To provide cloud-based ransomware recovery, you connect and configure the VMware Live Cyber Recovery service with the on-premises VMware Cloud Foundation instance.
Activate a VMware Live Cyber Recovery Region for Cloud-Based Ransomware Recovery for VMware Cloud Foundation
Before you can begin configuring the VMware Live Cyber Recovery service, you first activate a VMware Cloud on AWS region.
Procedure
- Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
- On the Services page, locate the VMware Live Recovery tile, and click Launch service.
- In the left navigation bar, select Deployments, and from the Set up deployment drop-down button, select Set up cyber recovery region.
- On the VMware Cloud Services page, select the checkbox to allow the creation of an OAuth app to authorize VMware Live Cyber Recovery to access VMware Cloud Services and click Next.
On the VMware Cloud on AWS page, select the checkbox to allow the creation of an OAuth app to authorize VMware Live Cyber Recovery to access VMware Cloud on AWS click Next.
On the Activation page, select your AWS region from the drop-down menu and click Next.
In the Summary section, select the confirmation check box and click Finish.
Deploy a Cloud File System for Cloud-Based Ransomware Recovery for VMware Cloud Foundation
To replicate virtual machine snapshots, you deploy a cloud file system in the VMware Live Cyber Recovery service.
Procedure
- Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
- On the Services page, locate the VMware Live Recovery tile, and click Launch service.
- On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
On the Dashboard page, in the Quick setup section, click Deploy the cloud file system.
-
In the Deploy cloud file system dialog box, configure the following settings, configure the remaining settings according to your VMware Cloud Foundation Planning and Preparation Workbook, and click Deploy.
Setting
Value
On-premises
Selected
Use an existing SDDC in (AWS location)
Selected
Create a Protected Site for Cloud-Based Ransomware Recovery for VMware Cloud Foundation
After you deploy a cloud file system for storing virtual machine snapshots, you create a protected site.
Procedure
- Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
- On the Services page, locate the VMware Live Recovery tile, and click Launch service.
- On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
On the Dashboard page, in the Quick setup section, click Set up a protected site.
In the Set up protected site dialog box, configure the following settings, configure the remaining settings according to the values in your VMware Cloud Foundation Planning and Preparation Workbook, and click Set up.
Setting
Value
On-premises site
Selected
Use public internet
Selected
Deploy the VMware Live Cyber Recovery Connector Appliances for Cloud-Based Ransomware Recovery for VMware Cloud Foundation
To provide connectivity to the VMware Live Cyber Recovery service, you deploy two VMware Live Cyber Recovery Connector appliances in the VMware Cloud Foundation instance.
Procedure
- Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
- On the Services page, locate the VMware Live Recovery tile, and click Launch service.
- On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
On the VMware Live Cyber Recovery page, in the left navigation pane, click Protected sites to expand the list of protected sites.
Select the name of your protected site according to your VMware Cloud Foundation Planning and Preparation Workbook.
Deploy a VMware Live Cyber Recovery Connector appliance.
On the Protected sites page, under Connectors, click Deploy.
In the Deploy connector appliance window, click Copy next to the Appliance OVA URL.
- Log in to the management domain vCenter Server at https://<management_vcenter_server_fqdn>/ui by using an account with Administrator privileges.
- In the VMs and templates inventory, expand the management domain vCenter Server tree and expand the management domain data center.
Right-click the Cloud-Based Ransomware Recovery folder you created and select Deploy OVF template.
On the Select an OVF template page, select URL, paste the OVF link you copied and click Next.
In the Source verification dialog box, click Yes.
On the Select a name and folder page, in the Virtual machine name text box, enter a virtual machine name according to your VMware Cloud Foundation Planning and Preparation Workbook, and click Next.
On the Select a compute resource page, select the compute resource according to your VMware Cloud Foundation Planning and Preparation Workbook, and click Next.
On the Review details page, review the settings, acknowledge the certificate is not trusted by clicking Ignore, and click Next.
On the License agreements page, accept the license agreement and click Next.
On the Select storage page, select the vSAN datastore according to your VMware Cloud Foundation Planning and Preparation Workbook, and click Next.
On the Select networks page, from the Destination network drop-down menu, select the management VLAN port group according to your VMware Cloud Foundation Planning and Preparation Workbook, and click Next.
On the Ready to complete page, click Finish and wait for the completion of the process.
Power on the VMware Live Cyber Recovery Connector appliance.
- In the VMs and templates inventory, expand the management domain vCenter Server tree and expand the management domain data center.
Expand the Cloud-Based Ransomware Recovery folder.
Right-click the connector appliance and, from the Actions menu, select .
