Jump to content

Recommended Posts

Posted (edited)
Has anyone moved to Redstor and how did you find it, looking at 365 and VM

 

I had a demo, setup a trial, and backed up all my servers into it and enabled the M365 backups (it throttles your trial to only 25 accounts though on that front). It's very easy to setup and use, a little time consuming getting all on your on-prem servers into it but it's very straight forward.

 

What it lacks:

Centralised management of your backed up machines - Installing the agent is a one by one job, changing options/settings is a one by one job. However, that's relatively minimal, once you're setup it does seem like set and forget.

Linux - They have a supported list of OS's and builds. I've got one VM on 22.04 which isn't in their supported list yet, but you can manually install their 20.04 version and it appears to work fine... guess i'll just be unsupported for issues in that case though, but it's only my unifi wifi controller so all i really need from it is the config backup for unifi. I also run FreePBX which was built with the FreePBX ISO, that identifies itself as "Sangoma" rather than RHEL/CentOS like it did in the past. RedStor agent didn't like that, so again i had to manually install the agent, based on their RHEL7 rpm. All straight forward enough, but you might have to ask support for some details for the manual install.

 

It feels almost old fashioned, doing a system state backup with an agent, but with a very modern spin on it. I'm so used to just vacuuming up VMs at the hypervisor level that it felt like a backwards step, but once you get into it, it seems like a really solid product. Meanwhile, zero hardware required on prem, BUT you can setup to store a local copy if you wish.

 

I've made accounts for me and my two techs, they've both got user accounts but with delete permissions removed, so I'm the only account that can delete data from our RedStor account. Guy on the demo did say that if i request it, they can take the delete permissions away from me too. They don't have the ability to delete, intentionally, but they can give it back to me by following a series of questions if i ever request it. If you do delete something, the data is staggered between their data centres so if you delete something you have about two weeks (I think that's what he said) before it's removed from the other data centre, so support can recover it for you in that instance.

Edited by mrbios
  • Thanks 1
Posted
Thanks hopefully they can add some of those features in the future, we're going to trial it shortly.Think I should be able to backup a RockyLinux VM and only lose file level recovery which isn't needed for it.https://support.redstor.com/hc/en-gb/articles/5927131286813-1397-How-to-backup-and-recover-Hyper-V-virtual-machines
Posted
Thanks hopefully they can add some of those features in the future, we're going to trial it shortly.Think I should be able to backup a RockyLinux VM and only lose file level recovery which isn't needed for it.https://support.redstor.com/hc/en-gb/articles/5927131286813-1397-How-to-backup-and-recover-Hyper-V-virtual-machines

 

You could probably install the RHEL agent on it if you wanted to get file level backups.

 

So far support has been really good, there's a fair bit they can do on your behalf it seems if a feature doesn't exist in the agent..... I have a remote access server for sims, wanted to back it up just for ease of restore (would be very easy to rebuild manually mind...) I wanted to exclude the Users directory, but i wanted to include the local admin and default folders within it. I can't do that in the agent, but seems support can include sub folders on my behalf for top level folders i've excluded. They proactively fixed a problem with a linux VM backing up for me too lol

  • Thanks 1
  • 2 weeks later...
  • 3 weeks later...
Posted
I suppose the risk with the Synology backup is the risk of discs and possible fire/flood/power going down. Barracuda seems a decent value option for edu.... Pay for staff, get students free I believe...
Posted
Our Synology is hosted in a data centre. We managed to find a provider who set it all up for us so don't have to have it onsite, we access it through a secure web portal.
Posted
I suppose the risk with the Synology backup is the risk of discs and possible fire/flood/power going down. Barracuda seems a decent value option for edu.... Pay for staff, get students free I believe...

 

They are so cheap you could buy TWO boxes cheaper than licensing for one year of alternatives. Put them in different buildings. Ours lives in the exam office room, this room is safer than the server room.

Posted
I've read that restoring from Synology really sucks, no way to restore full mailboxes for example and having to restore emails individually. This puts me off the idea completely - it's great having stuff backed up but if I can't restore effectively what's the point?
Posted (edited)

Ive just gone into activebackup restore, selected a test account, gone to onedrive and mail, selected service mail, under restore I have the option to restore files or "entire mailbox". If I click entire mailbox I get the option to restore entire mailbox to a new folder, original folders but overwrite existing or original folder skip existing. It took 1:40 seconds to restore 822 emails totalling 307.7Mb, I restore to a new folder and the email plus structure was in the folder.

 

Downside, I couldnt rename the folder before restoring, it was named "restore_20240510_162623"

Edited by KK20
Posted
I've read that restoring from Synology really sucks, no way to restore full mailboxes for example and having to restore emails individually. This puts me off the idea completely - it's great having stuff backed up but if I can't restore effectively what's the point?

 

Only used it a couple of times in anger, worked as expected and didn't need to restore emails individually.

Posted (edited)

oh thats good! I'll try and track down the complaint list I found and post it up if you guys wouldn't mind reviewing and commenting?

 

Can't find the thread, but found this:

 

"It works with caveats. For example you cant d/l an entire users onedrive directory through the activebackupforbusinesso365 (ab4bo365) client, but rather have to go through file station instead. This is a known issue. Also, you can only restore emails one at a time not an entire mailbox; the file station trick doesnt work in this context either."

Edited by ThomL
Posted (edited)

using same screen as before, I select onedrive from service, I can select top level "all" or individual files then restore. same choices as before - to a new folder, overwrite existing or skip existing. This was through activebackup. Not sure why you would ever use filestation as the destination is 365land

 

It should note that there is a timeline screen at the bottom where you can select different backups for older file versions should you so wish.

