In this article we go over the steps to install Ubuntu with a bonded NIC, create the LVM on the boot drive, and then initialise an XFS formatted volume on the bulk storage provided by the server
Then we add this to Veeam as a Hardened Linux Repository with Immutable backups and then secure the Ubuntu server down so it cant be remotely accessed easily to protect your backups
Important – By continuing you are agreeing to the disclaimer here
Setting Up The RAID Array
For this section we will go through creating the RAID array, this will vary depending on the server and I will try to add methods for each model as they crop up, for now this will show you on a Dell system using iDRAC 9
Log into the iDRAC and head to Storage/Overview/Physical disks and click Create Virtual Disk
data:image/s3,"s3://crabby-images/28f5e/28f5e6c813a9905db7178b202040f6cb44133e97" alt=""
Give a name to the disk and select the layout, I want RAID 6 as this is backup server so resiliency is important
For advanced settings, make sure Read Ahead is selected for the read policy for a backup server this gives extra performance, and write policy should be write back only if your controller has a battery backup onboard so you dont loose data in the event of a power outage, the Dell H700 series have one by default, and write through if you dont
Then click Next
data:image/s3,"s3://crabby-images/a3ccf/a3ccfedb81f3e51242c9115dc74729a9d0fdfdc5" alt=""
Select all the disks you want in this RAID pool and click Next
data:image/s3,"s3://crabby-images/d1d29/d1d290e1f875e03d0bf46c2efce6f8262698e568" alt=""
Click Next here
data:image/s3,"s3://crabby-images/aa584/aa58464890e244db2735f3ee14167d1ce384a32a" alt=""
Click Add To Pending when you are happy
data:image/s3,"s3://crabby-images/19acf/19acf734d9549eb58f67a7a07c9ad852e310ccc7" alt=""
Once thats applied you will likely need to reboot for the OS to pick it up
Ubuntu Install
To start, you’ll need an Ubuntu Server ISO, the latest LTS version is ideal
Boot into the iso on the server you want to have as your repository
Navigate through the installer selecting your keyboard language
When the installer loads for networking we need to create a bond for the NICs we want to use
For this server there is only 2 connected NICs
data:image/s3,"s3://crabby-images/eec8a/eec8a2fa7e3ea0805b584a774218348ecbe80579" alt=""
Click create bond with the mode balance-alb, this is a simple load balanced setting that doesnt need any particular switch config
If your systems use LACP you can select 802.3ad and an XMIT Hash of Layer2+3
data:image/s3,"s3://crabby-images/c2303/c230374bd349fea89ced091466f47c152f9bcacb" alt=""
If the connection switches are a Dell VLT stack, like your cores may be, using a port channel not in LACP, active mode, the above will likely not work, however this should
data:image/s3,"s3://crabby-images/4e8c2/4e8c2b758a1e520eabbf5148a3c40486ac3de094" alt=""
Once thats created we need to edit the bond and set a static IP on it, this works similarly to a VIP in VMware systems
How you set the static IP on the bond will depend on your networking, but you this is the same as setting a static IP on any NIC on Ubuntu
Then fill in the proxy server if you have one, if not skip over it, then continue with the mirror check
Then setup the main disk for use, this wants to be the main boot drive, like a BOSS card for Dell servers, this will be 512GB max, do not use the main large disk pool as this is needed for the repository and cant have the OS installed to it
data:image/s3,"s3://crabby-images/12108/121081ff5ac4e9f602c52a59071d57c43140cd67" alt=""
Then confirm and continue
And configure the LVM to use the full disk, as this is just the boot volume, making sure the 80TB disk is not in a Logical Volume, if it is, delete it