- Obtain the VMware Live Cyber Recovery Orchestrator FQDN and passcode.
On the VMware Live Cyber Recovery page, in the left navigation pane, click Protected sites to expand the list of protected sites.
Select the name of your protected site according to your VMware Cloud Foundation Planning and Preparation Workbook.
On the Protected sites page, under Connectors, click Deploy.
Copy the VMware Live Cyber Recovery Orchestrator FQDN into your VMware Cloud Foundation Planning and Preparation Workbook and make a note of the temporary site-specific passcode.
Configure the VMware Live Cyber Recovery Connector on the console.
- In the VMs and templates inventory, expand the management domain vCenter Server tree and expand the management domain data center.
Expand the Cloud-Based Ransomware Recovery folder.
Select the connector appliance and, on the Summary page, click Launch web console.
Log in to the VMware Live Cyber Recovery Connector appliance by using the admin / vmware#1 user.
Follow the instructions and configure the values according to your VMware Cloud Foundation Planning and Preparation Workbook using the latest temporary site-specific passcode.
Verify that the console shows a Success message for Adding connector to on-premises site.
Repeat this procedure to deploy the second VMware Live Cyber Recovery Connector appliance.
Create and Configure a Custom Role in vSphere for Cloud-Based Ransomware Recovery for VMware Cloud Foundation
To limit privileges and scope for VMware Live Cyber Recovery integration with vSphere, create a vSphere custom role with the required privileges and an integration service account in the vsphere.local domain. To provide the necessary privileges to the integration service account, assign the custom role to the service account.
UI Procedure
Obtain the VMware Live Cyber Recovery Connector appliance admin user password.
- Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
- On the Services page, locate the VMware Live Recovery tile, and click Launch service.
- On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
On the VMware Live Cyber Recovery page, in the left navigation pane, click Protected sites to expand the list of protected sites.
Select the name of your protected site according to your VMware Cloud Foundation Planning and Preparation Workbook.
On the Protected sites page, under Connectors, click the menu next to the connector appliance and click Show password.
In the Connector password dialog box, copy the admin password.
Log in to the VMware Live Cyber Recovery Connector appliance at <vlcr_connector_fqdn>:22 as admin by using the password from Step 1.
- To create and configure the custom role in vSphere, run the following command.
drc create-vcenter-user --vcenter <workload_domain_vcenter_server_IP_address> --admin-username [email protected] --admin-password VMw@re1! --new-username [email protected] --new-password VMw@re1! --vcenter-role "VMware Live Cyber Recovery to vSphere Integration" --snapshot-privs --failback-privs
Note: By running the command, you create a service account in the vsphere.local domain and a role with minimal privileges, and you associate the user with the role. The command creates a Propagate to children permission on the inventory root.
PowerShell Procedure
Start PowerShell.
Replace the values in the sample code with values from your VMware Cloud Foundation Planning and Preparation Workbook and run the commands in the PowerShell console.
$sddcManagerFqdn = "sfo-vcf01.sfo.rainpole.io" $sddcManagerUser = "[email protected]" $sddcManagerPass = "VMw@re1!" $sddcDomainName = "sfo-w01" $vlcrRole = "VMware Live Cyber Recovery to vSphere Integration" $domainFqdn = "vsphere.local" $vlcrServiceAccount = "svc-vlcr-vsphere" $vlcrServiceAccountPass = "VMw@re1!"
Create a custom role for VMware Live Cyber Recovery.
Perform the configuration by running the command in the PowerShell console.
Add-vSphereRole -server $sddcManagerFqdn -user $sddcManagerUser -pass $sddcManagerPass -sddcDomain $sddcDomainName -roleName $vlcrRole
In the dialog box that opens, navigate to the vSphereRoles folder and open the vlcr-vsphere-integration.role file.
The default path for the vSphereRoles folder is C:\Program\Files\WindowsPowerShell\Modules\PowerValidatedSolutions\<powervalidatedsolutions_version>\vSphereRoles.
Create an integration service account in the vSphere.local domain for VMware Live Cyber Recovery by running the following command.
Add-SsoUser -server $sddcManagerFqdn -user $sddcManagerUser -pass $sddcManagerPass -ssoUser $vlcrServiceAccount -ssoPass $vlcrServiceAccountPass
Assign the custom role to the integration service account for VMware Live Cyber Recovery by running the following command.
Add-vCenterGlobalPermission -server $sddcManagerFqdn -user $sddcManagerUser -pass $sddcManagerPass -sddcDomain $sddcDomainName -domain $domainFqdn -principal $vlcrServiceAccount -role $vlcrRole -propagate true -type user -localdomain
Repeat the procedure for any isolated VI workload domains in the VMware Cloud Foundation instance.
