In order to create a SoftNAS Cloud® and Veeam Backup solution customized to your organization's individual needs, there is a fair bit of information you will need to gather, and a number of decisions that will need to be made. This primer is intended to help you identify the information needed to make informed decisions for your SoftNAS Cloud deployment with Veeam backups to the cloud. To guide you towards the solution that is right for you, the checklist below will help you record the key data required when you start your actual deployment of SoftNAS Cloud in AWS as a repository for Veeam backup data.
...
For each section of the checklist, additional information is provided in a linked section below. These informative articles can be used to help you make deployment decisions or create prerequisite resources that will be needed for your deployment.
Deployment Checklist:
The following document serves as a checklist, and as such is designed so that our users can copy and paste to a separate document (or export), and mark up as necessary. We recommend that the checklist be used to record all data to be used in your deployment for easy reference during both planning and your actual deployment.
- Deployment: Determine your deployment type. SoftNAS supports two different deployment types. Select one of the below:
- Premise to AWS Cloud
- AWS Cloud to AWS Cloud
- AWS Account: Record your AWS account credentials (how to create an AWS account listed below)
- Account ID or Alias:_____________________
- IAM User Name:_______________________
- Password:____________________________
- AWS Identity and Access Management: Ensure you have set up your AWS Identity and Access Management (IAM) configuration to use with SoftNAS Cloud and record the IAM Role you will use below:
- IAM Policy and Role created:____________________________
- IAM Role Name:______________________________________
- SoftNAS Cloud Offering: Determine what SoftNAS Cloud offering you use for your deployment. Select one of the below SoftNAS Cloud Offerings:
- SoftNAS Cloud® Essentials 1TB
- SoftNAS Cloud® Essentials 10TB
- SoftNAS Cloud® Essentials 20TB
- SoftNAS Cloud® Essentials 50TB
- SoftNAS Cloud® Essentials 1TB+MMS Consumption
- SoftNAS Cloud® Essentials BYOL
- Other non-Essentials:___________________________
- Networking: Understand the premise data center firewall or other network changes required to access SoftNAS Cloud in AWS as your Veeam repository:
- Data center networking and firewall changes requested and complete
- Data center networking and firewall changes requested and complete
- AWS Instance Size: Select the AWS instance size for your deployment.
Select one of the below:- i3.xlarge
- i3.2xlarge
- i3.4xlarge
- i3.8xlarge
- Other:________________________
- AWS Storage Selection: Select the type of AWS storage to use for your backup data in AWS.
Select one of the below:- AWS S3 Standard (Recommended for Veeam and SoftNAS Cloud Essentials)
- Other:________________________
- Add a self-signed certification to your SoftNAS Cloud and Veeam deployment:
- Add the certification:
- Add the certification:
- AWS VPC: Record the name of the VPC that you will use for your SoftNAS Cloud deployment
- VPC Name:____________________
- Data Transfer Protocol and AWS Instance Security Group: You can select to use NFS or CIFs/SMB as the protocol to allow Veeam to transfer backup data to the SoftNAS Cloud repository.
Select one of the below:- NFS
- CIFs/SMB
- AWS Key Pair: You may need your AWS Key Pair .pem file to launch SoftNAS in AWS and will need to know where to get it if needed.
- Key Pair .pem file location:_____________________
- AWS Access Key: You will need your Access key ID and Secret access key the first time you allocate storage in SoftNAS Cloud StorageCenter admin console, record your Access key ID and Secret access key below (you should keep this information secure)
- Access key ID:____________________________________
- Secret access key:_________________________________
- Deploy Your SoftNAS Cloud AWS instance via WAN:
- Connect Veeam to SoftNAS in AWS via WAN:
Anchor AWSVeeamDeployment AWSVeeamDeployment
Deployment
AWSVeeamDeployment | |
AWSVeeamDeployment |
There are two supported deployments of Veeam and SoftNAS Cloud to back up your data to the cloud.
Supported: Veeam Backup of On Premise Data to SoftNAS in the Cloud
If the data you want to backup is located on premise and you want to leverage SoftNAS Cloud on AWS to store backup data on AWS cloud storage, the deployment below is recommended and supported.
- Veeam and the data you want to backup will be located in you premise data center.
