News, guidelines and various community projects
Recently active
This is a recent research by security specialists of the Dolos Group to determine if an attacker can access the organisation network from a stolen device and also perform lateral network movement.They were handed a Levovo Laptop preconfigured with the standard security stack for this organization. No prior information about the laptop, test credentials, configuration details, etc were given. They stated it was a 100% blackbox test.Once the got hold of the device, they headed straight to work and performed some reconnaissance of the laptop (BIOS settings, normal boot operation, hardware details, etc) and noted a lot of best practices were being followed, negating many common attacks. For example:Pcileech/DMA attacks were blocked because Intel’s VT-d BIOS setting was enabled. All BIOS settings were locked with a password. The BIOS boot order was locked to prevent booting from USB or CD. Secureboot was fully enabled and prevented any non-signed operating systems. Kon-boot auth bypass did
The Notorious Kube Genius Geoff had a problem.After saving the company's Kasten setup by doing a DR restore he was told that Junior Joe’s full access to the cluster would be removed but he still needed access to Kasten to perform his duties which involved only certain functions with policies. NKGG referenced the Kasten documentation concerning Authentication and decided it was time to leverage Open ID connect to do this and in that manner limit Junior Joe’s access.https://docs.kasten.io/latest/access/authentication.html#openid-connect-authenticationThis was going to be no walk in the park. NKGG had never ventured into this area of IT before so he decided to read up on the protocol itself and found a great free resource:https://auth0.com/resources/ebooks/the-openid-connect-handbookThe handbook was offered by Auth0 and they had a free plan to start out with so NKGG decided to give their service a try. You can sign up for free here:http://Auth0: Secure access for everyone. But not just a
Happy SysAdmin Day, community! First of all, come and join us today for the celebration of SysAdmin Appreciation Day with @Rick Vanover, @Geoff Burke and @coolsport00! It’s gonna be fun! Second, I bet you noticed a new special header banner here in Community Hub!It’s special indeed and has Easter eggs in it with some discrepancies and even practices that you don’t want to repeat! Will you find them all? Let’s give it a try!
Hey Veeam Community,Check this episode to learn about #BeatTheGostev challenge, SysAdmin Appreciation Day and how I and @Rick Vanover are going to celebrate it, as well as highlights of the week! Shout-outs to @Nico Losschaert, @vNote42 and @Chris.Arceneaux for making it into recap this week As promised, here are the #BeatTheGostev challenge registration pages: DACH https://go.veeam.com/beat-the-gostev-deBenelux https://go.veeam.com/beat-the-gostev-enUKI https://go.veeam.com/beat-the-gostev-ukiRU & CIS https://go.veeam.com/beat-the-gostev-ru
Happy Friday and SysAdmin Day!Veeam Community Recap #38 is here.@Rick Vanover is on the beach #FloridaVibes and we’re breaking the rule about content today!Shout-outs to @Chris.Childerhose, @ThePlaneskeeper, @chris_eromosele and @Link State for making it into recap this week Check it out now, and do not forget to join us later today for a SysAdmin Day Celebration!
Veeam Backup and Replication is comprehensive data protection and disaster recovery solution which is capable of creating image-level backups of virtual, physical servers, cloud machines, and restoration as well. The technology used in the product optimizes data transfer and resource consumption, which helps to minimize storage costs and the recovery time in case of a disaster. Veeam Backup and Replication provides a centralized console for administering backup, restore, and replication operations in all supported platforms (virtual, physical, and cloud environments). The prerequisite requires you to have a SQL Server already running in your environment. Please see "how to download and install Microsoft SQL Server 2019 Express Edition and Microsoft Management Studio on Windows Server", how to install Microsoft SQL Server 2019 and MsSQL Command line tools on Ubuntu Linux, and how to install MSSQL Server 2019 Developer Edition and SQL Server Management Studio on Windows. With Veeam Back
Recently, Lionel Gilles, a French-based Offensive Computer Security researcher based in Paris, France published a PoC tool on NTLM Relay Attack known as PetitPotam that exploits the MS-EFSRPC (Encrypting File Services Remote Protocol). PetitPotam is a classic NTLM Relay Attack, and such attacks have been previously documented by Microsoft along with numerous mitigation options to protect users. Here is an example of such documents: NT LAN Manager: How to prevent NTLM credentials from being sent to remote servers. Below are some related guides: Active Directory Authentication methods: How do Kerberos and NTLM work? how does cached domain logon work?, and What is Pass the Hash Attack and how to mitigate the attack. PetitPotam takes advantage of servers where the Active Directory Certificate Services (AD CS) is not configured with protections for NTLM Relay Attacks. The mitigations below outline to customers how to protect their AD CS servers from such attacks and help in mitigating the W
Windows 11 enables security by design from the chip to the cloud. Recently, Windows 11 was announced to raise security baselines with new built-in hardware security requirements that will give customers the confidence that they are even more protected from the chip to the cloud on certified devices. Windows 11 is redesigned for hybrid work and security with built-in hardware-based isolation, proven encryption, and our strongest protection against malware. Also, Windows 11 makes it easier for customers to get the most protection from these advanced attacks out of the box with the requirement of a TPM 2.0 chip to help ensure they benefit from security backed by a hardware root-of-trust. You may want to see Measured Boot, Secure Boot, Trusted Boot, and Early Launch Anti-Malware: How to secure the Windows 10 boot process, and Windows 11 Feature-specific, Hardware and Software Requirements: How to upgrade to Windows 11 from Windows 10 as a Windows Insider. Windows 11 focuses on increasing
Hello y’all! I’d like to know what software or tools you often use to project and draw your Veeam environments.Do you use MS Visio, LucidChart or something else?
