-
- Enthusiast
- Posts: 90
- Liked: 5 times
- Joined: Oct 31, 2022 11:39 pm
- Full Name: Backup Administrator
- Contact:
Hardened Repository best practice deployment
I wonder if there is a best practice guidelines on how to plan, architect and deploy the Hardened Backup repository.
Shall I configure it as Backup Job from the VMware or the Backup Copy job from the XFS repo?
Shall I configure it as Backup Job from the VMware or the Backup Copy job from the XFS repo?


-
- Expert
- Posts: 138
- Liked: 23 times
- Joined: Mar 18, 2021 6:04 pm
- Contact:
Re: Hardened Repository best practice deployment
Hello,
It's quite simple, just follow this guide https://bp.veeam.com/vbr/Security/harde ... linux.html
I don't understand the second question?
It's quite simple, just follow this guide https://bp.veeam.com/vbr/Security/harde ... linux.html
I don't understand the second question?
-
- Product Manager
- Posts: 10277
- Liked: 2746 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: Hardened Repository best practice deployment
Hi Backup Operator
Hannes has created some blog post with guidelines:
https://www.veeam.com/sys507
Best,
Fabian
Hannes has created some blog post with guidelines:
- Selecting Hardware and Setting Up Environment for Veeam Hardened Repository
- Installing Ubuntu Linux for Veeam Hardened Repository
- Securing Veeam Hardened Repository Against Remote Time Attacks
- Ubuntu Linux Essentials: Booting Into Single User Mode and Protecting Against Unauthorized Access
- Securing Veeam Hardened Repository
https://www.veeam.com/sys507
Best,
Fabian
Product Management Analyst @ Veeam Software
-
- Service Provider
- Posts: 73
- Liked: 10 times
- Joined: Sep 19, 2018 12:11 pm
- Full Name: Frank Wijmans
- Location: The Netherlands
- Contact:
Re: Hardened Repository best practice deployment
I dont want to hijack this topic, but I've been playing around with these blogpost myself for a couple of days and I was wondering how this auditing works.
I'm not a real Linux guy and pretty green when it comes to security as well. And the hardening script does a lot of changes when it comes to generating audit logs. But how or where do I find those audit logs? Is this something which is generated autmatically after running that script? Or do I need to configure this myself?
Any info would greatly appreciated!
I'm not a real Linux guy and pretty green when it comes to security as well. And the hardening script does a lot of changes when it comes to generating audit logs. But how or where do I find those audit logs? Is this something which is generated autmatically after running that script? Or do I need to configure this myself?
Any info would greatly appreciated!
-
- Product Manager
- Posts: 15126
- Liked: 3232 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: Hardened Repository best practice deployment
Hello,
audit logs are in /var/log/audit/
auditd uses the path automatically, yes.
Best regards,
Hannes
audit logs are in /var/log/audit/
auditd uses the path automatically, yes.
Best regards,
Hannes
-
- Expert
- Posts: 168
- Liked: 37 times
- Joined: Jan 19, 2016 1:28 pm
- Full Name: Jóhannes Karl Karlsson
- Contact:
Re: Hardened Repository best practice deployment
Mildur wrote: ↑Jun 07, 2023 3:08 pm Hi Fabian,
If one has setup Rocky linux according to the Veeam documentation (as documented in the blog by Hannes), thus with root disabled, ssh disabled and the DISA STIG profile, minimal install, is the VHR script doing anything more?
https://www.veeam.com/sys507
Or is it just to apply to Linux repository setup that was not initially setup according to the Veeam documentation on VHR?
Regards,
Jóhannes
-
- Expert
- Posts: 138
- Liked: 23 times
- Joined: Mar 18, 2021 6:04 pm
- Contact:
Re: Hardened Repository best practice deployment
Hello,
Generic question: how do you connect to the repo once SSH is disabled? Especially if it's not a VM. Using the server KVM over ip console and then enabling ssh temporarily? Then sudo if root login is disabled?
Generic question: how do you connect to the repo once SSH is disabled? Especially if it's not a VM. Using the server KVM over ip console and then enabling ssh temporarily? Then sudo if root login is disabled?
-
- Veeam Software
- Posts: 179
- Liked: 25 times
- Joined: Sep 26, 2022 9:54 am
- Full Name: Pierre-Yves Bandet
- Contact:
Re: Hardened Repository best practice deployment
ideally you don't 
But when it's required, yes you can use a KVM or better a physical console, so you do not need to enable SSH at all.

But when it's required, yes you can use a KVM or better a physical console, so you do not need to enable SSH at all.
-
- Expert
- Posts: 138
- Liked: 23 times
- Joined: Mar 18, 2021 6:04 pm
- Contact:
Re: Hardened Repository best practice deployment
Thanks. Yeah in theory you don't, but of course irl you sometimes have to log in there 
-
- Enthusiast
- Posts: 57
- Liked: 12 times
- Joined: Jan 06, 2022 1:55 pm
- Full Name: IanE
- Contact:
Re: Hardened Repository best practice deployment
For my linux repos, SSH is generally disabled, the firewall doesn't have the ssh rule enabled, the iLO card uses unique credentials per host, each is connected to a disabled LAN port.FrenchBlue wrote: ↑Nov 12, 2024 8:42 am Hello,
Generic question: how do you connect to the repo once SSH is disabled? Especially if it's not a VM. Using the server KVM over ip console and then enabling ssh temporarily? Then sudo if root login is disabled?
So although it isnt impossible, an attacker must compromise multiple layers to gain access.
The flipside of that is that there's a lot to unpick on the rare occasions that I need to jump on!
Who is online
Users browsing this forum: Bing [Bot], Semrush [Bot] and 147 guests