{"id":29927,"date":"2019-10-31T21:32:42","date_gmt":"2019-10-31T18:32:42","guid":{"rendered":"https:\/\/prohoster.info\/blog\/bekap-mne-na-lentu-zapili-rasskaz-ot-pervogo-litsa\/"},"modified":"2019-10-31T21:32:42","modified_gmt":"2019-10-31T18:32:42","slug":"bekap-mne-na-lentu-zapili-rasskaz-ot-pervogo-litsa","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/bekap-mne-na-lentu-zapili-rasskaz-ot-pervogo-litsa","title":{"rendered":"\"Back up to tape for me.\" A first-person account","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In <noindex><a rel=\"nofollow\" href=\"https:\/\/m.habr.com\/ru\/company\/veeam\/blog\/438714\/\">the previous article<\/a><\/noindex> We told you about the new features in the Update 4 released in January for Veeam Backup &amp; Replication 9.5 (VBR), intentionally not mentioning backups to magnetic tape. A discussion about this area deserves a separate article, as there were indeed many new features.<\/p>\n<p>\u2013 Guys from QA, will you write an article?<br \/>\n\u2013 Why not!<\/p>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/6e0943b5851642c604bfaecfc24b66f0.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h1>Tape Drives in the 21st Century<\/h1>\n<p>\nData storage on magnetic tapes (cassettes, \"<b>tapes<\/b>\", as we in R&amp;D call them) is not limited to the outdated ZX-Spectrum computer, where one game could load into 48 kb of RAM from <noindex><a rel=\"nofollow\" href=\"https:\/\/www.google.com\/search?q=%D0%BA%D0%B0%D1%81%D1%81%D0%B5%D1%82%D0%B0+zx-spectrum&amp;tbm=isch\">a tape recorder<\/a><\/noindex> for several minutes. Over a quarter of a century, the speed and capacity of tapes have increased by 6-7 orders of magnitude. This is not quite a fair comparison, and by <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%97%D0%B0%D0%BA%D0%BE%D0%BD_%D0%9C%D1%83%D1%80%D0%B0\">Moore's Law<\/a><\/noindex> the standard <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Linear_Tape-Open\">LTO<\/a><\/noindex> it is not keeping up. Nonetheless, modern technologies allow recording 12 terabytes of data (up to 30 terabytes in compressed mode) on a kilometer-long tape of one cassette, thus, the $160 drive leaves competitors behind in terms of the cost of long-term storage of large amounts of data, even considering the investments in read\/write equipment. Data on such tapes is reliably stored for 15-30 years.<\/p>\n<p>Let me approach it from another angle. Recently, <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%92%D0%B8%D1%80%D1%83%D1%81-%D0%B2%D1%8B%D0%BC%D0%BE%D0%B3%D0%B0%D1%82%D0%B5%D0%BB%D1%8C\">ransomware<\/a><\/noindex> has hit a new level. They can lie in wait within a large company's infrastructure for weeks and months, and with the emergence of another zero-day vulnerability, they can destroy (not without human help, as big money is at stake) not only all data but also all backups that can be reached. Here\u2019s <noindex><a rel=\"nofollow\" href=\"https:\/\/krebsonsecurity.com\/2019\/02\/payroll-provider-gives-extortionists-a-payday\/\">a fresh example<\/a><\/noindex>, when a company had to pay the ransom. The so-called <b>air gap<\/b>, i.e., physically isolated backups from the infrastructure, have essentially become the only reliable protection against such scenarios. Magnetic tape is one of the timeless solutions.<\/p>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/f8a69910c75e97855beaa699302b1699.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHowever, one specification and technological innovations in iron and barium ferrite from leading manufacturers (IBM, HPE, Oracle, Dell) are not enough for reliable data protection; good software is needed. At Veeam, we have an entire team dedicated to tape backups, with about 10 people analyzing, planning, researching, developing, and testing daily. You might have seen the results of this work in previous articles (<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/veeam\/blog\/250951\/\">one<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/veeam\/blog\/349964\/\">two<\/a><\/noindex>). What has been accomplished over the past year?<\/p>\n<h1>Glossary<\/h1>\n<p>\nThere comes a choice between freedoms regarding the native language and bureaucratic phrases that complicate readability. I prefer the former, so I apologize in advance if any jargon from the list below is jarring to someone. Here, I will briefly remind you what each term means. <\/p>\n<p><b class=\"spoiler_title\">Experts in VBR can skip this part<\/b><b>Job <\/b>is the task of backing up. Essentially, the entire VBR is built on jobs. Besides backup and replication, it may also involve copying to tape (backup to tape job). I should mention that restoring from a backup (restore) is also a job, but in this article, the term will specifically refer to backup.