Hyper-V Backup and Secure DMZ Servers: A How-to Guide
From a security point of view, a secure option that is being used for example by VPS hosting providers that we work with, is to DMZ the VMs, not the hyper-v host.
By DMZ-ing the VMs instead of the host, you can access and backup the host as usual and have only the VMs exposed to the outside. Attackers cannot easily access the host from the VM. Only the Hyper-V integration services would potentially and theoretically permit some malicious software perhaps to talk to the host; however, Microsoft has safeguarded this quite well so far.
All strategies including the above have their own pros and cons:
- Adding a new backup NAS in the internal LAN and open the port between DMZ Hyper-V Server for backups
In that case the attacker takes over the host and can do whatever he wants, including damaging the backup device. By the way, ransomware does this, too. It can find network access shares and damage all files there as well.
- Adding a new NAS in the DMZ. Pro: no need change anything in the firewall
In that case the downside is the attacker could gain full access to the host, all VMs on it, and all backups of it, leaving you potentially with nothing to restore from in case of an attack.
If you DMZ all VMs using static IP addresses, the risk is limited to the internals of each VM. The downside is you need to DMZ all VMs separately, but the host would remain on the internal network and protected as-is, including backups etc.
Another security ‘trick’ is to setup an isolated virtual switch and attach a separate NIC for those DMZ VMs so the VMs have no way of talking to the internal network, including the host. That would give you another layer of security in case someone hacks into the VM.
Welcome to BackupChain, the Hyper-V Server Backup Software for IT Professionals!
Download BackupChain now, our Server 2016 backup software that is specifically made for IT pros. Cloud backup, Hyper-V virtual machine backup, VMware server backup, Exchange server backup, and complete file server backup, all in one package. Beyond server backup, BackupChain also includes a DIY cloud server that works on all versions of Windows from XP to Windows 10, and from Windows Server 2003 to Windows Server 2016.
Backup Software Overview
BackupChain Server Backup SoftwareDownload BackupChain
Cloud Backup
Backup VMware Workstation
Backup FTP
Backup VirtualBox
Backup File Server
Hyper-V Backup
Backup Hyper-VPopular
- Hyper-V Links, Guides, Tutorials & Comparisons
- Veeam Alternative
- How to Back up Cluster Shared Volumes
- DriveMaker: Map FTP, SFTP, S3 Site to a Drive Letter (Freeware)
Resources
- Free Hyper-V Server
- Remote Desktop Services Blog
- SCDPM Blog
- SCOM Blog
- V4 Articles
- Knowledge Base
- FAQ
- Sitemap
- Backup Education
- Backup Sichern
- Hyper-V Scripts in PowerShell
- FastNeuron
- BackupChain (Greek)
- BackupChain (Deutsch)
- BackupChain (Spanish)
- BackupChain (French)
- BackupChain (Dutch)
- BackupChain (Italian)
Backup Software List
BackupChain
Veeam
Unitrends
Symantec Backup Exec
BackupAssist
Acronis
Zetta
Altaro
Windows Server Backup
Microsoft DPM
Ahsay
CommVault
IBM
Other Backup How-To Guides
- KB 2885541 Packet sniffing tool does not sniff all network traffic through port mirroring on Windows 2012 Server VMs
- VMware Workstation Start & Stop VMs from Command Line
- VMware Workstation Speed-Up, How to Fix Slow Performance
- How to Install a Virtual Machine Inside a Virtual Machine (Hyper-V)
- Free Disk2VHD Hyper-V VHDX Physical to Virtual Conversion P2V
- How to Backup a Virtual Server While Running
- Hyper-V Backup Quick Start Guide
- How to Open ISO in Hyper-V Server: Mount ISO to Drive
- Free eBooks for Hyper-V and Windows Server Admins
- Freeware Backup Software–Watch Out!
- How to fix error CLSID {463948d2-035d-4d1d-9bfc-473fece07dab} Access Denied
- How to Delete VSS Shadows or Snapshots
- 9 Editions of Windows Server 2012 Compared At a Glance
- How to fix: Selected writer ‘Microsoft Hyper-V VSS Writer’ is in failed state, VSS_WS_FAILED_AT_PREPARE_SNAPSHOT
- 0x8004230f VSS_E_UNEXPECTED_PROVIDER_ERROR VSS snapshot creation failed
- 8 Pros and Cons of Hyper-V Backup using USB External Drives
- How to fix ‘Microsoft Hyper-V VSS Writer’ is in failed state, Writer Failure code: 0x800423f3
- How to Convert from Dynamic VHD/VHDX Disk Format to / from Fixed in Hyper-V
- Hyper-V Stop 0x0000000A BSOD Error Causes and Fixes KB2776366
- Windows 11 Hyper-V Backup, Step-by-Step