To provide cloud-based ransomware recovery, you connect and configure the VMware Live Cyber Recovery service with the on-premises VMware Cloud Foundation instance.

Activate a VMware Live Cyber Recovery Region for Cloud-Based Ransomware Recovery for VMware Cloud Foundation

Before you can begin configuring the VMware Live Cyber Recovery service, you first activate a VMware Cloud on AWS region.

Procedure

  1. Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
  2. On the Services page, locate the VMware Live Recovery tile, and click Launch service.
  3. Select Deployments from the left navigation and from the Set Up Deployment button, select Set up Cyber Recovery region.
  4. On the Set Up Cyber Recovery region page, in the Activation section, select your AWS region from the drop-down menu and click Next.

  5. On the Version page, select the Deployment version from the drop-down menu and click Next.
  6. In the Summary section, select the confirmation check box and click Finish.

Configure the API Token for Cloud-Based Ransomware Recovery for VMware Cloud Foundation

You configure an API token within the VMware Cloud Services console to ensure the VMware Live Cyber Recovery service can assign Organization Owner, Administrator and VMware Cloud on AWS NSX Cloud Admin service roles.

Procedure

  1. Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ as Organization owner.
  2. From the User/Organization settings menu, select My account.

  3. On the My account page, select the API Tokens tab.

  4. Click Generate a new API token.

  5. On the Generate a new API token page, in the Token name text box, enter a token name according to your VMware Cloud Foundation Planning and Preparation Workbook.

  6. In the Define scopes section, select the following roles and click Generate.

    Role Type Role

    All Organization Roles

    Organization Owner

    Service Roles

    VMware Cloud.VMware Cloud on AWS.Administrator
    VMware Cloud.VMware Cloud on AWS.NSX Cloud Admin
  7. In the Token generated dialog box, copy the token.

  8. Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
  9. On the Services page, locate the VMware Live Recovery tile, and click Launch service.
  10. On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
  11. On the Dashboard page, in the Quick setup section, click Configure the API token.

  12. In the Configure API token dialog box, enter the API token and click Validate.

  13. Verify the API token is validated and click OK.

Deploy a Cloud File System for Cloud-Based Ransomware Recovery for VMware Cloud Foundation

To replicate virtual machine snapshots, you deploy a cloud file system in the VMware Live Cyber Recovery service.

Procedure

  1. Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
  2. On the Services page, locate the VMware Live Recovery tile, and click Launch service.
  3. On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
  4. On the Dashboard page, in the Quick setup section, click Deploy the cloud file system.

  5. In the Deploy cloud file system dialog box, configure the following settings, configure the remaining settings according to your VMware Cloud Foundation Planning and Preparation Workbook, and click Deploy.

    Setting

    Value

    On-premises

    Selected

    Use an existing SDDC in (AWS location)

    Selected

Create a Protected Site for Cloud-Based Ransomware Recovery for VMware Cloud Foundation

After you deploy a cloud file system for storing virtual machine snapshots, you create a protected site.

Procedure

  1. Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
  2. On the Services page, locate the VMware Live Recovery tile, and click Launch service.
  3. On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
  4. On the Dashboard page, in the Quick setup section, click Set up a protected site.

  5. In the Set up protected site dialog box, configure the following settings, configure the remaining settings according to the values in your VMware Cloud Foundation Planning and Preparation Workbook, and click Set up.

    Setting

    Value

    On-premises site

    Selected

    Use public internet

    Selected

Deploy the VMware Live Cyber Recovery Connector Appliances for Cloud-Based Ransomware Recovery for VMware Cloud Foundation

To provide connectivity to the VMware Live Cyber Recovery service, you deploy two VMware Live Cyber Recovery Connector appliances in the VMware Cloud Foundation instance.

Procedure

  1. Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
  2. On the Services page, locate the VMware Live Recovery tile, and click Launch service.
  3. On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
  4. On the VMware Live Cyber Recovery page, in the left navigation pane, click Protected sites to expand the list of protected sites.

