Overview of Veeam Backup & Replication 9.5 Update 4

At the end of January, Update 4 for Veeam Availability Suite 9.5 was released, packed with features like a full-fledged major release. Today, I'll briefly talk about the key updates implemented in Veeam Backup & Replication, and I promise to write about Veeam ONE in the near future. In this review, we will cover:

  • the versions of systems and applications now supported by the solution
  • working with cloud infrastructures
  • backing up improvements
  • recovery enhancements
  • new support for vSphere and Hyper-V

We'll also learn about improvements in working with Linux virtual machines, new plugins, and other features.

Overview of Veeam Backup & Replication 9.5 Update 4

So, welcome to the details.

Support for Windows Server 2019, Hyper-V 2019, the latest applications, and platforms

Microsoft Windows Server 2019 is supported as:

  • the guest OS for protected virtual machines
  • the server for installing Veeam Backup & Replication and its remote components
  • a machine that can be backed up using Veeam Agent for Microsoft Windows

Similar support has been implemented for Microsoft Windows 10 October 2018 Update.

The new version of the hypervisor is supported Microsoft Windows Server Hyper-V 2019, including support for VMs with virtual hardware version 9.0.

For popular systems and applications Microsoft Active Directory 2019, Exchange 2019 and SharePoint 2019 supports application-aware backup and application object recovery using Veeam Explorer tools.

For VMs with a guest OS of Windows, support has been implemented for Oracle Database 18c — also with application awareness, including log backup and the ability to restore to a chosen point.

Additionally, support is now available for VMware vSphere 6.7 U1 ESXi, vCenter Server, and vCenter Server Appliance (VCSA), as well as VMware vCloud Director 9.5.

Flexible backup storage options with Capacity Tier

Capacity Tier is a new approach to backup storage in a scalable repository (scale-out backup repository, SOBR) with automated data upload to cloud storage.

With the Capacity Tier and storage policies, you can organize an efficient multi-tier storage system where fresh backups are readily available (in sufficiently fast storage) for quick recovery. After the set period, they will transition to 'second freshness' and automatically move to a remote site—in this case, the cloud.

To use the Capacity Tier, you need:

  1. one or more SOBR repositories containing one or more extent repositories
  2. one cloud repository (known as object storage repository)

S3 Compatible, Amazon S3, Microsoft Azure Blob Storage, and IBM Cloud Object Storage are supported.

If you plan to use this functionality, you will need to:

  1. Configure backup repositories to be used as extents of the SOBR repository.
  2. Set up the cloud repository.
  3. Configure a scalable SOBR repository and add extent repositories to it.
  4. Bind the cloud repository to the SOBR and define the data storage policy and their upload to the cloud—this will be the configuration of your Capacity Tier.
  5. Create a backup job that saves backups to the SOBR repository.

Point 1 is quite obvious (for those who may have forgotten, there is documentation in Russian). Let's move on to point 2.

Cloud storage as part of Veeam Backup infrastructure

Detailed instructions for configuring the cloud repository (aka object storage) are written here (currently in English). In short, you need to do the following:

  1. In the view Backup Infrastructure select the node Backup Repositories in the left panel and click on Add Repository.
  2. Choose which cloud storage you want to configure:

    Overview of Veeam Backup & Replication 9.5 Update 4

  3. Then follow the wizard steps (for example, I will consider Amazon S3)

Note: Storage classes Standard and Infrequent Access.

  1. First, enter the name and a brief description of our new storage.
  2. Then specify the account for accessing Amazon S3—choose an existing one from the list or click Add and enter a new one. From the list of data center region Data center region select the required region.

    Overview of Veeam Backup & Replication 9.5 Update 4

    Tip: A Cloud Credentials Manager has been developed to specify the accounts used when working with cloud components. Cloud Credentials Manager.

    Overview of Veeam Backup & Replication 9.5 Update 4

  3. If you need to manage internet traffic through a gateway, you can select the option Use gateway server and specify the required gateway.
  4. Specify the settings for the new storage: the required bucket, the folder where our backups will be stored, an optional limit on total space, and the storage class (optional).

    Overview of Veeam Backup & Replication 9.5 Update 4

    Important! Only one storage can be associated with a specific folder! You must not configure multiple storages that 'point' to the same folder.

