WP Best Practices Improve Recovery Objectives
WP Best Practices Improve Recovery Objectives
Fabian Kessler,
Product Management Analyst,
Veeam Software
10 Best Practices to Improve Recovery Objectives
Contents
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
No. 1: Back up the right data the right way . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
Application-aware processing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
Application-aware processing — Guest script processing . . . . . . . . . . . . . . . . . . . . . . . 5
Storage snapshots . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Cloud-native snapshots . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
No. 2: Use immutable backup storage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Hardened repository . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Object Storage with Object Lock . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
WORM tape . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
No. 3: Test your backups with SureBackup and Health Checks . . . . . . . . . . . . . . . . . . . . . . . . . 8
No. 4: Ensure that the hardware is fast enough for backup and restore . . . . . . . . . . . . . . . . . . . 9
Potential bottlenecks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
Proxy server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
Backup repository . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Testing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
No. 5: Choose the right restore mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Operating system or application failure after installing updates . . . . . . . . . . . . . . . . . . 11
Malware/ransomware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
No. 6: Have spare hardware ready (or service) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Where do you want to restore? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
How can you access the recovered data? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
No. 7: Avoid chicken-egg issues . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Encrypted backups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Configuration backup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
No. 8: Test a disaster recovery plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
No. 9: Empower application owners with self-service capabilities . . . . . . . . . . . . . . . . . . . . . . 15
Veeam Enterprise Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
Enterprise Application Plug-ins . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
No. 10: Use current versions of Veeam . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Veeam Backup & Replication V10 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Veeam Backup & Replication V11 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Conclusion . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
About the Author . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
About Veeam Software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 2
10 Best Practices to Improve Recovery Objectives
Introduction
When we talk about data backup and restore, This recovery objectives don’t follow
we need to talk about two essential terms: a general rule. Each company has other
requirements for their business which defines
• Recovery Point Objective (RPO)
their recovery objectives. If you want to read
• Recovery Time Objective (RTO) about RPO and RTO, our blog post “Why do
recovery time and recovery point objectives
Knowing how much data loss is tolerable matter?” explains more about RPO and RTO
for business impact (RPO) and the maximum and how to gather the information required
amount of time your business can tolerate to define the values for your environment.
to be offline (RTO) is important (Picture 1). It
defines how you build your backup strategy, This white paper will show you best practices
how frequently the backup jobs will run and to help you to achieve and optimize your
what type of backup is required. personal recovery objectives.
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 3
10 Best Practices to Improve Recovery Objectives
Application-aware processing
Application-aware processing (AAIP) prepares applications With AAIP, you can protect many applications directly within
on VM’s or physical machines for a consistent backup. the backup job settings.
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 4
10 Best Practices to Improve Recovery Objectives
Application-aware processing —
Guest script processing
Storage snapshots
Storage snapshots on your production storage give you low With Veeam Backup & Replication, you can benefit from both
RPOs and RTOs, regardless of the backup software you use. methods with supported storage appliances. Restoring a VM,
You can orchestrate snapshots directly with the storage files or application data from a storage snapshot (Picture 4)
appliance console or with Veeam Backup & Replication. is as easy as it is from a Veeam backup.
A storage snapshot does not just protect a single VM. When
the snapshot is taken, all VMs on that storage volume are
protected at the same time.
Cloud-native snapshots
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 5
10 Best Practices to Improve Recovery Objectives
Hardened repository
A hardened repository is a repository on a Linux server that • Do not install any other applications on the machine.
uses the immutability attribute in Linux file systems. Any Only the basic tools should be installed on the hardened
supported backup file stored in this Linux repository is made repository. Each additional application could introduce
immutable for the configured time. When immutability is new security risks to the server. For example, if you
enabled, all backups are protected for at least seven days decide to install a monitoring agent, additional security
(Picture 6). GFS backups are automatically protected for hardening might be needed.
the entire retention period. However, the the duration
of immutability depends on the requirements for each In addition to security precautions, it is recommended to
individual organisation. use XFS as a file system to benefit from our Fast Clone
technology. With this technology you can create synthetic
Configure the duration of immutability to be shorter than full backups without additional storage consumption.
the retention period of your backup jobs or you get warnings
in your backup job sessions.
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 6
10 Best Practices to Improve Recovery Objectives
The implementation must follow our best practices: Picture 7 — Immutably for object storage
WORM tape
As an alternative to object storage, tapes are still a viable
backup target. Tape backups give you air-gapped copies of
your backups. For added protection, use WORM tapes to
protect the tapes from being erased. WORM tapes can be
added like standard tapes in the Veeam Backup & Replication
console (Picture 8).
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 7
10 Best Practices to Improve Recovery Objectives
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 8
10 Best Practices to Improve Recovery Objectives
No. 4: Ensure that the hardware is fast enough for backup and restore
To achieve the defined RPO and RTO goals, sufficient hardware is required. This applies not
only to the backup hardware used, but also to components in your production environment
that could become a potential bottleneck.
Potential bottlenecks
Since every backup application processes a large amount of • What transport method does my proxy server use?
data, it is important that the data flow is efficient and that all • Have I allocated sufficient resources to my backup proxy?
resources involved in the backup process are used optimally.
• Do I have suitable storage as the primary backup target?
To meet the desired RPO and RTO, consider the following:
Veeam Backup & Replication provides advanced statistics
• Does my productive environment provide me with on the efficiency of the data flow and lets you identify
enough I/O and read/write speed to meet my RPO/RTO bottlenecks (Picture 9) in data transfer.
requirements?
• How is the productive environment connected to
the backup environment in terms of networking?
