News, guidelines and various community projects
Recently active
We are unable to access the Veeam Backup Enterprise Manager Web UI, receiving a "localhost refused to connect" error. Initial troubleshooting steps included checking firewall rules and verifying if port 9443 was listening, but the service was not running. We identified that the Veeam Backup Enterprise Manager service was not present or visible on the server.VBR ver is 12.3.2 localhost refused to connect.Try:Checking the connectionChecking the proxy and the firewallERR_CONNECTION_REFUSEDC:\Windows\system32>netsh advfirewall firewall add rule name="veeam.xy.com 9443" dir=in action=allow protocol=TCP localport=9443Ok. Veeam Backup Enterprise Manager' service does not appear in the services.msc. I just joined in the team and don’t know if previous engineer has done anything.EM is local as per logs.Integration] EnterpriseManager: { IsAddedToEM: True, IsEnterpriseManagerLocal: True } (timestamp 2026-04-15 22:36:05) Please advise me how to get the enterprise manager back in action.
PS C:\Windows\system32> Get-Service -Name *Veeam* | Select Name, Status, StartType Name Status StartType---- ------ ---------VeeamAHVSvc Running AutomaticVeeamAWSSvc Running AutomaticVeeamAzureSvc Running AutomaticVeeamBackupCdpSvc Stopped AutomaticVeeamBackupRESTSvc Running AutomaticVeeamBackupSvc Stopped AutomaticVeeamBackupUpdateSvc Running AutomaticVeeamBrokerSvc Stopped AutomaticVeeamCatalogSvc Running AutomaticVeeamCloudSvc Stopped AutomaticVeeamDataAnalyzerSvc Stopped AutomaticVeeamDeploySvc Running AutomaticVeeamDistributionSvc Running AutomaticVeeamExplorersRecoverySvc Running AutomaticVeeamFilesysVssSvc Running AutomaticVeeamGCPSvc Running AutomaticVeeamKastenSvc Running AutomaticVeeamMountSvc Running AutomaticVeeamNFSSvc Running AutomaticVeeamPVESvc
Many of my customers (luckily) are using Sure Backups. Some of the subnets are also quite small (i.e., smaller than /24). When configuring the network settings in the Virtual Lab wizard, there is a little problem which can easily be handled. Veeam automatically inserts the appropriate letters for masking in the masquerading network.For example, if you configure a /24 network, the wizard inserts a “D” in the fourth octet. This is correct and must be done this way. The situation is different if the subnet is smaller. For example, if you have a /25 network and enter it in the wizard, the fourth octet of the masquerading network no longer displays a letter, but the number of the subnet mask. To avoid this, simply click on the fourth octet of the masquerading network and enter a “0”. Then confirm with OK. If you now reopen the configured network in the wizard via “Edit”, the “D” will now also appear here and the network can be used in the Virtual Lab.Original post on my blog:Veeam: Virtual
ContextWe have been using the vCloud Director Self-Service Plugin to allow our tenants to initiate their own restores. Essentially how it works is to provide them with limited access to Enterprise Manager, scoped to just their vCloud Organization. The ProblemRecently however, all file restores and downloads started to fail for them, as well as files restores performed by me directly on the Enterprise Manager server. Those restore failed with the following error(s):Error occurred during the FLR job executionSerialization for transport spec is not implementedUpdating FLR session historyUnable to prepare files for download. TroubleshootingTo resolve this, I searched high and low for a resolution, including:Confirming that the restore worked on the B&R console; it did However I found that when initiating from Enterprise manager, the FLR session opened up, but it didn’t log any attempt to restore a file, indicating that it never got that far in the process Recreating the Enterprise Man
V13 upgrades cleanly when the VBR server is already cleaned up first. Most delays come from legacy backup-copy jobs, old agent deployments, nested repositories, removed job settings, or unsupported infrastructure that was still tolerated before the upgrade. Check the starting build first, clear blockers before mounting the ISO, and validate backup plus restore behavior afterward. 1. Supported starting pointDirect to v13.0.1 only from:v12.3.1 build 12.3.1.1139 or later v12.3.2If the server is on an earlier v12.3.x build:patch to v12.3.1 build 1139 firstIf the server is on v12.2.x or older:stage through v12.3.1 first2. Installer blockers to clear before the ISO is mountedThese stop the upgrade:backup metadata not upgraded to v12 format legacy backup-copy jobs Veeam Agent for Windows before v6 using LocalDB nested repository paths UNC path still configured in Export VBK File Copy jobs targeting the backup server jobs still using "Transform previous chains into rollbacks"Do not wait for t
