-
- Veteran
- Posts: 527
- Liked: 142 times
- Joined: Aug 20, 2015 9:30 pm
- Contact:
Transaction Log Backups across a firewall
So our backup servers and backup repositories are in a separate AD forest and firewall zone from some of the guest VMs we need to backup. I created a guest interaction proxy in the same zone as the guest VMs and opened the required ports from the backup server to the guest interaction proxy. I am able to perform application-aware processing, including truncating SQL server transaction logs. However, if I try to enable periodic transaction log shipping, it fails with a connection error. I can see in our firewall logs that the guest interaction proxy is attempting to initiate a connection to the backup repository. However, we don't want to allow any connections from the network that contains the guest VMs to the backup server network since the guest VMs are in an insecure network. Is there a way to get transaction log shipping to work without opening any ports from the guest VM network to the backup repository?
-
- Product Manager
- Posts: 14301
- Liked: 2879 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: Transaction Log Backups across a firewall
Hello,
first, what you see is "works as designed". The log shipping server (in your case the guest interaction proxy) is transferring the data to the repository.
Best regards,
Hannes
first, what you see is "works as designed". The log shipping server (in your case the guest interaction proxy) is transferring the data to the repository.
No realistic way. I have seen customers doing accidentally (because firewall was in place) SQL logshipping over VIX but the performance is horrible slow (some hundred KB/s) as VIX interface does not allow higher speed.Is there a way to get transaction log shipping to work without opening any ports from the guest VM network to the backup repository?
Best regards,
Hannes
-
- Veteran
- Posts: 527
- Liked: 142 times
- Joined: Aug 20, 2015 9:30 pm
- Contact:
Re: Transaction Log Backups across a firewall
So what section in the Firewall Ports document would be relevant here? https://helpcenter.veeam.com/docs/backu ... l?ver=95u4
If I need to open ports, I want to make sure I only cover what is required.
If I need to open ports, I want to make sure I only cover what is required.
-
- Product Manager
- Posts: 14301
- Liked: 2879 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: Transaction Log Backups across a firewall
Hello,
just to make sure: you are using Hyper-V ?
a shorter list only relevant for SQL can be found here
You need at least the "Microsoft Windows Servers Connections" described in this section
Also keep in mind ports for restore
Best regards,
Hannes
just to make sure: you are using Hyper-V ?
a shorter list only relevant for SQL can be found here
You need at least the "Microsoft Windows Servers Connections" described in this section
Also keep in mind ports for restore
Best regards,
Hannes
-
- Veteran
- Posts: 527
- Liked: 142 times
- Joined: Aug 20, 2015 9:30 pm
- Contact:
Re: Transaction Log Backups across a firewall
Yes in this case it is Hyper-V, though I assume the ports would be the same regardless. I have the ports listed under "Windows Server Connections" open from the backup server to the guest interaction proxy. For the connections initiated by the guest interaction proxy to the backup repository, would it only be 2500-5000? That's what I see listed under log shipping.
Also I haven't found anything on how to do it, but since it says "Default range of ports used by Veeam data mover service for data transmission over the network", does that mean it's possible to change the port range Veeam uses?
Also I haven't found anything on how to do it, but since it says "Default range of ports used by Veeam data mover service for data transmission over the network", does that mean it's possible to change the port range Veeam uses?
-
- Product Manager
- Posts: 14301
- Liked: 2879 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: Transaction Log Backups across a firewall
I'll ask to add the guest interaction proxy to the documentation. But it should be 2500-5000 in both directions and 49152 to 65535 from guest interaction proxy to repository.
Yes, you can change the port range in backup infrastructure -> managed servers -> Microsoft windows -> server -> credentials tab -> ports
Yes, you can change the port range in backup infrastructure -> managed servers -> Microsoft windows -> server -> credentials tab -> ports
-
- Veteran
- Posts: 527
- Liked: 142 times
- Joined: Aug 20, 2015 9:30 pm
- Contact:
Re: Transaction Log Backups across a firewall
Thanks appreciate the info!
-
- Lurker
- Posts: 1
- Liked: never
- Joined: Jun 26, 2019 2:25 pm
- Contact:
Re: Transaction Log Backups across a firewall
When I understand correctly, I need a Logshipping server with a firewall ports configuration mentioned here?
https://helpcenter.veeam.com/docs/backu ... l?ver=95u4
But I can change the port range to our liking? So if I want to use 4995 - 5000 for the log shipping server it can be done.
Is it possible to make transaction log backups without the use for a Logshipping server?
https://helpcenter.veeam.com/docs/backu ... l?ver=95u4
But I can change the port range to our liking? So if I want to use 4995 - 5000 for the log shipping server it can be done.
Is it possible to make transaction log backups without the use for a Logshipping server?
-
- Veeam Software
- Posts: 21069
- Liked: 2115 times
- Joined: Jul 11, 2011 10:22 am
- Full Name: Alexander Fogelson
- Contact:
Re: Transaction Log Backups across a firewall
Yes, you can change the port range. And yes, you can avoid log shipping server and transfer data directly between the VM and repository.
-
- Enthusiast
- Posts: 58
- Liked: 12 times
- Joined: Sep 09, 2010 9:45 am
- Full Name: Anders Lorensen
- Contact:
Re: Transaction Log Backups across a firewall
When transfering data directly from SQL server to Repository server, what ports are used? The documentation does not include this as far as I can see. (on https://helpcenter.veeam.com/archive/ba ... ports.html)
Is it TCP 2500-5000 and/or TCP 49152-65536 ?
Is it TCP 2500-5000 and/or TCP 49152-65536 ?
-
- Product Manager
- Posts: 14301
- Liked: 2879 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: Transaction Log Backups across a firewall
Hello,
yes, that's because the log shipping server is missing
https://helpcenter.veeam.com/docs/backu ... ml?ver=100
Best regards,
Hannes
yes, that's because the log shipping server is missing
https://helpcenter.veeam.com/docs/backu ... ml?ver=100
Best regards,
Hannes
Who is online
Users browsing this forum: Bing [Bot], dbeerts, Semrush [Bot] and 211 guests