ESX Virtualization

VMware ESXi, vSphere, VMware Backup, Hyper-V... how-to, videos....

Nakivo Backup and Replication - #1 Backup solution for Virtual, physical, cloud, NAS and SaaS

Menu
  • Certification
      • VCP-DCV vSphere 8
          • vcp2024-125.
        • Close
    • Close
  • VMware
    • Configuration Maximums
    • vSphere
      • vSphere 8.0
      • vSphere 7.0
      • vSphere 6.7
      • vSphere 6.5
      • vSphere 6.0
      • Close
    • VMworld
      • VMware EXPLORE 2024
      • VMware EXPLORE 2023
      • VMware EXPLORE 2022
      • VMworld 2019
      • VMworld 2018
      • VMworld 2017
      • VMworld 2016
      • VMworld 2015
      • VMworld 2014
      • VMworld 2013
      • VMworld 2012
      • VMworld 2011
      • Close
    • Close
  • Microsoft
    • Windows Server 2012
    • Windows Server 2016
    • Windows Server 2019
    • Close
  • Categories
    • Tips – VMware, Microsoft and General IT tips and definitions, What is this?, How this works?
    • Server Virtualization – VMware ESXi, ESXi Free Hypervizor, VMware vSphere Server Virtualization, VMware Cloud and Datacenter Virtualization
    • Backup – Virtualization Backup Solutions, VMware vSphere Backup and ESXi backup solutions.
    • Desktop Virtualization – Desktop Virtualization, VMware Workstation, VMware Fusion, VMware Horizon View, tips and tutorials
    • How To – ESXi Tutorials, IT and virtualization tutorials, VMware ESXi 4.x, ESXi 5.x and VMware vSphere. VMware Workstation and other IT tutorials.
    • Free – Free virtualization utilities, ESXi Free, Monitoring and free backup utilities for ESXi and Hyper-V. Free IT tools.
    • Videos – VMware Virtualization Videos, VMware ESXi Videos, ESXi 4.x, ESXi 5.x tips and videos.
    • Home Lab
    • Reviews – Virtualization Software and reviews, Disaster and backup recovery software reviews. Virtual infrastructure monitoring software review.
    • Close
  • Partners
    • NAKIVO
    • StarWind
    • Zerto
    • Xorux
    • Close
  • This Web
    • News
    • ESXi Lab
    • About
    • Advertise
    • Archives
    • Disclaimer
    • PDFs and Books
    • Close
  • Free
  • Privacy policy

Zerto 10 announced with a Real-Time Ransomware Detection and Air Gap Vault with immutability

By Vladan SEGET | Last Updated: May 19, 2023

Shares

Zerto 10 launch event was excellent. Having a Kevin Mitnick as one of the presenters really helps indeed, but Zerto 10 looks pretty solid. With features announced in this release, we won't look at ransomware the same way as we did before. If you have a spare hour, watch the recording here, you won't regret. Now, to the content and to the news about what has been announced that Zerto 10 will bring to fight ransomware and other new features.

The fact that the IT is in war against ransomware isn't new. What changes is that IT has better and better tools to fight it to win battles. Usually, the battle is over when ransomware encrypts your servers, endpoints, and also backups. The first “weapon” we've seen over the couple of years was an immutability of backups. So every vendor now has a possibility to have backups stored within an immutable repository. This is good, but with that, there is also the duration during which you'll need to restore your whole system.

Zerto since several years is now part of HP Enterprise, and that's where Zerto might get an advantage over traditional, software-only data protection vendors.

Zerto has been within the industry for over a 10 years and there are some top challenges that Zerto hears:

  • Threads evolution
  • Slow speed of recovery
  • Low ration of data recovery if you pay the ransom
  • Staying with compliance with GDPR, SOX, HIPAA, ….

Zerto Encryption Analyzer

As we know, Zerto is known as a product that is able to tap into a virtual machine’s IO stream causing no overhead or performance problems compared to traditional hypervisor snapshots and use that data to captures and copies the IOs from VMs, to the remote site where a journal system keeps those data.

Zerto 10 adds a new component that will be able to detect encryption within the IOs. Usually where there is an encryption, there might be a ransomware attack happening, right? And that's exactly the Zerto's new feature all about – detect encryption at the early stage! When most, if not all, of your data is already encrypted and you're looking to recover, that's already too late….

