News, guidelines and various community projects
Recently active
Hi All, Would it be possible to replace or update the OpenSSL component only on the Veeam Agent for Windows [v13.0.3.1220] due to the Critical bug below, or is it better to wait until Veeam released the latest update ? Recommended Action: Download and install patches as instructedDescription:A heap buffer overflow from converting large OCTET STRINGs to hex on 32 bit OpenSSL may crash or allow code execution; caused by 32 bit multiplication overflow; affects non FIPS OpenSSL 3.x on 32 bit systems.Affected Products:OpenSSLCVE IDs:CVE-2026-31789Vendor Information:https://www.openssl.org/news/vulnerabilities.htmlVendor Patch Download:https://wiki.openssl.org/index.php/Binaries Thank you,
We are planning to upgrade Veeam Backup & Replication from v12 to v13, and I understand that PostgreSQL will be upgraded from version 15 to version 17 during the upgrade process.After completing our validation, including backup and restore tests, we would like to uninstall PostgreSQL 15 from the VBR server.Could anyone share the recommended procedure for safely removing PostgreSQL 15 after the upgrade? Are there any prerequisites or checks that should be performed before uninstalling it?Thank you in advance for your help.
Using YARA rules in the backup environment With the rise of cyber threats, particularly ransomware attacks, simply performing backups and restores is no longer sufficient. Restoring data without ensuring it is free of threats can lead to re-infection of the environment.Starting with version 12.1, Veeam Backup & Replication (VBR) has integrated native support for YARA rules into its Malware Detection ecosystem. This combination enables data integrity validation both before and during recovery processes. What are YARA rules?YARA (Yet Another Recursive Acronym) is an open-source tool widely adopted in incident response to identify and classify malicious artifacts.Unlike approaches based solely on the closed signatures of traditional antivirus software, YARA operates using customizable rules:Pattern-based signatures: Identification via specific strings, byte sequences, hashes, or file structures. Conditional logic: Precise rule definition to determine whether a file is malicious or ano
Ever since I discovered the Magic Ports port-mapping tool, I've had the idea of creating a solution where you simply provide a list of systems (ESXi, vCenter, Veeam Backup & Replication, Veeam Repository, etc.) and assign their roles. From that alone, the tool automatically generates both a graphical and textual representation of the relationships and TCP/IP communication between them. Those relationships are automatically scraped from the Veeam documentation and stored in a SQLite database.I also created an interactive explorer that lets you navigate and better understand the relationships between the many Veeam roles.Building on my previous experience generating Draw.io diagrams with Python, I started developing this tool. After overcoming quite a few setbacks, I finally decided to publish this proof of concept (PoC).The project is still incomplete and currently supports only Veeam Backup & Replication v12, so it isn't fully up to date yet. However, I think it's mature enough
When ransomware hits, the pressure to restore starts almost immediately. People want systems back, and every minute of downtime hurts. The recovery team is expected to move fast. That pressure is real, but moving too fast is how bad recovery decisions get made.My rule is simple: do not reconnect a restored workload to production until the recovery point has been validated in isolation.The newest restore point is not automatically the right one. Encryption may be the first visible sign of an attack, but the attacker could have been in the environment for days or weeks. A successful backup tells us that Veeam captured the data. It does not tell us whether the workload is safe to reconnect.Start with the incident timeline. Work with the security team to identify when the compromise may have started and select a candidate restore point from before that window. For Windows workloads, Veeam Secure Restore can then scan the restore point with Veeam Threat Hunter, supported antivirus software,
The Veeam Configuration Backup is one of those features that may not receive much attention until the day it is actually needed.It protects the configuration of the Veeam Backup & Replication server, including jobs, repositories, proxies, credentials, infrastructure settings, security information, restore sessions, and catalog data.This becomes especially important in environments that use tape.If the Veeam Backup & Replication server needs to be rebuilt and there is no valid Configuration Backup available, additional recovery steps may be required. In a tape environment, for example, it may be necessary to inventory and catalog the tapes again before their contents can be properly identified.During a recent troubleshooting scenario, I encountered an issue where the Veeam Configuration Backup failed every time it was executed.At the same time, the Users and Roles section of the Veeam console was not loading correctly.In this article, I will describe the symptoms, the precaution
Hi everyone,We're currently using the new Veeam Backup & Replication v13 Appliance and have a question regarding post-backup automation.In our previous Windows-based Veeam installation, we had a scheduled task that would automatically shut down the backup server after the backup job had completed successfully. This worked well for our 3-2-1 backup strategy, as the backup server only needed to be online during the backup window.After migrating to the v13 Appliance, we can't seem to find a similar option or supported method to automatically power off the appliance once all backup jobs have finished.Has anyone implemented this on the v13 Appliance? Is there a built-in feature, or is there a recommended approach for scheduling an automatic shutdown after all backup jobs have completed?Any suggestions or best practices would be appreciated.