<\/p>\n<p><b>Storage <\/b>is a historically established name. These are files in <b>the repository <\/b>(repository), which contain backups \u2013 <b>full <\/b>and <b>incremental.<\/b>A single storage can contain one or several virtual machines.<\/p>\n<p><b>Chain <\/b>is a sequence of interconnected storages. To restore data from the nth incremental storage, all previous storages from (n-1) to 1 and the full storage referenced by the first incremental are needed.<\/p>\n<p><b>Source<\/b>, <b>Target <\/b>are the source and the target. The source is the original entity that the job processes. In the case of backups\/replicas, this is usually a virtual machine in the hypervisor. In the case of tape jobs, the source is the backup job itself (or the files in the case of a file to tape job). The target for backup jobs is the repository where backups are stored. For tape jobs, it is the media pool.<\/p>\n<p><b>Media pool<\/b> \u2013 <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/custom_media_pools.html?ver=95u4\">is a pool of media, in our case \u2013 cartridges. A logical container created by the user that contains cartridges from one or several libraries. Thus, a tape job always has a media pool as a target, meaning that data is written not to a specific cartridge or any cartridge in the library, but to a specific set of them. The media pool has a data retention setting, after which the cartridge can be overwritten. Users can create standard and<\/a><\/noindex> GFS pools. <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/gfs_media_pools.html?ver=95u4\">Each of these types can now also be WORM or non-WORM, more on this below.<\/a><\/noindex>Media set<\/p>\n<p><b>media set<\/b> \u2013 <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/tape_media_sets.html?ver=95u4\">media set<\/a><\/noindex> \u2013 a set of tapes in the media pool that are continuously written to for backups\/files. For GFS pools, media sets are also tied to an interval (for example, yearly), with tapes rotating only within their specific interval.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/watch?v=75xm3JMxWE0\"><b>Drive<\/b>, <b>changer<\/b><\/a><\/noindex> \u2013 elements of the tape library. The drive reads and rewinds the tape, while the changer is a robot that moves tapes between storage slots, unload slots, and the drive. There are also <b>standalone drives<\/b> (standalone) where a person performs the role of the changer. A correctly installed manufacturer driver on a Windows machine connected to the library is mandatory for the drive; however, we can work with the changer without drivers, using native SCSI.<\/p>\n<p><\/p>\n<h1>Tenant to tape. The provider is protected \u2013 clients are protected.<\/h1>\n<p>\nLet's lay the cards on the table. The most significant feature of our update designed for <noindex><a rel=\"nofollow\" href=\"https:\/\/www.veeam.com\/cloud-connect-service-providers.html\">cloud providers.<\/a><\/noindex>, using VBR in their infrastructure. Development started two years ago. Soon, we realized we wouldn't be able to handle such a serious task by the next release, took a brief pause, and ultimately released the feature in 9.5 Update 4.<\/p>\n<p>In short, providers now have the ability to copy their clients' backups to tapes using tape jobs in the GFS pool. This offers providers \u2013 who are very important to our hearts and commercial department \u2013 two opportunities:<\/p>\n<ul>\n<li>to protect their clients (<b>tenants<\/b>, tenant \u2013 renter) from data loss due to accidental deletion or infrastructure issues (\"flood in the server room\");<\/li>\n<li>to provide tenants with an additional service of recovering data from an old backup that has long been deleted from the cloud repository according to data retention policies but is still available on tapes.<\/li>\n<\/ul>\n<p>\nFrom a marketing perspective, the functionality is very appealing, and from our side \u2013 equally challenging to implement.<\/p>\n<h2>Development<\/h2>\n<p>\nThe main issue that has arisen is data encryption. Most cloud backups are encrypted, with statistics showing about two-thirds of the total. This figure surprised us, as we assumed almost everything was encrypted, but it turns out that many clients seem to have unreserved confidence in their providers.