The detection is done at the block level so where a possibly encrypted block is detected, it happens in the very early stage.

The detection system is actually sitting within the Zerto VRA appliance (the appliance that is responsible for moving the data at the block level), so all you have to do is activate a single check box, which activates the inline detection that collects the encryption metrics data. Those data can be then sent via a new API to ZVM, or to other systems.

Just to note, this feature has no additional cost.

As being said, you can leverage external systems, via new API and hook it to other anti-malware security systems that are external to Zerto. Here is an example at Github

New Vault architecture with immutability and Encrypted periodic replication via Physical air gap direct connect RCIP (Remote copy over IP)

The architecture of Immutable Vault with which has been announced, has an ongoing encrypted periodic replication with a physical air gap with direct connection via RCIP. The physical connections between the storage systems used with Remote Copy over IP (RCIP) are through an IP-capable network. Each link between a pair of storage systems is a logical link between a controller node on one storage system and a controller node on the other storage system in the configuration. These links use an Ethernet port from each of the nodes in the storage systems. HPE Alletra systems are part of the architecture.

Another feature of Zerto's software, in conjunction with HP, as it is now an HP company, is that they're have a Vault architecture that has a encrypted periodic replication where physical direct connect air gap is maintained. The architecture is on the bellow screenshot from the presentation. All snapshots in the vault are immutable, all Zerto components needed for recovery are stored in the vault.

So if you lose the Production and replication targets, because they're encrypted by a ransomware, you still have a vault that you know that is immutable, disconnected from the network, and clean. So you just need to chose the restore point that has been identified as “clean” before the ransomware started to spread out, an start your production from those immutable copies.

The vault does not have an exposed management port and does not have any single point of compromise. The Resilience Automation Server (RAS) inside the vault is a lightweight VM that works with native HPE switch and array services to control the RCIP on the HPE Alletra. It uses randomization to reduce traffic predictability.

The vault will allow you to recover all the components from a clean restore point (Zerto Virtual Manager, journals and replicas) so you'll be able to rebuild a clean Zerto deployment inside the vault, even if, the outside world has been destroyed by ransomware.

Screenshot from the presentation video.

Hardened Linux Appliance instead of Windows system for Zerto

Another new feature of the Zerto 10 is the new hardened Linux Zerto Virtual Manager Appliance to which Zerto moves to. It is a stripped down Linux with hardened kernel, with minimum services actives, with a reduced attack surface, including an MFA and RBAC.

You don't have to worry about how do you migrate, because Zerto provides a tool that migrates everything, not only the settings, VPGs, Recovery plans etc….. The migration, apparently, is very fast, it takes about 5 min.

The upgrades and updates will be much easier than dealing with Microsoft's MSIs. The UI stays the same so no changes for admins from the usage perspective, no need to learn anything new.

Zerto 10 and Enhanced and Expanded Microsoft Azure Integration at Scale

At azure, the challenge is often a cost, when operating a large infrastructures. Zerto 10 has optimized their footprint in Azure on their components, but also lower the number of API calls so overall, for large scale protection workloads in Azure, the Zerto infrastructure is more “lighter” in terms of resources, but also those API calls.

There is also a new support for multi-disk consistency API leveraging new Azure API co-developed with Microsoft. This will allows applications using multiple disks to have a single consistency point.

Zerto for Microsoft Azure will be available in the Azure Marketplace in July.

Zerto is used in Azure now have the same scalability as on-prem. Migration to and from Azure, DR to and from Azure, all those moves are seamless.

Final Words

Zerto Virtual Replication is able to provide very aggressive RPOs with its journaling technology and continuous replication architecture without putting more pressure on production environment which may be the case with traditional backup systems using VDDK and snapshots.

Zerto is able to replicate your virtual environment across your servers and storage platforms. Zerto provides a robust and easy-to-use migration and disaster recovery solution. Zerto has the ability to thoroughly test your BC/DR plans while maintaining the online state of the production environment.

