Host-based backup of VMware vSphere VMs.
Post Reply
v.tom
Enthusiast
Posts: 28
Liked: 5 times
Joined: May 06, 2014 2:28 pm
Full Name: Tom
Contact:

Proxy in DMZ design

Post by v.tom »

Hi,

I have would like to backup some VM's in a DMZ cluster, so I have deployed a proxy in the DMZ cluster.
The security guy was not pleased that the proxy server needs a open port to the vCenter (port 443) which is in the non-DMZ network.

He asked if there is a solution which does not require to open an outbound port from within the DMZ.

What are the best practices in this case?
VMCE certified
foggy
Veeam Software
Posts: 21070
Liked: 2115 times
Joined: Jul 11, 2011 10:22 am
Full Name: Alexander Fogelson
Contact:

Re: Proxy in DMZ design

Post by foggy »

Tom, you could add host to Veeam B&R console directly, instead of adding it via vCenter. In this case connection to vCenter Server would not be required.
tsightler
VP, Product Management
Posts: 6011
Liked: 2843 times
Joined: Jun 05, 2009 12:57 pm
Full Name: Tom Sightler
Contact:

Re: Proxy in DMZ design

Post by tsightler »

From a design perspective, the proxy itself does not need to be in the DMZ at all. Can you tell me a little more about your specific DMZ configuration? Is the ESXi host also "in" the DMZ from a management perspective. In other words, does the management interface for that ESXi host live in the DMZ, or just the VMs.

Typically what I see is that the VMs are given IPs in the DMZ, but the ESXi host itself has it's management interface still accessible from the vCenter. In that scenario you can just use a proxy on your production network to backup VMs in the DMZ using network mode. Of course if you have a firewall between your vCenter and the ESXi host that might not be ideal from a performance perspective.

Also, there is a very good reason why the proxy requires a connection to vCenter. The VMware VADP APO which is being used by the proxy, requires the session to be authenticated during the backup so it must contact the vCenter server. If you post some more about your setup we can probably find a solution. In general I do not recommend placing a proxy within the DMZ itself as that means the traffic is likely to flow across a firewall which is normally not ideal.
Post Reply

Who is online

Users browsing this forum: Google [Bot] and 49 guests