ESX Virtualization

VMware ESXi, vSphere, VMware Backup, Hyper-V... how-to, videos....

Nakivo Backup and Replication - #1 Backup solution for Virtual, physical, cloud, NAS and SaaS

Menu
  • Certification
      • VCP-DCV vSphere 8
          • vcp2024-125.
        • Close
    • Close
  • VMware
    • Configuration Maximums
    • vSphere
      • vSphere 8.0
      • vSphere 7.0
      • vSphere 6.7
      • vSphere 6.5
      • vSphere 6.0
      • Close
    • VMworld
      • VMware EXPLORE 2024
      • VMware EXPLORE 2023
      • VMware EXPLORE 2022
      • VMworld 2019
      • VMworld 2018
      • VMworld 2017
      • VMworld 2016
      • VMworld 2015
      • VMworld 2014
      • VMworld 2013
      • VMworld 2012
      • VMworld 2011
      • Close
    • Close
  • Microsoft
    • Windows Server 2012
    • Windows Server 2016
    • Windows Server 2019
    • Close
  • Categories
    • Tips – VMware, Microsoft and General IT tips and definitions, What is this?, How this works?
    • Server Virtualization – VMware ESXi, ESXi Free Hypervizor, VMware vSphere Server Virtualization, VMware Cloud and Datacenter Virtualization
    • Backup – Virtualization Backup Solutions, VMware vSphere Backup and ESXi backup solutions.
    • Desktop Virtualization – Desktop Virtualization, VMware Workstation, VMware Fusion, VMware Horizon View, tips and tutorials
    • How To – ESXi Tutorials, IT and virtualization tutorials, VMware ESXi 4.x, ESXi 5.x and VMware vSphere. VMware Workstation and other IT tutorials.
    • Free – Free virtualization utilities, ESXi Free, Monitoring and free backup utilities for ESXi and Hyper-V. Free IT tools.
    • Videos – VMware Virtualization Videos, VMware ESXi Videos, ESXi 4.x, ESXi 5.x tips and videos.
    • Home Lab
    • Reviews – Virtualization Software and reviews, Disaster and backup recovery software reviews. Virtual infrastructure monitoring software review.
    • Close
  • Partners
    • NAKIVO
    • StarWind
    • Zerto
    • Xorux
    • Close
  • This Web
    • News
    • ESXi Lab
    • About
    • Advertise
    • Archives
    • Disclaimer
    • PDFs and Books
    • Close
  • Free
  • Privacy policy

Practical Tips to protect your Veeam Backup Repositories

By Vladan SEGET | Last Updated: December 21, 2023

Shares

Veeam Backup repositories (but not only Veeam's) are one of the principal targets of ransomware. When your backups are wiped out or encrypted, you're left with nothing to restore. Designing your backup infrastructure against ransomware attacks is one of the keys in order to succeed (or rather not fail) when dealing with ransomware attacks.

When you detect that your company was hit by ransomware, you can be sure that the bad guys will go after your backup files, no matter what. How to protect those files? How to protect your backup infrastructure? How to architect it to be safe? In this post, we'll give you some practical tips to protect your Backup Repositories.

3-2-1-1-0 rule: Three different copies of data, two different media, one of which is off-site. That’s where the rule starts, have comprehensive ransomware protection with at least one copy being immutable and zero surprises with recovery verification. Use Copy Jobs and/or Replication as an additional layer of protection. It's easy to set up a secondary site with a single ESXi which will be used as a target for your most critical VM's replicas.

Storage Snapshots can save you –  Many SAN devices support storage snapshots. Use it! Take storage snapshots on backup storage if possible. If the storage device holding backups supports this capability it may be definitely worth using this feature to prevent ransomware attacks!

Stay away from Microsoft AD – Veeam Backup Server should stay away from your Microsoft Active Directory (AD) Domain. If you're getting attacked, most likely they'll go after your Domain admin or privileged credentials to make as much damage as possible on maximum systems within your organization.

Separate user accounts – By default, Veeam is configured to allow anyone in the local administrator's group full access to the Veeam console. Veeam has separate roles to assign to each user depending on what job they will be performing.

It is also important to follow proper password change policies for accounts that have access to do operations in Veeam. This is especially the case if someone leaves the company, as it is time to change the password.

Do Not use RDP on the Veeam Backup server – Why? It's because it's more secure to install a Veeam Backup console for day-to-day operations. Also, you can use ILO, Drac, iPMI to remote access your server. Or you can go directly to the server room and from the console do your patching, upgrading etc.

Use Multi-factor authentication – de facto a standard nowadays. Veeam's latest version 12 allows directly enabling MFA on an account and login to the Veeam console. Even if someone has access to your Veeam server, he/she will not be able to start your Veeam Backup console and do possible damage.

Veeam Multi-factor authentication

Let Veeam Backup Server be only a backup server – It's fairly often, especially with small businesses, that I see that the Veeam backup server has to hold other roles, such as file server, WSUS, app-server…. Not good.

Close Windows Firewall ports except the ones needed by Veeam – Keep the firewall on for all domains (public, private, and if applicable domain). Check the help page at Veeam here for those necessary ports.

Encrypt backups – you might think that encrypting your backups is not necessary. I'd say, it's an extra layer of protection as attacker if he/she get access to the backup files, those will be unreadable so it will be much harder to access your data. However, it will not prevent the attacker (if he's already in your system) from wiping those backups out, even encrypted.

Edit your job > Storage > Advanced > Storage TAB

Use storage of different kind – Tapes, Tapes, Tapes. Yes, but virtual! As you might already heard, you can use software to simulate tapes. One of those is StarWind VTL.