- You will need a VPN or other secure network connection to AWS to secure the NFS or CIFs/SMB traffic to the cloud
- SoftNAS Cloud will be running in the AWS cloud and connected to AWS S3 storage for your backup files
Supported: Veeam Backup of Cloud Data to SoftNAS in the Cloud
If the data you want to backup is located in the AWS cloud and you want to leverage SoftNAS Cloud on AWS to store backup data on AWS cloud storage, the deployment below is recommended and supported.
...
If the data you want to backup is located in the AWS cloud and you want to leverage SoftNAS Cloud on AWS to store backup data on AWS cloud storage, the deployment below is recommended and supported.
Anchor AWSVeeamAccount AWSVeeamAccount
AWS Account
AWSVeeamAccount | |
AWSVeeamAccount |
If you plan on saving you backups to SoftNAS Cloud on AWS, you/your company will need an AWS account. If you/your company does not have and AWS Account, you can create one here.
Once you have your AWS credentials (Account ID or alias, IAM username, Password), you will be able to log into the AWS Marketplace and select a SoftNAS Cloud Essentials offering here.
Anchor AWSVeeamIAM AWSVeeamIAM
AWS Identity and Access Management
AWSVeeamIAM | |
AWSVeeamIAM |
SoftNAS highly recommends the use of AWS Identity and Access Management with your SoftNAS instances. To use IAM with SoftNAS instances you will need to create an IAM Policy and IAM Role before you launch your SoftNAS instance in AWS. The process is simply and you can follow the instructions here to create the IAM Policy and Role to use with your SoftNAS Cloud deployment.
Anchor AWSVeeamSoftNASCloudOffering AWSVeeamSoftNASCloudOffering
SoftNAS Cloud Offering
AWSVeeamSoftNASCloudOffering | |
AWSVeeamSoftNASCloudOffering |
SoftNAS recommends use of SoftNAS Cloud Essentials and AWS S3 Object storage for use with Veeam for backups. SoftNAS Cloud Essentials is our base offering which only supports Object storage. Object storage is less expensive than Block storage and is a good option for use as storage for Veeam backups.
...
You can also use SoftNAS Cloud Enterprise or SoftNAS Cloud Platinum offerings for Veeam backups is you have a need for an enterprise storage solution beyond just the features/functionality offered in our SoftNAS Essentials offering.
Anchor AWSVeeamNetworking AWSVeeamNetworking
Networking
AWSVeeamNetworking | |
AWSVeeamNetworking |
If you are deploying Veeam and SoftNAS Cloud to back up data from your premise data center to the cloud, you will likely need to make some network security changes to your data center’s network/firewall to allow Veeam running in the datacenter to be able to connect to the SoftNAS Cloud in AWS. The information below is provided to help you make or request changes to your network team to ensure the network changes are ready when you are read to deploy SoftNAS.
NFS
If you will be using the NFS protocol to transmit data from Veeam on premise to SoftNAS Cloud in AWS, you will need to allow the following ports to traverse from your datacenter to the SoftNAS Cloud instance in AWS. Firewall changes may be required.
...
Type | Protocol | Port Range | Source | Source Value | Notes |
---|---|---|---|---|---|
SSH | TCP | 22 | Custom | x.x.x.x/32 | (ssh) SSH Access to SoftNAS |
Custom TCP Rule | TCP | 443 | Custom | x.x.x.x/32 | (https) HTTPS Access to SoftNAS |
Custom TCP Rule | TCP | 2500-5000 | Custom | x.x.x.x/32 | Default range of ports used for Veeam data transmission job channels |
Custom TCP Rule | TCP, UDP | 2049 | Custom | x.x.x.x/32 | (nfs) Standard NFS port |
Custom TCP Rule | TCP, UDP | 111 | Custom | x.x.x.x/32 | (sunrpc) Standard NFS ports. Port 111 is used by the port mapper service. |
CIFs/SMB
If you will be using CIFs/SMB to transmit data from Veeam on premise to SoftNAS Cloud in AWS, you will need to allow the following ports to traverse from your datacenter to the SoftNAS Cloud instance in AWS. Firewall changes may be required.
...
Anchor | ||||
---|---|---|---|---|
|
A list of SoftNAS Cloud Essentials recommended instance sized for use with Veeam can be found here. You can learn more about how the resources of an AWS instance can impact performance below.
...