  5. Select the name of your protected site according to your VMware Cloud Foundation Planning and Preparation Workbook.

  6. Deploy a VMware Live Cyber Recovery Connector appliance.

    1. On the Protected sites page, under Connectors, click Deploy.

    2. In the Deploy connector appliance window, click Copy next to the Appliance OVA URL.

    3. Log in to the management domain vCenter Server at https://<management_vcenter_server_fqdn>/ui by using an account with Administrator privileges.
    4. In the VMs and templates inventory, expand the management domain vCenter Server tree and expand the management domain data center.
    5. Right-click the Cloud-Based Ransomware Recovery folder you created and select Deploy OVF template.

    6. On the Select an OVF template page, select URL, paste the OVF link you copied and click Next.

    7. In the Source verification dialog box, click Yes.

    8. On the Select a name and folder page, in the Virtual machine name text box, enter a virtual machine name according to your VMware Cloud Foundation Planning and Preparation Workbook, and click Next.

    9. On the Select a compute resource page, select the compute resource according to your VMware Cloud Foundation Planning and Preparation Workbook, and click Next.

    10. On the Review details page, review the settings, acknowledge the certificate is not trusted by clicking Ignore, and click Next.

    11. On the License agreements page, accept the license agreement and click Next.

    12. On the Select storage page, select the vSAN datastore according to your VMware Cloud Foundation Planning and Preparation Workbook, and click Next.

    13. On the Select networks page, from the Destination network drop-down menu, select the management VLAN port group according to your VMware Cloud Foundation Planning and Preparation Workbook, and click Next.

    14. On the Ready to complete page, click Finish and wait for the completion of the process.

  7. Power on the VMware Live Cyber Recovery Connector appliance.

    1. In the VMs and templates inventory, expand the management domain vCenter Server tree and expand the management domain data center.
    2. Expand the Cloud-Based Ransomware Recovery folder.

    3. Right-click the connector appliance and, from the Actions menu, select Power > Power on.

  8. Obtain the VMware Live Cyber Recovery Orchestrator FQDN and passcode.
    1. On the VMware Live Cyber Recovery page, in the left navigation pane, click Protected sites to expand the list of protected sites.

    2. Select the name of your protected site according to your VMware Cloud Foundation Planning and Preparation Workbook.

    3. On the Protected sites page, under Connectors, click Deploy.

    4. Copy the VMware Live Cyber Recovery Orchestrator FQDN into your VMware Cloud Foundation Planning and Preparation Workbook and make a note of the temporary site-specific passcode.
  9. Configure the VMware Live Cyber Recovery Connector on the console.

    1. In the VMs and templates inventory, expand the management domain vCenter Server tree and expand the management domain data center.
    2. Expand the Cloud-Based Ransomware Recovery folder.

    3. Select the connector appliance and, on the Summary page, click Launch web console.

    4. Log in to the VMware Live Cyber Recovery Connector appliance by using the admin / vmware#1 user.

    5. Follow the instructions and configure the values according to your VMware Cloud Foundation Planning and Preparation Workbook using the latest temporary site-specific passcode.

    6. Verify that the console shows a Success message for Adding connector to on-premises site.

  10. Repeat this procedure to deploy the second VMware Live Cyber Recovery Connector appliance.

Create and Configure a Custom Role in vSphere for Cloud-Based Ransomware Recovery for VMware Cloud Foundation

To limit privileges and scope for VMware Live Cyber Recovery integration with vSphere, create a vSphere custom role with the required privileges and an integration service account in the vsphere.local domain. To provide the necessary privileges to the integration service account, assign the custom role to the service account.

UI Procedure

  1. Obtain the VMware Live Cyber Recovery Connector appliance admin user password.

    1. Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
    2. On the Services page, locate the VMware Live Recovery tile, and click Launch service.
    3. On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
    4. On the VMware Live Cyber Recovery page, in the left navigation pane, click Protected sites to expand the list of protected sites.