<\/p>\n<p>The paradigm is simple: the provider should not be able to decrypt the data of its tenants. In this new feature, however, it is required for the provider to open storages with backups. This is necessary to transfer data blocks, for example, to create <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/virtual_full_backup.html?ver=95u4\">a virtual full backup<\/a><\/noindex>. The main point is that this needs to be done independently of the tenant, as the required keys are not transmitted to the provider during the job execution.<\/p>\n<p>The solution to this problem, which is also involved in another crucial feature of the released add-on \u2013 <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/capacity_tier.html?ver=95u4\">Capacity Tier<\/a><\/noindex> \u2013 lies in adding an additional encryption key. The archive key is stored in the provider's database in an encrypted form. Using a clever scheme on the provider's side, it is possible to open the storage, move, and re-encrypt data blocks between storages (since each has its own key), but it is not possible to decrypt the data itself.<\/p>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/6e09b2f145e53edf70461436785fc6f4.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n The clever scheme (working version)<\/p>\n<p>I would like to add that all engineers in R&amp;D really love encryption in our product, although no one knows all the details of how it works. (There was also a joke about 'why it works at all,' but the editors didn\u2019t let that pass.)<\/p>\n<h2>Testing<\/h2>\n<p>\nHundreds of bugs were recorded for this feature. The most challenging areas were encryption, the user interface, and issues with restore.<\/p>\n<p>From a testing perspective, the difficulty was the large variability, the 'combinatorics' of tenant job types and repositories \u2013 I mean both source and target during backup restoration in the infrastructure. All this is threaded through the logic within <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/backup_copy_gfs.html?ver=95u4\">the GFS model<\/a><\/noindex> (including the new one \u2013 parallelism and daily media sets, more on that below), and in general, the unfamiliar cloud specificity for the types. Don\u2019t forget to generously season with encryption. If we continue the metaphor, we have thoroughly indulged in this dish \u2013 but have also savored it from all sides.<\/p>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/9519ad918d9112197063f5f0e51b903c.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n Fragment of the test plan<\/p>\n<h2>As a result<\/h2>\n<p>\nA detailed description can be found in <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/cloud\/cloud_connect_tape.html?ver=95u4\">user manual<\/a><\/noindex> (currently in English): <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/cloud\/cc_backup_to_tape_backup.html?ver=95u4\">backup<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/cloud\/cc_backup_to_tape_restore.html?ver=95u4\">restore<\/a><\/noindex>. I will focus on the main points.<\/p>\n<h3>Backup<\/h3>\n<p>\nThe provider adds tenants to the tape job with a GFS pool as the target. With a cloud license available, the option is accessible on the second step of the wizard <b>Tenants<\/b>You can add all tenants at once or individually, or you can choose only a specific quota (but not a subquota) of a particular tenant. Mixing tenant backups and regular local backups in one job is not allowed.<\/p>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/757caa178b0827bf4daa85a167f0fb05.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nOther settings are almost entirely identical to a standard job in the GFS pool.<\/p>\n<p>Data restoration can be done both on the provider's side and on the tenant's side.<\/p>\n<h3>Restoration on the provider's side<\/h3>\n<p>\nIt is performed through a new wizard. Here you can drill down to a specific job, restoring the entire chain that was in the repository on a specific day.<\/p>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/5cddb5299f9483469abe4a5fabe83ef0.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThere are three options for restoration:<\/p>\n<ol>\n<li>To the original location. In this case, the original backup, if available, is deleted; tenant jobs are automatically reconfigured to the restored chain. It is implied that such a restoration will be completely invisible to the client, only for a short time they will be disconnected from the cloud repository.