Encrypted VMs
Veeam Backup & Replication provides support for VMware vSphere encrypted VMs.
- Backup of encrypted VMs
- Restore of encrypted VMs
- Replication of encrypted VMs
- Failback of encrypted VM replicas
To back up VMware encrypted VMs, the backup infrastructure must meet the following requirements:
- VM encryption instances must be preconfigured in the virtual infrastructure: you must set up the Key Management Server (KMS), create the VM encryption policy, and assign it to VMs in advance.
- The backup proxy must be working in the Virtual appliance or Network transport mode:
- The backup proxy working in the Virtual appliance transport mode must be deployed on an encrypted VM.
- The backup proxy working in the Network transport mode uses the NBD protocol by default. If you want to use NBDSSL, select the Enable host to proxy traffic encryption in Network mode (NBDSSL) check box in the Transport Mode window. Note that traffic encryption puts more stress on the CPU of an ESXi host and can decrease performance.
Veeam Backup & Replication supports the following restore options:
The backup infrastructure must meet the following requirements:
- The backup proxy must be working in the Virtual appliance or Network transport mode:
- The backup proxy working in the Virtual appliance transport mode must be deployed on an encrypted VM.
- The backup proxy working in the Network transport mode uses the NBD protocol by default. If you want to use NBDSSL, select the Enable host to proxy traffic encryption in Network mode (NBDSSL) check box in the Transport Mode window. Note that traffic encryption puts more stress on the CPU of an ESXi host and can decrease performance.
To replicate VMware encrypted VMs, the backup infrastructure must meet the following requirements:
Note |
If you do not set up KMS, the replication job will not fail, but replicated VMs will not be encrypted in this case. |
- Source and target backup proxies must be working in the Virtual appliance or Network transport mode:
- At the Destination step of the wizard, click Choose near the Datastore field.
- In the Select Datastore window, select a datastore under the VM Encryption Policy node.
Note |
Multi-OS file-level restore for encrypted VM replicas is not supported. |