Configure a vSphere DRS Anti-Affinity Rule for the VMware Live Cyber Recovery Connector Appliances for Cloud-Based Ransomware Recovery for VMware Cloud Foundation
If you deploy multiple VMware Live Cyber Recovery Connector appliances, you must keep them on separate hosts and configure a vSphere DRS to run the virtual machines on different hosts in the default management vSphere cluster.
Procedure
- Log in to the management domain vCenter Server at https://<management_vcenter_server_fqdn>/ui by using an account with Administrator privileges.
- In the Hosts and clusters inventory, expand the management domain vCenter Server tree and expand the management domain data center.
Select the default management vSphere cluster and click the Configure tab.
In the left pane, select Add VM/Host rule.
, and clickConfigure the following settings, configure the remaining settings according to your VMware Cloud Foundation Planning and Preparation Workbook, and click OK.
Setting
Value
Enable rule
Selected
Type
Separate virtual machines
Add the Connector Appliances to the First Availability Zone VM Group for Cloud-Based Ransomware Recovery for VMware Cloud Foundation
If you configured the management domain with two availability zones, to provide failover to the second availability zone, add the VMware Live Cyber Recovery Connector appliances to the VM group for the first availability zone. The virtual machine write operations are performed synchronously across both availability zones and each availability zone has a copy of the data.
Procedure
- Log in to the management domain vCenter Server at https://<management_vcenter_server_fqdn>/ui by using an account with Administrator privileges.
- In the Hosts and clusters inventory, expand the management domain vCenter Server tree and expand the management domain data center.
Select the default management vSphere cluster, and click the Configure tab.
In the left pane, select
.Select the VM group for the first availability zone, and click Add.
In the Add group member dialog box, configure the settings according to your values in your VMware Cloud Foundation Planning and Preparation Workbook, and click OK.
Register a VI Workload Domain vCenter Server for Cloud-Based Ransomware Recovery for VMware Cloud Foundation
After deploying the VMware Live Cyber Recovery Connector appliances into the VMware Cloud Foundation instance, you register the VI workload domain vCenter Server, using its IP address, with the VMware Live Cyber Recovery service through the VMware Live Cyber Recovery Connector appliance.
Procedure
- Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
- On the Services page, locate the VMware Live Recovery tile, and click Launch service.
- On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
On the VMware Live Cyber Recovery page, in the left navigation pane, click Protected sites to expand the list of protected sites.
Select the name of your protected site according to your VMware Cloud Foundation Planning and Preparation Workbook.
Register the VI workload domain vCenter Server.
On the Protected sites page, under vCenters, click Register vCenter.
In the Register vCenter dialog box, configure the following settings, enter your values from the VMware Cloud Foundation Planning and Preparation Workbook, and click Register.
Setting Value Authenticate with restricted vCenter user
Selected
Add a Recovery SDDC for Cloud-Based Ransomware Recovery for VMware Cloud Foundation
To provide a VMware Cloud on AWS SDDC instance for facilitating the recovery of business workload virtual machines, you add a recovery SDDC to the protected site.
Procedure
- Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
- On the Services page, locate the VMware Live Recovery tile, and click Launch service.
- On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
On the VMware Live Cyber Recovery page, in the left navigation pane, click Protected sites to expand the list of protected sites.
Select the name of your protected site according to your VMware Cloud Foundation Planning and Preparation Workbook.
Add a recovery SDDC.
In the top right, click Add recovery SDDC.
In the Add recovery SDDC dialog box, select Attach existing SDDC and click Next.
Under Attach existing SDDC, select the recovery SDDC and click Next.
In the Confirm section, enter ATTACH SDDC in the text box and click Attach.
Configure Email Alerts for Cloud-Based Ransomware Recovery for VMware Cloud Foundation
You configure VMware Live Cyber Recovery to send an email when the Service Level Agreements (SLAs) status changes and when a recovery plan finishes running.
Procedure
- Log in to the VMware Cloud Services console at https://console.cloud.vmware.com/ with a user assigned the VMware Live Cyber Recovery Orchestrator Admin role.
- On the Services page, locate the VMware Live Recovery tile, and click Launch service.
- On the VMware Live Recovery page, for the region where the service is enabled, click Manage region.
On the VMware Live Cyber Recovery page, in the left navigation pane, click Settings.
On the Settings page, click Email alerts.
In the Configure email alerts dialog box, select the Send SLA change email alerts check box, configure the remaining settings according to your VMware Cloud Foundation Planning and Preparation Workbook, and click OK.