<\/li>\n<li>To a new quota\/repository. The provider can, for example, create a separate temporary account for this purpose, which will be deleted later. The backup appears in the tenant's infrastructure after synchronization with the provider's database.<\/li>\n<li>Directly to the disk of a Linux or Windows server registered in the provider's infrastructure. This chain can then be written to a flash drive and sent to the tenant.<\/li>\n<\/ol>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/963c2cb3f394d4417675e5c74538c293.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>Restoration on the tenant's side<\/h3>\n<p>\nThis option implies that the client has their own tape infrastructure and a large volume of data for restoration. The provider can physically send the tape with the recorded backups to the client via a delivery service, who catalogs it on their equipment, decrypts the tapes and backups, and works with the backups as if they recorded them on tape themselves. This is a hack to avoid downloading terabytes over WAN.<\/p>\n<h1>Significant improvements to the GFS pool<\/h1>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Backup_rotation_scheme#Grandfather-father-son\">GFS<\/a><\/noindex>-media pools appeared in VBR two years ago, in version 9.5. In the released update, both due to the emergence of the Tenant to tape feature and at the request of users, we have greatly enhanced this functionality.<\/p>\n<h2>Daily media sets<\/h2>\n<p>\nA new <b>daily <\/b>(daily) media set. Now, you can store daily backups in the GFS pool, including not only full backups but also incremental ones. The latter take up significantly less space, which is intended for tape saving. It is implied that these tapes are continuously rotated in the library and are not sent for remote storage. For a restore from an incremental point, tapes from one of the older media sets (weekly, monthly, quarterly, or yearly) will be needed. You cannot enable a daily media set without enabling the weekly set to ensure that, in most cases, the weekly tapes are required for recovery from an incremental copy. They are either always kept in the library or stored at a less remote warehouse.<\/p>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/dc512ff16ee0f4ad3637de855b30096c.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe logic of tape jobs in the GFS media pool <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/gfs_to_tape_hiw.html?ver=95u4\">is not the simplest<\/a><\/noindex>, technical writers can attest to that. In short, without going into details, only full backups (including virtual full backups) are copied into the weekly and older media sets, one for each date, whereas the daily media set contains all backups present in the repository for the current day, since the backup job can be initiated more frequently than once a day.<\/p>\n<h2>Parallelism, start time, and waiting in GFS pools<\/h2>\n<p>\nNow, parallel writing for multiple chains or jobs on several library drives is possible in GFS media pools (previously it was only available in regular pools). This is enabled at the step <b>Options<\/b> of the media pool. <\/p>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/595c1f4f07738c044b0e585ed8cc3135.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>Important clarification<\/b>: the same file is always written in one stream, so for multiple large virtual machines, it is recommended to enable <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/per_vm_backup_files.html?ver=95u4\">per-VM settings on the repository<\/a><\/noindex>, so that the backup consists of multiple chains.<\/p>\n<p>Additionally, it is now possible to choose <b>the start time for the GFS job itself<\/b>. Many users disliked the midnight start and the subsequent wait of nearly an entire day until the source job completed. Now this time can be set, for example, to the late evening when there is already something to copy to tape. Moreover, upon user requests, we have added an option in the advanced settings that could previously only be activated with a registry key. All you need to do is select <b>Process the most recent restore point instead of waiting<\/b> \u2013 and what is present in the repository at the start of the tape job (for instance, a point from yesterday) is copied directly to the tape, with no waiting involved.<\/p>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/3499ac7d81103efac9571b42f6dcd5ee.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h1>Enhanced multiple library operation<\/h1>\n<p>\nWe'll discuss a situation where more than one library is added to a media pool. We supported this before, but now and then we receive complaints from clients about unpredictable behavior.