Skip to main content
Answer

Honest Opinion: Veeam Server Internet Access

  • October 16, 2025
  • 5 comments
  • 89 views

I need some honest opinions here.  Do you all restrict internet access in your Veeam infrastructure?  We have our infrastructure segmented with VLANs and firewall rules, and only allow access from jump boxes to those specific devices.  Is allowing internet access on the Veeam devices (for updates, license updates, etc.) a bad idea?  I feel like with the precautions we have in place, allowing internet access would not be an issue, but I wanted to see what other professionals think, and maybe point out a scenario/flaw that I'm not thinking about.

Best answer by Chris.Childerhose

The answer to this is going to be “It depends”.  If you have all the precautions in place then allowing access is not an issue as you need that for license updates, patches, etc.

We have all our VBR servers with internet access and have to with VCC servers being an MSP.  As long as you have the security in place you should have no issues.  But there are some that due to strict requirements cannot have it.

5 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • Answer
  • October 16, 2025

The answer to this is going to be “It depends”.  If you have all the precautions in place then allowing access is not an issue as you need that for license updates, patches, etc.

We have all our VBR servers with internet access and have to with VCC servers being an MSP.  As long as you have the security in place you should have no issues.  But there are some that due to strict requirements cannot have it.


Tommy O'Shea
Forum|alt.badge.img+5
  • Veeam Legend
  • October 16, 2025

I agree with Chris. Personally I don’t see much of a risk in outbound access to the internet, but some organizations have strict policies where everything needs to be whitelisted, even outbound. In these cases you can refer to the Veeam Port List to determine exactly what needs to be enabled.


Iams3le
Forum|alt.badge.img+11
  • Veeam Legend
  • October 16, 2025

Hi ​@stryker54141, I firmly believe the decision to allow or not to allow internet access for Veeam infrastructure should be based on your organisation's specific needs and compliance requirements! If you do not have this strict requirement, plug in that cable with the right security and hardening in place as ​@Chris.Childerhose have discussed above. I will also recommend taking a look at this link: https://bp.veeam.com/security/Design-and-implementation/Hardening/Workgroup_or_Domain.html


  • Author
  • Comes here often
  • October 16, 2025

Thanks everyone for your great input!!


lukas.k
Forum|alt.badge.img+12
  • Veeam Vanguard
  • October 17, 2025

Just from the security perspective an internet access is not needed for the operational tasks that Veeam performs. Licence updates etc. could be done manually but comes with a workload (obviously).

Depending on your organizational requirements you should decide from that perspective.

 

My blueprint says that you should segment DR systems as well (dedicated, seperated VLANs for Veeam data, Veeam oobm like iLOs and optional Veeam oobm for VHR). In case you run this properly there can be whitelist entries for allowing Veeam servers to communicate to license servers etc. located online.

In a world where we’re going to cloud-based object storage repos you will not be able to avoid internet access in general for a very long time anyways imo.