Network
Ensure that the required bandwidth is available. The Veeam It is not recommended to perform these tasks over a slow
proxy server and the primary Veeam backup repository network connection, as this could affect the performance of
should be in the same location as the production the backup job or the recovery process.
environment to optimize backup and restore tasks.
Proxy server
Decide on the optimal transport method. With Veeam Backup Network mode is usually the slowest method for backups
& Replication, you can choose between three transport and restores, especially if your ESXi servers only have
methods for backups and restores: 1Gbit management interfaces. If you still need to use
• Direct storage access network mode, make sure you use a 10Gig NIC for the ESXi
(optional: Backup from storage snapshots) server’s management port.
• Virtual application (HotAdd) SAN storage usually has poor single-stream performance
• Network (NBD) but good parallel-stream performance. So, for restoring
large single discs, hot-add is usually the fastest method. We
Perform backup and restore tests with different transport recommend deploying at least one hot-add proxy for restores
modes to find out which mode offers the best performance if you use other transport modes in your backup jobs.
for your environment.
For more information on our transport methods, see our
white paper 10 Best Practices for VMware vSphere Backups.
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 9
10 Best Practices to Improve Recovery Objectives
Backup repository
To optimize backup and restore times, use a physical server To optimize recovery times with a virtual repository, do
with internal hard drives and an enterprise raid controller not use VMFS-based discs for your backup repository on
as the primary backup storage. This will give you the best a vSphere host. You will need to set up a new ESXi host to
performance for backups and restores. open the VMFS datastore in the event of a complete server
failure. This additional step takes time which is better
If you still choose to run your backup repository on a virtual invested in recovering your data.
machine, consider a dedicated virtualisation environment
to ensure that your backup repositories are separated from Deduplication appliances are not recommended as primary
the production environment. backup storage. However, deduplication appliances can be
suitable as secondary backup storage or for long-term storage.
Testing
Test backups and restores in your environment to see if Test the best transport mode for your environment.
your hardware is fast enough for your defined recovery Perform test recoveries with different restore modes
goals. Detect potential bottlenecks early. before putting your backup system into production.
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 10
10 Best Practices to Improve Recovery Objectives
Most likely only the operating system drive will have issues
after an update of the operating system or an application.
Restoring all drives would overwrite data newer than
the backup. So, only the affected drive must be restored.
Malware/ransomware
If you have been attacked by ransomware or malware, Also, check the contents of your backups for traces of
it is important that you don’t start immediately with malware. With Veeam Backup & Replication, you can
the recovery. Once you have recovered the machines leverage Instant VM Recovery Sessions or Secure Restore
that you believe have been affected, there is a good (Picture 11) to check the restore point for malware. If
chance that these machines will be reinfected. you use Secure Restore, the recovery time is significantly
higher and chances are you will not achieve your desired
After an attack, assume that all systems have already been recovery time goals.
affected. It is important that you shut down your backup
server and production environment as soon as possible. If you need to restore hundreds or thousands of VMs,
Consult a security expert before you turn a system back on consider restoring everything to an isolated environment.
and restore the data. If you do not have your own security The forensic team can check the machines individually and
department, contact a security company or your security then release them to the production environment.
insurance company if they have one.
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 11
10 Best Practices to Improve Recovery Objectives
Planning for recovery also means thinking about how Workplace as a service
your staff can access the data after a disaster.
In the case of a strict “no home office” policy, you can
We should think about the client devices and how they turn to a “workplace as a service” provider. With this
can access the server. For the end-user devices, there option, you can rent a complete workplace infrastructure
are two options. for your staff to be up and running in the first few days
after the disaster.
Bring your own device/home office.
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 12
10 Best Practices to Improve Recovery Objectives
Encrypted backups
Configuration backup
After the fire event, you decide to install a new Veeam
Backup & Replication Server to be able to restore your
environment from the cloud-based object storage.
The configuration backup (Picture 13) will allow you to
restore the configuration from the lost backup server to
a newly installed backup server. To be able to do that,
the configuration backup must be available in case you lose
your backup server. A few ideas on how to achieve that:
Picture 13 — Configuration backup
• Use a repository in your secondary location for
the configuration backup job
• Use File Copy Jobs to copy the configuration backup to
a second location
• Use File to Tape Jobs to have a copy of the configuration
backup on Tape
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 13
10 Best Practices to Improve Recovery Objectives
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 14
10 Best Practices to Improve Recovery Objectives
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 15
10 Best Practices to Improve Recovery Objectives
Veeam Backup & Replication V10 Veeam Backup & Replication V11
With Veeam Backup & Replication V10 recovery features Along with Veeam Backup & Replication V11, Continuous
such as next-generation Instant Recovery engine and Data Protection (CDP) has been released. CDP allows you
Instant Database Recovery have been introduced. to replicate virtual machines from one vSphere Cluster
The next-generation Instant Recovery engine enables to another vSphere Cluster with a minimum RPO of two
you to initiate Instant Recovery for multiple VMs at once seconds (Picture 16). With CDP, you can do immediate
with much better performance comparted to the previous recoveries to a latest state or desired point in time. This
version. V10 also brought Instant Recovery for individual new opportunity minimizes data loss and eliminates
disks. If the problem occurs only on one disk, there is no downtime in your environment.
need to recover the entire VM.
Conclusion
Following these best practices will ensure that you can meet your recovery point objectives
and recovery time objectives. You will be prepared to recover your data with no more data loss
than expected.
Veeam’s backup and recovery products can help you follow the best practices. To learn more,
download a 30-day FREE trial today!
To conclude the white paper, here are the important key points summarized again:
• Use the right hardware to achieve the goals of your backup strategy
• Use immutable and/or air gapped backup storage
• Have and test your disaster recovery plan
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 16
10 Best Practices to Improve Recovery Objectives
© 2022 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 17