  5. On the final step, we check all settings and click Finish.

Configuring backup uploads to the cloud storage

Now we configure the SOBR repository accordingly:

  1. In the view Backup Infrastructure select the node Backup Repositories in the left panel and click on Add Scale-out Repository.
  2. In the wizard step Performance Tier we specify the extents for it and tell how to store backups in them:

    Overview of Veeam Backup & Replication 9.5 Update 4

  3. At this step Capacity Tier:
    • we choose the option Extend scale-out backup repository capacity with object storage (extend the repository's capacity by utilizing object storage) and specify which cloud object storage to use. You can choose from a list or start the creation wizard by clicking Add.
    • we specify the days and hours when uploads to the cloud can be performed — for this, we click the button Window (upload window).
    • we configure the retention policy — specifying how many days the data will remain in the SOBR repository before being considered 'second freshness' and eligible for transfer to the cloud — in our example, this is 15 days.
    • you can enable data encryption during upload to the cloud — to do this, select the option Encrypt data uploaded to object storage and specify which of the passwords stored in Credentials Manager, should be used. Encryption is performed using AES 256-bit.

      Overview of Veeam Backup & Replication 9.5 Update 4

By default, data is collected from the extents and transferred to object storage using a special type of job — SOBR Offload job. It runs in the background, is named after the SOBR repository with the suffix Offload (for example, Amazon Offload) and performs the following operations every 4 hours:

  1. Checks whether the backup chains stored in the extents meet the criteria for transfer to object storage.
  2. Collects verified chains and sends them block by block to object storage.
  3. Records the results of its session in a database so that the administrator can view them if necessary.

The scheme for transferring data and the storage structure in the cloud is shown in the image below:

Overview of Veeam Backup & Replication 9.5 Update 4

Important! To create such a multi-tiered storage system, you will need a license for an edition no lower than Enterprise.

Backups saved to the cloud can, of course, be used for restoration directly from the storage location. You can also download them from the cloud to on-premises and restore them using even the free Veeam Backup Community Edition.

What's new in cloud infrastructure management

For working with Amazon

  • Restoration from backups directly to AWS is supported for VMs running Windows or Linux guest OS, as well as for physical machines. All this can be restored to virtual machines in AWS EC2 VM, including Amazon Government Cloud and Amazon China.
  • Built-in UEFI2BIOS conversion is supported.

For working with Microsoft Azure

  • Support for Azure Government Cloud and Azure CSP subscriptions has been implemented.
  • You can choose a network security group when restoring to Azure IaaS VMs.
  • When signing into the cloud using an Azure account, you can now specify an Azure Active Directory user.

What's new in application support

  • For running applications on vSphere virtual machines, support for Kerberos authenticationhas been implemented. This will allow you to disable NTLM in the network settings of the guest OS to prevent attacks using hash transmission, which is very relevant for infrastructures with not the highest level of control.
  • Transaction log backup module SQL and Oracle now uses a non-system disk as an auxiliary location for backing up logs, where space is often limited, instead utilizing the volume with the maximum available space. On Linux VMs, the directory will be used C, depending on the available space. /var/tmp or /tmpWhen backing up logs
  • Oracle redo logs will be analyzed in order to preserve guaranteed restore points Guaranteed Restore Points (which are part of the built-in feature Oracle Flashback Oracle Data Guard).
  • Support added Enhanced backup.

The maximum supported size of disk and backup file has increased more than 10 times: with a block size of 1 MB for the .VBK file, the maximum disk size in backup can now reach 120 TB, and the maximum total size of the backup file can go up to 1 PB. (Confirmed with testing of 100 TB for both values.)

  • For unencrypted backups, the volume of metadata has been reduced by 10 MB.
  • For unencrypted backups, the metadata volume is reduced by 10 MB.
  • Optimized the performance of backup job initialization and completion processes; as a result, backups of small VMs will run nearly twice as fast.
  • The module responsible for publishing VM image content has been redesigned, resulting in a significant speedup for file-level and object-level recovery.
  • Preferred Networks settings will now also be applied to WAN accelerators.

