ESX Virtualization

VMware ESXi, vSphere, VMware Backup, Hyper-V... how-to, videos....

Nakivo Backup and Replication - #1 Backup solution for Virtual, physical, cloud, NAS and SaaS

Menu
  • Certification
      • VCP-DCV vSphere 8
          • vcp2024-125.
        • Close
    • Close
  • VMware
    • Configuration Maximums
    • vSphere
      • vSphere 8.0
      • vSphere 7.0
      • vSphere 6.7
      • vSphere 6.5
      • vSphere 6.0
      • Close
    • VMworld
      • VMware EXPLORE 2024
      • VMware EXPLORE 2023
      • VMware EXPLORE 2022
      • VMworld 2019
      • VMworld 2018
      • VMworld 2017
      • VMworld 2016
      • VMworld 2015
      • VMworld 2014
      • VMworld 2013
      • VMworld 2012
      • VMworld 2011
      • Close
    • Close
  • Microsoft
    • Windows Server 2012
    • Windows Server 2016
    • Windows Server 2019
    • Close
  • Categories
    • Tips – VMware, Microsoft and General IT tips and definitions, What is this?, How this works?
    • Server Virtualization – VMware ESXi, ESXi Free Hypervizor, VMware vSphere Server Virtualization, VMware Cloud and Datacenter Virtualization
    • Backup – Virtualization Backup Solutions, VMware vSphere Backup and ESXi backup solutions.
    • Desktop Virtualization – Desktop Virtualization, VMware Workstation, VMware Fusion, VMware Horizon View, tips and tutorials
    • How To – ESXi Tutorials, IT and virtualization tutorials, VMware ESXi 4.x, ESXi 5.x and VMware vSphere. VMware Workstation and other IT tutorials.
    • Free – Free virtualization utilities, ESXi Free, Monitoring and free backup utilities for ESXi and Hyper-V. Free IT tools.
    • Videos – VMware Virtualization Videos, VMware ESXi Videos, ESXi 4.x, ESXi 5.x tips and videos.
    • Home Lab
    • Reviews – Virtualization Software and reviews, Disaster and backup recovery software reviews. Virtual infrastructure monitoring software review.
    • Close
  • Partners
    • NAKIVO
    • StarWind
    • Zerto
    • Xorux
    • Close
  • This Web
    • News
    • ESXi Lab
    • About
    • Advertise
    • Archives
    • Disclaimer
    • PDFs and Books
    • Close
  • Free
  • Privacy policy

Security Tips for Nakivo Backup and Replication users

By Vladan SEGET | Last Updated: October 5, 2022

Shares

In this post, we'll highlight some security tips for Nakivo Backup and Replication users. Ransomware continues to spread and threaten many small, medium, or large businesses. It's important to stay protected and protect your backup servers and backup files.

Nakivo Backup and Replication is usually installed on top of an Operating System (Windows, Linux etc) so it's crucial that you protect the access to those servers and maintain them up-to-date with security patches.

MFA for Nakivo backup server

One of the protection methods which is more and more used is Multi-Factor Authentication (MFA). Whether you run Windows or Linux, you can protect your server by placing it outside of Microsoft Active Directory (AD) with local user access only. If your Microsoft AD credentials get compromised, your bacup server stays isolated and protected.

There are solutions for Windows or Linux, for implementing MFA. It's easy to find an easy-to-use solution for both environments. In my lab, I'm using DUO security which allows me to protect my backup server VM via a third-party authentication mechanism.

For those of you who do not know how this works. It's an MSI file that you download from Duo (part of Cisco) – after creating an account with them, up to 10 FREE users. Duo Authentication for Windows Logon adds Duo two-factor authentication to these Windows and Windows Server login scenarios:

  • Local or domain account logins
  • Logins at the local console and/or incoming Remote Desktop (RDP) connections

The screenshot from the lab shows the Duo login screen before I open a session on my Windows server machine. As you can see, there are 3 options (I only use one). Duo Push is via Duo App, Phone Call or get the code via Text message (my case). You can check more at Duo Security here.

After I click the “Text me new codes” I receive a SMS with entry code that I enter, then click the Login button and I'm logged in…. Then only, I can login into my Nakivo Backup and Replication Software.

Once your backup server is protected with MFA, you can login only via this method.

Note that you should definitely check Duo Restore, which provide your users with the ability to back up and restore their Duo Mobile app with Duo Restore. This feature allows Android and iOS Duo Mobile users to back up their Duo-protected accounts and recover them when they get a new device — no help desk ticket is needed.

How do I protect my Backup files is I store them elsewhere than on my backup server?

The best backup rule is to store multiple copies of backups in different locations. If your backup server gets hacked (even if you have protected it the best you could), it's always more difficult for hackers to deleted backups stored in the public cloud infrastructure that is protected by immutability.

Immutable backups = undeletable

Even me, as an admin, cannot delete my immutable backups (during a certain period of time only, which is configurable). Immutability is one of the ultimate protections against hackers, ransomware and so on.

