Jump to content

Recommended Posts

Posted

How do you do it - your Veeam backup infrastructure?

 

Curious to see how people have structured Veeam in terms of what’s virtualised, what isn’t, what storage you are using (focusing on on-prem at the moment, but let me know what cloud options you use too), how many hosts/servers, how much storage vs organisation size.

 

We’ve had a number of disks fail on our current veeam server, so figured now is as good a time as any to review, learn and improve!

 

Cheers,

Stephen

Posted (edited)

I suspect you may get some vague responses with it being backup and all.

 

As long as you’re following this you should be good.

https://community.veeam.com/blogs-and-podcasts-57/3-2-1-1-0-golden-backup-rule-569

 

If you’re using RPA for cyber cover immutable cloud backup doesn’t suffice so a rotated hard drive or tape library is the only way.

 

My main advice would be have a box not on the domain and with the credentials to it not stored digitally anywhere, I know this to be what saved a few trusts after a cyber attack.

Edited by CrootUK
  • Thanks 2
Posted (edited)

Our standard setup for a secondary type site is:

 

Non domain joined Veeam VM, which lives on the schools Hyper-V cluster (Cluster is on it's own domain rather than the schools production domain) Local firewall on VM is fully enabled, RDP disabled e.t.c. All the associated backup hardware / VM lives on it's own VLAN with ACLs applied on the core to it.

 

Veeam VM backs up to a NAS device over SMB for the normal daily & other routine backups.

 

A second NAS on a scheduled basis is powered up and a full backup taken (usually bi-weekly) then shut down.

 

Syncro (Our RMM) monitors the event logs and reports on sucess / failiures.

 

We also have a separate backup job to PeaSoup with 7 days immutability.

 

The shift now really is moving to backing up the cloud data, apart from Net2, cashless catering and a few other bits and bobs the local VMs are becoming less and less important for us.

Edited by Aprice
  • Thanks 3
Posted

Veeam server runs on rack mounted physical hardware, not joined to domain. 2 OS SSDs in Raid 1.

Hyper-V hosts live on their own internal domain, Veeam connects to that, rather than the public facing domain that the client PCs and users are a part of.

Backs up to 12x8TB QNAP NAS on site (also not domain joined) and that backs up via a WAN connection (through our ISP) to another school in the trust, using QNAPs RTRR (real-time remote replication)

  • Thanks 1
Posted

Thanks all so far, useful info.

 

Bit more background info - I have recently "discovered" a number of old servers - but that must have been expensive when purchased as still pretty high spec. At a couple of sites, the existing backup infrastructure is significantly older, so trying to work out how best to use this hardware to refresh everything. Keen to find more about which components are virtualised vs kept physical, and the storage options. Some of these servers I'm hoping to repurpose can take a number of drives, but not sure how best to use that storage. Maybe make one a Linux hardened repository? Not sure if I make a physical Veeam server with the on-board storage, how secure that would be vs other options.

 

Cheers

Posted

Peasoup cloud here.

 

Veeam licence + 10TB of cloud storage worked out relatively cheap!

 

We backup to an on site NAS in another building (2 esxi hosts, 11 VM's)

 

Our Veeam B&R agent runs on a VM (non domain joined)

  • Thanks 1
Posted (edited)
Thanks all so far, useful info.

 

Bit more background info - I have recently "discovered" a number of old servers - but that must have been expensive when purchased as still pretty high spec. At a couple of sites, the existing backup infrastructure is significantly older, so trying to work out how best to use this hardware to refresh everything. Keen to find more about which components are virtualised vs kept physical, and the storage options. Some of these servers I'm hoping to repurpose can take a number of drives, but not sure how best to use that storage. Maybe make one a Linux hardened repository? Not sure if I make a physical Veeam server with the on-board storage, how secure that would be vs other options.

 

Cheers

 

Unless you’re significantly confident in hardening Linux as a OS i wouldn’t go near a harden repository, your better off handing that off to a cloud provider who can handle that for you, its really not that expensive. Id recommend chatting to CT.co.uk, they can even help with how to restructure the hardware you have to put you in a better place.

 

Without knowing the exact specs it will be hard to advise further, but usually you’d go with bigger but slower disks in a backup server.. cpu/ram really not so important for veeam, 6 core core, 8gb ram is the veeam reqs. https://www.veeam.com/products/veeam-data-platform/system-requirements.html#:~:text=If%20you%20deploy%20a%20worker,for%20product%20installation%20and%20logs

 

I’d suggest a physical box unless you have off domain hyper-v servers it doesn’t make sense to virtualise on just one server for veeam… is this covering multiple sites? do you have vpn/mpls/sdwan in place? if so you could centralise it? Lots of options but hard to help without quite a-lot of potentially exposing info. Id advise speaking to CT or someone similar.

Edited by CrootUK
  • Thanks 1
Posted
Unless you’re significantly confident in hardening Linux as a OS i wouldn’t go near a harden repository, your better off handing that off to a cloud provider who can handle that for you, its really not that expensive. Id recommend chatting to CT.co.uk, they can even help with how to restructure the hardware you have to put you in a better place.

 

Without knowing the exact specs it will be hard to advise further, but usually you’d go with bigger but slower disks in a backup server.. cpu/ram really not so important for veeam, 6 core core, 8gb ram is the veeam reqs. https://www.veeam.com/products/veeam-data-platform/system-requirements.html#:~:text=If%20you%20deploy%20a%20worker,for%20product%20installation%20and%20logs

 

I’d suggest a physical box unless you have off domain hyper-v servers it doesn’t make sense to virtualise on just one server for veeam… is this covering multiple sites? do you have vpn/mpls/sdwan in place? if so you could centralise it? Lots of options but hard to help without quite a-lot of potentially exposing info. Id advise speaking to CT or someone similar.

 

Yeah good point - I haven't looked very far into it yet, so wasn't sure if there was a ready to go Linux build specifically for this sort of thing! Unfortunately our current licensing is tied up until 2026 so don't think anyone would want to advise at this stage?

 

Yes true - hm how vague can I be but still useful....

 

Multi-site - would be interested in talking to anyone who is doing that, across multiple domains, as if an MSP?

Posted

Mine is off the domain entirely & does not have RDP active.

 

I've manually installed the Microsoft security baseline on it https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/windows-security-configuration-framework/windows-security-baselines

I bought a TPM for the server

Although I have had to turn off credential guard on it recently due to a bug in Veeam (grrrr)

 

I do have the iDrac active (With 2fa) for remote admin - Toying with removing it but it is handy...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...