Backup/en: Unterschied zwischen den Versionen

Aus TERRA CLOUD WIKI
Die Seite wurde neu angelegt: „This function shows you whether and how many data backups were skipped.<br> <br> '''A high rate of skipped backups can result from the following circumstances:''' # The intervals between data backups are too short and the next data backup is started during runtime # A very long data backup duration ensures that the subsequent data backup is skipped <br> '''Data backups may be skipped if the following two conditions are met together''': #The backup job is…“
Keine Bearbeitungszusammenfassung
 
(261 dazwischenliegende Versionen von 2 Benutzern werden nicht angezeigt)
Zeile 1: Zeile 1:
<languages/>
<languages/>
<span id="Einführung"></span>
<span id="Einführung"></span>
== '''Introduction''' ==
= '''Introduction''' =


<span id="Was_zeichnet_die_TERRA_CLOUD_Backuplösung_aus?"></span>
<span id="Was_zeichnet_die_TERRA_CLOUD_Backuplösung_aus?"></span>
=== What characterizes the TERRA CLOUD backup solution? ===
== What characterizes the TERRA CLOUD backup solution? ==
 
Communication between all components involved is always encrypted. All you need to do is install an agent on the server to be backed up. <br>
This then connects to our data center via ports 8086 and 8087. <br>
Since the connection is from the server to be secured to the outside, no incoming firewall rules or NAT need to be configured. <br>
Administration is carried out centrally via our backup portal. <br>
In this portal you can see all the servers that have been linked to your account through agent registration. <br>
The backup solution essentially consists of three components: Agent, Portal and Vault. The agent is the software component that runs as a service on your servers. <br>
The portal is used to configure and administer these agents. The Vault is the data vault in which the data backups are stored. <br>


TERRA CLOUD Backup is a comprehensive data backup solution. All necessary components are provided by TERRA CLOUD.<br>
This gives you a single point of contact for any questions or issues.<br>
<br>
Communication between all components involved is always encrypted. Only a single agent needs to be installed on the server to be backed up.<br>
It then connects to our data center via ports 8086 and 8087.<br>
Since the connection originates from the server being backed up, no inbound firewall rules or NAT configurations are required.<br>
<br>
Administration is handled via the multi-tenant [https://backup.terracloud.de TERRA CLOUD Backup Portal].<br>
In this portal, you can view all servers linked to your account through agent registration.<br>
<br>
The backup solution essentially consists of three components: '''Agent, Portal, and Vault''':<br>
The '''Agent''' is the software component that performs the backup on the system being protected. The '''Portal''' is used to administer and monitor these agents and to initiate restores. The '''Vault''' is the secure storage repository that receives and safely stores the backups. All backups are stored redundantly across two different data centers, distinguishing between a primary and a secondary vault.
<span id="Funktionsübersicht"></span>
<span id="Funktionsübersicht"></span>
=== Function overview ===
== Function overview ==


{| class="wikitable"
{| class="wikitable"
Zeile 26: Zeile 30:
!style="background-color:#7d5cab;color:#ffffff"|'''Hyper-V Agent'''
!style="background-color:#7d5cab;color:#ffffff"|'''Hyper-V Agent'''
|-
|-
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Create_image-based_backup_job Bare-Metal Restore]
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Create_image-based_backup_job Bare-Metal Restore*]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
Zeile 45: Zeile 49:
|-
|-
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Supported_operating_systems Backup of virtual systems (servers, VDI)]
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Supported_operating_systems Backup of virtual systems (servers, VDI)]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|-
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Defering_function Backup deferral (initial backup)]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
Zeile 54: Zeile 64:
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|-
|-
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Initial_backup_FTP_upload_/_send_data_carrier Initialbackup ext. HDD/FTP]
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Initial_backup_FTP_upload_/_send_data_carrier Initialbackup ext. HDD/FTP]
Zeile 86: Zeile 96:
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
|-
|-
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#File-based_backup Backup of files and folders]
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#File-based_backup Backup/Excluding Files and Folders]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
Zeile 205: Zeile 215:
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
|-
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#%E2%80%9CMonitoring%E2%80%9D_tab_in_the_TERRA_CLOUD_Backup_Portal Backup History Graph]
|style="background-color:#ffffff;text-align:center;"|[[Datei:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[Datei:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[Datei:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[Datei:Minus.jpg|10px]]
|}
|}
{| class="wikitable"
{| class="wikitable"
|-
|-
| style="background-color:#ffffff"| Included in '''TERRA CLOUD Backup Basic/Standard''' || style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
| style="background-color:#ffffff"| Included in '''TERRA CLOUD Backup Basic/Standard''' || style="background-color:#ffffff;text-align:center;"|[[Datei:Green check1.png|10px]]
|-
|-
| style="background-color:#ffffff"| Also included in '''TERRA CLOUD Backup Enterprise''' || style="background-color:#ffffff;text-align:center;"|[[File:Star.png|15px]]
| style="background-color:#ffffff"| Additionally included in '''TERRA CLOUD Backup Enterprise''' || style="background-color:#ffffff;text-align:center;"|[[Datei:Star.png|15px]]
|-
| style="background-color:#ffffff"| Bare-metal restore ('''BMR''') backups using a Windows agent on a '''Hyper-V host''' are not supported.<br>For further information, please see [https://wiki.terracloud.de/index.php/Backup_FAQ/en#How_can_a_BMR_backup_of_a_Hyper-V_host_be_created? here] || style="background-color:#ffffff;text-align:center;"|*
|}
|}
<span id="Produktvorstellung_und_Ersteinrichtung"></span>
<span id="Produktvorstellung_und_Ersteinrichtung"></span>
=== Product presentation and initial setup ===
== Product presentation and initial setup ==


Would you like to get an overview of the TERRA CLOUD backup? Then we recommend the recordings of the [https://b2b.wortmann.de/de-de/content/terracast/terracast.aspx TERRACASTS] of the “TERRA CLOUD Backup” theme week. <br>
To make getting started with TERRA CLOUD Backup as clear as possible, the following diagram illustrates the complete setup process—ranging from the installation of the agent and its automatic configuration via the Backup Portal to the final installation of the TERRA CLOUD Backup agent.<br>
It highlights the stages where the process can be significantly accelerated and standardized through features such as automatic agent configuration.<br>
[[Datei:Backup-EN-Einrichtungsprozess.png]]<br>
Following the diagram, we recommend familiarizing yourself with the fundamental concepts and functions of TERRA CLOUD Backup.<br>
A good supplement to this is the recordings of the TERRA CASTs, which you can find [https://www.wortmann.de/terracast here].<br>
<span id="Voraussetzungen"></span>
<span id="Voraussetzungen"></span>
== '''Requirements''' ==
= '''Requirements''' =


<span id="Unterstützte_Betriebssysteme"></span>
<span id="Unterstützte_Betriebssysteme"></span>
=== Supported operating systems ===
== Supported operating systems ==


==== Windows Agent ====
==== Windows Agent ====


'''Windows Server:''' <br>
'''Windows Server:''' <br>
* Windows Server 2025: Standard, Datacenter, Server Core
* Windows Server 2022: Essentials, Standard, Datacenter, Server Core
* Windows Server 2022: Essentials, Standard, Datacenter, Server Core
* Windows Server 2019: Essentials, Standard, Datacenter, Server Core
* Windows Server 2019: Essentials, Standard, Datacenter, Server Core
* Windows Server 2016: Essentials, Standard, Datacenter, Server Core
* Windows Server 2016: Essentials, Standard, Datacenter, Server Core
* Windows Server 2012 R2: Foundation, Essentials, Standard, Datacenter, Server Core
* Windows Server 2012: Foundation, Essentials, Standard, Datacenter, Server Core
* Windows Storage Server 2012: Standard, Workgroup<br>
<br>
'''Windows Client:''' <br>
'''Windows Client:''' <br>
* Windows 11: Home, Pro, Enterprise A)
* Windows 11: Home, Pro, Enterprise (Version 25H2)
* Windows 10: Home, Pro, Enterprise (version 20H2)
* Windows 10: Home, Pro, Enterprise (Version 22H2)
* Windows 8.1: Enterprise
'''Plug-ins:''' <br>
* Windows 8: Enterprise<br>
Please refer to the supported platforms and applications of the respective plug-ins in the
<br>
'''Notes:''' <br>
A) UEFI firmware is mandatory.<br>
<br>
'''Plugins:''' <br>
Please refer to the release notes for the supported platforms and applications of the respective plug-ins:
[https://drive.terracloud.de/getlink/fiLpZboTGRPeqzW1cqwS6yin Agent Doku/Release Notes]'''
[https://drive.terracloud.de/getlink/fiLpZboTGRPeqzW1cqwS6yin Agent Doku/Release Notes]'''
==== Linux Agent ====
==== Linux Agent ====


*CentOS 7 (up to Update 9) A)
* Debian 13 (up to Update 2)
*Debian 12
* Debian 12 (up to Update 12)
*Debian 11 (up to Update 7)
* Debian 11 (up to Update 11)
*Debian 10 (up to Update 13)
* Debian 10 (up to Update 13)
*openSUSE Linux 15 (up to Service Pack 5) B)
* openSUSE Linux 16 (up to Service Pack 0) <b>A) B)</b>
*Oracle Linux 9 (up to Update 2)
* openSUSE Linux 15 (up to Service Pack 6) <b>A) B)</b>
*Oracle Linux 8 (up to Update 8)
* Oracle Linux 10 (up to Update 1)
*Oracle Linux 7 (up to Update 9)
* Oracle Linux 9 (up to Update 7)
*Rocky Linux 9 (up to Update 2)
* Oracle Linux 8 (up to Update 10)
*Rocky Linux 8 (up to Update 8)
* Oracle Linux 7 (up to Update 9)
*Red Hat Enterprise Linux Server 9 (up to Update 2)
* Red Hat Enterprise Linux Server 10 (up to Update 1)
*Red Hat Enterprise Linux Server 8 (up to Update 8)
* Red Hat Enterprise Linux Server 9 (up to Update 7)
*Red Hat Enterprise Linux Server 7 (up to Update 9)
* Red Hat Enterprise Linux Server 8 (up to Update 10)
*SUSE Linux Enterprise Server 15 (up to Service Pack 5) B)
* Red Hat Enterprise Linux Server 7 (up to Update 9)
*SUSE Linux Enterprise Server 12 (up to Service Pack 5) B), C)
* Rocky Linux 10 (up to Update 1)
*Ubuntu Server 22.04
* Rocky Linux 9 (up to Update 7)
*Ubuntu Server 20.04
* Rocky Linux 8 (up to Update 10)
*Ubuntu Server 18.04
* SUSE Linux Enterprise Server 16 (up to Service Pack 0) <b>A)</b>
*Ubuntu Server 16.04<br>
* SUSE Linux Enterprise Server 15 (up to Service Pack 7) <b>A)</b>
* SUSE Linux Enterprise Server 12 (up to Service Pack 5) <b>A)</b>
* Ubuntu Server 24.04
* Ubuntu Server 22.04
* Ubuntu Server 20.04
* Ubuntu Server 18.04
<br>
<br>
'''Notes:''' <br>
'''Notes:''' <br>
A) The Linux agent will be supported on CentOS 7 until end of support on June 30, 2024. <br>
Since CentOS Stream is a pre-release version of RHEL and does not have long-term stable releases, the Linux agent on CentOS Stream is not supported. <br>
Because CentOS Stream is a pre-release version of RHEL and does not have long-term, stable releases, the Linux agent is not supported on CentOS Stream. <br>
<br>
B) This platform is not supported when using the standard BTRFS file system. <br>
<b>A)</b> This platform is not supported when the BTRFS file system is used. <br>
A) The agent is supported on this platform, but BMR backups are only supported for BIOS-based systems (not for UEFI-based systems). <br>
<b>B)</b> The Agent is supported on this platform, but BMR backups are not supported for an openSUSE 16.0 UEFI or openSUSE 15.6 UEFI system with a FAT16 EFI boot partition. <br>
<br>
<br>
'''Supported file systems on Linux:'''
'''Supported file systems on Linux:'''
Zeile 284: Zeile 301:
<br>
<br>
<span id="Unterstützte_Agentenversionen"></span>
<span id="Unterstützte_Agentenversionen"></span>
=== Supported Agent Versions ===
== Supported Agent Versions ==


For Windows, Hyper-V and vSphere agents, the following agent versions must be used from February 26, 2024. Other agent versions can no longer be used for backups and restores. There are no specific minimum requirements for Linux agents. <br>
{| class="wikitable"
{| class="wikitable" style="margin:left"
|+ style="text-align:left;"| Windows Agent
|-
|-
! Operating system !! Agent version x86!! Agent version x64!! Notice
! colspan="4" style="background-color:#7d5cab;color:#ffffff;" | '''Windows Agent'''
|-
|-
| Windows Server 2003 || 7.34.4009a || 7.34.4009a || EOL
! style="background-color:#7d5cab;color:#ffffff;" | '''Operating system'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Agent version x86'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Agent version x64'''
! style="background-color:#7d5cab;color:#ffffff;" | '''A notice'''
|-
|-
| Windows Server 2008 + R2 || 9.10.1013 || 9.30.1009 || EOL
| style="background-color:#ffffff;" | Windows Server 2003
| style="background-color:#ffffff;" | 7.34.4009a
| style="background-color:#ffffff;" | 7.34.4009a
| style="background-color:#ffffff;" | EOL
|-
|-
| Windows Server 2012 + R2 || - || 9.30.1009 || EOL
| style="background-color:#ffffff;" | Windows Server 2008 + R2
| style="background-color:#ffffff;" | 9.10.1013
| style="background-color:#ffffff;" | 9.30.1009
| style="background-color:#ffffff;" | EOL
|-
|-
| Windows Server 2016 || - || 9.30.1009 || -
| style="background-color:#ffffff;" | Windows Server 2012 + R2
| style="background-color:#ffffff;" | -
| style="background-color:#ffffff;" | 9.30.1009
| style="background-color:#ffffff;" | EOL
|-
|-
| Windows Server 2019 || - || 9.30.1009 || -
| style="background-color:#ffffff;" | Windows Server 2016
| style="background-color:#ffffff;" | -
| style="background-color:#ffffff;" | 9.50.6732
| style="background-color:#ffffff;" | -
|-
|-
| Windows Server 2022 || - || 9.30.1009 || -
| style="background-color:#ffffff;" | Windows Server 2019
| style="background-color:#ffffff;" | -
| style="background-color:#ffffff;" | 9.50.6732
| style="background-color:#ffffff;" | -
|-
|-
| Windows 7 || 9.10.1013 || 9.30.1009 || EOL
| style="background-color:#ffffff;" | Windows Server 2022
| style="background-color:#ffffff;" | -
| style="background-color:#ffffff;" | 9.50.6732
| style="background-color:#ffffff;" | -
|-
|-
| Windows 8 + 8.1 || 9.10.1013 || 9.30.1009 || EOL
| style="background-color:#ffffff;" | Windows Server 2025
| style="background-color:#ffffff;" | -
| style="background-color:#ffffff;" | 9.50.6732
| style="background-color:#ffffff;" | -
|-
|-
| Windows 10 || 9.10.1013 || 9.30.1009 || -
| style="background-color:#ffffff;" | Windows 7
| style="background-color:#ffffff;" | 9.10.1013
| style="background-color:#ffffff;" | 9.30.1009
| style="background-color:#ffffff;" | EOL
|-
|-
| Windows 11 || - || 9.30.1009 || -
| style="background-color:#ffffff;" | Windows 8 + 8.1
|}
| style="background-color:#ffffff;" | 9.10.1013
<span style="color:red"> Any operating system marked "EOL" can still be backed up with the appropriate agent version. However, neither Microsoft nor our software publisher offers support for these platforms. We would like to point out that TERRA CLOUD can only provide “best effort support”. In the event of an error, we cannot rely on the software manufacturer. It is strongly recommended that you keep operating systems up to date. If an update is not possible, periodic test restores should be performed. </span>
| style="background-color:#ffffff;" | 9.30.1009
{| class="wikitable" style="margin:left"
| style="background-color:#ffffff;" | EOL
|+ style="text-align:left;"| Hyper-V Agent
|-
|-
! Operating system !! Agent version x86!! Agent version x64!! Notice
| style="background-color:#ffffff;" | Windows 10
| style="background-color:#ffffff;" | 9.10.1013
| style="background-color:#ffffff;" | 9.50.6732
| style="background-color:#ffffff;" | -
|-
|-
| Windows Server >= 2012 R2 || - || 9.12.1002 || -
| style="background-color:#ffffff;" | Windows 11
| style="background-color:#ffffff;" | -
| style="background-color:#ffffff;" | 9.50.6732
| style="background-color:#ffffff;" | -
|}
|}
{| class="wikitable" style="margin:left"
<span style="color:red">Any operating system marked "EOL" can still be backed up using the corresponding agent version. However, neither Microsoft nor our software vendor offers support for these platforms. Please note that TERRA CLOUD can only provide "best-effort support." In the event of an error, we cannot rely on the software manufacturer for assistance.<br>
|+ style="text-align:left;"| vSphere Agent
It is strongly recommended to keep operating systems up to date. If an update is not possible, regular test restores should be performed.</span>
<br>
{| class="wikitable"
|-
|-
! Operating system !! Agent version x86!! Agent version x64!! Notice
! colspan="4" style="background-color:#7d5cab;color:#ffffff;" | '''Hyper-V Agent'''
|-
|-
| Windows Server >= 2012 R2 || - || 9.20.1008 || -
! style="background-color:#7d5cab;color:#ffffff;" | '''Operating System'''
|}
! style="background-color:#7d5cab;color:#ffffff;" | '''Agent Version x86'''
{| class="wikitable" style="margin:left"
! style="background-color:#7d5cab;color:#ffffff;" | '''Agent Version x64'''
|+ style="text-align:left;"| Linux agent
! style="background-color:#7d5cab;color:#ffffff;" | '''Note'''
|-
! Operating system !! Agent version x86!! Agent version x64!! Notice
|-
|-
| Supported Linux distributions || 8.90.1020 || 9.21.1002 || See [https://drive.terracloud.de/getlink/fiAcFX7NCczxs4pZD7Ua9krA/EN%20%28recommended%29 Release Notes] for supported Linux distributions
| style="background-color:#ffffff;" | Windows Server >= 2012 R2
| style="background-color:#ffffff;" | -
| style="background-color:#ffffff;" | 9.40.1009
| style="background-color:#ffffff;" | -
|}
|}
<span id="Netzwerkkonfiguration"></span>
<br>
=== Network configuration ===
{| class="wikitable"
 
{| class="wikitable" style="margin:left"
|+ style="text-align:left;"| Port overview TERRA CLOUD Backup
|-
|-
! Protocol !! Port!! Source !! Goal !! Function !! Notice
! colspan="4" style="background-color:#7d5cab;color:#ffffff;" | '''vSphere Agent'''
|-
|-
| TCP || 443 || agent || Portal || Automatic agent updates || <span style="color:red"> OLD 185.35.12.130 (until February 26, 2024) </span> / <span style="color:green"> NEW 185.35.13.210 (from February 26, 2024) </span>
! style="background-color:#7d5cab;color:#ffffff;" | '''Operating System'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Agent Version x86'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Agent Version x64'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Note'''
|-
|-
| TCP || 2546 || agent || Vault || Connection to the Vault for data backup, synchronization and restore || Secondary Vault also needs to be released. See Backup Portal -> Quick Links -> Vault Finder
| style="background-color:#ffffff;" | Windows Server from 2012 R2 to 2022
| style="background-color:#ffffff;" | -
| style="background-color:#ffffff;" | 9.22.1011
| style="background-color:#ffffff;" | -
|}
<br>
{| class="wikitable"
|-
! colspan="4" style="background-color:#7d5cab;color:#ffffff;" | '''Linux Agent'''
|-
|-
| TCP || 8086 || agent || Portal || Registration of an agent on the portal || <span style="color:red"> OLD 185.35.12.130 (until February 26, 2024) </span> / <span style="color:green"> NEW 185.35.13.210 (from February 26, 2024) </span>
! style="background-color:#7d5cab;color:#ffffff;" | '''Operating system'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Agent version x86'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Agent version x64'''
! style="background-color:#7d5cab;color:#ffffff;" | '''A notice'''
|-
|-
| TCP || 8087 || agent || AMP || Management of agents via the portal || <span style="color:red"> OLD 185.35.12.160/27 (until February 26th, 2024) </span> / <span style="color:green"> NEW 195.4.212.128/25 (from February 26th, 2024) < /span>
| style="background-color:#ffffff;" | Supported Linux distributions
| style="background-color:#ffffff;" | 8.90.1020
| style="background-color:#ffffff;" | 9.41.1020
| style="background-color:#ffffff;" |See [https://drive.terracloud.de/getlink/fiAcFX7NCczxs4pZD7Ua9krA/EN%20%28recommended%29 Release Notes] for supported Linux distributions
|}
|}
{| class="wikitable" style="margin:left"
<span id="Netzwerkkonfiguration"></span>
|+ style="text-align:left;"| Port overview TERRA CLOUD Hybrid Backup
== Network configuration ==
 
