Link Search Menu Expand Document

Security

Domain or workgroup

Backup Proxy servers can be either domain-joined or sit in a workgroup. The best practice is to use a separate domain. However when using them in a workgroup the following settings are required:

  • The Remote Registry service must run on the target machine. The service startup type must be set to Automatic.
  • Backup proxy server ports must be opened in Windows Firewall.

Security zones

The different components should be put within the following zones (networks):

Security zone Component
DMZ VB365 API/Portal
MGMT VB365 Server
STORAGE VB365 Backup Proxy/Repo server(s)
Backup storage(s)

This deployment can be further enhanced by:

  1. Putting a Reverse Proxy Server in front of the API/Portal server. This provides additional advantages:

    • Protects the API/Portal server from exposure by having clients pass through the Reverse Proxy Server before reaching the API/Portal server.
    • SSL/TSL certificates offloading.
  2. Putting a Web Application Firewall (WAF) in front of the API/Portal server. This provides additional advantages:

    • A WAF is a type of reverse proxy that protects the API/Portal server from exposure by having clients pass through the WAF before reaching the API/Portal server.
    • Set policies to protect against vulnerabilities in the application by filtering out malicious traffic.
    • DDoS attack protection (e.g. rate limiting).

Back to top

Copyright © 2019-2022 Solutions Architects, Veeam Software.