 

The screen can get fiddly because you need to juggle 1) what do you want to restore? Mail, onedrive, sharepoint, teams. 2) who do you want to restore or what context (i.e. not everyone can access every sharepoint library or team for example) 3) when. Generally ensure you select a user with more rights if you want to restore a full library (!why you would do this is beyond me though!) or a specific team (a restore for a pupil may not be the same as a restore from the owner etc. Use an admin context if you want a verbatim restore etc).

Edited by KK20
  • Thanks 1
Posted

I have recently put in a Synology solution, and just a word of warning, it is slow.

 

This could be because I didn't get a high enough spec box (DS923+), the 40 concurrent item limit enforced by Microsoft, or my own ineptitude, but it takes days to back up a 6TB M365 tenancy.

 

That being said, it is easy to setup and configure, and I've easily been able to tailor back ups so it doesn't need to back up everything, but if you need to recover you M365 estate because of a ransomware attack situation, I'm not sure this would be the ideal solution.

Posted
Yeah I would be wary about an on prem setup as ransomware backup - If an attacker gets enough information they could jump on the synology management console and trash the backups that way (Same as they could trash an on prem Veeam immutable storage if you left the iDrac active)
Posted
I have recently put in a Synology solution, and just a word of warning, it is slow.

 

This could be because I didn't get a high enough spec box (DS923+), the 40 concurrent item limit enforced by Microsoft, or my own ineptitude, but it takes days to back up a 6TB M365 tenancy.

 

That being said, it is easy to setup and configure, and I've easily been able to tailor back ups so it doesn't need to back up everything, but if you need to recover you M365 estate because of a ransomware attack situation, I'm not sure this would be the ideal solution.

 

 

Interesting, what sort of internet connection do you have? Is that for the initial backup or every incremental backup?

Posted
I have recently put in a Synology solution, and just a word of warning, it is slow.

 

This could be because I didn't get a high enough spec box (DS923+), the 40 concurrent item limit enforced by Microsoft, or my own ineptitude, but it takes days to back up a 6TB M365 tenancy.

 

That being said, it is easy to setup and configure, and I've easily been able to tailor back ups so it doesn't need to back up everything, but if you need to recover you M365 estate because of a ransomware attack situation, I'm not sure this would be the ideal solution.

 

Probably your internet connection

Posted
Yeah I would be wary about an on prem setup as ransomware backup - If an attacker gets enough information they could jump on the synology management console and trash the backups that way (Same as they could trash an on prem Veeam immutable storage if you left the iDrac active)

 

**Thinking aloud** What if the NAS was on its own internet only VLAN with no network access, and not storing the log on credentials anywhere (although obviously it would need to be accessed somehow for management)?

Posted
My synology takes around 8 hours, for the whole tenant even all the teams stuff which needed the extra permissions from Microsoft. (I have the cheapest +NAS)
  • Thanks 1
Posted
**Thinking aloud** What if the NAS was on its own internet only VLAN with no network access, and not storing the log on credentials anywhere (although obviously it would need to be accessed somehow for management)?

 

At some point you're going to need to logon to it. If your workstation is compromised & you logon to it, you're toast. I could only see it working if the NAS had local access only.

But even then, you've got to keep it up to date and hope there's no zero days for it.

 

(Yes, I'm paranoid, but it's not paranoia if everyone is out to get you :p)

Posted
At some point you're going to need to logon to it. If your workstation is compromised & you logon to it, you're toast. I could only see it working if the NAS had local access only.

But even then, you've got to keep it up to date and hope there's no zero days for it.

 

(Yes, I'm paranoid, but it's not paranoia if everyone is out to get you :p)

 

Absolutely.

 

I assume with cloud to cloud providers there are safeguards to prevent this? 2FA on admin accounts I would imagine is enforced, but are there usually other things like preventing mass data deletion?

Posted
At some point you're going to need to logon to it. If your workstation is compromised & you logon to it, you're toast. I could only see it working if the NAS had local access only.

But even then, you've got to keep it up to date and hope there's no zero days for it.

 

(Yes, I'm paranoid, but it's not paranoia if everyone is out to get you :p)

 

As well as it being in it's own vlan, no comms to the rest of the LAN, WAN only and firewalled WAN at that - you could put the front end of the nas behind a VPN, with 2FA on the VPN login before gaining access to the NAS web front end. Job done, nice and secure? Even if they have creds from say a keylogger they don't have your MFA to get in. Or is there a massive hole in this plan?

Posted
Absolutely.

 

I assume with cloud to cloud providers there are safeguards to prevent this? 2FA on admin accounts I would imagine is enforced, but are there usually other things like preventing mass data deletion?

 

Usually they have it setup that even if the admin of a tenant trashes everything, they can still recover. I know Veeam Could Connect providers have "insider threat protection"

https://helpcenter.veeam.com/docs/backup/cloud/cloud_connect_bin.html?ver=120

Posted
Probably your internet connection

 

Possible, I thought a 1Gbs uncontested line would be enough, but perhaps not?

 

Something is wrong with it though, it was taking over 2 days to backup our Sharepoint sites (around 400 sites, 7TB or so) and hogging the internet bandwidth whilst doing so (80 MBs shown on the dashboard). If I were to guess, I've probably chosen the wrong RAID, or it's trying to delete the old backup whilst downloading the new one. I will revisit over half term.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...