When working with tape environments in Veeam Backup for Tape, cleaning is often treated as a routine task.However, in practice, it plays a much bigger role than most people expect.Over time, I’ve seen stable environments suddenly start presenting errors, performance degradation, or unexpected behavior — and in many of these cases, the root cause was simply a lack of proper tape drive cleaning.In this post, I’ll share how tape drive cleaning actually works in practice, what is often overlooked, and why this small maintenance task can have a major impact on reliability. What Is a Cleaning TapeAt first glance, a cleaning tape looks just like a regular data cartridge.It follows the same physical format but uses a specific label, typically CLN or CLNU, depending on the vendor.The difference is internal.Instead of storing data, the cartridge contains a specialized cleaning material — typically a controlled, non-abrasive fabric — designed to safely interact with the drive’s read/write heads.F
I have backup job with forever forward incremenal and the retention set to 7 days.I also have backup copy to Azure Blob where immutable set to 30 days.When we use forever forward incremental then full backup will be merged with last increment, then how this work in immutable storage?If the immutable set to 30 days then full backup only for 1st day and rest 29 days is incremental and no full backup merged every day?
Here my configuration for azure blob where i set the immutable duration for 7 days. How we can make sure that we can’t delete any backup files inside this blob?I try connect to azure blob storage then upload new file and then i try to delete and i can deleted the file. Is the immutable not work since i can delete test file what i upload manually?
Hi teamI was wondering if anyone has noticed some strange behavior when configuring network during ISO installer workflow?I have done two installs now. When I go into the network portion and I select the connection toggle, it stays in the connecting state and eventually disconnects.For one repo, one nic actually connected.From a switch perspective, all is up and connectedI made the changes as per documentationInstalling from Veeam Hardened Repository ISO - Veeam Backup & Replication User Guide for VMware vSphereFor the repo that manages to connect to one nic, I configured LACP as per document but only with one nic. This got the repo on the network and I manually added added the second nic the bond from the CLI.The second repo, in the network workflow, the two nic are discovered but are not connecting.I ended up configuring one nic as an ethernet link. Then I created the LACP bond from the CLI and added the links manually. This worked.So not sure why I am seeing this strange behavio
Managed BCDR with Veeam Delivering Resilient Business Continuity & Disaster Recovery as a Managed ServiceProviding Business Continuity and Disaster Recovery (BCDR) as a managed service requires far more than “running backups.”Customers expect guaranteed recovery outcomes, predictable recovery times, and protection even when the backup infrastructure itself is compromised.This article walks through a real‑world MSP architecture for delivering Managed BCDR with Veeam using:Active/Standby Veeam Backup & Replication (VBR) Veeam Cloud Connect Veeam Data Cloud Vault (immutable object storage) Microsoft Azure as the disaster recovery execution platformWe’ll cover the business problem, architecture decisions, operational flows, DR activation, and practical configuration guidance, concluding with clear pros, cons, and limitations.The Business Problem MSPs Must SolveModern customers don’t buy backups — they buy recovery confidence.They require:Predictable RPO and RTO Protection against r
Hi, I’m trying to use a Veeam proxy on a satellite location to backup local resources to a configured VDC Vault. It fails with the error:4/22/2026 9:32:28 AM Failed : Processing [server-to-backup] Error: NFC storage connection is unavailable. Storage: [stg:datastore-355002,nfchost:host-354978,conn:vcenter-fqdn]. Storage display name: [VUSA-VMFS02]. Failed to create NFC download stream. NFC path: [nfc://conn:vcenter-fqdn,nfchost:host-354978,stg:datastore-355002@server-to-backup/server-to-backup.vmx]. Agent failed to process method {Transfer.FileToText}. (NFC storage connection is unavailable. Storage: [stg:datastore-355002,nfchost:host-354978,conn: vcenter-fqdn]. Storage display name: [SAN-storage].) (Failed to create NFC download stream. NFC path: [nfc://conn:vcsa.voortman.local,nfchost:host-354978,stg:datastore-355002@ server-to-backup/server-to-backup.vmx].) (Agent failed to process method {Transfer.FileToText}.) (0:08:25) I can, off course, create a ticket, but maybe someone has a
