This article documents how to configure Veeam Backup & Replication to use Azure Blob Storage Account private endpoints (via Azure VPN or Azure ExpressRoute) for Scale-Out Backup Repository offload to Capacity Tier or Archive Tier or to connect to an Object Storage Repository in Veeam Backup & Replication 12 or newer.
The Veeam Backup Server and the Archiver Appliance must have access to CRLs used by Azure over port 80.
instance name
and region
to match the virtual network you plan to use for the storage account, public IP address name,
and the availability zone
. It is assumed if you’re using Azure ExpressRoute that you have configured this prior.2. Under **↔ Point-to-site configuration**, select `Configure now`. You'll need to [generate a certificate using PowerShell](<https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-certificates-point-to-site>) for your connection. Specify an address pool, select `IKEv2` and `OpenVPN (SSL)` as your tunnel type, and for authentication type, choose `Azure certificate`, uploading the root certificate contents.
3. **↓ Download VPN client** and install this and the corresponding client certificate on the backup repository [gateway servers](<https://helpcenter.veeam.com/docs/backup/vsphere/azure_repository_account.html>) that will be communicating with Azure Blob. If you have not specified a gateway server, all scale-out backup repository extents must have access.
1. To disable public access for an existing storage account, select **Networking** >**Firewall and virtual networks** and ensure `public network access` is disabled. If you need to access Azure Blob from another resource without using a private endpoint, for example, to see container contents in the Azure Portal you will need to choose `enabled for selected virtual networks and IP addresses` instead.
2. Under **Networking > Private endpoint connections**, click add a**\+ Private endpoint**.
* Under **Basics,** enter a `name` and `network interface name.`
* For **Resource**, target sub-resource select `blob.`
* For **Virtual Network,** select the virtual network you want to associate. You can statically or dynamically allocate an IP address. In these instructions, we'll be using a static IP address.
* For **DNS,** make sure you've selected ◉ Yes to `integrate with DNS zone`.
DNS configuration
, you should be able to see a private link entry that points to the specific IP address. This is required to support Azure Archive Tier as Veeam Backup & Replication Azure Proxy Appliances are deployed dynamically.Note: The Veeam Backup Server must be able to resolve_ .blob.core.windows.net_ to the private link you created. This means the Azure DNS private link needs to resolve correctly on the Veeam Backup Server. This may require modifying DNS or modifying the Veeam Backup Server’s hosts file to point _.blob.core.windows.net_ to the relevant *.privatelink.blob.core.windows.net endpoint.
**Key Location:**HKLM\Software\Veeam\Veeam Backup and Replication
**Value Name:**ArchiveFreezingUsePrivateIpForAzureAppliance
Value Type: DWORD (32-Bit) Value **Value Data: **1
1 = Enable using Private IP | 0 = Disable
PowerShell cmdlet to create the registry value and enable the setting:
New-ItemProperty -Path 'HKLM:\SOFTWARE\Veeam\Veeam Backup and Replication\' -Name 'ArchiveFreezingUsePrivateIpForAzureAppliance' -Value "1" -PropertyType DWORD -Force
Copy
Key Location: HKLM\SOFTWARE\Veeam\Veeam Backup and Replication **Value Name:**ArchiveUsePrivateIpForAzureHelperAppliance **Value Type: **DWORD (32-Bit) Value Value Data: 1
1 = Enable Archive Appliance use Private IP | 0 = Disable (Default)
PowerShell cmdlet to create the registry value and enable the setting:
New-ItemProperty -Path 'HKLM:\SOFTWARE\Veeam\Veeam Backup and Replication\' -Name 'ArchiveUsePrivateIpForAzureHelperAppliance ' -Value "1" -PropertyType DWORD -Force
Copy
* For Linux-based Gateway servers, add the following entry to the ****/etc/VeeamAgentConfig**If the /etc/VeeamAgentConfig file is not present, it must be created.****** file:
ObjectStorageTlsRevocationCheck=0
Add your Azure object storage account to Veeam Backup & Replication.
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
Vendor | Product | Version | CPE |
---|---|---|---|
veeam | veeam_backup_\&_replication | 12.2 | cpe:2.3:a:veeam:veeam_backup_\&_replication:12.2:*:*:*:*:*:*:* |
veeam | veeam_backup_\&_replication | 12.1 | cpe:2.3:a:veeam:veeam_backup_\&_replication:12.1:*:*:*:*:*:*:* |
veeam | veeam_backup_\&_replication | 12 | cpe:2.3:a:veeam:veeam_backup_\&_replication:12:*:*:*:*:*:*:* |
veeam | veeam_backup_\&_replication | 11 | cpe:2.3:a:veeam:veeam_backup_\&_replication:11:*:*:*:*:*:*:* |