<\/p>\n<h2>Was<\/h2>\n<p>\n<img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/9164fbfc0a96cb9421f7567e59226aab.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nFor example, a tape job started, occupying two drives in the first library, but the parallelism settings allow it to use up to 4 drives. Should this job switch to the second library of the media pool and utilize it as well, or would that be resource overuse?<\/p>\n<p>Another case. The option to switch based on the condition \"no available tapes\" is selected; there is only one tape in the first library, but all data can potentially fit on it. However, the settings allow writing to two tapes in parallel. Should the second library be engaged in this case?<\/p>\n<p>We've decided to streamline this area by allowing explicit configuration of behavior.<\/p>\n<h2>Became<\/h2>\n<p>\n<img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/cb5b32748493ac237e1c51a36858b834.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/add_media_pool_tapes.html?ver=95u4\">The libraries in the media pool<\/a><\/noindex> now have roles - <b>active <\/b>and <b>passive<\/b>. And the media pool itself has two modes: fault-tolerant, or <b>failover <\/b>(failover) and <b>parallel writing<\/b> (paralleling). Now, depending on the requirements, the media pool can be configured differently.<\/p>\n<ul>\n<li>If you have multiple equal libraries and need to parallelize writing to them - enable the parallel writing mode, in which all libraries must be assigned active roles. In this case, new tapes and drives will be utilized immediately, as soon as the need arises, regardless of which library they are in. There is still a priority - we will first attempt to find resources in the library that is higher on the list.<\/li>\n<li>If there is one primary library and one old or standalone drive as a backup, enable the failover mode, placing the primary library at the top of the list and assigning a passive role to the backup devices. Switching to such a device will only occur when absolutely necessary to ensure the job can operate at all. This situation will be considered a fault, and a notification will be sent via email.<\/li>\n<\/ul>\n<p>There is a more complex situation that we do not currently support \u2013 multiple active libraries alongside passive ones. Feedback will show if there is a need for such configurations and whether we need to enhance this feature in the future. This is standard practice.<\/p>\n<h1>WORM Support<\/h1>\n<p>\n<b>WORM <\/b>\u2013 Write Once Read Many \u2013 tapes that cannot be erased or overwritten <noindex><a rel=\"nofollow\" href=\"https:\/\/www.ibm.com\/support\/knowledgecenter\/en\/STAKKZ\/con_LTOdrive_WORM_security.html\">at the hardware level<\/a><\/noindex>, data can only be appended. Their mandatory use is regulated by the rules of certain organizations, for example, those operating in the field of medicine. The main problem with such tapes in the past was that VBR during <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/inventoring_tapes.html?ver=95u4\">inventorying<\/a><\/noindex> or <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/cataloging_tapes.html?ver=95u4\">cataloging<\/a><\/noindex> recorded a header that could no longer be erased, causing tape jobs to fail with an error during such attempts.<\/p>\n<p>Full support for such tapes was implemented in 9.5 Update 4. WORM media pools, both normal and GFS, were added, where only tapes of this type can be placed.<\/p>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/a74ac16b6bf985665437b58d867ea2b0.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNew tapes feature a blue, \u2018frozen\u2019 icon. From the user's perspective, working with WORM tapes is no different from working with regular ones.<\/p>\n<p>The \u2018worminess\u2019 of tapes is initially determined by the suffix <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.oracle.com\/cd\/E28221_03\/SLTUG\/barcode_labels.htm#SLTUG912\">of the barcode<\/a><\/noindex>, but if the barcode is regular or unreadable, the driver provides this information upon the first tape insertion. WORM tapes cannot be placed in a regular media pool and written to. Interestingly, some users have already applied WORM barcodes to regular tapes and were surprised by the changes in their infrastructure after the update.