CRITICAL INFRA
Loading critical CVEs…
ALL EXPLOITED
Loading…

Disaster Recovery with Veeam: 3-2-1 strategy

3-2-1 rule explained

3 copies of data, on 2 different media, with 1 copy off-site. Plus extension 3-2-1-1-0: 1 immutable copy, 0 errors on restore test.

Recommended architecture

  1. Production: VMs on VMware/Hyper-V/Proxmox
  2. Primary backup: Veeam Backup Server with NAS/SAN repository
  3. Secondary backup: Hardened Linux repository with immutability (xfs reflink + chattr +i)
  4. Off-site: WAN Accelerator replication to secondary datacenter
  5. Optional cloud: Veeam Cloud Connect or S3 object lock

Test restore (the most ignored step!)

A backup that can't be restored = no backup. Veeam SureBackup runs automated test recovery monthly in isolated sandbox.

Ransomware protection

Immutable backups + air-gap are MANDATORY in 2026. Veeam Hardened Repository can't be deleted even by root for retention duration.

Example: immutable repository (hardened Linux)

A ransomware-resistant Veeam repository, on XFS with immutability:

# Veeam Hardened Repository — immutability pe XFS (anti-ransomware)
mkfs.xfs -m reflink=1,crc=1 /dev/sdb1
mkdir -p /mnt/veeam && mount /dev/sdb1 /mnt/veeam
# in jobul Veeam: bifezi 'Make recent backups immutable for N days'
# la nivel FS, backup-urile primesc automat atributul immutable:
lsattr /mnt/veeam/backups/*.vbk    # 'i' = imutabil, nu poate fi sters nici de root

Immutable repository (Linux commands)

You prepare a hardened repository on XFS with immutability:

# XFS cu reflink (necesar pt block clone Veeam)
mkfs.xfs -m reflink=1,crc=1 /dev/sdb1
mount -o rw,noatime /dev/sdb1 /mnt/veeam
# user dedicat (single-use), fara sudo persistent
useradd -m -s /bin/bash veeamrepo
# in job Veeam: 'Make backups immutable for 14 days'
lsattr /mnt/veeam/*.vbk    # 'i' = nu poate fi sters nici de root

Automated restore test

An untested backup does not count — verify it periodically:

# PowerShell (Veeam) — SureBackup / verificare rapida
Import-Module Veeam.Backup.PowerShell
Start-VBRSureBackupJob -Job 'DR-Test' -RunAsync
# sau restore de test al unei VM intr-un mediu izolat
Get-VBRBackup | Select-Object Name, JobName | Format-Table

Replication + cross-site failover

Besides backup, you replicate ready-to-boot VMs for disaster:

# PowerShell Veeam — job de replicare catre locatia secundara
Add-VBRViReplicaJob -Name 'DR-Repl' -Entity $vms -Server $drHost \
  -RestorePointsToKeep 7
# failover planificat (test) si failback
Start-VBRReplicaFailover -RestorePoint (Get-VBRRestorePoint -Name 'ERP')[0]

3-2-1 with object lock (S3)

An immutable offsite copy in object storage:

# repository S3 cu immutability (object lock, compliance mode)
aws s3api put-object-lock-configuration --bucket veeam-dr \
  --object-lock-configuration 'ObjectLockEnabled=Enabled,Rule={DefaultRetention={Mode=COMPLIANCE,Days=30}}'
# in Veeam: Backup Copy Job -> S3 capacity tier -> Make backups immutable