{| class="wikitable"
|-
! colspan="6" style="background-color:#7d5cab;color:#ffffff;" | '''Port overview TERRA CLOUD Backup'''
|-
! style="background-color:#7d5cab;color:#ffffff;" | '''Protocol'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Port'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Source'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Goal'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Function'''
! style="background-color:#7d5cab;color:#ffffff;" | '''A notice'''
|-
| style="background-color:#ffffff;" | TCP
| style="background-color:#ffffff;" | 443
| style="background-color:#ffffff;" | Agent
| style="background-color:#ffffff;" | Portal
| style="background-color:#ffffff;" | Automatic agent updates
| style="background-color:#ffffff;" | 185.35.13.210/32
|-
| style="background-color:#ffffff;" | TCP
| style="background-color:#ffffff;" | 2546
| style="background-color:#ffffff;" | Agent
| style="background-color:#ffffff;" | Vault
| style="background-color:#ffffff;" | Connection to the Vault for data backup, synchronization and restore
| style="background-color:#ffffff;" | '''*'''
|-
| style="background-color:#ffffff;" | TCP
| style="background-color:#ffffff;" | 8086
| style="background-color:#ffffff;" | Agent
| style="background-color:#ffffff;" | Portal
| style="background-color:#ffffff;" | Registering an agent on the portal
| style="background-color:#ffffff;" | 185.35.13.210/32
|-
| style="background-color:#ffffff;" | TCP
| style="background-color:#ffffff;" | 8087
| style="background-color:#ffffff;" | Agent
| style="background-color:#ffffff;" | AMP
| style="background-color:#ffffff;" | Management of agents via the portal
| style="background-color:#ffffff;" | 195.4.212.128/25
|}
<br>
{| class="wikitable"
|-
! colspan="6" style="background-color:#7d5cab;color:#ffffff;" | '''Port overview TERRA CLOUD Hybrid Backup'''
|-
|-
! Protocol !! Port!! Source !! Goal !! Function !! Notice
! style="background-color:#7d5cab;color:#ffffff;" | '''Protocol'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Port'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Source'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Goal'''
! style="background-color:#7d5cab;color:#ffffff;" | '''Function'''
! style="background-color:#7d5cab;color:#ffffff;" | '''A notice'''
|-
|-
| UDP || 123 || satellite || Internet || NTP time synchronization || -
| style="background-color:#ffffff;" | UDP
| style="background-color:#ffffff;" | 123
| style="background-color:#ffffff;" | Satellite
| style="background-color:#ffffff;" | Internet
| style="background-color:#ffffff;" | NTP time synchronization
| style="background-color:#ffffff;" | -
|-
|-
| TCP || 443 || satellite || Portal || Interface updates and Support Connect function || -
| style="background-color:#ffffff;" | TCP
| style="background-color:#ffffff;" | 443
| style="background-color:#ffffff;" | Satellite
| style="background-color:#ffffff;" | Portal
| style="background-color:#ffffff;" | Interface updates and Support Connect function
| style="background-color:#ffffff;" | -
|-
|-
| TCP || 2547 || satellite || Basevault || Heartbeat / Management || <span style="color:red"> ALT Satellite Vault Version <= 8.62 </span>
| style="background-color:#ffffff;" | TCP
| style="background-color:#ffffff;" | 2547
| style="background-color:#ffffff;" | Satellite
| style="background-color:#ffffff;" | Basevault
| style="background-color:#ffffff;" | Heartbeat / Management
| style="background-color:#ffffff;" | <span style="color:red">'''OLD Satellite-Vault version <= 8.62'''</span>'''*'''
|-
|-
| TCP || 12546 || satellite || Basevault || Heartbeat / Management || <span style="color:green"> NEW Satellite Vault Version > 8.62 </span>
| style="background-color:#ffffff;" | TCP
| style="background-color:#ffffff;" | 12546
| style="background-color:#ffffff;" | Satellite
| style="background-color:#ffffff;" | Basevault
| style="background-color:#ffffff;" | Heartbeat / Management
| style="background-color:#ffffff;" | <span style="color:green">'''NEW Satellite-Vault version > 8.62'''</span>'''*'''
|-
|-
| TCP || 12547 || satellite || Basevault || Data transfer for replication of data backups || -
| style="background-color:#ffffff;" | TCP
| style="background-color:#ffffff;" | 12547
| style="background-color:#ffffff;" | Satellite
| style="background-color:#ffffff;" | Basevault
| style="background-color:#ffffff;" | Data transfer for backup replication
| style="background-color:#ffffff;" | '''*'''
|}
|}
== '''Vault''' ==
'''* Note:'''<br>
Access must be enabled for both the primary and secondary Vaults using their respective FQDNs and IP addresses.<br>
You can find the public IP address of each Vault via the Vault Finder in the backup portal:<br>
[https://backup.terracloud.de backup.terracloud.de] → Quick Links → Vault-Finder
= '''Vault''' =


A vault is a virtual system that is operated in the TERRA CLOUD or a partner data center. <br>
A vault is a virtual system that is operated in the TERRA CLOUD or a partner data center. <br>
This system communicates with the backup agents and receives backups and stores them according to the defined retention periods. <br>
This system communicates with the backup agents and receives backups and stores them according to the defined retention periods. <br>
Backup packages include access to a shared backup platform in the form of a Vault account.
Backup packages include access to a shared backup platform in the form of a Vault account.
=== Vault-Account ===
== Vault-Account ==


The Vault account is a unique organizational unit on a Vault system; it is required for the authentication of a backup agent on the Vault.
A Vault Account is a unique organizational unit on a Vault system; it is required for authenticating a Backup Agent with the Vault.<br>
The name of the vault account is made up of your customer number at Wortmann AG and the name of your end customer in the TERRA CLOUD Center in capital letters.<br>
The Vault Account name is composed of your customer number at Wortmann AG and the name of your end customer in the TERRA CLOUD Center, written in capital letters.<br>
<br>
'''Example:'''<br>
12345-ENDKUNDEXY<br>
<br>
<br>
'''Example:'''
You require the Vault Account—for instance, when creating a new Vault Profile—so that the Agent can use the data from the profile to authenticate itself with the Vault system.<br>
12345-ENDKUNDEXY
The Vault Account is entered into the "Account" and "Username" fields.
You need the Vault account, for example when you create a new Vault profile, so that the agent can use the data from the profile to authenticate itself to the Vault system.
[[Datei:Ausschnitt aus dem Vault-profil.png|ohne]]<br>
The Vault account is stored for the “Account” and “Username” fields.
[[File:Ausschnitt aus dem Vault-profil.png|ohne]]<br>
<span id="Ablauf_des_Handshakes_zwischen_Agent_und_Vaultsystem"></span>
=== Process of the handshake between agent and vault system ===
 
Currently, the connection setup between an agent and its vault during a backup looks like this:
*The agent creates an encrypted tunnel to the vault and checks the public key of the TLS certificate.
*The Vault checks the agent's so-called Unique Identifier and approves the backup if there is a match.
*The agent then performs the backup and transmits the encrypted data via the previously opened tunnel.
On February 26th, 2024 we will make an adjustment to our vault systems so that the process will proceed as follows in the future:
*The agent creates an encrypted tunnel to the vault and checks the public key of the TLS certificate.
*The vault (also known as the primary vault) checks the agent's unique identifier and delegates it to its replication partner (also known as the secondary vault) if there is a match.
*The agent then checks whether a connection can also be established to the secondary vault.
*After the verification is complete, the secondary vault delegates the agent back to the primary vault to initiate the backup.
*The agent performs the backup and transmits the encrypted data via the previously opened tunnel.
These adjustments enable smooth pivoting between the primary and secondary vault, for example during an outage. In addition, a software check ensures that the agent can restore from the secondary vault in case of doubt or to improve performance. <br>
Please note that starting February 26, 2024, backups will be completed with warnings if there is no connectivity to the replication partner: <br>
[https://wiki.terracloud.de/index.php/Backup_Fehlerdiagnose/en#RSYN-W-07716_Failed_to_connect_to_or_negotiate_backup_with_alternate_vault ''RSYN-W-07716 Failed to connect to or negotiate backup with alternate vault''] <br>
Therefore, you should ensure that all your agents can reach the secondary vault via TCP port 2546 by February 26, 2024. <br>
To find out the address / IP of the secondary vault, you can use the Vault Finder from the quick links in the Backup Portal: <br>
[[File:Vault-Finder.png]]<br>
 
<span id="Allgemein"></span>
<span id="Allgemein"></span>
== '''General''' ==
= '''General''' =


<span id="Aufbewahrungsfristen"></span>
<span id="Aufbewahrungsfristen"></span>
=== Retention periods ===
== Retention periods ==


TERRA CLOUD Backup offers you a data backup retention period of up to 365 days in the Standard license model. <br>
TERRA CLOUD Backup offers you a data backup retention period of up to 365 days in the Standard license model. <br>
The retention period of a data backup on the Vault is determined by the selected retention type. <br>
The retention period of a data backup on the Vault is determined by the selected retention type. <br>
<span id="Aufbewahrungstypen"></span>
<span id="Aufbewahrungstypen"></span>
==== Retention Types ====
=== Retention Types ===


A retention type consists of two parameters that determine the retention time of a data backup.<br>
A retention type consists of two parameters that determine the retention time of a data backup.<br>
Zeile 423: Zeile 546:
The safeset must therefore be at least the defined X days old '''AND''' there must be at least Y data backups for the backup job.
The safeset must therefore be at least the defined X days old '''AND''' there must be at least Y data backups for the backup job.
<span id="Standardaufbewahrungstypen"></span>
<span id="Standardaufbewahrungstypen"></span>
===== Preconfigured retention types =====
==== Preconfigured retention types ====


The following retention types are already predefined and are automatically created when the agents are installed. <br>
The following retention types are pre-configured and automatically created during agent installation.<br>
Please note that 50 safe sets are included free of charge per backup job; additional safety points can be provided for an additional charge. <br>
Please note that 50 safesets are included free of charge per backup job; additional backup points can be added for an extra charge. <br>
<br>
<br>
'''Note:'''<br>
'''Note:'''<br>
From April 1st, 2024, 50 safe sets can be configured free of charge per backup job.<br>
Starting April 1, 2024, 50 safesets can be configured free of charge per backup job.<br>
<br>
'''24-Hours(hourly backup):'''<br>
This retention type is automatically created by an Intraday schedule and cannot be edited.<br>
It is required for the function [[Backup#TERRA_CLOUD_BACKUP_Enterprise:_High_Frequent_Backup_-_St%C3%BCndliche_Sicherungen|High Frequent Backup]].<br>
The data backups are kept for a maximum of 24 hours.<br>
<br>
<br>
'''48-Hours(hourly backup):'''<br>
'''24-Hour (Hourly Backup):'''<br>
This retention type is automatically created by an Intraday schedule and cannot be edited.<br>
This retention type is automatically created by a "Sub-Day" schedule and cannot be edited.<br>
It is required for the function [[Backup#TERRA_CLOUD_BACKUP_Enterprise:_High_Frequent_Backup_-_St%C3%BCndliche_Sicherungen|High Frequent Backup]].<br>
It is required for the function [https://wiki.terracloud.de/index.php/Backup/en#TERRA_CLOUD_BACKUP_Enterprise:_High_Frequent_Backup_-_Hourly_backups High Frequent Backup].<br>
The data backups are kept for a maximum of 48 hours.<br>
Backups are retained for a maximum of 24 hours.<br>
'''48-Hour (Hourly Backup):'''<br>
This retention type is automatically created by a "Sub-Day" schedule and cannot be edited.<br>
It is required for the function [https://wiki.terracloud.de/index.php/Backup/en#TERRA_CLOUD_BACKUP_Enterprise:_High_Frequent_Backup_-_Hourly_backups High Frequent Backup].<br>
Backups are retained for a maximum of 48 hours.<br>
<br>
<br>
'''Daily(daily backup):'''<br>
'''Daily (daily backup):'''<br>
This retention type is suitable for '''one backup per day'''.<br>
This retention type is suitable for '''one backup per day'''.<br>
In total, the data backups are retained for 30 days each and there must be at least 30 data backups in the job.<br>
Backups are retained for a total of 30 days each, and the job must contain at least 30 backups.<br>
<br>
<br>
'''4xDaily(four daily backups):'''<br>
'''4xDaily (four daily backups):'''<br>
This retention type is suitable for '''four backups per day'''.<br>
This retention type is suitable for '''four backups per day'''.<br>
In total, the data backups are kept for 10 days each and there must be at least 40 data backups in the job.<br>
Backups are retained for a total of 10 days each, and the job must contain at least 40 backups.<br>
<br>
<br>
'''Monthly(monthly backup):'''<br>
'''Monthly (monthly backups):'''<br>
This retention type is suitable for '''one backup per month'''. <br>
This retention type is suitable for '''one backup per month'''. <br>
In total, the data backups are kept for 365 days and there must be at least 12 data backups in the job.<br>
The backups are retained for a total of 365 days each, and there must be at least 12 backups in the job.<br>
<br>
<br>
 
'''Yearly (annual backup):'''<br>
This retention type is suitable for '''one backup per year''' and must be used for [https://wiki.terracloud.de/index.php/Backup/en#TERRA_CLOUD_BACKUP_Enterprise:_10_years_retention Retention of backups for 10 years].<br>
The backups are retained for a total of 3653 days each, and there must be at least 10 backups in the job.<br>
<span id="Ehemalige_Standardaufbewahrungstypen"></span>
<span id="Ehemalige_Standardaufbewahrungstypen"></span>
===== Former default retention types =====
==== Former default retention types ====


The following standard retention types have been used in the past for TERRA CLOUD backup and may still be stored on the systems:<br>
The following standard retention types have been used in the past for TERRA CLOUD backup and may still be stored on the systems:<br>
Zeile 466: Zeile 590:
This retention type is suitable for '''one backups per week'''.<br>
This retention type is suitable for '''one backups per week'''.<br>
In total, the data backups are kept for 31 days each and there must be at least 5 data backups in the job.<br>
In total, the data backups are kept for 31 days each and there must be at least 5 data backups in the job.<br>
<br>
<span id="Individuelle_Aufbewahrungstypen_erstellen"></span>
<span id="Individuelle_Aufbewahrungstypen_erstellen"></span>
===== Create individual retention types =====
==== Create individual retention types ====


If you do not want to use or add to the standard retention types, you have the option of defining your own retention types using the agent's advanced settings:
If you do not want to use or add to the standard retention types, you have the option of defining your own retention types using the agent's advanced settings:
[[File:Individuelle Aufbewahrungstypen.png|1200px|ohne]]
[[File:Individuelle Aufbewahrungstypen.png|1200px|ohne]]
<br>
<span id="Verbrauchswerte_für_die_Lizenzierung"></span>
== Consumption values for licensing ==


<span id="Archivfunktion"></span>
The consumption values of a TERRA CLOUD backup account consist of:
===== Archive function =====
* Natively protected data set of backup jobs
 
'''Archive function:''' <br>
The archive function of the TERRA CLOUD backup is based on the Yearly retention type and archives one data backup per year for a period of ten years.<br>
In the retention day calculation, three additional days were added to compensate for up to three leap years in the ten years. <br>
Here you will find a [[Backup#TERRA_CLOUD_BACKUP_Enterprise:_Archive function_-_10_years_storage|Example]] for a schedule with an active archive function.
 
'''Note:'''<br>
Please note that this function can only be used with the TERRA CLOUD Backup Enterprise product.<br>
Bare metal restores are only supported for backups up to 365 days old. <br>
<br>
'''Yearly:'''<br>
This retention type is suitable for '''one backup per year'''.<br>
In total, the data backups are kept for 3653 days and there must be at least 10 data backups in the job.<br>
 
<span id="Verbrauchswerte_für_die_Lizenzierung"></span>
=== Consumption values for licensing ===
 
The consumption values of a TERRA CLOUD backup account consist of:
* Natively protected data set of backup jobs
* Number of protected systems
* Number of protected systems
* Number of active safesets of the backup jobs
* Number of active safesets of the backup jobs
<br>
On the 15th calendar day of a month, the above-mentioned consumption values are determined and made available to you in the form of the [https://wiki.terracloud.de/index.php/Backup/en#Consumption_Reports consumption report] on the 16th calendar day. <br>
On the 15th calendar day of a month, the above-mentioned consumption values are determined and made available to you in the form of the [https://wiki.terracloud.de/index.php/Backup/en#Consumption_Reports consumption report] on the 16th calendar day. <br>
<span id="Verbrauchswerte_der_aktiven_Safesets"></span>
<span id="Verbrauchswerte_der_aktiven_Safesets"></span>
==== Consumption values of the active safe sets ====
=== Consumption values of the active safe sets ===


50 active safe sets are included in the inclusive quota per backup job and can be distributed depending on the [[https://wiki.terracloud.de/index.php/Backup/en#Retention_periods|retention scheme]] and [[https://wiki.terracloud.de/index.php/Backup/en#Schedule_Recommendations|Schedule configuration]]. <br>
50 active safe sets are included in the inclusive quota per backup job and can be distributed depending on the [https://wiki.terracloud.de/index.php/Backup/en#Retention_periods retention scheme] and [https://wiki.terracloud.de/index.php/Backup/en#Schedule_Recommendations Schedule configuration]. <br>
In order for a safeset to be considered expired and to be deleted, the retention parameters “Online storage (days)” and “Online copies” must be exceeded. <br>
In order for a safeset to be considered expired and to be deleted, the retention parameters “Online storage (days)” and “Online copies” must be exceeded. <br>
This can result in more than 50 safesets being present in the vault at the time of consumption measurement because expired backups have not yet been removed from the vault. <br>
This can result in more than 50 safesets being present in the vault at the time of consumption measurement because expired backups have not yet been removed from the vault. <br>
The TERRA CLOUD backup license model therefore includes a free buffer zone of 10 safe sets. <br>
The TERRA CLOUD backup license model therefore includes a free buffer zone of 10 safe sets. <br>
If 61 or more safe sets are used, all safe sets above the '''inclusive quota''' will be invoiced. <br>
If 61 or more safe sets are used, all safe sets above the '''inclusive quota''' will be invoiced. <br>
<br>
{| class="wikitable"
{| class="wikitable"
|+ Safeset consumption zones
|+ Safeset consumption zones
Zeile 520: Zeile 622:
| Additional consumption || 61 - ∞ Safe sets
| Additional consumption || 61 - ∞ Safe sets
|}
|}
== '''Portal''' ==
= '''Portal''' =


The configuration is carried out as an example as documented in the following sections. The administrator account “backupadmin@terracloud.de” was used for this configuration.<br>
The configuration is carried out as an example as documented in the following sections. The administrator account “backupadmin@terracloud.de” was used for this configuration.<br>
This corresponds to your specialist dealer administrator account (backup master account).  
This corresponds to your specialist dealer administrator account (backup master account).  
<span id="Aufbau_TERRA_CLOUD_Backup_Portal"></span>
<span id="Aufbau_TERRA_CLOUD_Backup_Portal"></span>
=== Structure of TERRA CLOUD Backup Portal ===
== Structure of TERRA CLOUD Backup Portal ==


[[File:Aufbau-backup-portal.jpg|ohne]]<br>
[[Datei:Aufbau-backup-portal.jpg|ohne]]
<br>
'''Description:''' <br>
'''Description:''' <br>
This diagram shows the structure of the backup portal.
This diagram shows the structure of the Backup Portal.
The upper level consists of the parent site, which you can recognize by its name consisting of your Wortmann AG customer number and the name of your company.
The upper level consists of the parent site, which you can recognize by its name consisting of your Wortmann AG customer number and your company name.
You can use this level to administer (child) sites and use all functions of the portal centrally. You can create users for both levels, these are stored in the diagram in <span style="color: green"> green </span style="color: green"> for the parent site and in <span style="color: blue"> blue </span style="color: green"> for the end customers' sites.
Through this level, you can administer (child) sites and centrally access all portal functions. You can create users for both levels; these are shown in the diagram in <span style="color: green"> green </span style="color: green"> for the parent site and in <span style="color: blue"> blue </span style="color: green"> for the end customer sites.
Please create your own site for your company, as marked with the NFR site in the diagram. <br>
Please create a separate site for your company, as indicated in the diagram with the NFR site. <br>
You can then move the agents for your systems into this site or register them directly into it via a user within the site. <br>
You can then move the agents for your systems to this site or register them directly via a user within the site. <br>
<br>
<br>
'''Note:'''<br>
'''Note:'''<br>
<pre style="color: red"> Please only register agents in the parent site if they will then be moved to the associated customer site for further configuration. </pre style="color: red">
<span style="color: red"> Please only register agents in the parent site if they will subsequently be moved to the associated customer site for further configuration.</span style="color: red">
<span id="Site_anlegen"></span>
== Site ==  
=== Create site ===


A site is a sub-area within your portal to separate and manage a group of computers to be secured. <br>
A "Site" is an administrative area within the TERRA CLOUD Backup Portal that represents an end-customer organization.<br>
Subsites ensure the clear separation of agents and backups from different customers.
Sites enable the separation of your tenants and simplify the management of backed-up systems.<br>
As soon as you book a backup package for a customer, we automatically create a (child) site for you, along with a registration user.<br>
This user can be used exclusively to register new agents with the backup portal; logging into the backup portal itself is not possible with these credentials.<br>
You can find the access details for this registration user under the "Users" tab within the respective site.<br>
<span id="Site_manuell_anlegen"></span>
=== Manually create site ===
 
Should you ever need to create a site manually, you will find a button for this under the "Sites" tab.<br>
This launches the site creation wizard.<br>
<br>
<br>
Click Sites in the navigation bar, then click Create New Site. <br>
[[Datei:Neue Site erstellen.png|1500px]] <br>
[[File:Subsite anlegen.png|border|Create site]]<br>
<br>
<br>
Now give the site a name.
<span id="Site-Name_vergeben"></span>
A useful name is the name of the end customer, which can be combined with a customer number assigned by you, e.g. 12345-End Customer.<br>
==== Site name assigned ====
Optionally, you can configure the customer number and contact addresses for the site. Then click “Save Site”. <br>
 
[[File:Site Informationen.png|border|Enter Site Information]] <br>
The first step is to assign a name to the new site.<br>
We recommend, for example, combining your customer's name with their customer number from your ERP system (12345-EndCustomer).<br>
Then click "Next".<br>
<br>
[[Datei: Backup-DE-Neue_Site_erstellen-1.png]] <br>
<br>
<br>
Now give the site a name. A useful name here would be the name of the end customer. <br>
Optionally, you can configure the customer number and contact addresses for the site. Then click “Save Site”. <br>
<span id="Benutzer_anlegen"></span>
<span id="Benutzer_anlegen"></span>
==== Create user ====
==== Create user ====


You can create different users for your end customer's site.
Optionally, you can then create an additional user with admin rights for the customer's site; this user will also be able to log in to the backup portal.<br>
If you specify a user with the role "User" or "Administrator" instead of your parent site administrator when registering the agent, the agent will be registered in the end customer site.<br>
<br>
<br>
'''Note:'''<br>
'''Note:'''<br>
Further information about the different user roles can be found in the [[Backup/en#Authorization_concept|Authorization Concept]].
You can find further information on the various user roles in the permissions concept. The screenshot below shows the configuration for a user with the "Admin" role.<br>
In the following screenshot you can see the configuration of a user with the "User" role. <br>
Please note that you must assign agents to users who do not have the "Admin" user role. <br>
Please note that you can still [[Backup/en#Assign_agents_to_users|Assign Agents to Users]] to users who do not have the "Administrator" user role<br>
<br>
[[File:User anlegen1.png|Create User|900px]] <br>
[[Datei: Backup-DE-Neue_Site_erstellen-2.png]] <br>
<span id="Benachrichtigungen_konfigurieren"></span>
<br>
==== Configure notifications ====
<span id="Vault-Profil"></span>
==== Vault Profile ====


