Regula 3-2-1 explicata
3 copii ale datelor, pe 2 medii diferite, cu 1 copie off-site. Plus extensia 3-2-1-1-0: 1 copie immutable, 0 erori la restore test.
Arhitectura recomandata
- Productie: VM-uri pe VMware/Hyper-V/Proxmox
- Backup primar: Veeam Backup Server cu repository pe NAS/SAN dedicat
- Backup secundar: Hardened Linux repository cu immutability (xfs reflink + chattr +i)
- Off-site: Replicare via WAN Accelerator la datacenter secundar
- Optional cloud: Veeam Cloud Connect sau S3 object lock
Politica backup
- Daily: incremental cu 14 zile retentie
- Weekly: full backup, 8 saptamani retentie
- Monthly: archive, 12 luni retentie
- Yearly: compliance archive, 7 ani
Test restore (cel mai ignorat pas!)
Backup care nu poate fi restored = backup care nu exista. Veeam SureBackup ruleaza automated test recovery lunar intr-un sandbox izolat. Verifica boot + ping + custom scripts.
RTO / RPO
- Critical apps (ERP, DB): RTO 1h, RPO 15min (CDP)
- Important (file server): RTO 4h, RPO 1h
- Standard (intern): RTO 24h, RPO 24h
Ransomware protection
Immutable backups + air-gap (tape sau hardened repo) sunt OBLIGATORII in 2026. Veeam Hardened Repository nu poate fi sters nici de root pentru durata retention.
Exemplu: repository imutabil (hardened Linux)
Un repository Veeam rezistent la ransomware, pe XFS cu immutability:
# Veeam Hardened Repository — immutability pe XFS (anti-ransomware)
mkfs.xfs -m reflink=1,crc=1 /dev/sdb1
mkdir -p /mnt/veeam && mount /dev/sdb1 /mnt/veeam
# in jobul Veeam: bifezi 'Make recent backups immutable for N days'
# la nivel FS, backup-urile primesc automat atributul immutable:
lsattr /mnt/veeam/backups/*.vbk # 'i' = imutabil, nu poate fi sters nici de root
Repository imutabil (comenzi Linux)
Pregatesti un hardened repository pe XFS cu immutability:
# XFS cu reflink (necesar pt block clone Veeam)
mkfs.xfs -m reflink=1,crc=1 /dev/sdb1
mount -o rw,noatime /dev/sdb1 /mnt/veeam
# user dedicat (single-use), fara sudo persistent
useradd -m -s /bin/bash veeamrepo
# in job Veeam: 'Make backups immutable for 14 days'
lsattr /mnt/veeam/*.vbk # 'i' = nu poate fi sters nici de root
Test de restaurare automat
Un backup netestat nu conteaza — verifici periodic:
# PowerShell (Veeam) — SureBackup / verificare rapida
Import-Module Veeam.Backup.PowerShell
Start-VBRSureBackupJob -Job 'DR-Test' -RunAsync
# sau restore de test al unei VM intr-un mediu izolat
Get-VBRBackup | Select-Object Name, JobName | Format-Table
Replicare + failover intre locatii
Pe langa backup, replici VM-uri gata de pornit la dezastru:
# PowerShell Veeam — job de replicare catre locatia secundara
Add-VBRViReplicaJob -Name 'DR-Repl' -Entity $vms -Server $drHost \
-RestorePointsToKeep 7
# failover planificat (test) si failback
Start-VBRReplicaFailover -RestorePoint (Get-VBRRestorePoint -Name 'ERP')[0]
3-2-1 cu object lock (S3)
O copie externa imutabila in object storage:
# repository S3 cu immutability (object lock, compliance mode)
aws s3api put-object-lock-configuration --bucket veeam-dr \
--object-lock-configuration 'ObjectLockEnabled=Enabled,Rule={DefaultRetention={Mode=COMPLIANCE,Days=30}}'
# in Veeam: Backup Copy Job -> S3 capacity tier -> Make backups immutable