data:image/s3,"s3://crabby-images/ba3ae/ba3aeb55288e94e2997c436d542c3d2644f9dd38" alt=""
Now we need to setup an the default account, this has sudo privileges
data:image/s3,"s3://crabby-images/ee0b3/ee0b38dc0d2a2c6e32175e9e740652535025c7b9" alt=""
Skip over Ubuntu Pro
Install SSH – this will be disabled later
data:image/s3,"s3://crabby-images/62426/624267839c2ab688107cfebe66e2caf598f889e4" alt=""
We need nothing from here, so skip over it and wait for the OS to install
data:image/s3,"s3://crabby-images/650ed/650ed68080d53010fdfaa79ec0aa03e0f61f764b" alt=""
Initialising Disks
This will wipe the disks you are initialising
Now those OS is installed lets get the disks initialised, run the following to check you have the right disks
sudo fdisk -l
This will then show everything
data:image/s3,"s3://crabby-images/46ae6/46ae68ca05ab7081d8903444eb65c02ceea1c50c" alt=""
This shows the root partition and the system files are on sdb, perfect
We want to initialize the 107TB disk for use in the Veeam backup repository, in my case it is sda3, typically on servers using virtual RAID volumes its sda or sdb, so make sure you substitute the right device in here
sudo mkfs.xfs -b size=4096 -m reflink=1,crc=1 /dev/sda
You may need to add -f to force this, but the system will tell you
You then get this
data:image/s3,"s3://crabby-images/0c1c7/0c1c7ac8df135374b083ae45d97ef287bcaa3ddd" alt=""
Now lets create a mount point
sudo mkdir /mnt/veeam-repo
Now we need an fstab entry to mount this on book, note the UUID of the drive, sda3 in our example, with
sudo blkid
data:image/s3,"s3://crabby-images/c7ce2/c7ce25e6d8585384fdbdc6239388801512052b9a" alt=""
Then run
echo 'UUID="Disk UUID" /mnt/veeam-repo xfs nosuid,nodev,nofail,x-gvfs-show 0 0' | sudo tee -a /etc/fstab
And run the following to check its in there
sudo cat /etc/fstab
Now we need to reload the daemon
sudo systemctl daemon-reload
Then run the following to mount drives under fstab
sudo mount -a
And we can confirm its mounted with
sudo mount
At the bottom we have
data:image/s3,"s3://crabby-images/86033/8603396e010e66db350afd79b7d16361bef97654" alt=""
Add Veeamsvc Account
Now we need the veeamsvc service account adding
sudo useradd -d /home/veeamsvc -m veeamsvc -s /bin/bash
Then set the password with
sudo passwd veeamsvc
Then add the veeamsvc account to the sudoers group
sudo usermod -a -G sudo veeamsvc
Take ownership of the repository with this account
sudo chown -R veeamsvc:veeamsvc /mnt/veeam-repo
And run
sudo chmod 700 /mnt/veeam-repo
Further hardening tasks can be done post Veeam install
Adding The Hardened Repository
Head to Backup Infrastructure
data:image/s3,"s3://crabby-images/6ac69/6ac6948e15b4268392528fa28759672f4f5e4e0c" alt=""
Then from managed Servers click Add Server
data:image/s3,"s3://crabby-images/e3d3f/e3d3f63819079749d47614ae223b86700dc241de" alt=""
Select Linux
data:image/s3,"s3://crabby-images/59970/599700f0a86af5af5a26527f635573d56cd37232" alt=""
Add the host name and description
data:image/s3,"s3://crabby-images/95d44/95d4409f6ce0a3edd0c6751248934274a921f00d" alt=""
Add a new single use credential for the veeamsvc account
data:image/s3,"s3://crabby-images/4abd3/4abd35c25b97bbbc663b2a4294bb15b53e512a42" alt=""
Add the credentials and click ok
data:image/s3,"s3://crabby-images/bca0d/bca0d1a1a43410cf76563990e5f8aebaddbf2882" alt=""
Then click Next
data:image/s3,"s3://crabby-images/d45c6/d45c6348ba67c661afa8de3a699acdbeb04dc3cb" alt=""
Click Yes on the SSH fingerprint warning
data:image/s3,"s3://crabby-images/63a9b/63a9bfed979b4902bdf99890bc455be0b8afe6cf" alt=""
Click apply
data:image/s3,"s3://crabby-images/9ed64/9ed64aa84efd2673f6cb27372f2838eb2d1d2785" alt=""