Well, even being on vacation the series must continue, so I present to you blog #5 in my series around v13. You can read it below as well as on my blog site via the link.Blog - How I’d Monitor Veeam v13 in the First Week How I’d Monitor Veeam v13 in the First Week Introduction The first week after a rollout is where a backup platform proves whether it is stable under normal production load. A single successful backup window is a good sign, but it is not enough to establish confidence in a newly upgraded or newly deployed v13 environment.Early monitoring should focus on patterns. Repeated warnings, creeping runtimes, repository latency, or noisy alerts often tell a more useful story than one obvious failure. The goal is to establish what normal looks like before the environment becomes busy enough to hide drift. Watch Job Trends, Not Just Failures The most important view in the first week is the trend line across scheduled jobs. Administrators should look for backups that complete more
If I had to share just one tip this #SysAdminDay, it wouldn't be a Veeam feature or a PowerShell script.It would be this:Know the environment you're protecting.It may sound simple, but it's one of the biggest lessons I've learned after working on many projects and handling several incidents over the past few years.Many people see a backup administrator's job as checking whether backup jobs completed successfully. Of course that's important, but in my opinion, that's only the tip of the iceberg.Long before an incident happens, the basics need to be done right. Healthy backups, a solid 3-2-1-1-0 strategy, monitoring, restore testing, up-to-date systems, security features, and good governance. Those are the foundations that give us confidence that, when the bad day comes, we have a real chance of recovering the environment.But there's something that becomes even more valuable when everything starts going wrong.Knowing the customer's environment.When an incident happens, customers panic. A
Hello everyone, I am looking to schedule daily backup jobs and copy jobs reports using powershell in veeam backup server. Could you please provide me the suitable script for reports as per jobname, server, latest backup run time, status. Backup version is 13.0
On of the large risks in IT isn’t just Ransomware, hardware faults, or even disaster recovery events.What happens when the person who knows how everything works quits? In many organizations, especially smaller ones, the Veeam Admin is not just responsible for dealing with backups and restores all day. Some of the tasks us Administrators do are:Windows Server Administrators Virtualization Administrators Storage Administrators Security Administrators Network Administrators Domain Administrators Cloud Administrators Disaster RecoveryYou get the point, we wear many hats, and have a lot of access and knowledge. Here are a few things you need to do in the case someone who is responsible for these items do. 1. Change Every password they knew.Veeam Service accounts, Repositories, Hypervisors, OS’s, Storage, Tape libraries, Storage arrays, Switches, Firewalls, Server management, Cloud accounts, Enterprise applications, Encryption passwords…. The list goes on and on, but you don’t know what was
From Veeam 12 to Veeam 13: Building a Future-Proof Backup & Recovery PlatformIn the coming period, we will take an important step in further strengthening our digital resilience. Our current Veeam 12 environment will be migrated to Veeam 13, based on the new Virtual Appliance architecture. At the same time, we will replace our existing, technically end-of-life backup hardware with a completely new infrastructure.For VNOG (Veiligheidsregio Noord- en Oost-Gelderland), cyber resilience is essential because our services directly support public safety and crisis response, where continuity really matters. VNOG is a regional public safety organisation responsible for fire and rescue services, we provide essential fire-fighting services and assistance in the event of accidents, disasters and crises to the 870,000 citizens of North and East Gelderland in the Netherlands.The new design is distributed across two data centres. Within our vSAN environment, which hosts approximately 180 Windows
Veeam Backup and Replication v13 on Windows includes an option to define a custom mirror repository. But what repository should you actually mirror? Is this option even intended for the windows based installation, cause it feels like the offical repos only host updates for the software appliance.
Once again we are in normal circumstances with a full docket of programming. @Madi.Cristil has picked out an awesome block of content that we have recapped, you can watch the video here: Featured Contentvia @EdwinMoraal via @Dynamic via @Stabz Vanguard Blog Spotlight - Stephen SeagraveThis week’s Vanguard Blog Spotlight comes from @Stephen Seagrave with the Frontline backup blog, discussing designs for insurance, business and more: Ransomware Insurance Requirements in Backup Design | FrontlineBackupSpecial Department Newsvia @Madi.Cristil via VUG New Zealandvia VUG BrazilNew Analyst Research: Enterprise AI Readiness: Data Controls and Recovery for AI Agents Enterprise AI Readiness: Data Controls and Recovery for AI AgentsWho’s NewThank you @safiya for prepping this week’s Who’s New, we are pleased to welcome +133 new members. The coolest usernames are @kraisy, @witzel, @ithelp and @gamer23. Alfred’s pick is @olimpias! Have a great weekend everyone.