You can configure email notification for the site using the “Notifications” tab. <br>
Once a TERRA CLOUD Backup package has been provisioned, you will receive the access credentials for your tenant's vault account.<br>
The address on file will be notified as soon as the selected events occur. <br>
These credentials are required for authentication between the agents and the vault (storage destination). <br>
[[File:Mailbenachrichtigung-neu2.png|ohne|900px]] <br>
These credentials must be saved into a vault profile within the wizard. <br>
<br>
Vault Name: <br>
The vault name is the display name for the vault profile. <br>
Recommendation: <br>
For simplicity, we recommend using the vault's FQDN (e.g., vault-wmh2-P001.terracloud.de) as the vault name. <br>
The chosen vault name serves only as a label and has no technical function. <br>
<br>
Address: <br>
Enter the vault's FQDN here (e.g., vault-wmh1-P001.terracloud.de). <br>
Account: <br>
Enter the provided vault account (e.g., 45814-ENDKUNDE). <br>
<br>
<br>
<font color="red">Please note that the portal-side email notification is currently not yet available for all agents. See [https://wiki.terracloud.de/index.php/Backup/en#Function_overview function overview]</font><br>
Username: <br>
Enter the provided vault account here as well (e.g., 45814-ENDKUNDE). <br>
The account and username have been set up identically to simplify the setup process. <br>
<br>
<br>
'''Encryption password changed' option: <br>'''
Password: <br>
This can, for example, warn you in the event of unauthorized access if an attacker wants to gain access to future backups by changing the encryption password. <br>
Enter the provided password; this vault password is used to authenticate the vault account and is not used to encrypt user data. <br>
The encryption password cannot be changed retroactively for existing safesets.<br>
<br>
<br>
'''Note:'''<br>
[[Datei: Backup-DE-Neue_Site_erstellen-3.png]] <br>
The change in the encryption password is also reflected in the "Status Feed". <br>
<br>
<br>
'''The basic configuration for your first end customer site is now complete.''' <br>
<span id="Automatische_Agent-Konfiguration"></span>
<br />
==== Automatic Agent Configuration ====
<span id="Vault-Profile_konfigurieren"></span>
==== Configure Vault Profiles ====


After providing a TERRA CLOUD backup package, you will receive the access data for the vault account for your tenant.
Finally, you have the option to enable automatic agent configuration so that new agents are configured automatically. <br>
The credentials are required for authentication between the agents and the vault (storage target). <br>
You can save the credentials in a Vault profile, e.g. For example, you don't have to enter it manually when registering an agent with the Vault.
Please click "Add New" to create a Vault profile.<br>
[[File:Vault konfigurieren.png|border|Add Vault]]<br>
<br>
<br>
'''Vault name:'''<br>
Prerequisites: <br>
The Vault Name is the displayed name of the Vault profile.
To have a backup job created fully automatically, an encryption password must be defined.<br>
Recommendation: To simplify matters, we recommend the FQDN of the vault (e.g. vault-wmh2-P001.terracloud.de).
With automatic agent configuration, the encryption password is passed as the default encryption password during the installation process itself. <br>
The chosen vault name has no technical function, but only serves as a designation. <br>
<br>
<br>
'''Address:'''<br>
Please select a vault profile and a job template. <br>
Please enter the FQDN of the vault (e.g. vault-wmh1-P001.terracloud.de).<br>
If you are logged in as a parent site user, you can choose from all the job templates you have previously created and saved at other (child) sites. <br>
<br>
<br>
'''Account:'''<br>
[[Datei: Backup-DE-Neue_Site_erstellen-4.png]] <br>
Please enter the submitted Vault account (e.g. 45814-ENDCUSTOMER).<br>
<br>
<br>
'''Username:'''<br>
<span id="Zusammenfassung"></span>
Please also enter the submitted Vault account (e.g. 45814-ENDCUSTOMER). <br>
==== Summary ====
The account and user name have been created identically to simplify setup.<br>
 
In the final step, you will receive a summary of the information entered. <br>
<br>
<br>
'''Password:'''<br>
[[Datei: Backup-DE-Neue_Site_erstellen-5.png]] <br>
Please enter the submitted password. This Vault password is used to authenticate the Vault account and is not used to encrypt user data.
Create the Vault profile via "OK".<br>
[[File:Vault Authentifizierung.png|border|Vault Settings]]<br>
<br>
<br>
The saved Vault profile should then be visible. <br>
<span id="Benachrichtigung_konfigurieren"></span>
[[File:Vault sichtbar.png|border|Visible Vault]] <br>
==== Configure notification ====


<span id="Automatische_Agent-Konfiguration"></span>
You can subsequently configure email notifications for the site via the "Notifications" tab. <br>
==== Automatic agent configuration ====
The specified address will receive a notification as soon as the selected events occur. <br>
 
[[Datei:Mailbenachrichtigung-neu2.png|ohne|900px]]
To have new agents automatically configured in the portal, please activate the "Automatically configure new agents" option under the "Automatic agent configuration" tab.<br>
<font color="red">Please note that portal-based email notification is currently not available for all agents. See [https://wiki.terracloud.de/index.php/Backup/en#Function_overview Function Overview]</font><br>
<br>
'''"Encryption password changed" option: <br>'''
This can alert you, for example, in the event of unauthorized access—such as when an attacker attempts to gain access to future backups by changing the encryption password. <br>
The encryption password '''cannot''' be changed retroactively for existing safesets.<br>
<br>
<br>
'''Requirements:''' <br>
'''Note:'''<br>
- Agent version 8.90a or newer <br>
Changes to the encryption password are also displayed in the "Status Feed". <br>
- Submission of a default encryption password in the installation process <br>
Please select a Vault profile and a job template. You can either use the already stored best practice template "Entire System Image" or create your own template. <br>
<br>
<br>
'''Default encryption password:''' <br>
'''The basic configuration for the (child) site is now complete.''' <br>
In order to create a backup job completely automatically, an encryption password must be defined.
You can subsequently review all settings made in the site creation wizard within the individual tabs of the respective (child) site and adjust them separately if necessary.<br>
With automatic agent configuration, the encryption password is passed as the default encryption password during the installation process.
[[File:AutoAgentConfig.png|border]]<br>
<br>
<br>
<span id="Eigene_Jobvorlagen_erstellen"></span>
<span id="Weitere_Benutzer_anlegen"></span>
===== Create your own job templates =====
=== Create additional users ===


You can create your own job templates by clicking on the "View" button next to the preset job template and creating an editable copy of the job template.
Just as in the Site Creation Wizard, you can also create additional portal users later from within the site via the "Users" tab.<br>
You can adapt this copy as you wish and, after saving it, use it for automatic agent configuration.
In addition to creating another administrator, you have the option here to select other user roles.<br>
Example for your own job template: <br>
<br>
[[File:Individueller Backup Job.png|framed|ohne]]<br>
'''Note:'''<br>
<span id="Berechtigungskonzept"></span>
You can find further information on the various user roles in the [https://wiki.terracloud.de/index.php/Backup/en#Authorization_concept permissions concept].<br>
=== Authorization concept ===
The following screenshot shows the configuration for a user with the "User" role.<br>
Please note that you can still [https://wiki.terracloud.de/index.php/Backup/en#Assign_agents_to_users assign agents] to users who do '''not''' have the "Administrator" role.<br>
[[Datei:User anlegen1.png|User anlegen|900px]] <br>
<span id="Jobvorlage_für_die_automatische_Agenten-Konfiguration_erstellen"></span>
=== Create job template for automatic agent configuration ===


This diagram shows the four different roles that can be assigned to a user. <br>
You can create your own job templates by opening the "Automatic Agent Configuration" tab for the respective site.<br>
You can create users either within a site or at the reseller level in your parent site; further information can be found in the diagram for the [[Backup/en#Structure_of_TERRA_CLOUD_Backup_Portal|Structure TERRA CLOUD Backup Portal]]
Click "View" next to the existing job template and then create an editable copy of the template.<br>
You can customize this copy as desired and use it for automatic agent configuration after saving it. <br>
[[Datei:AAC-01.png|1000px|ohne]]<br>
<br>
<br>
[[File:Berechtigungskonzept.jpg|ohne]]<br>
'''Note:'''<br>
=== Computer ===
The start time for the data backup is randomly selected within the time windows of '''18:00 – 21:00''' and '''02:00 – 06:00'''. <br>
 
Example of a custom job template: <br>
All registered systems are displayed in a table on the Computer tab. If you open the overview while logged in to a site, only the computers of the respective site (end customers) will be displayed. <br>
[[Datei:AAC-2.png|1000px|ohne]]
This part of the portal offers you the opportunity to fully administrate, configure and much more with the agents in a multi-client capable manner.'''<br>
<br>
<span id="Übersprungene_Datensicherungen"></span>
<span id="Multi-Faktor-Authentifizierung_(MFA)"></span>
==== Skipped backups ====
== Multi-Factor Authentication (MFA) ==
 
Multi-factor authentication (MFA) must be enabled to protect access to the TERRA CLOUD Backup Portal.<br>
<span id="MFA-Verfahren"></span>
=== MFA Process ===
 
<!--The following methods are available for multi-factor authentication:<br>
*Phone call
**The user receives an automated call and the verification code via a voice message.
*SMS
**The verification code is sent via SMS to the registered mobile number.-->
*TOTP (Time-based One-Time Password)
** The user employs an authenticator app, such as Microsoft Authenticator or Google Authenticator.<br>The app generates time-based one-time codes that are entered during login.
<span id="MFA_einrichten"></span>
=== Configure MFA ===


This function shows you whether and how many data backups were skipped.<br>
When creating a new user, the mandatory multi-factor authentication (MFA) requirement is enabled by default.<br>
Consequently, the user is prompted to set up MFA upon their first login.<br>
<!--Users can choose between the aforementioned methods.<br>
<br>
<br>
'''A high rate of skipped backups can result from the following circumstances:'''
[[File:Backup-DE-Konto verifizieren.png|500px|none]]<br>
# The intervals between data backups are too short and the next data backup is started during runtime
<br>-->
# A very long data backup duration ensures that the subsequent data backup is skipped
[[File:Backup-DE-TOTP konfigurieren.png|500px|none]]<br>
<!--<br>
[[File:Backup-DE-Konto verifizieren-2.png|500px|none]]<br>
<br>
<br>
'''Data backups may be skipped if the following two conditions are met together''':
[[File:Backup-DE-SMS_Anruf konfigurieren.png|500px|none]]-->
#The backup job is executed more frequently than once per day, through multiple backups per day or the [[https://wiki.terracloud.de/index.php/Backup/en#TERRA_CLOUD_BACKUP_Enterprise:_High_Frequent_Backup_-_Hourly_backups High-Frequent Backup]]
Since multi-factor authentication (MFA) was not previously mandatory, there may be user accounts where it has not yet been enabled.<br>
#A data backup is already in progress or the Vault is performing important maintenance work on the backup job
These users must set up MFA subsequently.<br>
<!--Users currently still have the option to skip the initial MFA setup and complete it at a later time.<br>-->
To do this, the user first logs in to the TERRA CLOUD Backup Portal without having MFA set up.<br>
Then, the '''Edit my profile''' entry is opened via the menu in the top right corner (three dots).<br>
[[File:Backup-DE-MFA nachträglich konfigurieren-1.png|300px|none]]<br>
Multi-factor authentication can then be set up in the '''Two-factor configuration''' section.<br>
[[File:Backup-DE-MFA nachträglich konfigurieren-2.png|600px|none]]<br>
<!--[[File:Backup-DE-MFA nachträglich konfigurieren-3.png|300px|none]]-->
<br>
<br>
Through the use of e.g. B. High-frequency backups, with up to 24 backups per day, the vault only has a short time window for maintaining the backup job.<br>
<span id="MFA_zurücksetzen"></span>
To ensure that outdated data backups can be removed despite the high backup frequency, the agent is allowed to skip backups. <br>
=== Reset MFA ===
 
To reset two-factor authentication (MFA), please proceed as follows:
* If you haven't already done so, create a second user with administrator rights in the '''Backup Portal''' under '''Users'''.
* Then, log in using this second administrator account and, under '''Users''', open the administrator account for which the MFA needs to be reset.
* Enable the option highlighted in red in the screenshot.
[[File:Backup-DE-MFA zuruecksetzen.png|700px|none]]<br>
The next time this user logs in, two-factor authentication will need to be set up again.<br>
You can remove the additional administrator account if desired once MFA has been successfully set up.
<br>
<br>
'''Skipped backup rate:'''<br>
<span id="Berechtigungskonzept"></span>
You will be shown the percentage of data backups skipped in the last 48 hours.<br>
== Authorization concept ==
In this example, due to a misconfiguration, backups were made almost every minute to illustrate how this display works.
[[Datei:Übersprungene Sicherungen.png|1000px|ohne]]
If you click on the value, you will be shown an overview of the data backups with information about whether they were skipped:<br>
[[Datei:Sicherungen übersprungen-2.png|300px|ohne]]
 
<span id="Computer_in_eine_andere_Site_verschieben"></span>
=== Move computer to another site ===


You can move as many computers as you want to another site using the Move Computers action.<br>
This table shows the four different roles that can be assigned to a user, as well as the registration user automatically created by the TERRA CLOUD.<br>
This function makes it possible, for example, to assign systems that were accidentally registered in the [https://wiki.terracloud.de/index.php/Backup/en#Structure_of_TERRA_CLOUD_Backup_Portal Parent-Site] to the end customer's site. <br>
You can create users either within a site or at the reseller level in your parent site.<br>
[[Datei:Computer verschieben 2024.png|500px]]
For further information, please refer to the diagram showing the [[Backup#Aufbau_TERRA_CLOUD_Backup_Portal|structure of the TERRA CLOUD Backup Portal]].
<br>
<br>
Please select the desired site for the selected computers: <br>
{| class="wikitable"
<br>
!style="background-color:#7d5cab;color:#ffffff"|'''User and Portal Management'''
[[Datei:Computer verschieben 2.png|400px]]
!style="background-color:#7d5cab;color:#ffffff"|'''Read Only*'''
 
!style="background-color:#7d5cab;color:#ffffff"|'''Execute Only*'''
<span id="Benutzern_Agenten_zuweisen"></span>
!style="background-color:#7d5cab;color:#ffffff"|'''User**'''
=== Assign agents to users ===
!style="background-color:#7d5cab;color:#ffffff"|'''Administrator'''
 
!style="background-color:#7d5cab;color:#ffffff"|'''Registration User***'''
Users who do not have the "Administrator" role must be assigned to agents who can be managed by them. <br>
|-
You can do this either via the user configuration within the site or via the Sites tab within your parent site.
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Assign_agents_to_users Can assign agents to other users*]
In this example, only SERVER01 and SERVER02 have been assigned to the user for management. <br>
|style="background-color:#ffffff;text-align:center;"|[[Datei:Minus.jpg|10px]]
[[File:Systeme zuweisen2.png]]<br>
|style="background-color:#ffffff;text-align:center;"|[[Datei:Minus.jpg|10px]]
<span id="Löschung_von_Datensicherungen"></span>
|style="background-color:#ffffff;text-align:center;"|[[Datei:Minus.jpg|10px]]
=== Deletion of data backups ===
|style="background-color:#ffffff;text-align:center;"|[[Datei:Green check1.png|10px]]
 
|style="background-color:#ffffff;text-align:center;"|[[Datei:Minus.jpg|10px]]
<span id="Computer_aus_dem_Portal_und_vom_Vault_löschen"></span>
|-
==== Delete computers from the portal and vault ====
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Move_computer_to_another_site Move computers to another site]
 
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
You can have a computer's data backups completely deleted as an administrative user via the Backup Portal.<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
'''This type of deletion includes:'''
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
# Deletion of the computer from the portal (online or offline computer)
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
# Delete the backup of all backup jobs of this computer on the primary and secondary vault
|-
# Delete the registered computer on the Vault<br>
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Deletion_of_data_backups Delete backup jobs and computers from the vault]
<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
'''Procedure for deleting a computer:''' <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
# Select the desired system using the checkbox on the left side of the backup portal
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
# Under Actions, select Delete selected computer(s).
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
# Switch to the “Completely Wipe Computer” option <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
# Enter "CONFIRM" in the input field of the dialog to confirm the deletion
|-
The deletion job will be executed after a quarantine period of '''24 hours'''.
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Agent_Upgrade_Center Agent Upgrade Center]
[[File:Computer-loeschen.png|ohne]]<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
'''Cancel deletion job:''' <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
Within the quarantine period of 24 hours, you can select the computer as described above and cancel the deletion request using the "Cancel deletion of the selected computer(s)" action.
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
<span id="Backup_Jobs_aus_dem_Portal_und_vom_Vault_löschen"></span>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
==== Delete backup jobs from the portal and vault ====
|-
 
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Reports Report function]
You can have the data backups of a backup job completely deleted as an administrative user via the Backup Portal. <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
'''This type of deletion includes:'''
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
#Delete the backup job from the portal
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
#Delete all data backups of the backup job on the primary and secondary vault
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
#Delete the registered backup job on the Vault<br>
|-
<br>
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Create_additional_users Create additional users]
'''Procedure for deleting a backup job:''' <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
#Open the "Select Action" drop-down menu for the desired job under the "Job" tab of the respective computer
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
#Choose the “Delete Job” option
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
#Switch to the “Delete Job Completely” option (screenshot below)
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
#Enter "CONFIRM" in the input field of the dialog to confirm the deletion
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
The deletion job will be executed after a quarantine period of '''24 hours'''.
|-
[[File:Job-loeschen.png|ohne]]<br>
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Ransomware_Threat_Detection Handling potential threats]
<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
'''Cancel deletion job:''' <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
Within the quarantine period of 24 hours, you can select the backup job as described above and cancel the deletion job using the "Cancel deletion" action.
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
<span id="Einzelne_Datensicherungen(Safesets)_vom_Vault_löschen"></span>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
==== Delete individual data backups (safesets) from the vault ====
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
 
|-
You can have selected data backups of a backup job completely deleted as an administrative user via the Backup Portal. <br>
!style="background-color:#7d5cab;color:#ffffff"|'''Agent and backup management'''
<br>
!style="background-color:#7d5cab;color:#ffffff"|'''Read Only*'''
'''This type of deletion includes:'''
!style="background-color:#7d5cab;color:#ffffff"|'''Execute Only*'''
#Delete the selected data backup of the backup job on the primary and secondary vault and, if applicable, the satellite<br>
!style="background-color:#7d5cab;color:#ffffff"|'''User**'''
<br>
!style="background-color:#7d5cab;color:#ffffff"|'''Administrator'''
'''Procedure for deleting individual data backups (safesets):''' <br>
!style="background-color:#7d5cab;color:#ffffff"|'''Registration User***'''
#Open the "Select Action" drop-down menu for the desired job under the "Job" tab of the respective computer
|-
#Choose the “Delete Backup” option
|style="background-color:#ffffff;"|Register agents on the portal
#Select the safesets to be deleted and click "Delete" (screenshot below)
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
#Enter "CONFIRM" in the input field of the dialog to confirm the deletion<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
'''Note:''' <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
<p style="color: #FF0000;">The deletion of individual data backups (safesets) is carried out immediately and cannot be stopped after confirmation!</p>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
[[File:Safesets-loeschen.png|ohne]]<br>
|-
<br />
|style="background-color:#ffffff;"|Configure agents on the portal
<span id="Anpassung_im_Backup_Portal_nach_einer_Datenmigration"></span>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
=== Adjustment in the backup portal after a data migration ===
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
 
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
After migrating the data/backups to, for example, a dedicated vault system, the configuration must be adjusted in the backup portal. <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
After the migration, the backup agent should connect to another vault system and, if necessary, also use other access data for authentication. <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
The procedure differs slightly depending on the migration method. Please make the following adjustments after consultation in the migration process (support ticket). <br>
|-
<span id="Migration_des_Vaultaccounts"></span>
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Schedule_Recommendations Create and view schedules]
==== Vault account migration ====
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
 
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
With this variant, the entire vault account is moved to another vault system. A vault account is an organizational unit for an end customer.
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
You will receive the access data and the name of the vault account when you provide the account, e.g. 12345-DEMO. <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
Please carry out the following steps after successfully moving the account:
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
# For each agent, access the "Vault Settings" in the Backup Portal
|-
# Edit the current vault connection and swap the FQDN of the old vault system with that of the new vault system
|style="background-color:#ffffff;|[https://wiki.terracloud.de/index.php/Backup/en#Backup_Jobs Create and edit backup jobs]
# Also customize the vault profile for this site
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
The following screenshot shows the current vault connection that needs to be edited.
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
[[File:Migration Vaultaccount.png|framed|ohne]]<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
<span id="Migration_der_Daten_in_einen_neuen_Vaultaccount"></span>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
==== Migration of data to a new vault account ====
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
 
|-
The prerequisite for this method is a new vault account, e.g. B. on a TCBE vault system. With this variant, only the affected computers and their backup jobs are moved. <br>
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Advanced_Agent_Configuration Advanced Agent Configuration***]
Since authentication will now take place via the new account, all positions in the vault connection must be changed. <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
# For each agent, access the "Vault Settings" in the Backup Portal
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
# Edit the current vault connection and replace all vault credentials with those of the new vault account
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
# Also adjust the vault profile of the affected site
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
[[File:Migration in einen neuen Vaultaccount.png|1500px|ohne]]<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
 
|-
<span id="Berichte"></span>
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Deletion_of_data_backups Backup jobs and computers from the portal interface delete]
=== Reports ===
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
 
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
The reporting function gives you access to various data sets from the TERRA CLOUD backup via various preconfigured reports. <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
The underlying database receives new records twice a day through the TERRA CLOUD Vaults. <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
Please note that in connection with a TERRA CLOUD backup satellite, only data sets for the existing safe sets and consumption as of the base vault are available. <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
TERRA CLOUD backup satellites are not connected to the reporting function. <br>
|-
<br>
!style="background-color:#7d5cab;color:#ffffff"|'''Backup operation and recovery'''
'''Requirements:'''<br>
!style="background-color:#7d5cab;color:#ffffff"|'''Read Only*'''
In order to view reports, the “Vault account” must be synchronized with the respective site. <br>
!style="background-color:#7d5cab;color:#ffffff"|'''Execute Only*'''
Automatic synchronization of the Vault account – How it works:<br>
!style="background-color:#7d5cab;color:#ffffff"|'''User**'''
*Below the “Vault Settings” is the Vault Registration <span style="color:#FF0000;">(1)</span>
!style="background-color:#7d5cab;color:#ffffff"|'''Administrator'''
*the “Vault Account” <span style="color:#FF0000;">(2)</span> will be transferred to the site <span style="color:#FF0000;">(3)</span>
!style="background-color:#7d5cab;color:#ffffff"|'''Registration User***'''
<br>
|-
[[File:Berichtsfunktion BETA.png|border|1600px|ReportFunction(BETA)]]<br>
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Run_job_manually Start backup manually]
<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
For the synchronization to work, the following requirements must be met:<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
#The Vault account may NOT be used across sites (same Vault account in different sites)
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
#The agent was registered in a self-created site (https://backup.terracloud.de/Sites).
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
Different Vault accounts can be used within a site as long as they are not used in other sites.<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
<br>
|-
'''Necessary permission of the user:'''<br>
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Restoring_a_Backup_Job Recovery carry out]
To access the Reports page, you must be logged in as a user with the Administrator role. <br>
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
Reports can be scheduled and automatically sent by email (PDF, XLS, CSV).
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
<br>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
<span id="Bericht_zur_Sicherungsüberprüfung"></span>
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
==== Backup Verification Report ====
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
 
|-
This report provides you with an overview of the most recently performed automated [[Backup/en#Automated_recovery_tests|Recovery Tests]] by your vSphere Recovery Agents. <br>
!style="background-color:#7d5cab;color:#ffffff"|'''Monitoring and information'''
On the one hand, you have the option of exporting this view as a PDF document, and on the other hand, you can configure a regular export including email delivery using the "E-mail/Schedule" menu item.
!style="background-color:#7d5cab;color:#ffffff"|'''Read Only*'''
[[File:Bericht Sicherungsüberprüfung.png|ohne|950 px]]<br>
!style="background-color:#7d5cab;color:#ffffff"|'''Execute Only*'''
<br />
!style="background-color:#7d5cab;color:#ffffff"|'''User**'''
=== Agent Upgrade Center ===
!style="background-color:#7d5cab;color:#ffffff"|'''Administrator'''
!style="background-color:#7d5cab;color:#ffffff"|'''Registration User***'''
|-
|style="background-color:#ffffff;"|[https://wiki.terracloud.de/index.php/Backup/en#Monitoring_2 View last backup status]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
|-
|style="background-color:#ffffff;"|View/download log files
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
|-
|style="background-color:#ffffff;"|Statusfeed view
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
|-
|style="background-color:#ffffff;"|View backup job configuration
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Green check1.png|10px]]
|style="background-color:#ffffff;text-align:center;"|[[File:Minus.jpg|10px]]
|}
{| class="wikitable"
|-
|style="background-color:#ffffff;"|* Assignment required to administer the agent based on the role.
|-
|style="background-color:#ffffff;"|** Assignment of the respective agent is not necessary<br>if it was registered on the portal by the user.
|-
|style="background-color:#ffffff;"|*** This user is automatically created when ordering a backup package.
|-
|style="background-color:#ffffff;"|**** Agent description, retention types, email notification,<br>bandwidth limitation, Agent logs.
|}
== Computer ==


The Agent Upgrade Center offers you the opportunity to upgrade Windows agents from version 8.7x via portal.<br>
All registered systems are displayed in a table on the Computer tab. If you open the overview while logged in to a site, only the computers of the respective site (end customers) will be displayed. <br>
This part of the portal offers you the opportunity to fully administrate, configure and much more with the agents in a multi-client capable manner.'''<br>
<span id="Übersprungene_Datensicherungen"></span>
=== Skipped backups ===
 
This function shows you whether and how many data backups were skipped.<br>
<br>
<br>
'''Update Individual Agents''' <br>
'''A high rate of skipped backups can result from the following circumstances:'''
You can select systems via the “Computer” tab and initiate the agent update under “Actions”.
# The intervals between data backups are too short and the next data backup is started during runtime.
[[File:Agenten auf ausgewählten Computern aktualisieren.png|framed|ohne]]<br>
# A very long data backup duration ensures that the subsequent data backup is skipped.
'''Data backups may be skipped if the following two conditions are met together''':
#The backup job is executed more frequently than once per day, through multiple backups per day or the [https://wiki.terracloud.de/index.php/Backup/en#TERRA_CLOUD_BACKUP_Enterprise:_High_Frequent_Backup_-_Hourly_backups High-Frequent Backup].
#A data backup is already in progress or the Vault is performing important maintenance work on the backup job.
Through the use of e.g. B. High-frequency backups, with up to 24 backups per day, the vault only has a short time window for maintaining the backup job.<br>
To ensure that outdated data backups can be removed despite the high backup frequency, the agent is allowed to skip backups. <br>
<br>
<br>
'''Status display''' <br>
'''Skipped backup rate:'''<br>
In addition to the current version, you can use the icon to see whether the agent can be updated (purple dot) or is currently being updated.
You will be shown the percentage of data backups skipped in the last 48 hours.<br>
As soon as an agent has been successfully updated, a checkmark will be displayed next to the version number. If you move the cursor to the symbol next to the version number, the respective meaning will be displayed, e.g. "New agent version available".
In this example, due to a misconfiguration, backups were made almost every minute to illustrate how this display works.
In the following screenshot you can see an agent that is currently being updated.
[[Datei:Übersprungene Sicherungen.png|1000px|ohne]]
[[File:Agent-Upgrade-center.png|framed|ohne]]<br>
If you click on the value, you will be shown an overview of the data backups with information about whether they were skipped:<br>
<br>
[[Datei:Sicherungen übersprungen-2.png|300px|ohne]]
'''Update Agents for Entire Sites''' <br>
<span id="Computer_in_eine_andere_Site_verschieben"></span>
To do this, access the Agent Upgrade Center via your master login and select the desired agent and then the respective sites.
=== Move computer to another site ===
[[File:Agent Upgrade Center 3.png|ohne|1000px]]<br>
<br>
Then select whether you want the agents to be updated automatically or immediately:
[[File:Agentupgradecenter.png|framed|ohne]]<br>


== '''Windows Agent''' ==
You can move as many computers as you want to another site using the Move Computers action.<br>
 
This function makes it possible, for example, to assign systems that were accidentally registered in the [https://wiki.terracloud.de/index.php/Backup/en#Structure_of_TERRA_CLOUD_Backup_Portal Parent-Site] to the end customer's site. <br>
<span id="Installation_über_das_Setup"></span>
[[Datei:Computer verschieben 2024.png|500px]]
=== Installation via Setup ===
Please select the desired site for the selected computers: <br>
[[Datei:Computer verschieben 2.png|400px]]
<span id="Benutzern_Agenten_zuweisen"></span>
== Assign agents to users ==
 
Users who do not have the "Administrator" role must be assigned to agents who can be managed by them. <br>
You can do this either via the user configuration within the site or via the Sites tab within your parent site.<br>
In this example, only SERVER01 and SERVER02 have been assigned to the user for management. <br>
[[File:Systeme zuweisen2.png]]
<span id="Löschung_von_Datensicherungen"></span>
== Deletion of data backups ==
 
<span id="Computer_aus_dem_Portal_und_vom_Vault_löschen"></span>
=== Delete computers from the portal and vault ===


Please download TERRA Backup Agent. To do this, log in to your portal and select the appropriate version under Downloads on the right. <br>
You can have a computer's data backups completely deleted as an administrative user via the Backup Portal.<br>
[[File:Agent Sprache.png|border|Select language]] <br>
<br>
<br>
Now start the installation on the server to be backed up. First select the desired language in which you would like to be guided through the installation. <br>
'''This type of deletion includes:'''
[[File:Agent Assistent.png|border|Click Next]] <br>
# Deletion of the computer from the portal (online or offline computer)
<br>
# Delete the backup of all backup jobs of this computer on the primary and secondary vault
On the "Support Information and Release Notes" page, click Next<br>
# Delete the registered computer on the Vault<br>
[[File:Agent Supporthinweise.png|border|Support Notes]] <br>
'''Procedure for deleting a computer:''' <br>
<br>
# Select the desired system using the checkbox on the left side of the backup portal.
Accept the license terms and click Next. <br>
# Under Actions, select Delete selected computer(s).
[[File:Agent Lizenzbestimmungen.png|border|Confirm License Terms]] <br>
# Switch to the “Completely Wipe Computer” option.<br>
# Enter "CONFIRM" in the input field of the dialog to confirm the deletion.
The deletion job will be executed after a quarantine period of '''24 hours'''.
[[File:Computer-loeschen.png|ohne]]
'''Cancel deletion job:''' <br>
Within the quarantine period of 24 hours, you can select the computer as described above and cancel the deletion request using the "Cancel deletion of the selected computer(s)" action.
<span id="Backup_Jobs_aus_dem_Portal_und_vom_Vault_löschen"></span>
=== Delete backup jobs from the portal and vault ===
 
You can have the data backups of a backup job completely deleted as an administrative user via the Backup Portal. <br>
<br>
<br>
In the next installation step, select “Custom” and click Next. <br>
'''This type of deletion includes:'''
[[File:Agent Benutzerdefiniert.png|border|Setup type]] <br>
#Delete the backup job from the portal
#Delete all data backups of the backup job on the primary and secondary vault
#Delete the registered backup job on the Vault<br>
'''Procedure for deleting a backup job:''' <br>
#Open the "Select Action" drop-down menu for the desired job under the "Job" tab of the respective computer.
#Choose the “Delete Job” option.
#Switch to the “Delete Job Completely” option (screenshot below).
#Enter "CONFIRM" in the input field of the dialog to confirm the deletion.
The deletion job will be executed after a quarantine period of '''24 hours'''.
[[File:Job-loeschen.png|ohne]]
'''Cancel deletion job:''' <br>
Within the quarantine period of 24 hours, you can select the backup job as described above and cancel the deletion job using the "Cancel deletion" action.
<span id="Einzelne_Datensicherungen(Safesets)_vom_Vault_löschen"></span>
=== Delete individual data backups (safesets) from the vault ===
 
As an administrative user, you can completely delete selected backups from a backup job via the Backup Portal. <br>
<br>
<br>
The local logon credentials can usually be adopted. Click on Continue. <br>
'''This type of deletion includes:'''
[[File:Agent lokales System.png|border|Logon Credentials]] <br>
#Deleting the selected backup(s) from the backup job on the primary and secondary vaults, and if applicable, the satellite.
'''Procedure for deleting individual backups (safesets):''' <br>
#Open the "Select Action" drop-down menu for the desired job under the "Job" tab of the respective computer.
#Select the "Delete Backup" option.
#Select the safesets to be deleted and click "Delete" (image below).
#Enter "CONFIRM" in the dialog box to confirm the deletion.<br>
<br>
<br>
Select the desired installation directory. Then click Next. <br>
'''Note:'''
[[File:Agent Pfad.png|border|Select path]] <br>
<p style="color: #FF0000;">The deletion of individual backups (safesets) is executed immediately and cannot be stopped after confirmation. become!</p>
<br>
[[Datei:Safeset-Löschung.png|850px|ohne]]
In addition to the actual backup agent, other plug-ins can be installed. Depending on the type of server, individual Microsoft SQL database instances or Exchange mailboxes can be backed up. <br>
<br />
Select the plug-ins you want and then click Next. <br>
<span id="Anpassung_im_Backup_Portal_nach_einer_Datenmigration"></span>
[[File:Agent plugins.png|border|Plugins]] <br>
== Adjustment in the backup portal after a data migration ==
 
After migrating the data/backups to, for example, a dedicated vault system, the configuration must be adjusted in the backup portal. <br>
After the migration, the backup agent should connect to another vault system and, if necessary, also use other access data for authentication. <br>
The procedure differs slightly depending on the migration method. Please make the following adjustments after consultation in the migration process (support ticket). <br>
<span id="Migration_des_Vaultaccounts"></span>
=== Vault account migration ===
 
With this variant, the entire vault account is moved to another vault system. A vault account is an organizational unit for an end customer.<br>
You will receive the access data and the name of the vault account when you provide the account, e.g. 12345-DEMO. <br>
Please carry out the following steps after successfully moving the account:
# For each agent, access the "Vault Settings" in the Backup Portal.
# Edit the current vault connection and swap the FQDN of the old vault system with that of the new vault system.
# Also customize the vault profile for this site.
The following screenshot shows the current vault connection that needs to be edited.
[[File:Migration Vaultaccount.png|framed|ohne]]<br>
<span id="Migration_der_Daten_in_einen_neuen_Vaultaccount"></span>
=== Migration of data to a new vault account ===
 
The prerequisite for this method is a new vault account, e.g. B. on a TCBE vault system. With this variant, only the affected computers and their backup jobs are moved. <br>
Since authentication will now take place via the new account, all positions in the vault connection must be changed. <br>
# For each agent, access the "Vault Settings" in the Backup Portal.
# Edit the current vault connection and replace all vault credentials with those of the new vault account.
# Also adjust the vault profile of the affected site.
[[File:Migration in einen neuen Vaultaccount.png|1500px|ohne]]<br>
<span id="Berichte"></span>
== Reports ==
 
The reporting function gives you access to various data sets from the TERRA CLOUD backup via various preconfigured reports. <br>
The underlying database receives new records twice a day through the TERRA CLOUD Vaults. <br>
Please note that in connection with a TERRA CLOUD backup satellite, only data sets for the existing safe sets and consumption as of the base vault are available. <br>
TERRA CLOUD backup satellites are not connected to the reporting function. <br>
<br>
<br>
Enter the email address and password of the user created in [https://wiki.terracloud.de/index.php/Backup/en#Create_user 5.2.1]. Confirm with Next. <br>
'''Requirements:'''<br>
[[File:Agent login.png|border|Enter login information]] <br>
In order to view reports, the “Vault account” must be synchronized with the respective site. <br>
Automatic synchronization of the Vault account – How it works:<br>
*Below the “Vault Settings” is the Vault Registration <span style="color:#FF0000;">(1)</span>
*the “Vault Account” <span style="color:#FF0000;">(2)</span> will be transferred to the site <span style="color:#FF0000;">(3)</span>
<br>
<br>
Confirm with Install. <br>
[[File:Berichtsfunktion BETA.png|border|1600px|ReportFunction(BETA)]]<br>
[[File:Agent bestaetigen.png|border|Install]] <br>
<br>
<br>
If you are then redirected back to agent registration, the access data you entered is probably incorrect or you are having problems with the <br>
For the synchronization to work, the following requirements must be met:<br>
Network connection. First try pinging backup.terracloud.de. If this works, you can use Telnet to check whether port 8086 can be reached. <br>
#The Vault account may NOT be used across sites (same Vault account in different sites)
[[File:Agent fertigstellen.png|border|Complete installation]] <br>
#The agent was registered in a self-created site (https://backup.terracloud.de/Sites).
Different Vault accounts can be used within a site as long as they are not used in other sites.<br>
<br>
<br>
After 5 minutes at the latest, the server you just registered should appear under “Computer” within your portal. <br>
'''Necessary permission of the user:'''<br>
[[File:Computer sichtbar.png|1600px|border|List of computers in the portal]] <br>
To access the Reports page, you must be logged in as a user with the Administrator role. <br>
Reports can be scheduled and automatically sent by email (PDF, XLS, CSV).
<br>
<br>
On the right side under “Site Name” you can read “End Customer1” in our case. This is because we registered the agent with the user backupkunde@endkunde1.de, <br>
<span id="Bericht_zur_Sicherungsüberprüfung"></span>
which belongs to the “End Customer1” subsite. This way we can now filter for computers that belong to the “End Customer1” subsite. This allows you to quickly list all computers in an organizational unit. <br>
=== Backup Verification Report ===
<span id="Silent_Installation_unter_Windows"></span>
 
==== Silent installation under Windows ====
This report provides you with an overview of the most recently performed automated [[Backup/en#Automated_recovery_tests|Recovery Tests]] by your vSphere Recovery Agents. <br>
On the one hand, you have the option of exporting this view as a PDF document, and on the other hand, you can configure a regular export including email delivery using the "E-mail/Schedule" menu item.
[[File:Bericht Sicherungsüberprüfung.png|ohne|950 px]]<br>
<br />
== Agent Upgrade Center ==


The agent can also be installed in silent mode. This is helpful if the agent is to be rolled out automatically on multiple systems. <br>
The Agent Upgrade Center offers you the opportunity to upgrade Windows agents from version 8.7x via the portal.<br>
<br>
'''Update Individual Agents''' <br>
You can select single systems via the “Computer” tab and initiate the agent update under “Actions”.
[[File:Agenten auf ausgewählten Computern aktualisieren.png|900px|framed|ohne]]<br>
<br>
<br>
'''An example of the silent installation including the image plug-in: <br>'''
'''Status display''' <br>
''Agent-Windows-x64-x-xx-xxxx.exe /s /v" REGISTERWITHWEBCC=True AMPNWADDRESS=backup.terracloud.de AMPUSERNAME=backupkunde@firmaXYZ.de AMPPASSWORD=password FEATUREVOLUMEIMAGE=ON /qn"'' <br >
In addition to the current version, you can use the icon to see whether the agent can be updated (purple dot) or is currently being updated.
'''Explanation:'''<br>
As soon as an agent has been successfully updated, a checkmark will be displayed next to the version number. If you move the cursor to the symbol next to the version number, the respective meaning will be displayed, e.g. "New agent version available".<br>
''Agent-Windows-x64-x-xx-xxxx.exe'': The agent (x64) setup is called.<br>
In the following screenshot you can see an agent that is currently being updated.
''REGISTERWITHWEBCC=True'': The agent should be registered on the backup portal.<br>
[[File:Agent-Upgrade-center.png|framed|ohne]]<br>
''AMPNWADDRESS=backup.terracloud.de'': The address of the backup portal is passed.<br>
''AMPUSERNAME=backupkunde@firmaXYZ.de'': The user of the customer site is transferred.<br>
''AMPPASSWORD=password'': The password you assigned for the customer site user.<br>
<br>
<br>
'''Parameters for plugins:'''<br>
'''Update Agents for Entire Sites''' <br>
Plug-ins can be added after the ''AMPPASSWORD'' separated by a space as in the example above.
To do this, access the Agent Upgrade Center via your master login and select the desired agent and then the respective sites.
Image Plugin: ''FEATUREVOLUMEIMAGE=ON''<br>
[[File:Agent Upgrade Center 3.png|ohne|1000px]]<br>
Exchange Plugin (Legacy): ''FEATUREEXCHANGE=ON''<br>
Exchange Plug-in (From 2010): ''FEATUREEXCHANGE2010=ON''<br>
SQL Plugin: ''FEATURESQL=ON''<br>
Cluster plugin: ''FEATURECLUSTER=ON''<br>
Oracle Plugin: ''FEATUREORACLE=ON''<br>
<br>
<br>
'''Installation in another directory:'''<br>
Then select whether you want the agents to be updated automatically or immediately:
If required, please specify the following parameter directly after /s /v" to install in another directory:<br>
[[File:Agentupgradecenter.png|framed|ohne]]<br>
''SILENTINSTALDIR=\"Path''
= '''Backup Jobs''' =
Example:<br>
''SILENTINSTALLDIR=\"C:\Program Files\Example\''<br>
<span id="Silent_Agenten-Registrierung"></span>
==== Silent Agent Registration ====


The following entry in the command line is sufficient to re-register the agent on the portal:<br>
<span id="File_Level_Job"></span>
''C:\Program Files\TERRA Cloud Backup\Agent\buagent.exe" -cmdline --reregister --amplogin backupkunde@firmaXYZ.de --amppassword USERPW --ampserver "backup.terracloud.de" --ampport 8086' '<br>
== File-based backup ==
<br>
The Terra Cloud Backup services must then be restarted.<br>
To do this, start Powershell with administrator rights and enter the following:<br>
''Get-Service -DisplayName "TERRA Cloud Backup*" | Restart service''<br>
<br>


<span id="Agent_mit_dem_Vault_verknüpfen"></span>
<span id="Funktionsweise"></span>
===Associate Agent with Vault ===
=== How it works ===


Every newly registered computer is initially displayed as “Not configured” in the portal. First, at least one vault (data safe) must be assigned to the computer. <br>
The backup software accesses the file system of the system to be backed up. The files are read and divided into 32KB blocks; a checksum is calculated for each of these blocks.<br>
Click on the server you want to configure (DC in this example). This will open the settings for this computer. Then click on “Configure manually” on the right. <br>
The delta can be determined in subsequent backups using the checksums. The blocks identified for backup are compressed and encrypted.
[[File:Manuelle Konfiguration.png|border|Manual Configuration]] <br>
<span id="Schneller_Datei-Scan"></span>
<br>
=== Fast File Scan ===
Now click on “Add Vault” on the right.<br>
Then select the Vault profile created in [https://wiki.terracloud.de/index.php/Backup/en#Configure_Vault_Profiles 4.2.1] under “Vault profile”, in our case this is “Vault_Endkunden1”. All fields should then be automatically filled with the set values. <br>
[[File:Vault Einstellungen1.png|border|Vault Settings]] <br>
<br>
The agent establishes a test connection to the vault. If the connection cannot be established, for example because incorrect access data was entered, you will receive an error message. <br>
If everything is OK, the vault will now appear under the “Vault Settings”. <br>
[[File:Vault Einstellungen uebersicht.png|1600px|border|Overview]] <br>


<span id="Erweiterte_Agentenkonfiguration"></span>
The "Quick File Scan" or "QFS Quick File Scanning" function allows the Windows agent to pre-filter files based on the timestamp (modified date) in the file system to determine the delta.<br>
=== Advanced Agent Configuration ===
Files whose modification date is newer than the last backup are read in and compared with the delta file of the last backup using the calculated checksums of the 32KB blocks.<br>
Only blocks that have not yet been backed up will be included in the backup.
<span id="Vor-_und_Nachteile_filebasiert"></span>
=== Advantages and disadvantages file-based===


Individual settings can be configured for each computer. These include, for example: B. Mail notification and bandwidth limitation. <br>
'''Advantages:''' <br>
Go to “Computer” in the portal. Select a server and then click on “Advanced” to make specific settings. <br>
#BMR backup possible
[[File:Erweiterte Agentenkonfiguration.png|border|1500px|Overview of Advanced Agent Configuration]]<br>
#Included as standard with the agent, no additional plugin is required
#No reboot required after installation
#Granular troubleshooting possible
#Files/directories can be excluded
#Can be administered from the agent console without portal access
#Script-based restore possible via VPR file
<br>
<br>
'''Options:'''<br>
'''Disadvantages:''' <br>
Under this point you can add a description to the system, for example: B. to store the ticket number in the description in a support case.<br>
#Slower with lots of small files
We recommend the option “Log errors and stop backup” for current Windows agents; this is the default setting after installation or update.<br>
#Navigation via portal when restoring individual files
The option "Log errors and continue backup" offers the advantage that backups can also be carried out if, for example, B. VSS problems can sometimes go through. <br>
#[https://wiki.terracloud.de/index.php/Backup_Fehlerdiagnose/en#The_contents_of_the_OneDrive_folder_are_not_being_backed_up The OneDrive folder cannot currently be backed up.]
The files not backed up in this job will result in an increased delta afterwards.<br>
=== Best Practice ===
 
<pre style="color: green">
1.In the best case scenario, use a file-based backup job only to back up individual files and folders.
2.Add the “Entire Server” option to existing file-based BMR backup jobs.
3.Use an image-based job to configure new BMR backups.
4. File-based backup jobs are only recommended for up to a million files; above a million files we recommend an image backup job.
</pre style="color: green">
<span id="Komplexe_Exklusionen/Inklusionen_in_dateibasierten_Jobs_konfigurieren"></span>
=== Configure complex exclusions/inclusions in file-based jobs ===
 
The following instructions can be used for both local file-based backup jobs and UNC jobs (network shares). <br>
When configuring one of the job types mentioned above, the portal can only be excluded or included to a limited extent. <br>
Using the Backup Portal, you can only select one directory per exclusion entry in the job configuration and exclude folders and/or files in the respective subdirectory.
This means that the entry only applies to the level below. <br>
<br>
<br>
'''Retention Types:'''<br>
'''Example complex exclusion:'''<br>
The currently stored retention types are displayed here; after installation, “Daily” and “Monthly” are stored by default.<br>
You want to exclude all directories that end with '''_Backup''' in a backup job because they
You can use this tab to create your own storage types, which you can then choose from in the schedule. When configuring, please note that 50 safe sets per job are included free of charge.<br>
Contains data backups that should not be included in the TERRA CLOUD backup.<br>
'''<code>D:\Data\*\*\*_Backup\*.*</code>'''<br>
In this exclusion there are two levels of different directories, each containing subdirectories ending in _Backup.<br>
These directories and their contents are excluded using the syntax shown.<br>
However, this complex exclusion expression cannot be configured in the portal and must therefore be copied manually into the job's configuration file.<br>
<br>
<br>
'''Notifications (agent side):'''<br>
'''Deposit exclusion in the job configuration:''' <br>
As of August 2021, the “Notifications” tab is only available if an agent-side mail notification is already configured. <br>
1. Configure any exclusion <br> for the job
This agent function has been replaced by the [[https://wiki.terracloud.de/index.php/Backup/en#Configure_notifications|Notification via the TERRA CLOUD Backup Portal]].<br>
2. Stop both TERRA CLOUD Backup Agent <br> services
<br>
3. Open the JOBNAME.vvc file in the agent installation directory <br>
'''Enable agent-side notification manually:'''<br>
4. Swap the exclusion created by step 1 with the one you want as in the following example <br>
If you want to continue using agent-side notification, you can configure it using the following steps. <br>
Exclude = "D:\*\*\*_Backup\*.*" <br>
1. Stop the "TERRA Cloud Backup Agent" and "TERRA Cloud Backup BUAgent" <br> services on the desired system
5. Start both services again <br>
2. Open the "global.vvc" file in the TERRA CLOUD Backup Agent <br> installation directory
6. In the Backup Portal, check the job configuration and schedule and save it again if necessary
3. Please add the following lines, if they are not present, after the curly braces of the "OpenFile" block
7. If you modify it manually, you will receive a warning in the Backup Portal, which you can simply confirm <br>
  notification {
8. After confirming the warning, please check whether the configuration has been applied as desired <br>
  MailOnError = True
For a complex inclusion, you can use these instructions analogously.
  MailOnFailure = True
<span id="Bedrohungserkennung"></span>
  MailOnSuccess = True
=== Ransomware Threat Detection ===
  }
 
4. Start the services "TERRA Cloud Backup Agent" and "TERRA Cloud Backup BUAgent" <br> on the desired system
This file-based backup option allows the agent to scan the system for potential threats during backup. <br>
5. Open the TERRA CLOUD Backup Portal and update your browser if necessary
If a possible threat is detected, the data backup is marked as a “potential threat”. <br>
6. Complete the configuration using the “Notification” tab, which is now visible again
The current and all subsequent backups will retain this flag until one of the actions is taken. <br>
<br>
<br>
'''Performance:'''<br>
Note:<br>
Bandwidth limitation and execution priority can be configured under this point. <br>
The agent does not check for possible errors in a seed backup or the first backup
According to current knowledge, changing the execution priority has no noticeable effect, so we recommend keeping the default value.<br>
Ransomware threats when threat detection is enabled in a job.
Bandwidth limitation is particularly recommended for weak connections during your customer's working hours.<br>
[[File:Ransomware-1.png|border|1200px]]<br>
At least 1.5 Mbps should be allocated for a backup.<br>
<span id="Handhabung_von_potenziellen_Bedrohungen"></span>
<br>
=== Handling potential threats ===
'''Agent log files:''' <br>
 
Under this tab you can view all global (cross-job) log files of the agent, which can be helpful for troubleshooting.<br>
When ransomware threat detection is triggered, the following options are available via the "Manage potential threat" action: <br>
For example, log files of the BUAgent can be viewed; this service (TERRA Cloud Backup BUAgent) is responsible for the agent's communication with the backup portal.<br>
[[File:Ransomware-2.png|border|250px|none]]<br>
<br />
1. Using the "Restore" option, you can configure a granular restore and—after the restore is complete—[https://wiki.terracloud.de/index.php/Backup/en#Delete_individual_data_backups_(safesets)_from_the_vault delete the flagged backup from the backup chain].
[[File:Ransomware-3.png|border|350px|none]] <br>
2. In the event of a false positive, you can select the "Delete potential threat warning" option and confirm the deletion of the warning.
[[File:Ransomware-4.png|border|350px|none]] <br>
<span id="Image_Level_Job"></span>
== Image-based backup ==


<span id="Aktualisierung_des_Agenten"></span>
<span id="Funktionsweise"></span>
=== Agent Update ===
=== How it works ===


The TERRA CLOUD Backup Agent can be updated as follows:<br>
In contrast to a file-based backup job, which protects individual files and folders when backing up,
<br>
an image job backs up all blocks of a selected volume.<br>
'''Windows (manual):''' <br>
It is possible to set up a BMR backup if all system-relevant volumes are backed up.
*As of agent version 8, the agent can be updated directly via the setup of the newer agent version
=== Changed Block Tracking ===
*When you start a setup of a newer agent, you will be asked if you want to update
:[[File:Agent-Update.png|border|Perform update]]<br>
<br>
'''Windows (Agent Updater):''' <br>
*Agents from agent version 8 can be updated using the Windows Agent Updater
*You can find the Windows Agent Update in the download area of the backup portal
*You will receive feedback about the individual steps, as shown in the illustration
:[[File:Windows Agent Updater.png|border|Perform update]]<br>
<br>
'''Windows (Agent Upgrade Center):''' <br>
You can update multiple agents centrally via the TERRA CLOUD Backup Portal. Instructions can be found at: <br>
[[Backup/en#Agent_Upgrade_Center|Agent Upgrade Center]]
== '''Linux Agent''' ==
<span id="Dokumentation_Linux_Agent"></span>
=== Documentation Linux Agent ===


You can find extensive documentation and further information in [https://drive.terracloud.de/dl/fiLpZboTGRPeqzW1cqwS6yin/Documentation%20and%20Release%20Notes/Documentation/DE/Linux%20Agent%20and%20Oracle%20Plug-in%20v9.2%20-%20User%20Guide.pdf?inline Linux Agent User Guide].
The image plug-in installs a changed block tracking driver, which requires a restart after installation. This can be used to determine which blocks have changed in relation to the last backup.
<span id="Vorbereitung_der_Installation_für_eine_Bare_Metal_Sicherung"></span>
<span id="Vor-_und_Nachteile_Imagebasiert"></span>
=== Preparing the installation for a bare metal backup ===
=== Advantages and Disadvantages Image-based===


The bare metal backup of the TERRA CLOUD Backup Linux agent requires the software [https://relax-and-recover.org Relax and Recover], in a supported version, on the system to be backed up.<br>
'''Advantages:''' <br>
We recommend installing the software via the package manager of the respective distribution and, if necessary, updating it to the supported version. <br>
#BMR backup possible
The currently supported version of Relax and Recover can be found in the release notes of the TERRA CLOUD Backup Linux agent.<br>
#Faster for lots of small files
#Recommended for natively protected data volumes of 1TB or more
#Requires less processing power than file-based backup
#Convenient Restore (Image is attached)
#Navigation via Explorer when restoring
#The OneDrive folder can be included in the backup<br>
<br>
<br>
<font color="red">Please note that TERRA CLOUD cannot provide support for the installation or commissioning of the Relax and Recover software.</font>
'''Disadvantages:''' <br>
#Exclusion of individual files and folders is not possible
#Restore only possible on disks of the same size/larger
#Restart required after plugin installation
#No granular troubleshooting possible
#ReFS is not supported
=== Best Practice ===


=== Installation ===
<pre style="color: green">
1. The restart can be done at a later point in time (usually after the end of work). The agent can be configured without restarting.
2. To protect the entire system, including the possibility of a bare metal restore, select the "Entire Server" and "BMR" options.
3. If data (such as local backups / dumps) needs to be excluded, you can move it to a separate volume and explicitly not include this volume in the backup set.<br>
The "Entire Server" option cannot be used in this case.
</pre style="color: green">
== UNC-Backup Job ==


'''Step 1:''' Please download TERRA Backup Agent. <br>
<span id="Dokumentation"></span>
To do this, log in to the backup portal and select the appropriate version under Downloads on the right. <br>
=== Documentation ===
[[File:Linux-Agent-Download.png|ohne]]
<br>
'''Step 2:''' Please unpack the archive with ''tar -zxf PACKAGE-NAME.tar.gz''. <br>
[[File:Linux Agent unzip-2.png|ohne]]
<br>
'''Step 3:''' Please then switch to the unpacked agent directory and start the installer shell script via ''./install.sh''
<br>
[[File:Linux Agent install.sh.png|1500px|ohne]]
<br>
'''Step 4:''' Please read and confirm the license agreement first and follow the instructions in the installation wizard to configure the installation. <br>
In the screenshot of the example installation, the default setting for the following queries has been selected:
#Installation directory ''/opt/BUAgent''
#Language email notification ''(deprecated agent email notification)''
#Encryption method
You can accept the default values by confirming the queries with ENTER. <br>
[[File:Linux Agent Installation.png|ohne]]
<br>
'''Step 5:''' Please indicate whether a bare metal restore backup is desired. <br>
If the answer is YES, please note that [[Backup#Preparation_der_Installation_f%C3%BCr_eine_Bare_Metal_Sicherung|Relax and Recover]] must already be installed on the system in a supported version. <br>
The default value for the Relax and Recover directory is ''/sbin/rear''. <br>
[[File:Linux Agent enable BMR.png|ohne]]
'''Step 6:''' Please register the Linux agent on the TERRA CLOUD Backup Portal: <br>
#Portal address = backup.terracloud.de
#Portal connection port = 8086 ''(default value)''
#Portal username = [[Backup#Create_User|User]] of the end customer's site
#Portal password = Password of the user of the end customer's site
<br>
[[File:Linux Agent Portal Registrierung.png|ohne]]
'''Step 7:''' Please check in the TERRA CLOUD Backup Portal whether the agent has been successfully registered in your end customer's site. <br>
[[File:Linux Agent im Portal.png|ohne]]


== '''Backup Jobs''' ==
Complete setup instructions can be found in Chapter 5.4 of the Windows Agent User Guide at [https://drive.terracloud.de/getlink/fiLpZboTGRPeqzW1cqwS6yin Agents Doku/ Release Notes] (Documentation -> EN -> Windows Agent -> User Guide )
<span id="Funktionsweise"></span>
=== How it works ===


<span id="Dateibasiertes_Backup"></span>
The Windows agent connects to the stored network share and saves the selected files. For authentication, a user must be provided with read and write permissions.
=== File-based backup ===
=== Best Practice ===


<span id="Funktionsweise"></span>
<pre style="color: green">
==== How it works ====
1. A UNC backup job should protect a maximum of 500,000 files or 1 TB of native data. If more data needs to be backed up, we recommend distributing it across several UNC backup jobs.
2. Since backing up a network share via a DFS namespace is not supported, we recommend backing up the server share directly without using the namespace.
3. Recommended backup method for files stored on NAS systems (e.g. from Synology, QNAP).
</pre style="color: green">
<span id="Zeitplan"></span>
== Schedule Recommendations ==


The backup software accesses the file system of the system to be backed up. The files are read and divided into 32KB blocks; a checksum is calculated for each of these blocks.
The schedule determines when a data backup should be started and with which retention type it should be saved. <br>
The delta can be determined in subsequent backups using the checksums. The blocks identified for backup are compressed and encrypted.
The following articles go into more detail about various recommended schedule configurations. <br>
<span id="Schneller_Datei-Scan"></span>
<span id="Erneute_Sicherungsversuche"></span>
==== Fast File Scan ====
=== Renewed backup attempts ===


The "Quick File Scan" or "QFS Quick File Scanning" function allows the Windows agent to pre-filter files based on the timestamp (modified date) in the file system to determine the delta.
The “''Automatic restart for time-controlled backup''” function offers the option of restarting an incorrect or failed data backup. <br>
Files whose modification date is newer than the last backup are read in and compared with the delta file of the last backup using the calculated checksums of the 32KB blocks.
This can be particularly helpful if, for example, in the first backup attempt. B. a Microsoft VSS shadow copy cannot be created. <br>
Only blocks that have not yet been backed up will be included in the backup.
We recommend waiting a few minutes between backup attempts so that e.g. B. Load peaks can be avoided. <br>
<span id="Vor-_und_Nachteile_filebasiert"></span>
==== Advantages and disadvantages file-based====
 
'''Advantages:''' <br>
#BMR backup possible
#Included as standard with the agent, no additional plugin is required
#No reboot required after installation
#Granular troubleshooting possible
#Files/directories can be excluded
#Can be administered from the agent console without portal access
#Script-based restore possible via VPR file
#Threat detection feature can be used<br>
<br>
<br>
'''Disadvantages:''' <br>
[[File:Erneute Sicherungsversuche.png|500px|border]]
#Slower with lots of small files
<span id="Tägliche_und_monatliche_Sicherung"></span>
#Navigation via portal when restoring individual files
=== Daily and Monthly Backup ===
==== Best Practice ====


<pre style="color: green">
This schedule runs one backup per day, using a Daily or Monthly retention type. <br>
1.In the best case scenario, use a file-based backup job only to back up individual files and folders
The last calendar day uses the Monthly retention type, and all other days use the Daily retention type.<br>
2.Add the “Entire Server” option to existing file-based BMR backup jobs
The time was configured identically due to the priority, so that every day except the last calendar day, line 1 does not apply and line 2 must be checked. <br>
3.Use an image-based job to configure new BMR backups
Since the conditions in line 2 are met on any other day, this is executed. <br>
4. File-based backup jobs are only recommended for up to a million files; above a million files we recommend an image backup job
This configuration prevents daily and monthly backups from being created on the last calendar day. <br>
</pre style="color: green">
<br>
<span id="Dateibasierten_Backup_Job_erstellen"></span>
'''Example configuration:''' <br>
==== Create file-based backup job ====
[[File:jobzeitplan.png|border|Create schedule|1000 px]]<br>
<span id="Vier_tägliche_Sicherungen"></span>
=== Four daily backups ===


Click on the “Jobs” tab. Then click “Create new job for local system”. <br>
This schedule runs four backups per day, with retention type "4xDaily".<br>
[[File:neuer job lokal.png|border|Create new job for local system]]<br>
The backup times were set at the beginning and end of the working day plus two additional backups within the working day. <br>
In the example configuration below, the backup is performed on the hour at 6 a.m., 9 a.m., 12 p.m. and 3 p.m.<br>
If the system data is changed 24/7, it is recommended to distribute it at equal intervals, e.g. E.g. 0/6/12/18<br>
<br>
<br>
The “Create new job” window opens.
'''Example configuration:''' <br>
[[File:Filebasierter-Job.jpg|framed|ohne]]<br>
[[File:Benutzerdefinierter Zeitplan.png|none|300 px]] <br>
<br>
<br>
Please first give the job a name. The name “BMR” (for Bare Metal Restore) is used in the example. <br>
[[File:4x-Daily.png|ohne|1000 px]]<br>
The default encryption algorithm is AES 256 bit, which is considered very secure. <br>
<span id="Sicherung_von_Clients_mit_den_Windows-Sicherungsereignisauslösern"></span>
=== Backing up clients using the Windows backup event triggers ===
 
Unlike a scheduled server backup, a client system's usage time can vary, making a fixed backup schedule less suitable. <br>
The Windows backup event triggers, which start the data backup dynamically depending on the time of triggering, are suitable for these purposes. <br>
The following Windows events can be selected as triggers: <br>
<br>
<br>
'''''Then enter an encryption password (maximum 31 characters). Resetting an encryption password is not possible!''''' <br>
'''Event:'''<br>
In the middle area you will find the directory structure that the agent transmits to the portal.
'''1. Shutdown'''<br>
Here you can easily select all the directories and folders you want to back up.
Before the system is shut down or restarted, the user receives a message asking whether the data backup should be performed before shutdown. <br>
In this example, the BMR and Entire Server options have been configured. Please note our
This not only backs up the actual system files, but also the bootloader. This means you can restore an entire server later.
With the “Bare Metal Restore” the entire ''c:\ system partition'' is backed up in addition to the data required for booting.
On the right you will then see the backup set. Objects marked with “+” are saved. If you would like to exclude individual data from the backup, <br>
select the file and click “Exclude”. Objects marked with “-” are excluded from the backup. <br>
Confirm the setting by clicking on “Create job”. <br>
A window will then automatically open to configure the schedule. <br>
<span id="Komplexe_Exklusionen/Inklusionen_in_dateibasierten_Jobs_konfigurieren"></span>
==== Configure complex exclusions/inclusions in file-based jobs ====
 
The following instructions can be used for both local file-based backup jobs and UNC jobs (network shares). <br>
When configuring one of the job types mentioned above, the portal can only be excluded or included to a limited extent. <br>
Using the Backup Portal, you can only select one directory per exclusion entry in the job configuration and exclude folders and/or files in the respective subdirectory.
This means that the entry only applies to the level below. <br>
<br>
<br>
'''Example complex exclusion:'''<br>
'''2. Login'''<br>
You want to exclude all directories that end with _Backup in a backup job because they
A user login starts the data backup. <br>
Contains data backups that should not be included in the TERRA CLOUD backup.
<code>D:\Data\*\*\*_Backup\*.*</code>
In this exclusion there are two levels of different directories, each containing subdirectories ending in _Backup.
These directories and their contents are excluded using the syntax shown.
However, this complex exclusion expression cannot be configured in the portal and must therefore be copied manually into the job's configuration file.<br>
<br>
<br>
'''Deposit exclusion in the job configuration:''' <br>
[[File:Backup vor dem Herunterfahren.png|border|ohne]]<br>
1. Configure any exclusion <br> for the job
<br>
2. Stop both TERRA CLOUD Backup Agent <br> services
'''Waiting time between backups:'''<br>
3. Open the JOBNAME.vvc file in the agent installation directory <br>
The triggering can be limited to once or twice a day, for example. B. If you restart multiple times, you won't be asked for a backup every time you restart.
4. Swap the exclusion created by step 1 with the one you want as in the following example <br>
<br>
Exclude = "D:\*\*\*_Backup\*.*"
[[File:Alternative_Backup_Trigger.png|border|900px|ohne]]
5. Start both services again <br>
<span id="TERRA_CLOUD_BACKUP_Enterprise:_High_Frequent_Backup_-_Stündliche_Sicherungen"></span>
6. In the Backup Portal, check the job configuration and schedule and save it again if necessary
=== TERRA CLOUD BACKUP Enterprise: High Frequent Backup - Hourly backups ===
7. If you modify it manually, you will receive a warning in the Backup Portal, which you can simply confirm <br>
8. After confirming the warning, please check whether the configuration has been applied as desired <br>
For a complex inclusion, you can use these instructions analogously.
<span id="Bedrohungserkennung"></span>
==== Ransomware Threat Detection ====


This file-based backup option allows the agent to scan the system for potential threats during backup. <br>
The High Frequency Backups feature enables hourly backups and thus an RPO of 60 minutes. <br>
If a possible threat is detected, the data backup is marked as a “potential threat”. <br>
Hourly backups must be created with retention types [https://wiki.terracloud.de/index.php/Backup/en#Preconfigured_retention_types Retention Types "24-Hours" and "48-Hours"] using the "Intraday" schedule view. <br>
The current and all subsequent backups will retain this flag until one of the actions is taken. <br>
In the example shown below, all 50 safesets of the [https://wiki.terracloud.de/index.php/Backup/en#Consumption_values_of_the_active_safe_sets inclusive quota] are scheduled. <br>
Note: The agent does not check for possible errors in a seed backup or the first backup
It was assumed that most changes to the data set are made between 9 a.m. and 5 p.m.<br>
Ransomware threats when threat detection is enabled in a job.
<br>
[[File:Ransomware-1.png|border|1200px]]<br>
This schedule performs a total of eleven backups per day in the following distribution:
 
* Nine backups are performed hourly between 9 a.m. and 5 p.m. with the retention type "24-Hours"
<span id="Handhabung_von_potenziellen_Bedrohungen"></span>
* One backup at 8 p.m. with the retention type "Daily" or on the last calendar day "Monthly"
==== Handling potential threats ====
<br>
 
'''Note:'''<br>
If ransomware threat detection fails, the following options are available through the Manage Potential Threat action. <br>
Please note that the hourly backups may only be used in conjunction with a TERRA CLOUD Backup Enterprise Vault. <br>
[[File:Ransomware-2.png|border|250px|ohne]]<br>
<br>
'''Example configuration:''' <br>
# Please add a new line to your schedule using "Add schedule"
# Select the "Intraday" schedule view for this line
# Configure how often the high-frequency backup should back up within a day, e.g. every full hour between 9 a.m. and 5 p.m. (see screenshot)
# Confirm the configuration with "OK".
# Finally, you can decide how long the data backups should be kept using the two new retention types available, 24-hours and 48-hours
<br>
[[File:Untertägiger Zeitplan.png|framed|ohne]]
<br>
<br>
1. The "Recovery" option allows you to configure granular recovery and delete the infected backup individually after recovery.
'''Full schedule:'''
[[File:Ransomware-3.png|border|350px|ohne]] <br>
[[File:Ohne Retries Zeitplanansicht.jpg|border|none|1200 px]]
<br>
<br>
2. In case of a hoax, you can select the "Delete a potential threat alert" option and confirm the deletion of the alert.
<span id="TERRA_CLOUD_BACKUP_Enterprise:_10_Jahres_Aufbewahrung"></span>
[[File:Ransomware-4.png|border|350px|ohne]] <br>
=== TERRA CLOUD BACKUP Enterprise: 10 years retention ===
<span id="Imagebasiertes_Backup"></span>
=== Image-based backup ===


<span id="Funktionsweise"></span>
The sample schedule shown below includes all 50 safesets of the [https://wiki.terracloud.de/index.php/Backup/en#Consumption_values_of_the_active_safe_sets Included quota].<br>
==== How it works ====
It is assumed that all documents to be archived will be stored on the system and backed up by December 31st.
<br>
This schedule performs one data backup per day at 11:30 PM with the following retention types:
* Daily on all days of the month except the last day
* Monthly on the last day of the month, from January to November
* Yearly on the last day of the year
'''Note on the Yearly Retention Type'''<br>
The "Yearly" retention type was added as the default retention type in February 2026.<br>
<br>
'''Sample Schedule:''' <br>
[[Datei:Zeitplan + Archivfunktion.png|border|1000 px]]
<br>
<span id="Job_manuell_ausführen"></span>
==Run job manually ==


In contrast to a file-based backup job, which protects individual files and folders when backing up,
If you wish, you can also run jobs manually. <br>
an image job backs up all blocks of a selected volume. It is possible to set up a BMR backup if all system-relevant volumes are backed up.
[[File:manuell ausfuehren.png|1600px|border|Run job manually]] <br>
==== Changed Block Tracking ====
<br>
Click “Start Backup”. <br>
[[File:job ausfuehren.png|border|Run job]] <br>
<br>
Completed backup process: <br>
[[File:Prozessdetails.png|border|Process Details]] <br>
<br>
Since the agent is able to compress, in this case only 14.27 GB of data was transferred and stored in the vault for a complete Windows Server 2025 VM. The original size of the system is 33.95 GB. <br>
This is an initial backup, as 33.95 GB is also stored under Changed. <br>
We can also see under the “Jobs” tab that the backup process was completed successfully: <br>
[[File:Erfolgreich abgeschlossen.png|border|Backup Status Completed Successfully]]<br>
<br>
Further details can be viewed by clicking on “Completed” in the middle. <br>
<span id="Zurückstellungsfunktion"></span>
== Defering function ==


The image plug-in installs a changed block tracking driver, which requires a restart after installation. This can be used to determine which blocks have changed in relation to the last backup.
The deferral function allows you to split the initial backup into multiple backup stages. <br>
<span id="Vor-_und_Nachteile_Imagebasiert"></span>
After the specified time window (e.g., 8 hours) has elapsed, an incomplete safeset is created. <br>
==== Advantages and Disadvantages Image-based====
The blocks not yet backed up are "deferred" and can be backed up in the next backup stage. <br>
 
You will receive a warning at the end of the backup that the deferral is still active.<br>
'''Advantages:''' <br>
Please select the "Use deferral" option and specify a backup time window of at least 15 minutes to a maximum of 48 hours. <br>
#BMR backup possible
This function can be used for both manual and scheduled execution. <br>
#Faster for lots of small files
[[Datei:Zurückstellung.png|gerahmt|ohne]]<br>
#Recommended for natively protected data volumes of 1TB or more
<p style="color: red"><br>
#Requires less processing power than file-based backup
#Convenient Restore (Image is attached)
#Navigation via Explorer when restoring<br>
<br>
<br>
'''Disadvantages:''' <br>
'''Important:''' <br>
#Exclusion of individual files and folders is not possible
A backup with the resume function enabled results in an incomplete backup if interrupted.<br>
#Restore only possible on disks of the same size/larger
For '''file-based''' backups, data successfully backed up prior to the interruption can be restored.<br>
#Restart required after plugin installation
For '''image-based''' backups, however, restoration is only possible if the backup has been fully completed.<br>
#No granular troubleshooting possible
</p>
#ReFS is not supported
#Threat detection feature cannot be used
==== Best Practice ====
 
<pre style="color: green">
1. The restart can be done at a later point in time (usually after the end of work). The agent can be configured without restarting.
2. To protect the entire system, including the possibility of a bare metal restore, select the "Entire Server" and "BMR" options.
3. If data (such as local backups / dumps) needs to be excluded, you can move it to a separate volume and explicitly not include this volume in the backup set. The "Entire Server" option cannot be used in this case.
</pre style="color: green">
<span id="Imagebasierten_Backup_Job_erstellen"></span>
==== Create image-based backup job ====
 
'''Requirement:''' <br>
The image plug-in must be installed on the system.
If the plug-in is not yet installed, you can run the agent setup again and use the "change" option to install the plug-in later.<br>
<br>
<br>
'''Create job:''' <br>
'''Recommendation:''' <br>
In the backup portal, please select the image job under "Select job task" as shown in the following screenshot:
The deferral function can be used '''exclusively''' for the initial backup. You can select the deferral during manual execution or specify it in the schedule.
[[File:Image Job erstellen 1.png|framed|ohne]]<br>
We recommend adding a reminder in the agent description that the deferral function is active in the schedule. After the first successful backup without deferral, you can remove the function from the schedule and the reminder from the agent description.
[[Datei:Zurückstellung im Zeitplan.png|gerahmt|ohne]]<br>
<br>
<br>
'''Configure job:''' <br>
The deferral can be used to split the initial backup or seed backup into multiple backup operations. You will receive a warning in the log file until the backup job has completed completely. For a BMR job, BMR protection is only provided after the first successful completion without deferral.<br>
In this screenshot you can see an example configuration from an image job. In this, the “Bare Metal Restore” and “Entire Server” options were selected and included in the backup set. <br>
Instead of showing the file system, the agent only shows individual volumes. <br>
[[File:Image-Job-erstellen-1.jpg|framed|ohne]]<br>
<br>
<br>
'''Application Aware Backup' option:''' <br>
'''Example:''' <br>
In addition to a BMR backup, this option also enables the transaction logs of a Microsoft SQL Server to be truncated and backed up.
In order to use this, you must provide the access data required for the SQL instance.
We recommend not using this option and using your own SQL job for a comprehensive backup of a SQL instance.<br>
<br>
<br>
'''Entire Server' option:''' <br>
'''Day 1:''' <br>
If you add this option to the backup set, all partitions (volumes) of a system will be included in the backup. This excludes removable storage media (e.g. external hard drives or USB sticks). Partitions (volumes) added later are automatically included; there is no need to adjust the configuration.<br>
The backup job is started with a deferral for the first time and completes the backup after a defined period of 8 hours, and Safeset 1 has been created. <br>
<br>
'''Day 2:''' <br>
The backup is started again and creates Safeset 2 after 8 hours. <br>
<br>
<br>
'''Note:''' <br>
'''Day 3:'''<br>
<pre style="color: red">For an image-based backup job, BMR protection is automatically provided by the "Entire Server" option, but in order to be able to offer a standard configuration for file- and image-based backup jobs, the option was changed BMR additionally added in the screenshot above. </pre style="color: red">
On the third run, the backup job completes before the 8-hour period, Safeset 3 is created, and the seed backup is successfully completed. <br>
=== UNC-Backup Job ===
The status of the backup job changes from "Deferred with Warnings" to "OK". <br>
= '''Windows Agent''' =


<span id="Dokumentation"></span>
<span id="Dokumentation_Windows_Agent"></span>
==== Documentation ====
== Documentation Windows Agent ==


Complete setup instructions can be found in the [https://drive.terracloud.de/dl/fiVM8MnznhjtvF6Fo5d81P/Agent%20v9.2%20for%20Microsoft%20Windows%20-%20User%20Guide.pdf?inline User Guide of the Windows Agent ] Chapter 5.4.  
You can find extensive documentation and further information in [https://drive.terracloud.de/getlink/fi8mnw3UmM5mSru5xADtxU/Windows%20Agent Windows Agent User Guide].
<span id="Funktionsweise"></span>
== Installation ==
==== How it works ====


The Windows agent connects to the stored network share and saves the selected files. For authentication, a user must be provided with read and write permissions.
<span id="Installation_über_das_Setup"></span>
==== Best Practice ====
=== Installation via Setup ===


<pre style="color: green">
Please download TERRA Backup Agent. To do this, log in to your portal and select the appropriate version under Downloads on the right. <br>
1. A UNC backup job should protect a maximum of 500,000 files or 1 TB of native data. If more data needs to be backed up, we recommend distributing it across several UNC backup jobs.
[[File:Agent Sprache.png|border|Select language]] <br>
2. Since backing up a network share via a DFS namespace is not supported, we recommend backing up the server share directly without using the namespace.
3. Recommended backup method for files stored on NAS systems (e.g. from Synology, QNAP).
</pre style="color: green">
<span id="Zeitplan"></span>
=== Schedule Recommendations ===
 
The schedule determines when a data backup should be started and with which retention type it should be saved. <br>
The following articles go into more detail about various recommended schedule configurations. <br>
<span id="Erneute_Sicherungsversuche"></span>
==== Renewed backup attempts ====
 
The “''Automatic restart for time-controlled backup''” function offers the option of restarting an incorrect or failed data backup. <br>
This can be particularly helpful if, for example, in the first backup attempt. B. a Microsoft VSS shadow copy cannot be created. <br>
We recommend waiting a few minutes between backup attempts so that e.g. B. Load peaks can be avoided. <br>
<br>
<br>
[[File:Erneute Sicherungsversuche.png|1000px|border]]
Now start the installation on the server to be backed up. First select the desired language in which you would like to be guided through the installation. <br>
 
[[File:Agent Assistent.png|border|Click Next]] <br>
<span id="Tägliche_und_monatliche_Sicherung"></span>
==== Daily and Monthly Backup ====
 
This schedule runs one backup per day, using a Daily or Monthly retention type. <br>
The last calendar day uses the Monthly retention type, and all other days use the Daily retention type.
The time was configured identically due to the priority, so that every day except the last calendar day, line 1 does not apply and line 2 must be checked. <br>
Since the conditions in line 2 are met on any other day, this is executed. <br>
This configuration prevents daily and monthly backups from being created on the last calendar day. <br>
<br>
<br>
'''Example configuration:''' <br>
On the "Support Information and Release Notes" page, click Next<br>
[[File:jobzeitplan.png|border|Create schedule|1000 px]]<br>
[[File:Agent Supporthinweise.png|border|Support Notes]] <br>
<span id="Vier_tägliche_Sicherungen"></span>
==== Four daily backups ====
 
This schedule runs four backups per day, with retention type "4xDaily".
The backup times were set at the beginning and end of the working day plus two additional backups within the working day. <br>
In the example configuration below, the backup is performed on the hour at 6 a.m., 9 a.m., 12 p.m. and 3 p.m.
If the system data is changed 24/7, it is recommended to distribute it at equal intervals, e.g. E.g. 0/6/12/18<br>
<br>
<br>
'''Example configuration:''' <br>
Accept the license terms and click Next. <br>
[[File:Benutzerdefinierter Zeitplan.png|none|300 px]] <br>
[[File:Agent Lizenzbestimmungen.png|border|Confirm License Terms]] <br>
<br>
<br>
[[File:4x-Daily.png|ohne|1000 px]]<br>
In the next installation step, select “Custom” and click Next. <br>
<span id="Sicherung_von_Clients_mit_den_Windows-Sicherungsereignisauslösern"></span>
[[File:Agent Benutzerdefiniert.png|border|Setup type]] <br>
==== Backing up clients using the Windows backup event triggers ====
 
Unlike a scheduled server backup, a client system's usage time can vary, making a fixed backup schedule less suitable. <br>
The Windows backup event triggers, which start the data backup dynamically depending on the time of triggering, are suitable for these purposes. <br>
The following Windows events can be selected as triggers: <br>
<br>
<br>
'''Event:'''<br>
The local logon credentials can usually be adopted. Click on Continue. <br>
'''1. Shutdown'''<br>
[[File:Agent lokales System.png|border|Logon Credentials]] <br>
Before the system is shut down or restarted, the user receives a message asking whether the data backup should be performed before shutdown. <br>
'''2. Login'''<br>
A user login starts the data backup. <br>
<br>
<br>
[[File:Backup vor dem Herunterfahren.png|border|ohne]]<br>
Select the desired installation directory. Then click Next. <br>
[[File:Agent Pfad.png|border|Select path]] <br>
<br>
<br>
'''Waiting time between backups:'''<br>
In addition to the actual backup agent, other plug-ins can be installed. Depending on the type of server, individual Microsoft SQL database instances or Exchange mailboxes can be backed up. <br>
The triggering can be limited to once or twice a day, for example. B. If you restart multiple times, you won't be asked for a backup every time you restart.
Select the plug-ins you want and then click Next. <br>
[[File:Agent plugins.png|border|Plugins]] <br>
<br>
<br>
[[File:Alternative_Backup_Trigger.png|border|900px|ohne]]
In the dialog box that follows, you can specify how the agent should encrypt the data. You can retain the default settings here.<br>
<span id="TERRA_CLOUD_BACKUP_Enterprise:_High_Frequent_Backup_-_Stündliche_Sicherungen"></span>
[[File:Backup-DE-Agent-Datenverschluesselung.png|border|Data encryption]] <br>
==== TERRA CLOUD BACKUP Enterprise: High Frequent Backup - Hourly backups ====
 
The High Frequent Backups function enables hourly backups and thus an RPO of 60 minutes. <br>
Hourly backups must be created using retention types [[https://wiki.terracloud.de/index.php/Backup/en#Preconfigured_retention_types Retention Types|"24-Hours" and "48-Hours"]]. <br>
In the example shown below, all 50 safe sets of the [[https://wiki.terracloud.de/index.php/Backup/en#Consumption_values_of_the_active_safe_sets|Inclusive quota]] are planned. <br>
The assumption was made that most changes to the database are made between 9 a.m. and 5 p.m.<br>
<br>
<br>
This schedule runs a total of eleven backups per day in the following breakdown:
Enter the email address and password of the registration users or the user created in [https://wiki.terracloud.de/index.php/Backup/en#Create_user 5.2.1]. Confirm with Next. <br>
* Nine data backups run every hour between 9 a.m. and 5 p.m. with the retention type "24-Hours"
[[File:Agent login.png|border|Enter login information]] <br>
* A backup at 8:00 p.m. with the retention type "Daily" or on the last calendar day "Monthly"
<br>
<br>
'''Note:'''<br>
In the next step, you can set a default encryption password. This is required if you wish to use automatic agent configuration.<br>
Please note that hourly backups may only be used in conjunction with a TERRA CLOUD Backup Enterprise Vault. <br>
[[File:Backup-DE-Agent-Kennwort.png|border|Encryption password]] <br>
<br>
<br>
'''Example configuration:''' <br>
Confirm with Install. <br>
[[File:Ohne Retries Zeitplanansicht.jpg|border|1200 px]]
[[File:Agent bestaetigen.png|border|Install]] <br>
<br>
<br>
 
If you are then redirected back to agent registration, the access data you entered is probably incorrect or you are having problems with the <br>
<span id="TERRA_CLOUD_BACKUP_Enterprise:_Archivfunktion_-_10_Jahre_Aufbewahrung"></span>
Network connection. First try pinging backup.terracloud.de. If this works, you can use Telnet to check whether port 8086 can be reached. <br>
==== TERRA CLOUD BACKUP Enterprise: Archive function - 10 years retention ====
[[File:Agent fertigstellen.png|border|Complete installation]] <br>
 
The archive function allows data to be backed up per year for 10 years using the retention type [[https://wiki.terracloud.de/index.php/Backup/en#Archive_function|“Yearly”]].
<br>
<br>
In the example shown below, all 50 safe sets of the [[https://wiki.terracloud.de/index.php/Backup/en#Consumption_values_of_the_active_safe_sets|Inclusive quota]] are planned. <br>
After 5 minutes at the latest, the server you just registered should appear under “Computer” within your portal. <br>
It was assumed that all documents to be archived would be stored on the system and backed up on December 31st.
[[File:Computer sichtbar.png|1600px|border|List of computers in the portal]] <br>
<br>
<br>
This schedule runs one backup per day at 11:30 p.m. with the following retention types:
On the right side under “Site Name” you can read “End Customer1” in our case. This is because we registered the agent with the user backupkunde@endkunde1.de, <br>
* Daily on all days of the month except the last day
which belongs to the “End Customer1” subsite. This way we can now filter for computers that belong to the “End Customer1” subsite. This allows you to quickly list all computers in an organizational unit. <br>
* Monthly on the last day of the month, January to November
<span id="Silent_Installation_unter_Windows"></span>
* Yearly on the last day of the year
==== Silent installation under Windows ====
 
The agent can also be installed in silent mode. This is helpful if the agent is to be rolled out automatically on multiple systems. <br>
<br>
<br>
'''Note:'''<br>
'''An example of the silent installation including the image plug-in: <br>'''
Please note that the archive function may only be used in conjunction with a TERRA CLOUD Backup Enterprise Vault. <br>
''Agent-Windows-x64-x-xx-xxxx.exe /s /v" REGISTERWITHWEBCC=True AMPNWADDRESS=backup.terracloud.de AMPUSERNAME=backupkunde@firmaXYZ.de AMPPASSWORD=password FEATUREVOLUMEIMAGE=ON /qn"'' <br ><br>
'''Explanation:'''<br>
''Agent-Windows-x64-x-xx-xxxx.exe'': The agent (x64) setup is called.<br>
''REGISTERWITHWEBCC=True'': The agent should be registered on the backup portal.<br>
''AMPNWADDRESS=backup.terracloud.de'': The address of the backup portal is passed.<br>
''AMPUSERNAME=backupkunde@firmaXYZ.de'': The user of the customer site is transferred.<br>
''AMPPASSWORD=password'': The password you assigned for the customer site user.<br>
<br>
<br>
'''Example configuration:''' <br>
'''Parameters for plugins:'''<br>
[[File:Zeitplan + Archivfunktion.png|border|1000 px]]
Plug-ins can be added after the ''AMPPASSWORD'' separated by a space as in the example above.
Image Plugin: ''FEATUREVOLUMEIMAGE=ON''<br>
Exchange Plugin (Legacy): ''FEATUREEXCHANGE=ON''<br>
Exchange Plug-in (From 2010): ''FEATUREEXCHANGE2010=ON''<br>
SQL Plugin: ''FEATURESQL=ON''<br>
Cluster plugin: ''FEATURECLUSTER=ON''<br>
Oracle Plugin: ''FEATUREORACLE=ON''<br>
<br>
<br>
 
'''Installation in another directory:'''<br>
<span id="Job_manuell_ausführen"></span>
If required, please specify the following parameter directly after /s /v" to install in another directory:<br>
===Run job manually ===
''SILENTINSTALDIR=\"Path''
 
Example:<br>
If you wish, you can also run jobs manually. <br>
''SILENTINSTALLDIR=\"C:\Program Files\Example\''<br>
[[File:manuell ausfuehren.png|1600px|border|Run job manually]] <br>
<span id="Silent_Agenten-Registrierung"></span>
<br>
==== Silent Agent Registration ====
Click “Start Backup”. <br>
 
[[File:job ausfuehren.png|border|Run job]] <br>
The following PowerShell command is sufficient to re-register the agent with the portal:<br>
''& "C:\Program Files\TERRA Cloud Backup\Agent\buagent.exe" -cmdline --reregister --amplogin 'backupkunde@firmaXYZ.de' --amppassword 'USERPW' --ampserver 'backup.terracloud.de' --ampport 8086''
'''Note:'''<br>
Please replace the placeholder values ​​with your actual TERRA CLOUD Backup portal login credentials.<br>
<br>
<br>
Completed backup process: <br>
Afterwards, the TERRA Cloud Backup services must be restarted once.<br>
[[File:Prozessdetails.png|border|Process Details]] <br>
To do this, launch PowerShell with administrator privileges and enter the following command:<br>
''Get-Service -DisplayName "TERRA Cloud Backup*" | Restart-Service''<br>
<br>
<br>
Since the agent is able to compress, in this case only 7.13 GB of data was transferred and stored in the vault for a complete Windows Server 2016 VM. The original size of the system is 19.30. <br>
This is an initial backup, as 19.30 GB is also stored under Changed. <br>
We can also see under the “Jobs” tab that the backup process was completed successfully: <br>
[[File:Erfolgreich abgeschlossen.png|border|Backup Status Completed Successfully]]
Further details can be viewed by clicking on “Completed” in the middle. <br>


<span id="Zurückstellungsfunktion"></span>
<span id="Installation_per_PowerShell_Skript"></span>
=== Defering function ===
=== Installation via PowerShell script ===


The deferral option allows a backup to be completed after a defined period of time, regardless of how much data from the initial backup has already been transferred. <br>
To achieve a fully automated installation of the TERRA CLOUD Backup Windows Agent, we developed the following PowerShell script and made it available in the download area of ​​the TERRA CLOUD Backup portal:<br>
After the defined security window of, for example, eight hours, a safeset is created.
A deferral can be defined in the schedule and in manual execution:
[[File:Zurückstellung.png|framed|ohne]]<br>
<p style="color: red"><br>
<br>
<br>
'''Important:''' <br>
[[Datei:Install-TCBWindowsAgent.png|border|Install-TCBWindowsAgent]]<br>
A backup with active deferral results in an incomplete backup. <br>
Restoring from a backup with active holdback can only be done for a file-based job.
</p>
<br>
<br>
'''Recommendation:''' <br>
'''Functions:'''
The defer feature can be used '''exclusively''' for initial backup. You can select the deferral during manual execution or store it in the schedule.
* Port check TCP 8086/8087
We recommend placing a reminder in the agent description that the defer feature is active in the schedule. After the first successful completion of the backup without deferral, you can remove the feature from the schedule and the reminder from the agent description.
* Check for pending restarts
[[File:Zurückstellung im Zeitplan.png|framed|ohne]]<br>
* Download the current setup
* Install the agent and register it with the portal
* Initiate automatic agent configuration, if configured in the portal<br>
<span style="color:red"> Administrator rights in PowerShell are required to run this script. It may also be necessary to unlock the script file after downloading by right-clicking and selecting Properties.</span><br>
<br>
<br>
Deferral can be used to split the initial backup or seed backup into multiple backup operations. You will receive a warning in the log file until the backup job has been completely completed. With a BMR job, BMR protection is only available after the first successful completion without deferral.<br>
Parameters:<br>
SiteUser: Site username<br>
SiteUserPassword: Site user password<br>
JobEncryptionKey: Encryption password for jobs to be created, provided automatic agent configuration has been configured on the customer site<br>
<br>
<br>
'''Example:''' <br>
Plug-in Parameters:<br>
ExchangeLegacy: Exchange Plug-in (Legacy)<br>
Exchange: Exchange Plug-in (2010 and later)<br>
SQL: SQL Plug-in<br>
Cluster: Cluster Plug-in<br>
Oracle: Oracle Plug-in<br>
<br>
<br>
'''Day 1:''' <br>
Execution via PowerShell (without plug-ins):<br>
The backup job is started for the first time with a deferral and ends the backup after a defined period of 8 hours and Safeset 1 has been created. <br>
.\Install-TCBWindowsAgent.ps1 -SiteUser "register@terracloud.de" -SiteUserPassword "Password123!" -JobEncryptionKey "Terra456#"<br>
<br>
<br>
'''Day 2:''' <br>
'''Execution via PowerShell (with plugins):'''<br>
The backup will start again and create Safeset 2 after 8 hours. <br>
.\Install-TCBWindowsAgent.ps1 -SiteUser "register@terracloud.de" -SiteUserPassword "Password123!" -JobEncryptionKey "Terra456#" -SQL<br>
<br>
.\Install-TCBWindowsAgent.ps1 -SiteUser "register@terracloud.de" -SiteUserPassword "Password123!" -JobEncryptionKey "Terra456#" -Exchange<br>
'''Day 3:'''<br>
<span id="Agent_mit_dem_Vault_verknüpfen"></span>
On the third run, the backup job completes before the 8 hour period, Safeset 3 is created and the seed backup is completed successfully. <br>
==Associate Agent with Vault ==
The status of the backup job changes from "Postponed with Warnings" to "OK". <br>
<span id="Wiederherstellung_eines_Backup-Jobs"></span>
== '''Restore a backup job''' ==


After backing up data from a system, you can select “Restore” under “Actions” in the backup jobs.
Every newly registered computer is initially displayed as “Not configured” in the portal. First, at least one vault (data safe) must be assigned to the computer. <br>
=== Windows ===
Click on the server you want to configure (DC in this example). This will open the settings for this computer. Then click on “Configure manually” on the right. <br>
[[File:Manuelle Konfiguration.png|border|Manual Configuration]] <br>
<br>
Now click on “Add Vault” on the right.<br>
Then select the Vault profile created in [https://wiki.terracloud.de/index.php/Backup/en#Configure_Vault_Profiles 4.2.1] under “Vault profile”, in our case this is “Vault_Endkunden1”. All fields should then be automatically filled with the set values. <br>
[[File:Vault Einstellungen1.png|border|Vault Settings]] <br>
<br>
The agent establishes a test connection to the vault.<br>
If the connection cannot be established, for example because incorrect access data was entered, you will receive an error message. <br>
If everything is OK, the vault will now appear under the “Vault Settings”. <br>
[[File:Vault Einstellungen uebersicht.png|1600px|border|Overview]] <br>
In addition to the portal, the Windows agent can also be started via command line or script.<br>
Agent scripting is recommended, for example, to stop non-VSS-capable databases before backup (MySQL, MariaDB, etc.)
<span id="Job_erstellen"></span>
== Create job ==


<span id="Wiederherstellung_von_einer_filebasierten_Sicherung"></span>
<span id="Dateibasierten_Backup_Job_erstellen"></span>
==== Restore from a file-based backup ====
=== Create file-based backup job ===


Click on the “Jobs” tab. Then click “Create new job for local system”. <br>
[[File:neuer job lokal.png|border|Create new job for local system]]<br>
<br>
<br>
[[File:1 Wiederherstellung bmrlokal.png|border|file-based recovery]] <br>
The “Create new job” window opens.
[[File:Filebasierter-Job.jpg|framed|ohne]]<br>
<br>
<br>
You can use the calendar button to select the safeset from which you want to restore the data. <br>
Please first give the job a name. The name “BMR” (for Bare Metal Restore) is used in the example. <br>
Enter the job's encryption password. The Hint button displays your password hint once clicked. <br>
The default encryption algorithm is AES 256 bit, which is considered very secure. <br>
The folders and files to be restored can be set using check boxes for complete folders or files and then included in the recovery using “Include”. <br>
With the search function it is possible to search for specific files without looking for the file path. <br>
The wildcard characters * (for any number of characters) and ? (for a single character). <br>
However, the question mark cannot be used for an umlaut (ö,ä,ü). Select the appropriate files and add them to the recovery by clicking “Include Selected”. <br>
To search for files in a specific backup folder, enter the desired path in the Search Path field. <br>
When you include a folder in a restore, the subdirectories and files in that folder are also included by default. <br>
If you only want to restore a portion of the subdirectories or files in a folder, you can add filters to the include record. <br>
It is also possible, for example, to add a filter to restore only files with .doc or .docx extensions in a folder. <br>
If you exclude a folder from a restore, the subdirectories and files in that folder are also excluded by default. <br>
If you only want to exclude a portion of the subdirectories or files in a folder, you can add filters to the exclude record. <br>
For example, you can add a filter to exclude only files with .exe extensions in a folder from recovery. <br>
<br>
<br>
[[File:2 Nach Dateien suchen.png|border|Search for files]]<br>
'''''Then enter an encryption password (maximum 31 characters). Resetting an encryption password is not possible!''''' <br>
In the middle area you will find the directory structure that the agent transmits to the portal.<br>
Here you can easily select all the directories and folders you want to back up.<br>
In this example, the BMR and Entire Server options have been configured.<br>
This not only backs up the actual system files, but also the bootloader. This means you can restore an entire server later.<br>
With the “Bare Metal Restore” the entire ''c:\ system partition'' is backed up in addition to the data required for booting.<br>
On the right you will then see the backup set.<br>Objects marked with “+” are saved.<br>If you would like to exclude individual data from the backup, <br>
select the file and click “Exclude”. Objects marked with “-” are excluded from the backup. <br>
Confirm the setting by clicking on “Create job”. <br>
A window will then automatically open to configure the schedule. <br>
<span id="Imagebasierten_Backup_Job_erstellen"></span>
=== Create image-based backup job ===
 
'''Requirement:''' <br>
The image plug-in must be installed on the system.
If the plug-in is not yet installed, you can run the agent setup again and use the "change" option to install the plug-in later.<br>
<br>
<br>
You have the options to restore the files to the original location or to an alternative location. <br>
'''Create job:''' <br>
If you decide to use an alternative storage location, you can use the folder button to select the desired storage location.<br>
In the backup portal, please select the image job under "Select job task" as shown in the following screenshot:
You also have the options to overwrite existing files, not overwrite (this adds a numeric extension, e.g. .0001), rename incoming files and rename existing files.<br>
[[File:Image Job erstellen 1.png|framed|ohne]]<br>
<br />
<span id="Vorhandene_Daten_überschreiben"></span>
==== Overwrite existing data ====
 
If you try to restore multiple files with the same name to an alternate location and select Overwrite Existing Files, only the last file restored will be retained.<br>
Other files with the same name will be overwritten. To add a numeric extension (e.g. .0001) to a recovered filename, select Do not overwrite existing files.<br>
For example, if you restore a file named "filename.txt" to a location where there is a file with the same name, an extension is added to the restored file name (for example, "filename.txt.0001"). <br>
<p style="color: #FF0000;">
Under no circumstances should you select the entire C: volume and let it overwrite the existing volume. This will result in serious damage to the system!
</p>
<span id="Vorhandene_Dateien_umbenennen"></span>
==== Rename existing files ====
 
To add a numeric extension (e.g. .0001) to an existing filename, select Rename Existing Files. <br>
For example, if you restore a file named "filename.txt" to a location where there is a file with the same name, an extension is added to the existing file name (for example, "filename.txt.0001"). <br>
The name of the restored file is still “filename.txt”. <br>
<br />
<span id="Erweiterte_Wiederherstellungsoptionen"></span>
==== Advanced Recovery Options ====
 
<br>
<br>
[[File:3 Erweiterte Wiederherstellungsoptionen.png|border|Advanced Recovery Options]]<br>
'''Configure job:''' <br>
In this screenshot you can see an example configuration from an image job. In this, the “Bare Metal Restore” and “Entire Server” options were selected and included in the backup set. <br>
Instead of showing the file system, the agent only shows individual volumes. <br>
[[File:Image-Job-erstellen-1.jpg|framed|ohne]]<br>
<br>
<br>
[[File:4 Erweiterte Wiederherstellungsoptionen.png|border|Advanced Recovery Options Part 2]]<br>
'''Application Aware Backup' option:''' <br>
<br />
In addition to a BMR backup, this option also enables the transaction logs of a Microsoft SQL Server to be truncated and backed up.
<span id="Optionen_für_gesperrte_Dateien"></span>
In order to use this, you must provide the access data required for the SQL instance.
==== Locked File Options ====
We recommend not using this option and using your own SQL job for a comprehensive backup of a SQL instance.<br>
 
When restoring data from a local job, you can specify whether locked files should be overwritten by restored files with the same name. <br>
To do this, select one of the following options:<br>
<br>
<br>
*''' "Yes, overwrite locked files" '''<br>
'''Entire Server' option:''' <br>
Files in the system that are locked during recovery will be overwritten with the recovered files upon reboot. This option must be enabled for system state or system volume restores. <br>
If you add this option to the backup set, all partitions (volumes) of a system will be included in the backup. This excludes removable storage media (e.g. external hard drives or USB sticks). Partitions (volumes) added later are automatically included; there is no need to adjust the configuration.<br>
<br>
<br>
*''' "No, do not overwrite locked files" '''<br>
'''Note:''' <br>
Files in the system that are locked during recovery will not be overwritten with the recovered files with the same name upon reboot.
<pre style="color: red">For an image-based backup job, BMR protection is automatically provided by the "Entire Server" option, but in order to be able to offer a standard configuration for file- and image-based backup jobs, the option was changed BMR additionally added in the screenshot above. </pre style="color: red">
<br />
<span id="UNC_Backup_Job_erstellen"></span>
==== Streams ====
=== Create UNC Backup Job ===


When you run backups, information from your files is captured in different streams. <br>
In the '''TERRA CLOUD Backup Portal''', first navigate to '''Computers''' and select the relevant computer.<br>
The original data created by a user is called a data stream. <br>
Then, switch to the '''Jobs''' tab and select '''Select job task → Create UNC file job'''.<br>
Other information such as security settings, data for other operating systems, file references and attributes are stored in separate streams. <br>
[[Datei:Backup-DE-UNC Job (1).png|1000px|none]]<br>
When restoring data from a local job, you have the following options to choose from: <br>
In the window that follows, enter the required access credentials to establish a connection to the UNC share.<br>
The '''Domain''' field is optional and is only required if a domain is needed for authentication.<br>
[[Datei:Backup-DE-UNC Job (2).png|1000px|none]]<br>
Once the connection is successfully established, you will proceed to the actual job configuration.<br>
Assign a '''Name''' for the backup job and enter the desired '''Encryption password'''.<br>
You can optionally provide a '''Password hint'''.<br>
Next, you can define the desired '''Backup set'''.<br>
To do this, expand the previously entered UNC share in the central area and select the folders or files to be backed up.<br>
Then click '''Include''' to add the selected data to the backup set.<br>
If necessary, you can also define '''Exclusions''' to omit specific files or folders from the backup.<br>
[[Datei:Backup-DE-UNC Job (5).png|800px|none]]<br>
You can use the '''UNC credentials''' button to modify the previously entered access credentials for the UNC share if needed.<br>
Additional UNC shares can be added to the backup job using the '''Add UNC share''' button.<br>
<br>
<br>
*'''"Restore all streams"''' <br>
<span id="Erweiterte_Agentenkonfiguration"></span>
Restores all information streams. Use this option when restoring files to a system with an identical platform.<br>
== Advanced Agent Configuration ==
 
Individual settings can be configured for each computer. These include, for example: B. Mail notification and bandwidth limitation. <br>
Go to “Computer” in the portal. Select a server and then click on “Advanced” to make specific settings. <br>
[[File:Erweiterte Agentenkonfiguration.png|border|1500px|Overview of Advanced Agent Configuration]]<br>
<br>
<br>
*'''"Restore data streams only"''' <br>
'''Options:'''<br>
Select this option for cross-platform restores. With this option, conflicts do not arise due to system-specific data streams.
Under this point you can add a description to the system, for example: B. to store the ticket number in the description in a support case.<br>
We recommend the option “Log errors and stop backup” for current Windows agents; this is the default setting after installation or update.<br>
The option "Log errors and continue backup" offers the advantage that backups can also be carried out if, for example, B. VSS problems can sometimes go through. <br>
The files not backed up in this job will result in an increased delta afterwards.<br>
<br>
'''Retention Types:'''<br>
The currently stored retention types are displayed here; after installation, "4xDaily", "Daily", "Monthly" and "Yearly" are stored by default.<br>
You can use this tab to create your own storage types, which you can then choose from in the schedule.<br>
When configuring, please note that 50 safe sets per job are included free of charge.<br>
<br>
'''Notifications (agent side):'''<br>
As of August 2021, the “Notifications” tab is only available if an agent-side mail notification is already configured. <br>
This agent function has been replaced by the [https://wiki.terracloud.de/index.php/Backup/en#Configure_notifications Notification via the TERRA CLOUD Backup Portal].<br>
<br>
'''Enable agent-side notification manually:'''<br>
If you want to continue using agent-side notification, you can configure it using the following steps. <br>
1. Stop the "TERRA Cloud Backup Agent" and "TERRA Cloud Backup BUAgent" <br> services on the desired system.
2. Open the "global.vvc" file in the TERRA CLOUD Backup Agent <br> installation directory.
3. Please add the following lines, if they are not present, after the curly braces of the "OpenFile" block:
  notification {
  MailOnError = True
  MailOnFailure = True
  MailOnSuccess = True
  }
4. Start the services "TERRA Cloud Backup Agent" and "TERRA Cloud Backup BUAgent" <br> on the desired system.
5. Open the TERRA CLOUD Backup Portal and update your browser if necessary.
6. Complete the configuration using the “Notification” tab, which is now visible again.
<br>
'''Performance:'''<br>
Bandwidth limitation and execution priority can be configured under this point. <br>
According to current knowledge, changing the execution priority has no noticeable effect, so we recommend keeping the default value.<br>
Bandwidth limitation is particularly recommended for weak connections during your customer's working hours.<br>
At least 1.5 Mbps should be allocated for a backup.<br>
<br>
'''Agent log files:''' <br>
Under this tab you can view all global (cross-job) log files of the agent, which can be helpful for troubleshooting.<br>
For example, log files of the BUAgent can be viewed; this service (TERRA Cloud Backup BUAgent) is responsible for the agent's communication with the backup portal.<br>
<br />
<br />
<span id="Protokolloptionen"></span>
<span id="Aktualisierung_des_Agenten"></span>
==== Protocol options ====
== Agent Update ==
 
The TERRA CLOUD Backup Agent can be updated as follows:
<br>
'''Windows (manually):''' <br>
*Starting with agent version 8, the agent can be updated directly via the setup of the newer agent version.
*When you start a setup of a newer agent, you will be asked if you want to perform an update.
:[[Datei:Agent-Update.png|border|Update durchführen]]<br><br>
<br>
'''Windows (Agent Upgrade Center):''' <br>
You can update multiple agents centrally via the TERRA CLOUD Backup Portal. Instructions can be found at: <br>
[https://wiki.terracloud.de/index.php/Backup/en#Agent_Upgrade_Center Agent Upgrade Center]
<span id="Wiederherstellung_eines_Backup-Jobs"></span>
== Restoring a Backup Job ==


From the list, select one of the following logging levels:
<span id="Wiederherstellung_von_einem_File_Level_Job"></span>
*Files: Provides more detailed information and is typically used for troubleshooting. Provides information about files that are being restored. <br>
=== Restore from a file-based backup ===
*Directory: Provides less detailed information than the Files logging level. Provides information about folders that will be restored. <br>
*Summary: Provides top-level information including Vault/Agent version and backup size. <br>
*Minimal: Provides top-level information including Vault/Agent version. <br>
Changing the logging level only affects log files that are created afterwards. Log files that have already been created are not affected by this change. <br>
<br />
<span id="Leistungsoptionen"></span>
==== Performance options ====


To use all available bandwidth for recovery, select "Use all available bandwidth." <br>
Bandwidth throttling determines how much bandwidth an agent can consume for backups and restores.<br>
For example, you can limit traffic so that online users are not impacted and allow unrestricted usage at night so that scheduled backups or restores can occur as quickly as possible. <br>
Bandwidth throttling values are set at the machine (or agent) level and apply to backups and restores. <br>
When three jobs are running simultaneously on a computer, each job receives 1/3 of the specified maximum bandwidth. <br>
Possible bandwidth settings: Maximum bandwidth (upper limit) in MB per second that the agent is allowed to consume for all backups and restores. <br>
Period of time during the day when throttling is activated. Only one time window can be specified. <br>
There is no throttling outside the time window. The days of the week that throttling is enabled. <br>
Once the bandwidth throttling window begins during an ongoing backup or restore, the maximum bandwidth is dynamically applied to the running process. <br>
If the throttling window ends while a backup or restore is in progress, bandwidth throttling is removed. <br>
If you change an agent's bandwidth settings while a backup or restore is in progress, the new settings do not affect the ongoing process. <br>
The bandwidth settings are applied when the backup or restore starts and are not changed afterwards. <br>
<br />
<span id="Wiederherstellung_von_einem_anderen_Computer_(filebasiert)"></span>
==== Restore from another computer (file based) ====
It is possible to restore some or all of the data backed up on one computer to another computer with the same characteristics. <br>
To restore the data from another computer, you can redirect the data from a backup job in the Vault to another computer.<br>
If the data was backed up with a plug-in, the same plug-in and the corresponding installation (e.g. Microsoft SQL) must also be present on the target computer. <br>
The new computer then downloads information from the vault to restore the data to the new computer. <br>
''Example: Computer A backs up its data with Job A, Computer B restores Job A's data (Computer A's data) to Computer B.'' <br>
<br>
<br>
[[File:5 von einem anderen Computer wiederherstellen.png|border|recover from another computer]] <br>
[[File:1 Wiederherstellung bmrlokal.png|border|file-based recovery]] <br>
<br>
You can use the calendar button to select the safe set from which you wish to restore data.<br>
Then, enter the job's encryption password.<br>
Clicking the "Hint" button displays your password hint.<br>
<br>
You can select the folders and files to be restored using the checkboxes—choosing either entire folders or individual files.<br>
Clicking "Include" then adds them to the restoration process.<br>
<br>
The search function allows you to look for specific files without having to manually locate the full file path.<br>
This supports the wildcard characters * (representing any number of characters) and ? (for a single character).<br>
However, the question mark cannot be used for umlauts (ö, ä, ü).<br>
<br>
Select the desired files and add them to the recovery operation by clicking "Include selected".<br>
To search for files in a specific folder within the backup, enter the desired path into the "Search path" field.<br>
<br>
When you include a folder in a recovery operation, its subdirectories and files are included by default as well.<br>
If you wish to recover only a portion of the subdirectories or files, you can add filters to the inclusion set.<br>
For example, it is possible to recover only files with the .doc or .docx extension from a folder.<br>
<br>
<br>
[[File:1 Wiederherstellung bmrlokal.png|border|recovery]] <br>
When you exclude a folder from a recovery operation, its subdirectories and files are excluded by default as well.<br>
<br />
If you wish to exclude only a portion of the subdirectories or files, you can add filters to the exclusion set.<br>
<span id="Wiederherstellung_von_einer_imagebasierten_Sicherung"></span>
For instance, you can set a filter to exclude only files with the .exe extension within a folder from the recovery.<br>
==== Restore from an image-based backup ====
 
<br>
<br>
[[File:6 Wiederherstellung bmrlokal.png|border|Select items to restore]] <br>
[[File:2 Nach Dateien suchen.png|border|Search for files]]<br>
<br>
<br>
You can choose whether you want to restore a complete partition or individual files or folders. <br>
You have the options to restore the files to the original location or to an alternative location. <br>
Select the manufacturing you want and click “Configure Source Next”. <br>
If you decide to use an alternative storage location, you can use the folder button to select the desired storage location.<br>
You also have the options to overwrite existing files, not overwrite (this adds a numeric extension, e.g. .0001), rename incoming files and rename existing files.<br>
<br />
<br />
<span id="Volumewiederherstellung"></span>
<span id="Vorhandene_Daten_überschreiben"></span>
==== Volume Recovery ====
==== Overwrite existing data ====
 
If you try to restore multiple files with the same name to an alternate location and select Overwrite Existing Files, only the last file restored will be retained.<br>
Other files with the same name will be overwritten. To add a numeric extension (e.g. .0001) to a recovered filename, select Do not overwrite existing files.<br>
For example, if you restore a file named "filename.txt" to a location where there is a file with the same name, an extension is added to the restored file name (for example, "filename.txt.0001"). <br>
<p style="color: #FF0000;">
Under no circumstances should you select the entire C: volume and let it overwrite the existing volume. This will result in serious damage to the system!
</p>
<span id="Vorhandene_Dateien_umbenennen"></span>
==== Rename existing files ====
 
To add a numeric extension (e.g. .0001) to an existing filename, select Rename Existing Files. <br>
For example, if you restore a file named "filename.txt" to a location where there is a file with the same name, an extension is added to the existing file name (for example, "filename.txt.0001"). <br>
The name of the restored file is still “filename.txt”. <br>
<br />
<span id="Erweiterte_Wiederherstellungsoptionen"></span>
==== Advanced Recovery Options ====


<br>
<br>
[[File:8 Wiederherstellung BMR Image.png|border|Recovery]]<br>
[[File:3 Erweiterte Wiederherstellungsoptionen.png|border|Advanced Recovery Options]]<br>
<br>
<br>
Select the desired volume to be restored. <br>
[[File:4 Erweiterte Wiederherstellungsoptionen.png|border|Advanced Recovery Options Part 2]]<br>
<br />
<span id="Optionen_für_gesperrte_Dateien"></span>
==== Locked File Options ====
 
When restoring data from a local job, you can specify whether locked files should be overwritten by restored files with the same name. <br>
To do this, select one of the following options:<br>
<br>
<br>
[[File:9 Select Volume.png|border|Select Volume]]<br>
*''' "Yes, overwrite locked files" '''<br>
Files in the system that are locked during recovery will be overwritten with the recovered files upon reboot. This option must be enabled for system state or system volume restores. <br>
<br>
<br>
Next, select an existing volume to restore to. <br>
*''' "No, do not overwrite locked files" '''<br>
Click “OK” and then click “Run Restore” to start the restore process. <br>
Files in the system that are locked during recovery will not be overwritten with the recovered files with the same name upon reboot.
<br>
<br />
<span id="Dateien-_oder_Ordnerwiederherstellung"></span>
==== Streams ====
==== File or folder recovery ====


When you run backups, information from your files is captured in different streams. <br>
The original data created by a user is called a data stream. <br>
Other information such as security settings, data for other operating systems, file references and attributes are stored in separate streams. <br>
When restoring data from a local job, you have the following options to choose from: <br>
<br>
<br>
[[File:10 Restore auf Volume.png|border|Restore to Volume]]<br>
*'''"Restore all streams"''' <br>
Restores all information streams. Use this option when restoring files to a system with an identical platform.<br>
<br>
<br>
Select the volume from which individual files or folders should be restored and assign a valid drive letter. (Please do not use A & B) <br>
*'''"Restore data streams only"''' <br>
Now click on “Mount Volumes”. The backed up volume is mounted on the affected agent and you can restore the required files or folders to a local volume by dragging and dropping them. <br>
Select this option for cross-platform restores. With this option, conflicts do not arise due to system-specific data streams.
Under “Duration of inactivity”, set a generous time limit for how long the drive should be mounted. By default we recommend the value 60 minutes.<br>
<br />
<br />
<span id="Wiederherstellung_von_einem_anderen_Computer_(imagebasiert)"></span>
<span id="Protokolloptionen"></span>
==== Restore from another computer (image based) ====
==== Protocol options ====