Hello Community, We have two DC’s and running Veeam 13 for Backup and Replication of VMware Virtual Infrastructure. In previous versions we have backup server VM running in the secondary DC and replicated to the primary DC. In case of loss of secondary DC, we can recover the VM on the Primary DC by simply powering it ON and then recovering any other VMs. However with Veeam 13 we have observed that the Veeam policy doe snot allow the Veeam Server to be replicated. What should be the recovery steps for the Veeam backup server (we have deployed the Veeam software appliance)?My thoughts:Deploy a new Veeam backup server appliance with same network IP as the previous server. Import the config backup Rescan all the backup components.Is this the right approach or should we deploy the server appliance with a different IP and import the previous backup config? BR,Sudhir
With the release of Veeam Backup & Replication v13, backup validation has become even more critical—especially in enterprise environments where data integrity and compliance are non-negotiable. In this context, Veeam-Validator emerges as a practical solution to extend and automate the native Veeam validation capabilities. Download script:L1nkState/Veeam-Validator-: Veeam Backup Validator A PowerShell automation script to validate Veeam backups and optionally send HTML reports via email. Designed for Veeam Backup & Replication v12 and v13, schedulable via Windows Task Scheduler. What is Veeam Backup Validator (Technical Context)The native Veeam Backup Validator is a CLI utility designed to verify backup file integrity without performing a restore. It works by leveraging block-level checksums: during backup creation, hashes are generated for each data block, and later recalculated and compared to detect corruption.From an operational standpoint:Works at file-level (CRC checks) D
As a follow-up to my last article, “Lab View: How to Air-Gap Veeam without breaking operation,” in this article, I will discuss common mistakes with Air-Gap and how they break you Air-gapping your backups is one of the smartest moves you can make.Done right, it protects you from:Ransomware Insider threats Accidental deletion Catastrophic failureBut here’s the reality:Most air-gap strategies fail—not because they don’t exist, but because they’re implemented wrong.I’ve seen environments with “air-gapped backups” that looked secure on paper…and completely fell apart during recovery.Let’s break down the most common mistakes—and why they matter. 1. “We Have Immutability—We’re Good”This is the #1 misunderstanding.Immutability is powerful.But it’s not the same as an air gap.The mistake:Relying solely on immutable storage Assuming it covers all attack scenariosThe problem:Credentials can still be compromised Access paths still exist Attackers can still disrupt operationsThe fix:Combine immutab
Network Mapping in Veeam Orchestrator Recover Locations can not be deleted.Checking if any of you guys have experience this. I can delete the network mappings. However if I go back, the network mappings reappear. The only way I can make the mappings go away is to delete the Recover Location and re-add the Recovery Location. Is this normal behavior on VRO v13?
Hi, I’m considering supporting cross-platform recovery on a large production scale /w CC. I’m aware of the limitations presented with this. I’m really interested in hearing about experiences with recovering Prox backups into VM or Hyper-V and accounting for driver removal/install. What was your experience? Were you able to automate the workflow? What was more problematic, Windows or Linux? What about boot loaders/Grub & Kernel drivers? Thanks!
Dear all, this is just a quick guide, but maybe helpful for some of you!I had this behaviour with the latest release from yesterdays ISO, to patch to the latest release… After mounting the ISO and click on Setup.exe I received the following error:Unable to run the installer because files from this ISO are blocked for security reasons. Use the “Unblock” option in the file properties to proceed. It’s an easy step, but keep in mind, this you have to do on the ISO file itself, not on the Setup.exe file 😉So right-click on the ISO, and choose Unblock under Security. Hit OK/Apply and have fun, while applying your urgent updates! Take care, stay up2date and have a great weekend!
Please help, We are trying to backup large number of laptops, ± 400 using 1 proxy server to backup to S3 type of storage. We are experiencing performance issues. Laptops are using wi fi to connect to the cooperate network. We used a CSV file to configure protection group and our backup are scheduled during working hours. Please advise on the way forward for the best practice or recommendations.