What's new in recovery

The new ability to recover VMs entirely is called Staged Restore — staged recovery. In this mode, the VM is first restored from the desired backup to a 'sandbox' (now called DataLab), where you can run your script on the guest OS to make changes to the database contents, OS settings, or applications. The VM with the applied changes can then be moved to the production infrastructure. This might be useful, for example, to pre-install necessary applications, enable or disable settings, delete personal data, etc.

Overview of Veeam Backup & Replication 9.5 Update 4

You can read more about it here (in English).

Note: A license of at least Enterprise.

A new feature has also emerged Secure Restore — safe restoration (works for almost all types of recovery). Now you can check the guest OS files of the VM (directly in the backup) for viruses, trojans, etc., before the recovery process begins — for this, the VM disks are mounted to a mount server associated with the repository, and a scanning procedure is initiated using antivirus software installed on that mount server. (It is not necessary for the mount server and the VM itself to have the same antivirus.)

Out of the box, Microsoft Windows Defender, Symantec Protection Engine, and ESET NOD32 are supported; you can specify another antivirus if it supports command-line operation.

Overview of Veeam Backup & Replication 9.5 Update 4

You can read more about it here (in English).

What's new in working with Microsoft Hyper-V

  • Backup and replication jobs can now include groups of Hyper-V VMs.
  • Instant recovery in Hyper-V VMs from backups created using Veeam Agent supports Windows 10 Hyper-V as the target hypervisor.

What's new in working with VMware vSphere

  • Performance of the vPower NFS write cache is enhanced several times — for more efficient instant VM recovery and optimized SSD usage.
  • vPower NFS now works more effectively with the SOBR repository, allowing for more virtual machines to be processed in parallel.
  • The vPower NFS server now has an option for host authorization by IP address (by default, access is granted to the ESXi host providing the vPower NFS datastore). To disable this feature, navigate in the mount server registry to HKEY_LOCAL_MACHINE
    SOFTWAREWOW6432NodeVeeamVeeam NFS
    and create a key under it vPowerNFSDisableIPAuth
  • You can now configure a SureBackup job to use the vPower NFS cache (in addition to redirecting write changes to the vSphere datastore). This resolves issues with using SureBackup for VMs with disks larger than 2 TB when VMware VSAN is the only storage for vSphere.
  • Support for Paravirtual SCSI controllers with more than 16 attached disks has been implemented.
  • Quick Migration now automatically transfers vSphere tags; these tags are retained during instant VM recovery.

Improvements in support for Linux VMs

  • For accounts that need elevation to root, there is no need to add the option NOPASSWD:ALL for sudoers.
  • Support has been added for the enabled option !requiretty in sudoers (this is the default setting, for example, for CentOS).
  • When registering a Linux server, command switching can now be executed with the command su, if the command sudo is unavailable.
  • SSH fingerprint checking now applies to all connections to the Linux server — to protect against MITM attacks.
  • Reliability of the PKI authentication algorithm has been improved.

New plugins

Veeam Plug-in for SAP HANA — helps utilize the BACKINT interface for backup and recovery of HANA databases to/from the Veeam repository. Support for HCI SAP HANA has been implemented. The solution is SAP certified.

Veeam Plug-in for Oracle RMAN — allows you to use RMAN manager for backup and recovery of Oracle databases to/from the Veeam repository. (There is no need to replace the existing built-in OCI-based integration.)

Additional features

  • Experimental support for block cloning of deduplicated files on Windows Server 2019 ReFS. To enable this feature, find the key in the Veeam backup server registry HKEY_LOCAL_MACHINESOFTWAREVeeamVeeam Backup and Replication and create the value ReFSDedupeBlockClone (DWORD).
  • The setup now includes Microsoft SQL Server 2016 SP1.
  • Support for JSON has been implemented for working with the RESTful API.

What else to read and watch

Overview of the solution (in Russian)
Comparison of editions (in Russian)
User guide (in English) for VMware and Hyper-V

Only registered users can participate in the survey. Please log in, please.

Which of the new features are you most interested in learning more about first?

  • Capacity tier for backup storage

  • Working with Amazon cloud infrastructures

  • New plugins for backing up SAP HANA and Oracle databases

  • New recovery features Staged Restore, Secure Restore

  • New features of Veeam ONE

  • Other (I'll write in the comments)

20 users voted. 8 users abstained.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster