Skip to main content

Off-site backup storage server

Thread solved

Hi all,

Is there any way to easily create an offsite backup destination server?

My initial thoughts were to simply setup a docker container running the normal agent, create a storage location using the web interface, and set other backup plans to point to that backup location.
I soon realized that it wouldn't let me select this as a backup location for other servers.
Is this correct?
https://kb.acronis.com/content/62826

The next theory is that maybe you have to use the Acronis Storage or Acronis Storage Gateway?
https://www.acronis.com/en-us/blog/posts/building-private-cloud-backup-storage/
https://kb.acronis.com/content/59435

Alternatively, I could tunnel the external storage server to be network visible to the onsite servers, but I would like to maintain separation of networks for security.

Best,

Craig

0 Users found this helpful

Hello Craig,

It's not really clear what do you want to achieve. Looks like you want to store backups on an offsite location, but what's the plan to send data there if you want to segregate the networks?

I'd set up a storage node:

  • Only the storage node has access to both the agents that back up to it, and the external storage.
  • Agents would normally backup to this storage with a local storage medium as a jumping point,
  • then at an appropriate time the agent of the storage node would replicate backups to the external storage

You only need to expose the external storage to one place.

-- Peter

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 2
Comments: 1727

Hello Craig.

Please note the following limitations: 

 

  1. To backup data via the Docker agent only Files/Folders backup type should be used. Entire machine or Disks/volumes backup type is not supported.
  2. “Vulnerability Assessment” feature is shown as available in backup console UI when creating a protection plan, however its proper functioning is not guaranteed for Agent for Linux running inside the Docker container. 

If you have settled a full backup in the plan and you are trying to change the location that's not supported and it's expected as just Files/folders plans are supported.

Thanks in advance!

Péter Szatmári wrote:

Hello Craig,

It's not really clear what do you want to achieve. Looks like you want to store backups on an offsite location, but what's the plan to send data there if you want to segregate the networks?

I'd set up a storage node:

  • Only the storage node has access to both the agents that back up to it, and the external storage.
  • Agents would normally backup to this storage with a local storage medium as a jumping point,
  • then at an appropriate time the agent of the storage node would replicate backups to the external storage

You only need to expose the external storage to one place.

-- Peter

 

Thanks Peter!

Clarification:
I'm very new to Acronis. The cloud interface abstracted the Storage Location feature just enough to make it look like you could use almost any storage location from a registered agent as the backup location for another agent, where Acronis cloud would do the heavy lifting of data transfer/routing. As I mentioned, that does not seem to be the case.

The goal is really to just replace the backup to Cloud option with my own offsite storage. I was hoping for the same level of isolation between the Backup Agent and the Cloud storage, where an attacker on the backup agent machine couldn't easily wipe or attack the Cloud storage, but maybe I am misunderstanding how Acronis operates. This is preferred over directly routing an SMB share to the Backup Agent machine, since the attacker could then recover SMB credentials from the Backup Agent (probably not easily) and directly issue deletions to the SMB share.

Response:
It sounds like setting up an Acronis "storage node" is the right solution.

* Can the storage node itself be on a different non-visible network than the Backup Agent or does the Storage Node still need to be network visible to the Backup Agent machine? As in, does Acronis cloud route the backup data from Backup Agent --> Cloud --> Storage Node or does there need to be a direct connection between Backup Agent and Storage Node (open inbound port requests to storage node)?

* Does the Storage Node software require a special license? This makes it look like it is embedded in the normal Backup Agent installer for Windows?

Thank you so much for your help,

Craig

Jose Pedro Magalhaes wrote:

Hello Craig.

Please note the following limitations: 

 

  1. To backup data via the Docker agent only Files/Folders backup type should be used. Entire machine or Disks/volumes backup type is not supported.
  2. “Vulnerability Assessment” feature is shown as available in backup console UI when creating a protection plan, however its proper functioning is not guaranteed for Agent for Linux running inside the Docker container. 

If you have settled a full backup in the plan and you are trying to change the location that's not supported and it's expected as just Files/folders plans are supported.

Thanks in advance!

Thanks Jose. I did notice this when I tried using the GNU/Linux/Docker version of Backup Agent.

My main interest is to simply set up something like a Storage Node on GNU/Linux, hopefully inside Docker.

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 2
Comments: 1727

Hello Craig.

Management components (Acronis Management Server, Acronis Storage Node and Acronis Backup Appliance) do not require additional licenses, you only need licenses for machines\hosts you want to perform operations with.

Please refer to the following user-guides with the information about the nodes: 

https://www.acronis.com/en-us/support/documentation/AcronisCyberProtect…

https://www.acronis.com/en-us/support/documentation/AcronisCyberProtect…

https://www.acronis.com/en-us/support/documentation/AcronisCyberProtect…

If you face any issues during the deployment or errors feel free to contact our support https://kb.acronis.com/content/8153

Thanks in advance!