I have a migration from Veeam on Windows to Veeam on Linux, and I need to make sure there are no problems after the migration
I'm getting in my own way right now.I've set up an organization in Veeam M365. I want to edit it, but when I go to the connection settings, I'm asked for the application ID and a certificate.Which certificate should I select here? Veeam only suggests three options:1. Self-Service Patch Certificate2. Restful API3. (without friendly name) I didn’t have to specify a certificate during setup; I just followed the wizard.How can i choose the correct certificate?Maybe I'm just being stupid today.
I hear it all the time: my customers are looking for a backup solution they can set and forget, basically run itself. This article will focus on that - every backup solution needs to be monitored and troubleshoot issues. “Set it and forget it.”It sounds like the dream.You deploy your backup platform, configure your jobs, see everything turn green… and move on to the next project.No noise.No issues.No need to touch it.Until something goes wrong. The Illusion of “Everything Is Fine”In a lot of environments, backups quietly run in the background.Jobs complete Reports look clean Storage is filling (as expected… mostly)So naturally, attention shifts elsewhere.That’s the trap.Because backup environments don’t usually fail loudly at first.They drift. What “Set It and Forget It” Actually Looks Like Over TimeIt doesn’t break on Day 1.It slowly turns into:Jobs that run longer than they used to Warnings that get ignored (“it’s just a warning”) Storage growing faster than expected New workloads ad
When working with tape environments, tape backup troubleshooting in Veeam is often more complex than it initially appears. Many professionals associate errors directly with faulty media. However, in real-world scenarios, issues often originate from hardware behavior, environmental conditions, or subtle physical problems.In this article, I will share real troubleshooting cases and, more importantly, explain the reasoning behind each analysis. The goal is to demonstrate how to identify the root cause instead of relying only on error messages. Case 1 – Mechanical obstruction during tape movementScenarioBackup jobs started failing during tape movement operations between slots and drives.Observed symptomsFailures during load and unload operations Errors affecting a specific range of slots Intermittent behavior that initially appeared randomExample error:Unexpected slider block, cartridge is not pushed far enough into the slot(ROB_SLIDER_UNEXPECTED_BLOCK_DURING_INSERT) TroubleshootingManual
Air-gapping your backups sounds simple in theory:“Just isolate them so nothing can touch them.”But in practice?That’s where things get tricky.Because the moment you start locking things down too aggressively, you risk:Breaking backup jobs Slowing down restores Creating operational headaches Or worse—making recovery harder when you actually need itI’ve seen environments go too far:Backups fully isolated… but unusable Processes so manual they never get tested Security so tight it blocks recovery workflowsThat’s not resilience. That’s friction.So let’s talk about how to air-gap Veeam the right way—without breaking operations. First: What “Air-Gap” Actually MeansAir-gap doesn’t have to mean physically unplugged (although it can).In modern environments, it usually means:Logical isolation Controlled access Separation from production riskThe goal isn’t to make backups unreachable.The goal is to make them untouchable by attackers—while still usable by you. The Core PrincipleBackups should be e
Hi since upgrading my PVe to version 9.1 and the VBR to 13, the backup performance have degraded a lot. We have 1 worker per pve host, storage is Ceph. Did someone encounter this issue?
Hi,I am going over DR scenarios and have a query on improving our procedure.We have two sitesPrimary site Hosts all production servers (5x physical & 30ish virtual) Hosts the VSA virtual server Primary & immutable storage repositories Secondary DR Site Off-site storage repository 2x spare physical servers for use in DR scenarioBoth sites connected via VPN. Everything on Hyper-V Now my query - lets say the primary site is destroyed. We want to restore everything to the secondary site.First step I can’t login to Veeam console because it was hosted in the primary site. Therefore current procedure is to setup a new instance of VSA and import a backup of the config. Not a difficult task but it takes time which I’d rather not have to spend during an emergency scenario.Is there a better way? Does it make sense to replicate our VSA virtual machine to the secondary site? Maybe high availability? Or should we be hosting the VSA virtual machine at the secondary DR site with a proxy server
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.