    5. Select the name of your protected site according to your VMware Cloud Foundation Planning and Preparation Workbook.

    6. On the Protected sites page, under Connectors, click the menu next to the connector appliance and click Show password.

    7. In the Connector password dialog box, copy the admin password.

  2. Log in to the VMware Live Cyber Recovery Connector appliance at <vlcr_connector_fqdn>:22 as admin by using the password from Step 1.

  3. To create and configure the custom role in vSphere, run the following command.
    drc create-vcenter-user --vcenter <workload_domain_vcenter_server_IP_address>  --admin-username [email protected] --admin-password VMw@re1!  --new-username [email protected] --new-password VMw@re1!  --vcenter-role "VMware Live Cyber Recovery to vSphere Integration" --snapshot-privs --failback-privs
    Note: By running the command, you create a service account in the vsphere.local domain and a role with minimal privileges, and you associate the user with the role. The command creates a Propagate to children permission on the inventory root.

PowerShell Procedure

  1. Start PowerShell.

  2. Replace the values in the sample code with values from your VMware Cloud Foundation Planning and Preparation Workbook and run the commands in the PowerShell console.

    $sddcManagerFqdn = "sfo-vcf01.sfo.rainpole.io"
    $sddcManagerUser = "[email protected]"
    $sddcManagerPass = "VMw@re1!"
    
    $sddcDomainName = "sfo-w01"
    
    $vlcrRole = "VMware Live Cyber Recovery to vSphere Integration"
    
    $domainFqdn = "vsphere.local"
    $vlcrServiceAccount = "svc-vlcr-vsphere"
    $vlcrServiceAccountPass = "VMw@re1!"
  3. Create a custom role for VMware Live Cyber Recovery.

    1. Perform the configuration by running the command in the PowerShell console.

      Add-vSphereRole -server $sddcManagerFqdn -user $sddcManagerUser -pass $sddcManagerPass -sddcDomain $sddcDomainName -roleName $vlcrRole
    2. In the dialog box that opens, navigate to the vSphereRoles folder and open the vlcr-vsphere-integration.role file.

      The default path for the vSphereRoles folder is C:\Program\Files\WindowsPowerShell\Modules\PowerValidatedSolutions\<powervalidatedsolutions_version>\vSphereRoles.

  4. Create an integration service account in the vSphere.local domain for VMware Live Cyber Recovery by running the following command.

    Add-SsoUser -server $sddcManagerFqdn -user $sddcManagerUser -pass $sddcManagerPass -ssoUser $vlcrServiceAccount -ssoPass $vlcrServiceAccountPass
  5. Assign the custom role to the integration service account for VMware Live Cyber Recovery by running the following command.

    Add-vCenterGlobalPermission -server $sddcManagerFqdn -user $sddcManagerUser -pass $sddcManagerPass -sddcDomain $sddcDomainName -domain $domainFqdn -principal $vlcrServiceAccount -role $vlcrRole -propagate true -type user -localdomain
  6. Repeat the procedure for any isolated VI workload domains in the VMware Cloud Foundation instance.

Configure a vSphere DRS Anti-Affinity Rule for the VMware Live Cyber Recovery Connector Appliances for Cloud-Based Ransomware Recovery for VMware Cloud Foundation

If you deploy multiple VMware Live Cyber Recovery Connector appliances, you must keep them on separate hosts and configure a vSphere DRS to run the virtual machines on different hosts in the default management vSphere cluster.

Procedure

  1. Log in to the management domain vCenter Server at https://<management_vcenter_server_fqdn>/ui by using an account with Administrator privileges.
  2. In the Hosts and clusters inventory, expand the management domain vCenter Server tree and expand the management domain data center.
  3. Select the default management vSphere cluster and click the Configure tab.

