Hi all,
We have recently moved from VMWare to Hyper-V.
We use Veeam B&R V12 and have encrypted offsite backups going to a remote backups repository via a site-to-site VPN connection to a third party.
On VMWare, we used VMs as backups proxies and included only those VM addresses in the site to site VPN.
When we moved to Hyper-V, because of the on-host backups proxy architecture, we needed to add the Hyper-V host IPs into the VPN profile. On any given day, I’m happy that the remote team follow best practice in terms of security but I’m not willing to expect that to always be the case. I’m really not comfortable having our host IPs being directly accessible from a third party location, when they have control over the remote IP scheme.
Is there any way to introduce a VM as a backups proxy as per the VMWare architecture to remove the Hyper-V host from the VPN?
If not, is there any reason why I can’t just block all inbound access from the third party IPs? I would expect that all activity is initiated on my side, is that correct?
With thanks,
Simon