<\/p>\n<h2>The tape chip<\/h2>\n<p>\nAlongside the implementation of non-rewriteable tapes, work began on the <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Linear_Tape-Open#Cartridge_memory\">chip<\/a><\/noindex>. Standard attributes in the chip were not previously used by us; now we write and read some of them but do not consider them the primary source of data. The main reference point remains the tape header. This decision proved to be correct: a month after the release, we see how the \u2018zoo\u2019 of users\u2019 hardware presents surprises in terms of working with the chip.<\/p>\n<h1>Backup of NDMP volumes to tape<\/h1>\n<p>\nIn conclusion \u2013 regarding the most requested feature based on the number of reviews in this Update. Backup of NDMP volumes to tapes has become available. An NDMP server must be added to the VBR infrastructure. <noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/adding_ndmp_servers.html?ver=95u4\">add an NDMP server<\/a><\/noindex>, after which you can select volumes from this host in the file tape job. They are stored on tapes as files with a special attribute to distinguish them from regular ones during cataloging.<\/p>\n<p><img decoding=\"async\" alt=\"&quot;Back up to tape for me.&quot; A first-person account\" src=\"\/wp-content\/uploads\/2019\/03\/1358ba022d480fd102e8b7e5eb55bbf4.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe first implementation has certain limitations: extensions are not supported, and backup and restore are possible only for the full volume, not individual files. The backup operates via <noindex><a rel=\"nofollow\" href=\"https:\/\/linux.die.net\/man\/8\/dump\">dump<\/a><\/noindex> (in the case of NetApp \u2013 <noindex><a rel=\"nofollow\" href=\"https:\/\/kb.netapp.com\/app\/answers\/answer_view\/a_id\/1003891\/~\/network-data-management-protocol-%28ndmp%29-%2F-dump-phases-description-\">ufsdump<\/a><\/noindex>), there are specific details: the maximum number of incremental points is 9, after which a full backup is enforced.<\/p>\n<h1>In conclusion<\/h1>\n<p>\nThese were just the most significant innovations in magnetic tape backup in VBR 9.5 Update 4. Other changes are listed as follows:<\/p>\n<ul>\n<li>the ability to specify the order of source jobs and files in tape jobs;<\/li>\n<li>a Tape Operator role has been added (the user can do everything except restore from tape \u2013 that is handled by the Restore Operator);<\/li>\n<li>full include\/exclude masks have been added in the file tape job (except for NDMP);<\/li>\n<li>the recovery process in the file tape job has been improved (the folder is restored with those files that were present at the time of backup, rather than all that have ever been in it during its entire backup history \u2013 a highly requested feature, by the way);<\/li>\n<li>the speed of restoring a very large number of files from tapes has increased;<\/li>\n<li>the algorithm for selecting the next tape for writing has been refined, in particular, taking into account the volume of data written\/read throughout its entire life, selecting the most recent one;<\/li>\n<li>the stability of the product has improved.<\/li>\n<\/ul>\n<h1>Useful links<\/h1>\n<p>\nFor variety, here are a few links to Russian-language resources:<\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.veeam.com\/ru\/backup-replication-download.html\">Link to download the free trial version of VBR 9.5 Update 4<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/veeam\/blog\/349964\/\">Article on Habr \"Useful Tips for Archiving Veeam Backups to Magnetic Tape\"<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/veeam\/blog\/319654\/\">Article on Habr \"7 Useful Tips for Protecting Backups from Ransomware\"<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/helpcenter.veeam.com\/docs\/backup\/vsphere\/tape_device_support.html?ver=95u4\">User Manual section related to tapes (in English)<\/a><\/noindex><\/li>\n<li>And back to the previous place are the overview videos \"How It Works\" (though currently in English) \u2013 you can watch them <noindex><a rel=\"nofollow\" href=\"https:\/\/files-university.veeam.com\/EU\/VAS-T\/How%20It%20Works%20%28Published%29\/index.html\">here<\/a><\/noindex>. Tapes are discussed on slides 95 \u2013 102.