  4. In the left pane, select Configuration > VM/Host rules, and click Add VM/Host rule.

  5. Configure the following settings, configure the remaining settings according to your VMware Cloud Foundation Planning and Preparation Workbook, and click OK.

    Setting

    Value

    Enable rule

    Selected

    Type

    Separate virtual machines

Add the Connector Appliances to the First Availability Zone VM Group for Cloud-Based Ransomware Recovery for VMware Cloud Foundation

If you configured the management domain with two availability zones, to provide failover to the second availability zone, add the VMware Live Cyber Recovery Connector appliances to the VM group for the first availability zone. The virtual machine write operations are performed synchronously across both availability zones and each availability zone has a copy of the data.

Procedure

  1. Log in to the management domain vCenter Server at https://<management_vcenter_server_fqdn>/ui by using an account with Administrator privileges.
  2. In the Hosts and clusters inventory, expand the management domain vCenter Server tree and expand the management domain data center.
  3. Select the default management vSphere cluster, and click the Configure tab.

  4. In the left pane, select Configuration > VM/Host groups.

  5. Select the VM group for the first availability zone, and click Add.

  6. In the Add group member dialog box, configure the settings according to your values in your VMware Cloud Foundation Planning and Preparation Workbook, and click OK.

Register a VI Workload Domain vCenter Server for Cloud-Based Ransomware Recovery for VMware Cloud Foundation

After deploying the VMware Live Cyber Recovery Connector appliances into the VMware Cloud Foundation instance, you register the VI workload domain vCenter Server, using its IP address, with the VMware Live Cyber Recovery service through the VMware Live Cyber Recovery Connector appliance.

Procedure

  1. Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
  2. On the Services page, locate the VMware Live Recovery tile, and click Launch service.
  3. On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
  4. On the VMware Live Cyber Recovery page, in the left navigation pane, click Protected sites to expand the list of protected sites.

  5. Select the name of your protected site according to your VMware Cloud Foundation Planning and Preparation Workbook.

  6. Register the VI workload domain vCenter Server.

    1. On the Protected sites page, under vCenters, click Register vCenter.

    2. In the Register vCenter dialog box, configure the following settings, enter your values from the VMware Cloud Foundation Planning and Preparation Workbook, and click Register.

      Setting Value

      Authenticate with restricted vCenter user

      Selected

Add a Recovery SDDC for Cloud-Based Ransomware Recovery for VMware Cloud Foundation

To provide a VMware Cloud on AWS SDDC instance for facilitating the recovery of business workload virtual machines, you add a recovery SDDC to the protected site.

Procedure

  1. Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
  2. On the Services page, locate the VMware Live Recovery tile, and click Launch service.
  3. On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
  4. On the VMware Live Cyber Recovery page, in the left navigation pane, click Protected sites to expand the list of protected sites.

  5. Select the name of your protected site according to your VMware Cloud Foundation Planning and Preparation Workbook.

  6. Add a recovery SDDC.

    1. In the top right, click Add recovery SDDC.

    2. In the Add recovery SDDC dialog box, select Attach existing SDDC and click Next.

    3. Under Attach existing SDDC, select the recovery SDDC and click Next.

    4. In the Confirm section, enter ATTACH SDDC in the text box and click Attach.

Configure Email Alerts for Cloud-Based Ransomware Recovery for VMware Cloud Foundation

You configure VMware Live Cyber Recovery to send an email when the Service Level Agreements (SLAs) status changes and when a recovery plan finishes running.

Procedure

  1. Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
  2. On the Services page, locate the VMware Live Recovery tile, and click Launch service.
  3. On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
  4. On the VMware Live Cyber Recovery page, in the left navigation pane, click Settings.

  5. On the Settings page, click Email alerts.

  6. In the Configure email alerts dialog box, select the Send SLA change email alerts check box, configure the remaining settings according to your VMware Cloud Foundation Planning and Preparation Workbook, and click OK.