Nakivo supports Immutability too. The most important is to activate the immutability when you create a new bucket. If the bucket is already created, it's not possible to activate the immutability and you must recreate the bucket and re-send the backups in there.

Check our recent post – Protect your backups with Wasabi Immutable Storage Buckets – (New)

Backup Immutability Support in Nakivo Backup and Replication

To make backups immutable in Backup Repositories located in Amazon S3 or Wasabi, the following options must be enabled for the buckets where the repository is located:

  • Object Lock
  • Versioning

To make backups immutable in Backup Repositories located in Backblaze B2 Cloud Storage, File Lock (also known as Object Lock) must be enabled.

To make backups immutable in Backup Repositories located in Azure Blob Storage, the following options must be selected for the Azure storage account or container:

  • Enable version-level immutability support
  • Enable versioning for blobs

Notes: Disable Object Lock retention mode and retention period for the Amazon S3 or Wasabi bucket where the repository is located, as retention settings are set in NAKIVO Backup & Replication during job creation.

Backing up to Wasabi with Object Lock enabled may take longer compared to when Object Lock is disabled.

Links: Nakivo Trial and Duo Security

More about Nakivo on ESX Virtualization

  • Nakivo 10.7 New Features – (New)
  • Backup a file share with Nakivo Backup and Replication
  • NAS Backup with Nakivo Backup and Replication 10.6
  • Nakivo Backup and Replication FREE Edition Features and Limitations
  • How to configure immutable backups with Nakivo
  • Nakivo Backup 10.3 adds features for MSPs
  • SharePoint Online Backup with Nakivo Backup and Replication
  • Nakivo Backup and Ransomware Recovery
  • Nakivo Backup and Replication 10.2 Released with SharePoint Online backup and S3 Object Lock
  • Nakivo Backup and Replication 10 Released adding compatibility to vSphere 7

 

More posts from ESX Virtualization:

  • VMware EXPLORE 2022 (NEW)
  • vSphere 8.0 Page (NEW)
  • Patch your ESXi 7.x again
  • VMware vCenter Server 7.03 U3g – Download and patch
  • Upgrade VMware ESXi to 7.0 U3 via command line
  • VMware vCenter Server 7.0 U3e released – another maintenance release fixing vSphere with Tanzu
  • VMware vCenter Converter Discontinued – what’s your options?
  • How to upgrade VMware VCSA 7 Offline via patch ISO
  • vSphere 7.0 U3C Released
  • vSphere 7.0 Page[All details about vSphere and related products here]
  • VMware vSphere 7.0 Announced – vCenter Server Details
  • VMware vSphere 7.0 DRS Improvements – What's New
  • How to Patch vCenter Server Appliance (VCSA) – [Guide]
  • What is The Difference between VMware vSphere, ESXi and vCenter
  • How to Configure VMware High Availability (HA) Cluster

Stay tuned through RSS, and social media channels (Twitter, FB, YouTube)

Shares
Vote !

| Filed Under: Backup, Cloud, How To, Tips Tagged With: Security Tips for Nakivo Backup and Replication

About Vladan SEGET

This website is maintained by Vladan SEGET. Vladan is as an Independent consultant, professional blogger, vExpert x16, Veeam Vanguard x9, VCAP-DCA/DCD, ESX Virtualization site has started as a simple bookmarking site, but quickly found a large following of readers and subscribers.

Connect on: Facebook. Feel free to network via Twitter @vladan.

Private Sponsors

Featured

  • Thinking about HCI? G2, an independent tech solutions peer review platform, has published its Winter 2023 Reports on Hyperconverged Infrastructure (HCI) Solutions.
  • Zerto: One Platform for Disaster Recovery, Backup & Cloud Mobility: Try FREE Hands-On Labs Today!
Click to Become a Sponsor

Most Recent

  • Veeam Backup & Replication v13 Beta: A Game-Changer with Linux
  • What is Veeam Data Cloud Vault and how it can help SMBs
  • Nakivo Backup and Replication – Malware Scan Feature
  • Zerto 10 U7 released with VMware NSX 4.2 Support
  • XorMon NG 1.9.0 Infrastructure Monitoring – now also with Veeam Backup Support
  • Heartbeat vs Node Majority StarWind VSAN Failover Strategy
  • Vulnerability in your VMs – VMware Tools Update
  • FREE version of StarWind VSAN vs Trial of Full version
  • Commvault’s Innovations at RSA Conference 2025 San Francisco
  • VMware ESXi FREE is FREE again!

Get new posts by email:

 

 

 

 

Support us on Ko-Fi

 

 

Buy Me a Coffee at ko-fi.com

Sponsors

Free Trials

  • DC Scope for VMware vSphere – optimization, capacity planning, and cost management. Download FREE Trial Here.
  • Augmented Inline Deduplication, Altaro VM Backup v9 For #VMware and #Hyper-V – Grab your copy now download TRIAL.

VMware Engineer Jobs

VMware Engineer Jobs

YouTube

…

Find us on Facebook

ESX Virtualization

…

Copyright © 2025 ·Dynamik-Gen · Genesis Framework · Log in