Then Finish once its been added
data:image/s3,"s3://crabby-images/076dd/076dd66e689817d4261f552e02b36a724b23c214" alt=""
Now lets add a repository, click Backup Repositories and Add Repository
data:image/s3,"s3://crabby-images/d60c7/d60c7569c99d4554aa4379038f5f65e3b5a0575c" alt=""
Select Direct Attached Storage
data:image/s3,"s3://crabby-images/09620/09620e2c5525a5f7b612f72d29e57d6ded42026e" alt=""
Then a Linux Hardened Repository at the bottom
data:image/s3,"s3://crabby-images/143d2/143d226d79646936f01cf9d44131a72d002f6835" alt=""
Then add a name and description, then click Next
data:image/s3,"s3://crabby-images/4ebba/4ebbabf5816849f7289a8d9c955173672a550b7d" alt=""
Click populate to find the paths on the server we added
data:image/s3,"s3://crabby-images/fb25d/fb25dca9a59c15f43503f737a714760617185250" alt=""
Select our mount point on /mnt/veeam-repo, then click Next
data:image/s3,"s3://crabby-images/ea479/ea4792e63fa83131de59fe70ddeebb5377251f89" alt=""
I also added a sub path on the location, you dont need to do this, but it is optional
You can then see the capacity, dont forget to set immutability for however long you want it, this should be the same as the number of daily backups you will have for your jobs, you can change this later, GFS backups are made immutable for their entire period
Once set, immutable backups cannot be removed until they have expired
We also want to set the number of concurrent tasks to ~3x the number of physical cores, this is a rough rule of thumb, if you have spare CPU on the repository during jobs and not enough are running in parallel you can increase it
Now click Next
data:image/s3,"s3://crabby-images/e1298/e1298193abe19601cfb0d96fb08cba2e7bbfc7bb" alt=""
Keep these as defaults and click Next
data:image/s3,"s3://crabby-images/70924/70924030a21c58b9ac12dfd2fc6cd8457d2ff2de" alt=""
Then click Apply
data:image/s3,"s3://crabby-images/e84f3/e84f3e0741916b77e333eedcf50084b3ff8ca290" alt=""
When its done click Next, and Finish
data:image/s3,"s3://crabby-images/a7948/a7948ce4cbdb622a335b5600f9ae02ff80eda7d3" alt=""
If this is your first repository, you absolutely need to click Yes here, the config cant be stored on the VBR server
data:image/s3,"s3://crabby-images/c5f68/c5f687f0d3a252d3fdef32e107ecc7351ff5f851" alt=""
Post Deployment Hardening Tasks
Enable the UFW on Ubuntu
sudo ufw enable
Run the following commands to add the VBR rules
sudo ufw allow openssh
sudo ufw allow proto tcp from <veeammgmt> to any port 6162,2500:3300
sudo ufw allow proto tcp from <proxy> to any port 2500:3300
You need to do these one IP at a time, for example, on a VBR server on 192.168.1.12 we would use
sudo ufw allow proto tcp from 192.168.1.12 to any port 6162,2500:3300
Disable root logon by editing
sudo nano /etc/passwd
Then change the line
root:x:0:0:root:/root:/bin/bash
To
root:x:0:0:root:/root:/usr/sbin/nologin
Then once thtas all done, disable ssh
Ubuntu 2204 And Earlier
Disable and stop the SSH service with
sudo systemctl stop ssh
sudo systemctl disable ssh
Ubuntu 2404 And Newer
Disable the SSH socket
sudo systemctl disable --now ssh.socket
Then disable and stop the SSH service
sudo systemctl stop ssh
sudo systemctl disable ssh
Since the repo is in Veeam, remove the veeamsvc account from the sudoers group
sudo deluser veeamsvc sudo
Lastly, disable ping in the UFW by editing the before rules with
sudo nano /etc/ufw/before.rules
And then commenting out the following lines
data:image/s3,"s3://crabby-images/9626b/9626b27f6fbb1535e88118f1ac3a1f972e301bdd" alt=""
OS Updates
Periodically, its a good idea to update the OS
To do this, simply login via the remote console on your server IPMI, eg iDRAC/iLO, as the veeamrepo account and run
sudo apt update ; sudo apt upgrade -y