Before You Begin
Before you configure network settings for VMs, make sure that your Azure environment meets the requirements listed in the following table. Some of the requirements, such as peering connections between VNets, change the network topology of your Azure subscription. Plan these changes in advance, as organization security policies may restrict them.
|
Requirement |
When Required |
Purpose |
|---|---|---|
|
Always |
The privatelink.blob.core.windows.net and privatelink.queue.core.windows.net zones hold the DNS records of the private endpoints. Veeam Backup for Microsoft Azure components use these records to resolve the endpoint names to private IP addresses. You can create the zones manually or instruct Veeam Backup for Microsoft Azure to create and manage them automatically. |
|
|
Always |
The worker configuration defines the Azure region and the VNet in which Veeam Backup for Microsoft Azure launches worker instances. Create the configuration in the same region where the protected VM resides and select a VNet for the worker instances. |
|
|
Only if you create and manage the private DNS zones manually |
A virtual network link allows the resources of a VNet to resolve the records stored in a private DNS zone. Link both DNS zones to the VNet of the backup appliance and to the VNet selected for the worker instances. For application-aware processing, also link the VNets of the protected Azure VMs. |
|
|
Peering connections allow the backup appliance and the worker instances to resolve the private endpoints that reside in other VNets. Without peering connections, you must create a separate set of private endpoints and private DNS zones in each VNet. Veeam Backup for Microsoft Azure does not use the peering connections to transfer backup data — the components exchange control messages through Azure Queue Storage. |
|
|
Private endpoints for Azure Blob Storage and Azure Queue Storage |
Always |
Veeam Backup for Microsoft Azure transfers backup data through the private endpoint for Azure Blob Storage and exchanges control messages through the private endpoint for Azure Queue Storage. The backup appliance has no direct connection to the worker instances, so Azure Queue Storage acts as a proxy that delivers worker readiness messages, job progress updates and VSS agent statuses. Veeam Backup for Microsoft Azure creates the endpoints automatically at the first run of a backup policy, but you must configure DNS settings for them manually. |
|
Only if you create and manage the private DNS zones manually |
Disk access resources allow worker instances to export VM snapshots to a repository through a private connection. Veeam Backup for Microsoft Azure creates the resources automatically, but you must add their private endpoints to the privatelink.blob.core.windows.net DNS zone. |
Considerations and Limitations
Before you start the deployment, review the following dependencies and limitations:
- Veeam Backup for Microsoft Azure does not create peering connections between VNets automatically — you must create each connection manually in the Microsoft Azure portal.
- Due to Microsoft Azure limitations, you must create the worker configuration in the same Azure subscription where the private DNS zones reside, if you plan to protect Azure VMs that have Ultra Disks or Premium SSD v2 disks attached and you create the private DNS zones manually.
- To allow Veeam Backup for Microsoft Azure to update worker instances, the worker instances must have public access to the online Ubuntu repositories listed in section Ports.
- To store backups of Azure VMs in repositories, you must also configure network settings for storage accounts as described in section Configuring Network Settings for Storage Accounts.