5, 2021
MAC_Daddy_1974 wrote:

@vNote42 have you been able to post anything on How to setup Linux as repository server?

 

Hi @MAC_Daddy_1974 ! Just wrote an internal installation guide. I can recommend this post:

https://nolabnoparty.com/en/veeam-v11-hardened-repository-immutability-pt-1/ by @PValsecchi 


Shaokat
Forum|alt.badge.img+3
  • Influencer
  • 127 comments
  • May 6, 2021

@vNote42 thanks for share and your update 


JMeixner
Forum|alt.badge.img+17
  • Veeam Vanguard
  • 2650 comments
  • May 12, 2021

There is new blog post from @PValsecchi about setting up MFA for SSH loginsto Linux Hosts.

https://nolabnoparty.com/en/veeam-v11-hardened-repository-immutability-add-mfa-pt-3/

 

Nice and detailled tutorial...


Geoff Burke
Forum|alt.badge.img+22
  • Veeam Legend, Veeam Vanguard
  • 1312 comments
  • May 12, 2021

Great Information folks this really helps!


  • New Here
  • 1 comment
  • May 19, 2021

Hi 

I am looking to implement hardened repository im already using Veeam v11 however I have zero experience created Linux VM and required config on it.

Would anyone be so kind as to give me some pointers?

Thanks.

 


vNote42
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 1246 comments
  • May 19, 2021
Osvaldo wrote:

Hi 

I am looking to implement hardened repository im already using Veeam v11 however I have zero experience created Linux VM and required config on it.

Would anyone be so kind as to give me some pointers?

Thanks.

 

Check out excellent blog series by @PValsecchi :

https://nolabnoparty.com/en/veeam-v11-hardened-repository-immutability-pt-1/

https://nolabnoparty.com/en/veeam-v11-hardened-repository-immutability-configuration-pt-2/


Eddie Kwok
Forum|alt.badge.img+1
  • Experienced User
  • 49 comments
  • May 27, 2021

Thanks @vNote42


Forum|alt.badge.img+4
  • Experienced User
  • 576 comments
  • May 31, 2021

Thanks @vNote42 


Chris.Childerhose
Forum|alt.badge.img+21

Nice to see all of this information in one post.  Not sure it is possible but you should see about editing the main post with the updates versus them being within the pages.  Just would make things easier to find all in the first post.  Maybe we don’t have the editing ability either.  LOL


vNote42
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 1246 comments
  • May 31, 2021
Chris.Childerhose wrote:

Nice to see all of this information in one post.  Not sure it is possible but you should see about editing the main post with the updates versus them being within the pages.  Just would make things easier to find all in the first post.  Maybe we don’t have the editing ability either.  LOL

Good point chris!

Legends have the permission to edit their own posts only since a few weeks now. I future I will edit the original post to add updates. Thanks!

 


Chris.Childerhose
Forum|alt.badge.img+21
vNote42 wrote:
Chris.Childerhose wrote:

Nice to see all of this information in one post.  Not sure it is possible but you should see about editing the main post with the updates versus them being within the pages.  Just would make things easier to find all in the first post.  Maybe we don’t have the editing ability either.  LOL

Good point chris!

Legends have the permission to edit their own posts only since a few weeks now. I future I will edit the original post to add updates. Thanks!

 

No problem.  Just figured Rick does it for the v11 post he has so it keeps it tidy. :grinning:


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1345 comments
  • June 11, 2021

I've looked at the hardened repositories in the last days and the configuration itself is really easy. The Linux side is more complicated if you're not used to setup such systems 😅

@vNote42In your blog you've posted a screenshot of a dialog box requesting the change of the directory owner. Is this checkbox no longer existing in the GA release?


vNote42
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 1246 comments
  • June 11, 2021
regnor wrote:

I've looked at the hardened repositories in the last days and the configuration itself is really easy. The Linux side is more complicated if you're not used to setup such systems 😅

@vNote42In your blog you've posted a screenshot of a dialog box requesting the change of the directory owner. Is this checkbox no longer existing in the GA release?

Yes, for what you get it is really simple!

You probably mean this dialog-box?

Good question! I think I have not seen the dialog in installations since GA. But this could also be because I ran the command before. Did you run it before?


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1345 comments
  • June 11, 2021

Yes I meant that dialog. I forgot to change the owner and was wondering why Veeam couldn't create the job folders. So the dialog did probably only exist in the beta.


vNote42
Forum|alt.badge.img+13
  • Author
  • On the path to Greatness
  • 1246 comments
  • June 11, 2021
regnor wrote:

Yes I meant that dialog. I forgot to change the owner and was wondering why Veeam couldn't create the job folders. So the dialog did probably only exist in the beta.

Probably! Maybe @Rick Vanover  can answer this question?


Rick Vanover
Forum|alt.badge.img+10

@vNote42 @regnor Yes anything that has "TBD" Is likely a beta, preview or otherwise non-Generally Available build.

 

If this is in GA, let me know and I will get it into the bug fix cycle.

 

I do not believe I have seen this in GA myself.


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1345 comments
  • June 12, 2021
Rick Vanover wrote:

@vNote42 @regnor Yes anything that has "TBD" Is likely a beta, preview or otherwise non-Generally Available build.

 

If this is in GA, let me know and I will get it into the bug fix cycle.

 

I do not believe I have seen this in GA myself.


Well no it's not in GA but it would be a useful hint especially if you don't look in the documentation.


Adolfo_Veloz

I’m having problems with the tool, in the begining I was not aware that the xfs progs needed to be installed on my ubuntu version, and the installer failed, well, I just downloaded the xfsprogs and then the veeamhubrepo won’t start again, I deleted the file  ‘/etc/veeamhubtinyrepoman’ and started all over again, but in the end it crashes again with this error:

 

Can any one tell me how to reset the tool to start over clean? Thanx.

 


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1345 comments
  • June 17, 2021

I'm not sure if it works, but if you remove the Linux server in Veeam, does it uninstall all components and cleanup the system?


Adolfo_Veloz

I’m not getting to that step yet… this is before adding it to a Veeam Server.


Adolfo_Veloz

It is supposed that, once enabling ssh access the next screen will be:

 

 

Once there.. the number 3 option must be selected, and then add it to the Veeam Server 11.


Comment