I’ve been going through an AWS course recently, and while reading about S3 versioning, I was wondering how many times people look at versioning, backup, and disaster recovery thinking they solve the same problem.It’s a very common way to think about them, but once you start breaking it down, it becomes clear they operate at completely different layers.They all fall under the broader idea of data protection, but mixing them up usually becomes obvious when something actually goes wrong.Versioning (AWS S3 Versioning)This is the most immediate layer. I think in AWS, S3 Versioning answers a simple question: “Can I recover a previous version of this object?”If something gets overwritten or deleted, S3 keeps older versions so you can roll back.It’s fast, simple, and very effective for small mistakes — an accidental overwrite, a bad update, or a quick rollback.But it’s still operating inside the same system. Same bucket, same environment, same trust boundary.So it works well for object-level r
I got this number wrong on my first pass, so this post is partly a correction to myself. While fact checking a storage economics piece, I pulled the Block Generation figure from the unstructured data immutability page: up to 10 days added on object storage. Then I found the dedicated Block Generation page giving 30 for some providers. Same user guide, different answers, and a 20 day spread between the documented values. That seemed worth running all the way down. Short version: the feature is smart, the savings are real, and it's often missing from the capacity math I see.What Block Generation actually is Immutability on object storage is enforced object by object, and that creates a scale problem. A typical daily incremental reuses most of the blocks already sitting in the bucket. Veeam has walked through the math on the R&D Forums: at an ordinary daily change rate, nearly every block in a new restore point already exists in storage, so going back and pushing each one's lock forw
Grab your favorite drink — @Rick Vanover and I are back with another episode!We’re catching up on what’s been going on in the community and naturally ending up deep in a few interesting technical conversations along the way. This time that includes a browser-based VBR log analysis tool, what’s new with Kasten for Kubernetes v9 and OpenShift Virtualization, and a closer look at Subscription vs. Rental licensing.Always good conversations, always a few surprises. Happy weekend everyone! 💚 Featured Content via @Jason Orchard-ingram micro via @eprieto via @Andreas Buhlmann Vanguard Blog Spotlight via @benharmer https://benharmer.blog/2026/06/09/universal-cdp-how-to-protect-your-critical-workloads/#more-3158Special Department Newsvia @HunterLAFR via @Stephen Seagrave via @lukas.k , @CMF and Bradvia @mkevenaar and @JonahMay via @MatzeB and @ddomask via @Madi.Cristil via @Madi.Cristil Welcome to all Rising Star members! VeeamON Tour Italy 2026 Community Corner via @MarcoLuvi
It is hard to imagine modern IT environments without snapshots. They are quick to create, can be automated, and ideally to restore very fast to an earlier state. So it is no surprise that in day-to-day operations you often hear the sentence: “We have a snapshot — so we have a backup.” But is that really true?The short answer is: usually no. The slightly longer answer:A snapshot can be a very valuable recovery point. But only through independence from the production system, defined retention, copies to another medium, protection against manipulation, and reliable recoverability does it become a resilient backup concept. So, what actually is a backup? A backup is a separate, recoverable copy of production data, systems, or applications. Its purpose is to restore a defined state after data loss, corruption, user error, attacks, or infrastructure failures.What matters is not only that data from an earlier point in time exists “somehow”. A backup should primarily fulfill the following chara
Hi Community,Does anyone know the best way to backup the Nutanix Prism Centarl VM? Thank you!