We have more articles about StarWind VTL:

  • Protect your Backups with Wasabi Immutable Storage Buckets and StarWind VTL
  • Free StarWind VTL, VSAN Storage and more news
  • Veeam 3-2-1 Backup Rule Now With Starwind VTL
  • StarWind Virtual Tape Library (VTL) – Another layer of protection against Ransomware

Final Words

Every architecture is different. You have also different underlying hardware which offers different possibilities for ransomware protection and architecture. Immutability everywhere is a must. Coupled with strict access to your Veeam backup server you should eliminate a 90% of cases where your backups got into the hands of hackers. And if you have backups, you can restore…

Detailed articles about v12 new features:

  • Veeam Backup and Replication 12 (Beta2) Installation
  • Veeam Backup and Replication 12 (BETA) – adding Hardened Linux Repository
  • Veeam Backup and Replication v12 – news from Barcelona 2022
  • Veeam v12 direct backup to Wasabi – New UI
  • Veeam Immutable Backups – Your protection against Ransomware

More about Veeam on ESX Virtualization Blog:

  • What is Veeam VHR and how to quickly install and create hardened repository?(NEW)
  • Veeam Backup for Microsoft 365 v7 Released
  • Veeam Bare Metal Recovery Without using USB Stick (TIP)
  • Veeam v12 direct backup to Wasabi – New UI
  • Veeam VMCE – Why become Veeam Certified Engineer?
  • Veeam Backup and Replication v12 – news from Barcelona 2022
  • Veeam Backup for AWS – FREE backup of 10 instances
  • Veeam Backup for Microsoft 365 v6a – What’s New?
  • Veeam Backup for Google Cloud Platform – FREE 10 instances backup
  • Veeam Immutable Backups – Your protection against Ransomware
  • Veeam Backup and Replication 12 (Beta2) Installation
  • Veeam Backup and Replication 12 (BETA) – adding Hardened Linux Repository
  • Quickly setup a Veeam immutable repository via this GitHub Script

 

More posts from ESX Virtualization:

  • VMware vSAN 8 Update 2 with many enhancements announced during VMware Explore (NEW)
  • VMware vSphere 8 Update 2 New Upgrade Process for vCenter Server details (NEW)
  • VMware vCenter Server 8.0 U1b resolves further upgrade issues and adds bunch of security patches
  • VMware vCenter Server Appliance 8.0U1a Released
  • Homelab v 8.0 
    • NXJ6412 Maxtang EHL30 TPM Alert in vCenter Server 8.0 BIOS Config
    • vSphere 8 Lab with Cohesity and VMware vExpert gift – Maxtang’s NX 6412 NUC
    • VMware Cohesity vExpert Gift VMware EXPLORE 2022 Barcelona
  • vSphere 8.0 Page
  • Veeam Bare Metal Recovery Without using USB Stick (TIP)
  • ESXi 7.x to 8.x upgrade scenarios
  • A really FREE VPN that doesn’t suck
  • Patch your ESXi 7.x again
  • VMware vCenter Server 7.03 U3g – Download and patch
  • Upgrade VMware ESXi to 7.0 U3 via command line
  • VMware vCenter Server 7.0 U3e released – another maintenance release fixing vSphere with Tanzu
  • What is The Difference between VMware vSphere, ESXi and vCenter
  • How to Configure VMware High Availability (HA) Cluster

Stay tuned through RSS, and social media channels (Twitter, FB, YouTube)

Shares
5/5 - (2 votes)

| Filed Under: Backup, Cloud Tagged With: Tips to protect your Veeam Backup Repositories

About Vladan SEGET

This website is maintained by Vladan SEGET. Vladan is as an Independent consultant, professional blogger, vExpert x16, Veeam Vanguard x9, VCAP-DCA/DCD, ESX Virtualization site has started as a simple bookmarking site, but quickly found a large following of readers and subscribers.

Connect on: Facebook. Feel free to network via Twitter @vladan.

Private Sponsors

Featured

  • Thinking about HCI? G2, an independent tech solutions peer review platform, has published its Winter 2023 Reports on Hyperconverged Infrastructure (HCI) Solutions.
  • Zerto: One Platform for Disaster Recovery, Backup & Cloud Mobility: Try FREE Hands-On Labs Today!
Click to Become a Sponsor

Most Recent

  • Veeam Backup & Replication v13 Beta: A Game-Changer with Linux
  • What is Veeam Data Cloud Vault and how it can help SMBs
  • Nakivo Backup and Replication – Malware Scan Feature
  • Zerto 10 U7 released with VMware NSX 4.2 Support
  • XorMon NG 1.9.0 Infrastructure Monitoring – now also with Veeam Backup Support
  • Heartbeat vs Node Majority StarWind VSAN Failover Strategy
  • Vulnerability in your VMs – VMware Tools Update
  • FREE version of StarWind VSAN vs Trial of Full version
  • Commvault’s Innovations at RSA Conference 2025 San Francisco
  • VMware ESXi FREE is FREE again!

Get new posts by email:

 

 

 

 

Support us on Ko-Fi

 

 

Buy Me a Coffee at ko-fi.com

Sponsors

Free Trials

  • DC Scope for VMware vSphere – optimization, capacity planning, and cost management. Download FREE Trial Here.
  • Augmented Inline Deduplication, Altaro VM Backup v9 For #VMware and #Hyper-V – Grab your copy now download TRIAL.

VMware Engineer Jobs

VMware Engineer Jobs

YouTube

…

Find us on Facebook

ESX Virtualization

…

Copyright © 2025 ·Dynamik-Gen · Genesis Framework · Log in