Hi,i work for an MSP where a lot of clients are small businesses still using Shadowprotect. (even larger clients..) not always setup by us, but as we onboard them we want to start converting to Veeam.Certain smaller clients have physical machines acting as the Veeam B&R Console + backup repository with WD RED NAS HDD’s (only for the purpose of a backup destination, not a failover/actual backup server - due to $$)I’m trying to design a standard quote to help our sales team for a certain client type that doesn't mind spending a bit more money.Thinking of a Lenovo SR250 Maybe?? as the “entry level” Veaam setup(virtualised). (if clients require faster recovery against host failure of their production servers then a custom quote would be created for more of a 1:1 setup)I just want something that will still allow for replication failover (run replicas decently)So consider this, most these clients have a Domain controller VM, File Server VM, and MAYBE exchange VM.The backup server host wo
This is a phenomenal list of Veeam tools, both official and community tools. https://www.reddit.com/r/Veeam/comments/ot29ff/some_handy_veeam_tools/
HiMy setup is as follows : - 1 server (in a workgroup) with Veeam ONE (service account of service is a standalone user, member of Veeam ONE Administrators group and local administrators group)- 1 server (also in a workgroup) with VBR- several domain-joined Hyper-V serversProblem is situated in Veeam ONE : Adding the hyper-v servers with a domain-user (with of course local administrator group) is no problem.Adding the VBR server with a local administrator account is no problem.Adding Veeam ONE Agent on the VBR server is no problem.Problems : - in Infrastructure View : I am getting the error of bad hyper-v username logon attempt (refers to the user being used as service account on the server with Veeam ONEthe info of the Hyper-v server seems to be correct including the CPU graphs and so..Is there a way that another user can be chosen to collect the data instead of the Veeam ONE service account?- in Data Protection View : VBR server is not responding and getting the alarm : Server connect
We have total of 700 VM , we are planning to migrate 200 VM in first phase and 500 VM in second phase , we have veeam on front end and HP storeonce 5650 on backend ... I am not sure how to calculate number of catalyst required for total 700 VM for replication between two data centers ...is there a formula for this ..could some one please help
Could anyone share tutorial for configuring repository replication (backups) for Google Cloud Storage?t's giving user login error, I'm having configuration difficulties between Google and Veeam for Storage Standard
Hello, I have a monthly tape job that started last Monday. Today I found that the tape job failed with the Data error (cyclic redundancy check) for some backup jobs.I decided to manually start again the same tape job with new cartridges, however, I realized that it’s taken only the missed backup jobs from the previous failed jobs, for the other backup jobs the result is “success” but with the message “no backup files found”. Do you have an idea? Thanks in advance, Omar De Souza. PS: VBR 10
Hello there,I have a backup job which was going seamlessly. but in the last days it was failing after reaching 80% with error message attached below. I tried the job by disabling firewall rules nothing new occurred. All backup infrastructure components are working fine for other VMs. I have also checked firewall logs but there is nothing blocked related to this backup.Error message:Error: Unstable connection: unable to transmit data. Failed to upload disk. Skipped arguments: [vddkConnSpec>]; Agent failed to process method {DataTransfer.SyncDisk}. Exception from server: An existing connection was forcibly closed by the remote host Unable to retrieve next block transmission command. Number of already processed blocks: [11956]. Failed to download disk 'VM-Name.vmdk'. I need to figure out how to resolve this issue immediately.