Hi everyone,I have a question about using the proxy appliance as an internet proxy for VMs running inside a Veeam Virtual Lab.I enabled the internet access feature and configured HTTPS traffic on port 443. On a VM within the isolated network, I then configured the isolated-network IP address of the proxy appliance and the corresponding port as a proxy server in the web browser.However, internet access is not working.While troubleshooting, I started wondering how DNS resolution is supposed to work in this scenario. Typically, the VM sends DNS queries to an internal DNS server. If the requested hostname cannot be resolved locally, the DNS server forwards the query to an external DNS forwarder.Since the proxy appliance only proxies the web traffic, how are DNS queries from the isolated environment handled? Does the internal DNS server require a separate route or masquerading rule for external DNS resolution, or is DNS resolution handled by the proxy appliance as part of the proxy connecti
Hi everyone,I’d like to share a community project I have been working on: VBR Installer for Aliyun. https://github.com/Coku2015/VBR_Installer_for_Aliyun/The project provides a browser-based wizard for deploying a Veeam Software Appliance into your own Alibaba Cloud account. I created it to explore a more repeatable deployment workflow for Veeam users who operate workloads on Alibaba Cloud.The installer currently supports:VeeamSoftwareAppliance_13.0.2.29_20260617.ovaIt runs on Windows and macOS and requires Python 3.12+, QEMU (qemu-img), Git, and Alibaba Cloud CLI 3.3 or later.I have published a introduction and walkthrough here:https://blog.backupnext.cloud/en/2026/07/Veeam-Installer-for-Aliyun-launch/I would be very interested in feedback from the community.Thanks, and I hope this project is useful.
Hi everyone! I've been working in the lab on some Kubernetes deployments using MobaXterm Home Edition and Rancher. I started off using PuTTY, but found that it could be limiting for what I needed. So I began my hunt to find the best SSH client, and I ended up landing at MobaXterm. In this post, I want to talk a bit about why I opted to use MobaXterm and all of the great features it offers, especially pertaining to working with Kubernetes. Intuitive UI and Easy to NavigateWhile evaluating alternatives to PuTTY, I found that PuTTY along with other SSH terminals looked a bit dated and less approachable. Since this was my first time doing this much terminal-focused Kubernetes work, I wanted a tool I could easily navigate to reduce friction. MobaXterm has a very sleek interface that lends itself nicely to beginners and experts alike. 15 Session Settings/OptionsMobaXterm supports a wide range of session types (SSH, Telnet, RDP, etc.), which makes it useful as a single tool for connecting to
Setup:On-prem VBR 12.3.2 Veeam Backup for Microsoft Azure appliance, connected via External Repository Goal: Instant Recovery to VMware vSphere, restoring Azure VMs back to on-prem vCenter (testing DR failback scenario)What I've confirmed:Restore points ARE visible in VBR under Home → Backups → External Repository → Failback storage Each VM already shows 5 restore points. Platform shows correctly as Microsoft Azure, repository FailbackThe issue:When I right-click a restore point to start the recovery, "Instant Recovery to VMware vSphere" is not available / grayed out in the menu, even though the restore point is clearly present and shows 5 valid points.Questions:What conditions cause Instant Recovery to VMware vSphere to be unavailable even when a valid restore point is shown in the console? Does an active/running backup job on the same policy (I currently have other jobs running in parallel) block Instant Recovery for these VMs? Are there specific requirements for restore points impor
Hello,We are facing a backup issue with Veeam Agent for Microsoft Windows on one specific Windows 11 Pro workstation.We have two Windows 11 Pro PCs, both fully updated and both backing up to the same SMB share.On PC #2, backups work fine.On PC #1, backups always fail.The job starts normally and goes through: Initializing Preparing for backup Creating VSS snapshot Calculating digests Reading EFI partition Reading OS (C:) The failure occurs during Finalizing with the following errors: Application is shutting down. Unable to retrieve next block transmission command Exception of type 'Veeam.Backup.AgentProvider.AgentClosedException' was thrown What we already tried: Reinstalled the agent Recreated the backup job Updated the agent to 13.0.2.1102 Disabled antivirus for testing Confirmed SMB 3.1.1 Added this registry key:HKLM\SOFTWARE\Veeam\Veeam Endpoint BackupForceBufferedAccess (DWORD 32-bit) = 1 We also checked VSS earlier: writers are stable and the backup does not
I'm documenting a full move from VBR v13 on Windows to the v13.1 Software Appliance, run for real in my Pure Storage lab before any of it gets called a production map. Part 2 of the series just went up, and it's the architecture conversation, so I wanted to share the highlights here where the architecture arguments actually happen.The premise: the worst time to make design decisions is mid-migration. The appliance model changes enough old defaults that the target deserves a fresh sheet of paper, not a copy of what your Windows server had. Here's what ended up on my sheet.The backup server is now an appliance you don't log into. The VSA gives you a hardened, Veeam-managed Linux base with no OS access, and after years of preaching simplicity I find that liberating rather than scary. An OS I can't touch is an OS I can't break, and one an attacker finds much less interesting. The old placement rules still apply though: keep the control plane out of the blast radius of what it protects.Pr
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.