<\/li>\n<\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/veeam\/blog\/443716\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u043f\u043e\u0432\u0435\u0434\u0430\u043b\u0438 \u0432\u0430\u043c \u043e \u043d\u043e\u0432\u044b\u0445 \u0444\u0438\u0447\u0430\u0445 \u0432 \u0432\u044b\u0448\u0435\u0434\u0448\u0435\u043c \u0432 \u044f\u043d\u0432\u0430\u0440\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0438 Update 4 \u0434\u043b\u044f Veeam Backup &amp; Replication 9.5 (VBR), \u0433\u0434\u0435 \u043e\u0441\u043e\u0437\u043d\u0430\u043d\u043d\u043e \u043d\u0435 \u0443\u043f\u043e\u043c\u044f\u043d\u0443\u043b\u0438 \u0431\u044d\u043a\u0430\u043f\u044b \u043d\u0430 \u043c\u0430\u0433\u043d\u0438\u0442\u043d\u0443\u044e \u043b\u0435\u043d\u0442\u0443. \u0420\u0430\u0441\u0441\u043a\u0430\u0437 \u043e\u0431 \u044d\u0442\u043e\u0439 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u0437\u0430\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u0435\u0442 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u043d\u043e\u0432\u044b\u0445 \u0444\u0438\u0447 \u0431\u044b\u043b\u043e \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0442\u0435\u043b\u044c\u043d\u043e \u043c\u043d\u043e\u0433\u043e. \u2013 \u0420\u0435\u0431\u044f\u0442\u0430 \u0438\u0437 QA, \u043d\u0430\u043f\u0438\u0448\u0435\u0442\u0435 \u0441\u0442\u0430\u0442\u044c\u044e? \u2013 \u041f\u043e\u0447\u0435\u043c\u0443 \u0431\u044b \u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-29927","post","type-post","status-publish","format-standard","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u043f\u043e\u0432\u0435\u0434\u0430\u043b\u0438 \u0432\u0430\u043c \u043e \u043d\u043e\u0432\u044b\u0445 \u0444\u0438\u0447\u0430\u0445 \u0432 \u0432\u044b\u0448\u0435\u0434\u0448\u0435\u043c \u0432 \u044f\u043d\u0432\u0430\u0440\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0438 Update 4 \u0434\u043b\u044f Veeam Backup &amp; Replication.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/bekap-mne-na-lentu-zapili-rasskaz-ot-pervogo-litsa\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u00ab\u0411\u044d\u043a\u0430\u043f \u043c\u043d\u0435 \u043d\u0430 \u043b\u0435\u043d\u0442\u0443 \u0437\u0430\u043f\u0438\u043b\u0438\u00bb. \u0420\u0430\u0441\u0441\u043a\u0430\u0437 \u043e\u0442 \u043f\u0435\u0440\u0432\u043e\u0433\u043e \u043b\u0438\u0446\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u043f\u043e\u0432\u0435\u0434\u0430\u043b\u0438 \u0432\u0430\u043c \u043e \u043d\u043e\u0432\u044b\u0445 \u0444\u0438\u0447\u0430\u0445 \u0432 \u0432\u044b\u0448\u0435\u0434\u0448\u0435\u043c \u0432 \u044f\u043d\u0432\u0430\u0440\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0438 Update 4 \u0434\u043b\u044f Veeam Backup &amp; Replication.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/bekap-mne-na-lentu-zapili-rasskaz-ot-pervogo-litsa\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:32:42+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:32:42+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47\"Backup me to tape, please.\" A first-person account | ProHoster","description":"In the previous article, we shared the new features in the January Update 4 for Veeam Backup &amp; Replication.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/bekap-mne-na-lentu-zapili-rasskaz-ot-pervogo-litsa","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u00ab\u0411\u044d\u043a\u0430\u043f \u043c\u043d\u0435 \u043d\u0430 \u043b\u0435\u043d\u0442\u0443 \u0437\u0430\u043f\u0438\u043b\u0438\u00bb. \u0420\u0430\u0441\u0441\u043a\u0430\u0437 \u043e\u0442 \u043f\u0435\u0440\u0432\u043e\u0433\u043e \u043b\u0438\u0446\u0430 | ProHoster","og:description":"\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u043f\u043e\u0432\u0435\u0434\u0430\u043b\u0438 \u0432\u0430\u043c \u043e \u043d\u043e\u0432\u044b\u0445 \u0444\u0438\u0447\u0430\u0445 \u0432 \u0432\u044b\u0448\u0435\u0434\u0448\u0435\u043c \u0432 \u044f\u043d\u0432\u0430\u0440\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0438 Update 4 \u0434\u043b\u044f Veeam Backup &amp; Replication.","og:url":"https:\/\/prohoster.info\/en\/blog\/bekap-mne-na-lentu-zapili-rasskaz-ot-pervogo-litsa","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:32:42+00:00","article:modified_time":"2019-10-31T18:32:42+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"29927","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-20 23:04:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:45:25","updated":"2026-01-20 23:04:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/29927","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=29927"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/29927\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=29927"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=29927"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=29927"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}