Host-based backup of VMware vSphere VMs.
Post Reply
nbarry
Novice
Posts: 9
Liked: 1 time
Joined: Sep 04, 2019 1:41 pm
Full Name: Nathan Barry
Contact:

Enhancement/BugFix- Skip DNS lookups when configuring storage systems by IP address

Post by nbarry »

When configuring 3PAR storage integration Veeam B&R appears to connect, verify WSAPI connectivity and SSH, but during the storage scan step it appears to perform a reverse DNS lookup of the entered IP, then attempt to connect to the hostname returned by the PTR record, rather than the originally entered IP address. When there are stale PTR records in the environment this can cause interesting behavior and an inability to successfully add a 3PAR to B&R until the stale entries are removed and all DNS caches flushed from the application by a server reboot.

Request: When entering an array by IP address, completely skip all DNS logic.
Andreas Neufert
VP, Product Management
Posts: 6707
Liked: 1401 times
Joined: May 04, 2011 8:36 am
Full Name: Andreas Neufert
Location: Germany
Contact:

Re: Enhancement/BugFix- Skip DNS lookups when configuring storage systems by IP address

Post by Andreas Neufert »

My understanding is that this is not possible because of the secure communication and ceritifcates.
foggy
Veeam Software
Posts: 21069
Liked: 2115 times
Joined: Jul 11, 2011 10:22 am
Full Name: Alexander Fogelson
Contact:

Re: Enhancement/BugFix- Skip DNS lookups when configuring storage systems by IP address

Post by foggy »

Hi Nathan, we will discuss if it is possible internally, thanks for the feedback.
nbarry
Novice
Posts: 9
Liked: 1 time
Joined: Sep 04, 2019 1:41 pm
Full Name: Nathan Barry
Contact:

Re: Enhancement/BugFix- Skip DNS lookups when configuring storage systems by IP address

Post by nbarry »

Thanks for the response- Andreas- if you are using self-signed certificates however, and already accepted the certificate thumbprint, why would the additional reverse/ forward/ then connect to that result be necessary? It also ends up connecting to a completely separate endpoint if there are DNS issues
Andreas Neufert
VP, Product Management
Posts: 6707
Liked: 1401 times
Joined: May 04, 2011 8:36 am
Full Name: Andreas Neufert
Location: Germany
Contact:

Re: Enhancement/BugFix- Skip DNS lookups when configuring storage systems by IP address

Post by Andreas Neufert »

Certificate is for a DNS name not IP address.
nbarry
Novice
Posts: 9
Liked: 1 time
Joined: Sep 04, 2019 1:41 pm
Full Name: Nathan Barry
Contact:

Re: Enhancement/BugFix- Skip DNS lookups when configuring storage systems by IP address

Post by nbarry »

Correct- but this check occurs AFTER you have clicked accept that you do not care about the certificate and the ssh thumbprint is valid.
My enhancement request is basically if using IP> skip all DNS, simply prompt for acceptance of ssl thumbprint & ssh thumbprint, and connect.
Andreas Neufert
VP, Product Management
Posts: 6707
Liked: 1401 times
Joined: May 04, 2011 8:36 am
Full Name: Andreas Neufert
Location: Germany
Contact:

Re: Enhancement/BugFix- Skip DNS lookups when configuring storage systems by IP address

Post by Andreas Neufert »

I think this is not how it works from security perspective.

There is no certificate for the IP address. So we can not check the validity of the connection without the DNS in place.
It is one think to accept a specific certificate that is not trusted by Windows (and implemented CA authorities) but to not verify if the counterpart is actually the system that belongs to the certificate is not correct.

Anyway we do not have plans to implement such functionality.

Maybe you can avoid the reverse lookup by using the FQDN of the system in the first place then the usual A record is used to find out the IP.
Post Reply

Who is online

Users browsing this forum: uszy and 91 guests