Note: For Customers Using i3 Instances and leveraging an NVMe Disk as a Read Cache - A tested work-around is available in order to resolve a known issue with pools not importing properly after a reboot or shutdown. If you encounter this issue your data is NOT lost or damaged. Please contact SoftNAS Support for assistance in importing your pool.
Anchor AWSVeeamStorageSelection AWSVeeamStorageSelection
AWS Storage Selection
AWSVeeamStorageSelection | |
AWSVeeamStorageSelection |
SoftNAS recommends and supports use of AWS S3 Standard storage for Veeam backups with SoftNAS Cloud Essentials (SoftNAS Cloud Essentials only supports AWS S3 Object storage and does not support AWS EBS Block storage). AWS S3 Standard storage is recommended due to its durability and resiliency across multiple AWS Availability Zones providing you with multiple copies of your data in different AWS Availability Zones for protection against a full AWS Availability Zone failure.
...
- AWS S3 Standard-Infrequent Access
- AWS S3 One Zone-Infrequent Access
- AWS Glacier
Anchor AWSVeeamVPC AWSVeeamVPC
AWS VPC
AWSVeeamVPC | |
AWSVeeamVPC |
Your SoftNAS Cloud instance will need to run in a Virtual Private Cloud (VPC) in AWS. Creating a VPC is simple and you can create your VPC in advance or in step 3 “Configure Instance” when creating your SoftNAS Cloud instance. You can get more input on creating your VPC for use with SoftNAS Cloud with Veeam /wiki/spaces/SD/pages/92995922 For more information about AWS VPCs, click here.
Anchor AWSVeeamDTPandSecGroup AWSVeeamDTPandSecGroup
Data Transfer Protocol and AWS Instance Security Group
AWSVeeamDTPandSecGroup | |
AWSVeeamDTPandSecGroup |
An AWS Security Group is a set of firewall rules on the AWS network side that controls the network traffic for your instance. You can create new Security Group in the AWS EC2 console in advance or in Step 6 of the instance launch process.
SoftNAS Cloud supports use of either NFS or CIFs/SMB to transfer your data with Veeam to SoftNAS in the cloud. Depending on the protocol you are using, you will need to configure your firewall (see the Networking section above) as well as your AWS Instance Security Group for the protocol you select. The below provides example AWS Instance Security Group information for what SoftNAS recommends for use of Veeam with NFS and CIFs/SMB. You will need this information when you launch your SoftNAS AWS Instance.
NFS
(You will need to change Source value of “<Inbound IP>/CIDR” to the IP address and CIDR or IP Address Range and CIDR for your configuration. You can read more information on how to set the “Source” values here.)
CIFs/SMB
(You will need to change Source value of “<Inbound IP>/CIDR” to the IP address and CIDR or IP Address Range and CIDR for your configuration. You can read more information on how to set the “Source” values here.)
Anchor AWSVeeamKeyPair AWSVeeamKeyPair
AWS Key Pair
AWSVeeamKeyPair | |
AWSVeeamKeyPair |
AWS requires an AWS “Key Pair” to be selected as the last step to launch your new SoftNAS AWS instance. An AWS “Key Pair” consists of a public key that AWS stores, and a private key file that you store. Together, they allow you to connect to your instance securely. For SoftNAS Cloud AMIs, the private key file allows you to securely SSH into your instance. If you do not have or have lost your AWS “key pair”, you can learn how to create a new AWS “Key Pair” here.
Anchor AWSVeeamAccessKey AWSVeeamAccessKey
AWS Access Key
AWSVeeamAccessKey | |
AWSVeeamAccessKey |
Once your SoftNAS Cloud instance is launched, the first time you allocate AWS cloud storage to be used with your instance you will need to know your AWS Access Key. If you don’t already have this information available, you can create a new “Access key ID” and “Secret access key” using the instructions here (need a docs section that describes how to create a new set of AWS Access Keys, send you an email to create a new “AWS Access Key” section in our docs).
Anchor AWSVeeamDeploySolution AWSVeeamDeploySolution
Deploy Your Solution
AWSVeeamDeploySolution | |
AWSVeeamDeploySolution |
Once you have made your deployment decision listed above and satisfied prerequisites such as firewall configuration, you are ready to start your SoftNAS Cloud deployment with Veeam. SoftNAS recommends following the below steps to deploy your solution:
...