Zerto is:

  • RPOs of seconds
  • No impact to production because it does not use snapshots like traditional backup programs.
  • Simple workflow for rapid RTOs on day-to-day recovery scenarios.
  • Failover, failback and testing are all automated

Links: Zerto website

Zerto 10 Launch Event (recorded)

Press Release:

  • https://www.zerto.com/press-releases/zerto-unveils-real-time-encryption-detection-and-cyber-resilience-vault-for-hybrid-cloud-security/
  • https://www.zerto.com/press-releases/zerto-10-introduces-enhanced-disaster-recovery-and-mobility-for-microsoft-azure-at-scale/

The Zerto 10 product will be GA and available for downland, in a couple of weeks.

More about Zerto on ESX Virtualization

  • Zerto Platform 9.7 U1 supports vSphere 8.0
  • Zerto Platform Demo – VMware EXPLORE Barcelona 2022
  • Zerto 9.5 U1 Transition to Linux to reduce surface attack
  • Protect 10 VMs for Free with Zerto
  • Zerto Virtual Replication 9 adds Immutability and Instant Restore from long-term retention repository

 

More posts from ESX Virtualization:

  • Homelab v 8.0 (NEW)
    • NXJ6412 Maxtang EHL30 TPM Alert in vCenter Server 8.0 BIOS Config
    • vSphere 8 Lab with Cohesity and VMware vExpert gift – Maxtang’s NX 6412 NUC
    • VMware Cohesity vExpert Gift VMware EXPLORE 2022 Barcelona
  • vSphere 8.0 Page (NEW)
  • Veeam Bare Metal Recovery Without using USB Stick (TIP)
  • ESXi 7.x to 8.x upgrade scenarios
  • A really FREE VPN that doesn’t suck
  • Patch your ESXi 7.x again
  • VMware vCenter Server 7.03 U3g – Download and patch
  • Upgrade VMware ESXi to 7.0 U3 via command line
  • VMware vCenter Server 7.0 U3e released – another maintenance release fixing vSphere with Tanzu
  • What is The Difference between VMware vSphere, ESXi and vCenter
  • How to Configure VMware High Availability (HA) Cluster

Stay tuned through RSS, and social media channels (Twitter, FB, YouTube)

Shares
5/5 - (1 vote)

| Filed Under: Backup, Cloud, Server Virtualization Tagged With: Zerto 10

About Vladan SEGET

This website is maintained by Vladan SEGET. Vladan is as an Independent consultant, professional blogger, vExpert x16, Veeam Vanguard x9, VCAP-DCA/DCD, ESX Virtualization site has started as a simple bookmarking site, but quickly found a large following of readers and subscribers.

Connect on: Facebook. Feel free to network via Twitter @vladan.

Private Sponsors

Featured

  • Thinking about HCI? G2, an independent tech solutions peer review platform, has published its Winter 2023 Reports on Hyperconverged Infrastructure (HCI) Solutions.
  • Zerto: One Platform for Disaster Recovery, Backup & Cloud Mobility: Try FREE Hands-On Labs Today!
Click to Become a Sponsor

Most Recent

  • Veeam Backup & Replication v13 Beta: A Game-Changer with Linux
  • What is Veeam Data Cloud Vault and how it can help SMBs
  • Nakivo Backup and Replication – Malware Scan Feature
  • Zerto 10 U7 released with VMware NSX 4.2 Support
  • XorMon NG 1.9.0 Infrastructure Monitoring – now also with Veeam Backup Support
  • Heartbeat vs Node Majority StarWind VSAN Failover Strategy
  • Vulnerability in your VMs – VMware Tools Update
  • FREE version of StarWind VSAN vs Trial of Full version
  • Commvault’s Innovations at RSA Conference 2025 San Francisco
  • VMware ESXi FREE is FREE again!

Get new posts by email:

 

 

 

 

Support us on Ko-Fi

 

 

Buy Me a Coffee at ko-fi.com

Sponsors

Free Trials

  • DC Scope for VMware vSphere – optimization, capacity planning, and cost management. Download FREE Trial Here.
  • Augmented Inline Deduplication, Altaro VM Backup v9 For #VMware and #Hyper-V – Grab your copy now download TRIAL.

VMware Engineer Jobs

VMware Engineer Jobs

YouTube

…

Find us on Facebook

ESX Virtualization

…

Copyright © 2025 ·Dynamik-Gen · Genesis Framework · Log in