-
- Influencer
- Posts: 16
- Liked: 1 time
- Joined: Jul 14, 2014 3:56 pm
- Full Name: mythumbsclick
- Contact:
Veeam Firewall Ports
Hi All
Be good to get some feedback on how you are configuring local firewalls to allow Veeam traffic. I have a Windows Server 2012R2/vSphere environment and configure Windows Firewall via group policy to secure our internal network.
Initially I copied the automatically generated Veeam firewall rules on Proxys/Repo/Mount/B+R etc into group policies and this worked fine. However on revisiting the rules they are pretty open. Example:
Veeam Data Mover (Veeam Transport Service) (In)
Allow Rule: C:\Program Files (x86)\Veeam\Backup Transport\x86\VeeamAgent.exe (All traffic allowed for this program)
No IP or port specifics.
I decided to have a go at manually configuring all rules and have a GP for Proxies, GP for Repo, GP for B+R etc with ports and IPs from the Veeam Ports Doc but I have got myself into a bit of a mess and am constantly tweaking rules so as not to block Veeam traffic.
My questions is, have you bothered to do the same or do you have a more general/open set of rules?
Thanks!
Be good to get some feedback on how you are configuring local firewalls to allow Veeam traffic. I have a Windows Server 2012R2/vSphere environment and configure Windows Firewall via group policy to secure our internal network.
Initially I copied the automatically generated Veeam firewall rules on Proxys/Repo/Mount/B+R etc into group policies and this worked fine. However on revisiting the rules they are pretty open. Example:
Veeam Data Mover (Veeam Transport Service) (In)
Allow Rule: C:\Program Files (x86)\Veeam\Backup Transport\x86\VeeamAgent.exe (All traffic allowed for this program)
No IP or port specifics.
I decided to have a go at manually configuring all rules and have a GP for Proxies, GP for Repo, GP for B+R etc with ports and IPs from the Veeam Ports Doc but I have got myself into a bit of a mess and am constantly tweaking rules so as not to block Veeam traffic.
My questions is, have you bothered to do the same or do you have a more general/open set of rules?
Thanks!
-
- VP, Product Management
- Posts: 7076
- Liked: 1510 times
- Joined: May 04, 2011 8:36 am
- Full Name: Andreas Neufert
- Location: Germany
- Contact:
Re: Veeam Firewall Ports
I agree that our Port Matrix is a bit hard to understand and overloaded. Please check as well our Best Practices Guide. You will find some Visio diagrams that explain a bit more deeply the connections:
https://bp.veeam.expert/networking/readme.html (please click on the navigation menue on the right side to scroll through the diagrams).
https://bp.veeam.expert/networking/readme.html (please click on the navigation menue on the right side to scroll through the diagrams).
-
- Enthusiast
- Posts: 26
- Liked: 2 times
- Joined: May 07, 2016 2:42 pm
- Full Name: Jeff
- Contact:
Re: Veeam Firewall Ports
Hi,
My question would be what are the exe's to allow when you use Windows Firewall on the backup proxy server?
Is it just the C:\Program Files (x86)\Veeam\Backup Transport\x86\VeeamAgent.exe ?
To figure this out I did it this way:
1) I disabled the Firewall
2) Install the Veeam Backup Proxy on server.
3) Enabled the firewall.
I plugged these to the Domain Firewall and my backups were successful.
C:\Program Files (x86)\Veeam\Backup Transport\x64\VeeamAgent.exe
C:\Program Files (x86)\Veeam\Backup Transport\x64\VeeamPluginsHostX64
C:\Program Files (x86)\Veeam\Backup Transport\VeeamTransportSvc.exe
Thanks
Jeff
My question would be what are the exe's to allow when you use Windows Firewall on the backup proxy server?
Is it just the C:\Program Files (x86)\Veeam\Backup Transport\x86\VeeamAgent.exe ?
To figure this out I did it this way:
1) I disabled the Firewall
2) Install the Veeam Backup Proxy on server.
3) Enabled the firewall.
I plugged these to the Domain Firewall and my backups were successful.
C:\Program Files (x86)\Veeam\Backup Transport\x64\VeeamAgent.exe
C:\Program Files (x86)\Veeam\Backup Transport\x64\VeeamPluginsHostX64
C:\Program Files (x86)\Veeam\Backup Transport\VeeamTransportSvc.exe
Thanks
Jeff
-
- VP, Product Management
- Posts: 7076
- Liked: 1510 times
- Joined: May 04, 2011 8:36 am
- Full Name: Andreas Neufert
- Location: Germany
- Contact:
Re: Veeam Firewall Ports
Actually Veeam should take care on this.
But you need to allow remote RPC (see documentation) at the other servers so that we can connect and install our software if needed.
But you need to allow remote RPC (see documentation) at the other servers so that we can connect and install our software if needed.
-
- VP, Product Management
- Posts: 7076
- Liked: 1510 times
- Joined: May 04, 2011 8:36 am
- Full Name: Andreas Neufert
- Location: Germany
- Contact:
Re: Veeam Firewall Ports
This article could be interessting for you: https://univirt.wordpress.com/2018/03/0 ... m-backups/
-
- Enthusiast
- Posts: 94
- Liked: 16 times
- Joined: Nov 25, 2010 4:26 pm
- Full Name: Neil Murphy
- Contact:
Re: Veeam Firewall Ports
This link seems to be broken. The new page on the best practices guide is https://bp.veeam.expert/appendices/networking. The pages following this one have the networking diagrams.Andreas Neufert wrote: ↑Mar 18, 2018 8:05 pm I agree that our Port Matrix is a bit hard to understand and overloaded. Please check as well our Best Practices Guide. You will find some Visio diagrams that explain a bit more deeply the connections:
https://bp.veeam.expert/networking/readme.html (please click on the navigation menue on the right side to scroll through the diagrams).
-
- VP, Product Management
- Posts: 7076
- Liked: 1510 times
- Joined: May 04, 2011 8:36 am
- Full Name: Andreas Neufert
- Location: Germany
- Contact:
Re: Veeam Firewall Ports
Thanks for updating this here. It is the correct page in the Veeam best practices guide.
-
- Veteran
- Posts: 377
- Liked: 86 times
- Joined: Mar 17, 2015 9:50 pm
- Full Name: Aemilianus Kehler
- Contact:
Re: Veeam Firewall Ports
here https://www.veeam.com/kb1518 for particular services/tasks and their respective ports, every link in this thread is dead.
-
- Enthusiast
- Posts: 94
- Liked: 16 times
- Joined: Nov 25, 2010 4:26 pm
- Full Name: Neil Murphy
- Contact:
Re: Veeam Firewall Ports
Now the link has changed to https://bp.veeam.expert/networkingneilmurphy65 wrote: ↑Oct 24, 2018 11:06 am This link seems to be broken. The new page on the best practices guide is https://bp.veeam.expert/appendices/networking. The pages following this one have the networking diagrams.
Who is online
Users browsing this forum: Google [Bot] and 164 guests