Much has been said about backup and data protection. However, little is said about Backup Policy. In today's post I decided to address what are the aspects that surround a backup policy and why it is important to have one. What is Backup Policy?The backup policy is nothing more than a document that gathers all aspects related to the workload that the backup exerts on an IT environment. On this document we can gather all the information that is considered useful during the backup process or even during a moment of disaster that involves the failure of one or more IT services to operate. So I decided to talk about some topics that I consider important to include in any backup policy. Forget TemplatesA backup policy is a document about your backup routine. So, forget about any kind of templates or pre-made documents about backup policy. You are responsible for the backup. So, no one better than you to understand the data protection environment and landscape. Write a document from scratch
Hi all,a new 0Day vulnerability for Windows 10 clients has been released, the article also recommends deleting all the vss restore points and recreating themSecurity Update Guide - Loading - MicrosoftCheck Windows 10 for SeriousSAM and HiveNightmare Vulnerability Fix - Virtualization Howtohttps://github.com/GossiTheDog/HiveNightmarecommad check : icacls c:\windows\system32\config\samWorkaroundsRestrict access to the contents of %windir%\system32\configCommand Prompt (Run as administrator): icacls %windir%\system32\config\*.* /inheritance:eWindows PowerShell (Run as administrator): icacls $env:windir\system32\config\*.* /inheritance:eDelete Volume Shadow Copy Service (VSS) shadow copiesDelete any System Restore points and Shadow volumes that existed prior to restricting access to %windir%\system32\config. Create a new System Restore point (if desired).Impact of workaround Deleting shadow copies could impact restore operations, including the ability to restore data with third-party backu
Guten Tag and Hi to all the “German speaking” VUG members ! On the 23rd of July there is going to be the first session where VUG Germany and VUG Austria are partnering with each other and joining forces to deliver a session to you guys. However, this one is going to be in English As announced, we will have a Veeam User Group session on VMCE and generally how to approach multiple choice exams and could win no one less than @haslund for this session and are extremely happy that he does this session for us ! We are extremely looking forward to a great session with lots of tips and tricks! In addition, we offer all other VUG community members that you may also join this session, since it is in English anyway. If you would like to attend, press the “Attend” button and watch for the session link Best Regards and a GREAT start into the week !Your,VUGDE & VUGAT leaderboard
We are being told by our Veeam Cloud Connect Provider, Global Data Vault, that we still can’t upgrade to Veeam 11 since there are still bugs in the Cloud Director services. We are also being told that No other Cloud Connect Providers are on Veeam 11 yet because Veeam is telling them not to be until these problems are fixed. Are you hearing the same thing, or if you have Veeam 11 and have no issue with your Cloud Connect Provider, how long have they been compatible with version 11 and who is that Vendor?
This video is part of a series to help MSPs get their veeam service offerings up and running. 10-15 minute videos. This one is on Cloud Connect deployment. What to deploy and where, basic sizing, and some tips and tricks.
Hi everyone,It’s Community Recap time! While I and @Rick Vanover are getting ready to SysAdmin Day (next Friday, July 30th, you don’t want to miss this - register here!), check the new episode below Yes, we’re breaking the rule again!
Dear all,Apology I am a newbie here and my question may sound naive. We appreciate any help from your guys.We used Tivoli in the past to backup Oracle for both long term data keeping and DR. We created 3 sets of tapes. 2 sets would be always in the tape library and one at remote site. Every 2 weeks we get back the offsite set and load it into library, and send one set of tapes to remote site for storage.Could you please give some idea how to set up file-to-tape job (let say daily full backup of Oracle) in Veeam in similar fashion? Our idea is to create a media pool with 3 media sets. One media set online for backup for 2 weeks, another offline in the tape library and one media set in the vault (to keep in remote site). And we will rotate in that way for every 2 weeks.Will that work? We value your input very much.Thank you.Hien
If anyone uses Hitachi as their primary storage there is now a plugin that was posted in the Vanguard slack channel. Going to test this one out since we use Hitachi as one of our primary storage vendors.https://www.veeam.com/download_add_packs/vmware-esx-backup/hitachi/
Yes, it is no backup topic. But because we discussed a reason for my testing here already:I thought it could be interesting. In this post I investigate what happens when a VMware vSphere ESXi host loses its boot device. This device is meant to be a persistent device. For non-persistent devices like USB- and SD-card, behavior is quite clear: whole ESXi OS runs in memory, no mass-write operations should be directed to the device. When it breaks, ESXi isn’t missing it and keeps running.With a persistent device I was convinced that ESXi would die when it broke. BUT: ESXi survives. Not such a clean behavior like with non-persistent devices, but it survived. Reason for testingThere is a concrete reason for this testing. I want to answer the question, if it is safe to boot a ESXi host from a single disk. No Raid, just a single disk connected to a HBA. This would be an additional option for ESXi boot device. Why? Because VMware and other server vendors do not recommend to use non-persistent bo
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.