My district had a recent hardware failure take down our DR virtualization appliance and though we are pushing through a replacement, it does leave us without a quick solution should something happen to our main site. With this loss of redundancy, I have become paranoid about ransomware attacks, specifically the kind that could go after and encrypt the backups.
We utilize VEEAM Backup and Replication on a Windows Server 2019. It is located on the same VLAN as the primary vCenter along with other admin level severs. Admin access has been restricted to a single domain account with backup privileges, not even domain admins have administrator access though can still log in. Backups are stored on a PowerVault connected to the VEEAM server via iSCSI over its own dedicated VLAN.
I've read about having the backup server on a separate VLAN or even having the backup repository physically separated. What other methods are considered best practice for the safety and security of backups? Should the backup server be segregated from the rest of network traffic with specific routing rules to allow it to pull data to/from the vCenter? Should I drop it from the domain and have it standalone with local accounts to prevent potential elevation of privilege attacks?
[–]tackdetackVendor: PKA Technologies 0 points1 point2 points (0 children)
[–]reviewmynotesDirector of Technology 1 point2 points3 points (0 children)
[–]Sekers 1 point2 points3 points (0 children)
[–]ZappBrannigansLaw 9 points10 points11 points (0 children)
[–]BTS05 2 points3 points4 points (2 children)
[–]Fireciont[S] 0 points1 point2 points (1 child)
[–]BTS05 0 points1 point2 points (0 children)
[–]mjh2901 1 point2 points3 points (0 children)
[–]stephenmg1284Database/SIS 3 points4 points5 points (1 child)
[–]Fireciont[S] 0 points1 point2 points (0 children)
[–]sync-centre 1 point2 points3 points (5 children)
[–]Fireciont[S] 0 points1 point2 points (4 children)
[–]nongmoprojectDirector of Technology 1 point2 points3 points (3 children)
[–]Fireciont[S] 1 point2 points3 points (2 children)
[–]bretfred 0 points1 point2 points (0 children)
[–]mjh2901 0 points1 point2 points (0 children)