You can restore successfully backed up data to another computer with the same agent configuration. <br>
From the list, select one of the following logging levels:
To do this, you can transfer/copy existing backup jobs in the Vault to another computer. <br>
*Files: Provides more detailed information and is typically used for troubleshooting. Provides information about files that are being restored. <br>
Since an image job is a plugin job, the image plugin must exist on the target agent. <br>
*Directory: Provides less detailed information than the Files logging level. Provides information about folders that will be restored. <br>
<br>
*Summary: Provides top-level information including Vault/Agent version and backup size. <br>
''Example: Computer A is down/no longer in use, but now you need to restore data from Computer A. To do this, copy the job from computer A to computer B to perform a restore.'' <br>
*Minimal: Provides top-level information including Vault/Agent version. <br>
<br>
Changing the logging level only affects log files that are created afterwards. Log files that have already been created are not affected by this change. <br>
Select Computer B in the backup portal. <br>
From the Select Job Task menu, click Restore from Another Computer. <br>
The Restore from Another Computer dialog box opens. <br>
[[File:5 von einem anderen Computer wiederherstellen.png|border|recover from another computer]]<br>
<br>
In the "Vaults" list, select the vault in which the backup of Computer A was stored. If the restore is to be carried out across vaults, the agent must first be registered with the source vault. <br>
Once the correct vault is selected, you will find Computer A in the Computers tab. <br>
After computer A is selected, you will find its job in the Jobs tab. <br>
Confirm with OK once a selection has been made. <br>
The portal attempts to download required job information to Computer B. Once these are downloaded, the job will appear in Computer B's Jobs tab. <br>
A recovery process will start automatically. Once you have selected the desired restore here and entered the encryption password to decrypt required information, you can proceed with a normal image-based restore. <br>
[[File:12 Verschluesselungskennwort.png|border|Password is required]]<br>
<br>
[[File:Image Auswahl.PNG|border| Selecting the recovery type]] <br>
<br>
If an error occurs while downloading the job information, the restore cannot continue. <br>
This can happen if the job information is not available or a required plugin is not installed on the target computer. <br>
Make sure the required plugin is installed on the target computer before repeating the process. (Change installation via Agent Setup or via the "Select job task" action) <br>
=== Linux ===
 
Restoring a backup is the most common usage, allowing you to restore anything from a single file to a directory structure to an entire system. <br>
To start a restore, select a job (that is, highlight it) and do one of the following: <br>
*Select Actions and Restore. <br>
*Click the recovery icon (or use CTRL+R). <br>
*Right-click a job in the left pane. <br>
The recovery wizard will start. It offers the following options:
*Select a source device, vault, or directory type. Depending on which option you choose here, you can also select a vault and a backup. You can also choose to restore from a specific backup set or a series of backup sets. <br>
*Enter the password if the backup is encrypted. If the backup is not encrypted, this window may not appear. If you forget the password, you will not have access to the backup data. <br>
*Select the recovery objects (files or directories). You can expand the directories (if any) and select or deselect files to restore. <br>
*Enter recovery destination options. You can choose to restore files to the original location or another location, create subdirectories, and overwrite existing files. <br>
*Select the other recovery options. You can overwrite locked files and select all streams or only data streams. You can choose a log file with different levels of detail.<br>
*Click the Finish button to start the restore process. The restore will be performed and the process information will be displayed. <br>
You may want to view the log files after the process is complete. The recovery logs are identified by the prefix “RST” in the log list. <br>
<br />
<br />
<span id="Alternative_statische_IP_bei_einer_BMR-Rücksicherung_vergeben"></span>
<span id="Leistungsoptionen"></span>
==== Assign alternative static IP for a BMR restore ====
==== Performance options ====


By default, a BMR restore restores the original network configuration. <br>
To use all available bandwidth for recovery, select "Use all available bandwidth." <br>
If you would like to assign an alternative configuration, for example to carry out a test restore, we recommend starting the system without network access first. <br>
Bandwidth throttling determines how much bandwidth an agent can consume for backups and restores.<br>
With a Hyper-V, for example, you could initially boot into the recovery ISO without a connected external vSwitch. After adjusting the network configuration, you can connect the VM to the vSwitch. This ensures that the system never goes online with the old IP address.
For example, you can limit traffic so that online users are not impacted and allow unrestricted usage at night so that scheduled backups or restores can occur as quickly as possible. <br>
Please follow these steps to adjust the network configuration before restoring:
Bandwidth throttling values are set at the machine (or agent) level and apply to backups and restores. <br>
#Boot into the Restore ISO and initiate the restore until the step where you are asked to run ''./bmragent''.
When three jobs are running simultaneously on a computer, each job receives 1/3 of the specified maximum bandwidth. <br>
#Find the name and configuration of the network interface using ''ip address show''
Possible bandwidth settings: Maximum bandwidth (upper limit) in MB per second that the agent is allowed to consume for all backups and restores. <br>
#Take the interface offline by e.g. ''ip link set name of network interface down''
Period of time during the day when throttling is activated. Only one time window can be specified. <br>
#Delete the old IP address that you determined in the first step, e.g. ''ip address del 172.29.4.24/22 dev name of the network interface''
There is no throttling outside the time window. The days of the week that throttling is enabled. <br>
#Configure a new IP address using, for example, the following command ''ip address add 172.29.4.29/22 dev name of the network interface''
Once the bandwidth throttling window begins during an ongoing backup or restore, the maximum bandwidth is dynamically applied to the running process. <br>
#Take the network interface back online after customization
If the throttling window ends while a backup or restore is in progress, bandwidth throttling is removed. <br>
#Finally, configure the default gateway using, for example, ''ip route del default'' and then ''ip route add default via 172.29.4.1 dev name of the network interface''
If you change an agent's bandwidth settings while a backup or restore is in progress, the new settings do not affect the ongoing process. <br>
In this screenshot you can see an example of step 1 from the instructions:
The bandwidth settings are applied when the backup or restore starts and are not changed afterwards. <br>
[[File:Linux BMR.jpg|framed|ohne]]<br>
<br />
== '''Bare Metal Restore''' ==
<span id="Wiederherstellung_von_einem_anderen_Computer_(filebasiert)"></span>
==== Restore from another computer (file based) ====


A bare metal restore is a complete restore of a secured system, including all components required for the boot process (e.g. the bootloader). <br>
It is possible to restore some or all of the data backed up on one computer to another computer with the same characteristics. <br>
<span id="Disaster_Recovery_Möglichkeiten"></span>
To restore the data from another computer, you can redirect the data from a backup job in the Vault to another computer.<br>
=== Disaster recovery options ===
If the data was backed up with a plug-in, the same plug-in and the corresponding installation (e.g. Microsoft SQL) must also be present on the target computer. <br>
 
The new computer then downloads information from the vault to restore the data to the new computer. <br>
The following flow chart shows you possible workflows and recommendations for action for various ''[[DRaaS/en|Disaster Recovery]]'' scenarios. <br>
''Example: Computer A backs up its data with Job A, Computer B restores Job A's data (Computer A's data) to Computer B.'' <br>
<span id="Treiber_eines_gesicherten_Systems_exportieren"></span>
=== Export drivers of a secured system ===
 
You can export all drivers of a system using the following instructions:
# Create a directory in which the drivers should be stored, e.g. (C:\Drivers)
# Run this command with administrative permission in CMD:
    <code> dism /online /export-driver /destination:"C:\Driver" </code>
You can add the exported drivers when creating a new restore iso.
If complications arise during a BMR test restore, we recommend exporting the drivers of the protected system as described above and adding them to the restore ISO.
Please keep this ISO or drivers separately.
<span id="Restore_ISO_erzeugen"></span>
=== Create Restore ISO ===
 
To perform a bare metal restore, you need a restore iso (.iso file).
The Restore ISO is based on Windows PE and also contains the recovery software of the TERRA CLOUD backup solution, which is started automatically as soon as the system boots into the ISO.
You can create this ISO yourself and use it for BMR restore of all your systems.<br>
<br>
<br>
'''Download:''' <br>
[[File:5 von einem anderen Computer wiederherstellen.png|border|recover from another computer]] <br>
Please download the Bootable Media Creator from the Backup Portal. <br>
<br>
<br>
'''Installation:''' <br>
[[File:1 Wiederherstellung bmrlokal.png|border|recovery]] <br>
Now install the Bootable Media Creator, which also requires the Windows Assessment and Deployment Kit. By default you will be guided through the installation of the ADK components via the Bootable Media Creator Setup. Alternatively, you can use the following setups for the installation: <br>
https://backup.terracloud.de/Download/adksetup.exe <br>
https://backup.terracloud.de/Download/adkwinpesetup.exe <br>
Please note that both the ADK setup and the WINPE setup must be executed.
After installation, the image can be created very easily. <br>
First start the Bootable Media Creator and simply select a target directory below. <br>
[[File:Build Image.png|border|Create new Image]]<br>
<br>
You can add exported drivers from [[Backup/en#Export_drivers_of_a_secured_system|Export Drivers]] in this step by selecting the driver directory using "add".
Now click on “Continue” to create the image. <br>
[[File:Add Drivers.PNG|border|Add Drivers]]<br>
<br>
The image can now be burned onto a CD or attached to a virtual machine, for example. <br>
<br />
<br />
<span id="Restore_durchführen"></span>
<span id="Wiederherstellung_von_einer_imagebasierten_Sicherung"></span>
=== Perform restore ===
=== Restore from an image-based backup ===


The following instructions show a typical restore operation in a virtual machine. The ISO file was attached to the virtual machine.
The legacy adapters must be used as network adapters under both VMware and Hyper-V. <br>
After restarting the machine, a connection to the machine must be established via the console. The following image then appears:<br>
[[File:Press_any_key_to_boot_from_CD_or_DVD.PNG|border|800px|boot from CD or DVD]]<br>
<br>
<br>
In the first step, configure the time zone and the desired language, then click Next. <br>
[[File:6 Wiederherstellung bmrlokal.png|border|Select items to restore]] <br>
[[File:Restore sprache.jpg|border|Select language]]<br>
<br>
<br>
In the following window, accept the license terms and then click on “Next”. <br>
You can choose whether you want to restore a complete partition or individual files or folders. <br>
By default, the “System Restore” gets the IP address from a DHCP server. If there is no DHCP server or you want to assign the IP address manually, click on “Settings” in the main menu. <br>
Select the manufacturing you want and click “Configure Source Next”. <br>
Select the network interface and then click “Properties”. Assign an IP address and confirm with “Apply”. <br>
<br />
[[File:restore IP.png|border|IP Settings]]<br>
<span id="Volumewiederherstellung"></span>
<br>
==== Volume Recovery ====
To perform a restore process, click on “Restore My System” in the main menu. Click "Next" in the wizard. <br>
 
[[File:restore wizard.png|border|Wizard]]<br>
<br>
<br>
On the following page, enter your data for the vault (data storage) and confirm with Next. The system restore now tries to establish a connection to the vault. <br>
[[File:8 Wiederherstellung BMR Image.png|border|Recovery]]<br>
[[File:restore vault.png|border|Vault configuration]]<br>
<br>
<br>
On the following page you will see all the computers that belong to your account. Select the computer you want to restore. Then click on “Next”. <br>
Select the desired volume to be restored. <br>
[[File:Restore computer.png|border|Select computer]]<br>
<br>
<br>
On the following page you will see all backup jobs that belong to this computer. Select the job you want to restore. Then click on “Next”. <br>
[[File:9 Select Volume.png|border|Select Volume]]<br>
[[File:Restore job.png|border|Select job]]<br>
<br>
<br>
In the next step you can select which safeset should be backed up. Select the safeset you want and then click “Next”. <br>
Next, select an existing volume to restore to. <br>
If you have set up a password for the backup job, a password query will appear. Enter the password and confirm with OK. <br>
Click “OK” and then click “Run Restore” to start the restore process. <br>
[[File:Restore point pw.png|border|Enter password]]<br>
<br>
<br>
In the following step, the volumes that should be backed up can be selected. To do this, simply drag the partitions down into the “Destination” field. <br>
<span id="Dateien-_oder_Ordnerwiederherstellung"></span>
Then click on “Next”. <br>
==== File or folder recovery ====
[[File:Restore volume.png|border|Select volume via drag and drop]]<br>
 
<br>
<br>
In the last step, the settings can be checked again. Then check the box next to “Click here to confirm the restore plan”. Then click on “Next”. <br>
[[File:10 Restore auf Volume.png|border|Restore to Volume]]<br>
[[File:Restore confirm.png|border|confirm]]<br>
<br>
<br>
The restore process starts. <br>
Select the volume from which individual files or folders should be restored and assign a valid drive letter. (Please do not use A & B) <br>
[[File:Restore start.png|border|Restore starts]]<br>
Now click on “Mount Volumes”. The backed up volume is mounted on the affected agent and you can restore the required files or folders to a local volume by dragging and dropping them. <br>
Under “Duration of inactivity”, set a generous time limit for how long the drive should be mounted. By default we recommend the value 60 minutes.<br>
<br />
<span id="Wiederherstellung_von_einem_anderen_Computer_(imagebasiert)"></span>
==== Restore from another computer (image based) ====
 
You can restore successfully backed up data to another computer with the same agent configuration. <br>
To do this, you can transfer/copy existing backup jobs in the Vault to another computer. <br>
Since an image job is a plugin job, the image plugin must exist on the target agent. <br>
<br>
<br>
[[File:Restore2.png|border|Restore process]]<br>
''Example: Computer A is down/no longer in use, but now you need to restore data from Computer A. To do this, copy the job from computer A to computer B to perform a restore.'' <br>
<br>
<br>
If the restore process has been completed successfully, please confirm by clicking OK to close the window. Exit the wizard and restart the server. <br>
Select Computer B in the backup portal. <br>
<br />
From the Select Job Task menu, click Restore from Another Computer. <br>
 
The Restore from Another Computer dialog box opens. <br>
<span id="Backup_Satelliten"></span>
[[File:5 von einem anderen Computer wiederherstellen.png|border|recover from another computer]]<br>
== '''Backup satellites''' ==
<br>
 
In the "Vaults" list, select the vault in which the backup of Computer A was stored. If the restore is to be carried out across vaults, the agent must first be registered with the source vault. <br>
<span id="Beschreibung_und_Vorteile"></span>
Once the correct vault is selected, you will find Computer A in the Computers tab. <br>
=== Description and Benefits ===
After computer A is selected, you will find its job in the Jobs tab. <br>
Confirm with OK once a selection has been made. <br>
The portal attempts to download required job information to Computer B. Once these are downloaded, the job will appear in Computer B's Jobs tab. <br>
A recovery process will start automatically. Once you have selected the desired restore here and entered the encryption password to decrypt required information, you can proceed with a normal image-based restore. <br>
[[File:Image Auswahl.PNG|border| Selecting the recovery type]] <br>
<br>
[[File:12 Verschluesselungskennwort.png|border|Password is required]]<br>
<br>
If an error occurs while downloading the job information, the restore cannot continue. <br>
This can happen if the job information is not available or a required plugin is not installed on the target computer. <br>
Make sure the required plugin is installed on the target computer before repeating the process. (Change installation via Agent Setup or via the "Select job task" action) <br>
== Bare Metal Restore ==
 
A "bare metal restore" is a complete restoration of a backed up system, including all components required for the boot process (e.g. the bootloader). <br>
<span id="Disaster_Recovery_Möglichkeiten"></span>
=== Disaster recovery options ===


The backup satellite is a hardware appliance or a virtual machine that is used in your end customer's network and can receive backups via the local network.
The following flow chart shows you possible workflows and recommendations for action for various ''[[DRaaS/en|Disaster Recovery]]'' scenarios. <br>
The satellite provides you with all vault functions, e.g. providing volumes from an image backup. The rental devices or virtual machines are made available to you by the TERRA Cloud and, depending on their size and performance, are billed monthly in addition to the required backup packages.
<span id="Treiber_eines_gesicherten_Systems_exportieren"></span>
By using a satellite, you can implement a hybrid cloud backup solution, as backups are stored locally on a satellite and then replicated to a data center.<br>
=== Export drivers of a secured system ===
This backup concept enables the following advantages:
* Fast backup and restore, thanks to locally connected vault system (satellite)
* No acquisition costs as the hardware is provided to you
* Time decoupling between backup and replication possible
* Backup possible independently from the data center
* Initial backup can be performed directly against the satellite
* Your customer's bandwidth can be optimally utilized
<span id="Inbetriebnahme"></span>
=== Commissioning ===


After ordering your backup package including satellites, you will receive an email with the access data as soon as the vault account has been provided on the Basevault. <br>
You can export all drivers of a system using the following instructions:
You will receive a separate notification after the satellite has been deployed and shipped to you.<br>
# Create a directory in which the drivers should be stored, e.g. (C:\Drivers)
After receiving the satellite, the following steps must be carried out (hardware satellites):<br>
# Run this command with administrative permission in CMD:
* Set up and launch satellite in your end customer's network
dism /online /export-driver /destination:"C:\Driver"
* You can reach the satellite interface via the local address of the satellite (either static IP or DHCP)
You can add the exported drivers when creating a new restore iso.
* Please note that the satellite interface can be accessed via HTTPS and may need to be enabled in the browser first
If complications arise during a BMR test restore, we recommend exporting the drivers of the protected system as described above and adding them to the restore ISO.
* You can use the interface to change the access data in the user administration and, if necessary, adjust the network configuration
Please keep this ISO or drivers separately.
* Please deactivate the bypass mode using the Deactivate bypass mode function [https://wiki.terracloud.de/index.php/Backup/en#Features 10.3.1.3]
<span id="Restore_ISO_erzeugen"></span>
* The satellite is now prepared for productive use and must be saved as a backup target in the agents' vault settings (local IP of the satellite)
=== Create Restore ISO ===
* Initial backups can optionally be carried out directly against the satellite
Commissioning a satellite VM:<br>
* You will receive a Hyper-V VM container from TERRA Cloud Support, which you can import and virtualize under Hyper-V
** '''''Please note that only Hyper Hosts are compatible with the Windows Server 2019 operating system or higher!'''''
* Disk/network allocation must be done via Hyper-V Manager / VM Connect
* The remaining steps of commissioning a satellite VM are similar to commissioning a normal satellite
<span id="Satelliteninterface"></span>
=== Satellite interface ===


==== System ====
To perform a bare-metal restore, you need a restore ISO (.iso file).
 
The restore ISO is based on Windows PE and includes the recovery software for the TERRA CLOUD backup solution; this software launches automatically once the system boots from the ISO.
<span id="Anmeldung"></span>
You can create this ISO yourself and use it for the bare-metal restore of all your systems.<br>
===== Registration =====
<br>
 
'''Download:''' <br>
You can access the following interface in your browser using the satellite's IP address. There are two different users available, the image shows the administrative user who has <br> unrestricted access. In addition, there is a user who only has read rights; you can set the access data at a later date.<br>
Please download the Bootable Media Creator from the backup portal. <br>
The default login details for the admin user are:<br>
<br>
'''Installation:''' <br>
Install the Bootable Media Creator; this also requires the Windows Assessment and Deployment Kit (ADK).<br>
The Bootable Media Creator setup guides you through the installation of the ADK components by default. <br>
[[Datei:Backup-DE-Bootable Media Creator-1.png|700px|border]]<br>
<br>
<br>
''User = admin''<br>
[[Datei:Backup-DE-Bootable Media Creator-2.png|700px|border]]<br>
''Password = terra''<br>
<br>
<br>
[[File:AnmeldungSat.png|border|800px|Registration in the satellite interface]]<br>
[[Datei:Backup-DE-Bootable Media Creator-3.png|700px|border]]<br>
<br />
<br>
<span id="Informationen"></span>
[[Datei:Backup-DE-Bootable Media Creator-4.png|700px|border]]<br>
===== Informations =====
<br>
 
[[Datei:Backup-DE-Bootable Media Creator-5.png|700px|border]]<br>
The Information item shows you the dashboard with all the important vital indicators of the hardware, e.g. CPU, RAM or hard drive utilization.<br>
<br>
The satellite mode is also visible. A distinction is made between two modes, the active and inactive bypass mode.<br>
[[Datei:Backup-DE-Bootable Media Creator-6.png|700px|border]]<br>
With active bypass, the satellite rejects all agent requests, so communication for backups, restores, synchronizations or job creation takes place via the basevault. Accordingly, the Basevault address must be stored in the portal under the Vault Settings tab.<br>
With the inactive bypass, the satellite is activated and accepts all agent requests, thereby enabling communication for backups, restores, synchronizations
or job creation takes place via the satellite. Accordingly, the IP address of the satellite must be stored in the portal under the Vault Settings tab.<br>
<br>
<br>
'''Hard disk capacity:'''<br>
[[Datei:Backup-DE-Bootable Media Creator-7.png|700px|border]]<br>
Green = Between 0% and 85% <br>
Orange = From 85% to 95% <br>
Red = From 95% to 99.99% <br>
<br>
<br>
[[File:Warnung Speicher.png|border|800px|Storage warning in the overview]]<br>
[[Datei:Backup-DE-Bootable Media Creator-8.png|700px|border]]<br>
<br>
<br>
[[File:Warnung.png|border|Message Storage Warning]]<br>
[[Datei:Backup-DE-Bootable Media Creator-9.png|700px|border]]<br>
<br>
<br>
[[File:Speicher Alarm de.png|border|800px|Storage Alarm in the overview]]<br>
[[Datei:Backup-DE-Bootable Media Creator-10.png|700px|border]]<br>
<br>
<br>
[[File:95%-DE.png|border|Storage Alert]]<br>
[[Datei:Backup-DE-Bootable Media Creator-11.png|700px|border]]<br>
<br>
<br>
<span id="Funktionen"></span>
[[Datei:Backup-DE-Bootable Media Creator-12.png|700px|border]]<br>
===== Features =====
 
'''System functions:'''<br>
Under Functions you will find a list of the relevant services stored on the satellite. Please check whether all services are running.<br>
If a service is stopped, you can start it using the Play symbol. Please do not restart any services while the satellite is running.<br>
<br>
<br>
'''Satellite functions:'''<br>
[[Datei:Backup-DE-Bootable Media Creator-13.png|700px|border]]<br>
You can use this interface to shut down the satellite, restart it, or manually start a replication process.<br>
<br>
<br>
'''Disable bypass:'''<br>
[[Datei:Backup-DE-Bootable Media Creator-14.png|700px|border]]<br>
A satellite with bypass mode activated cannot accept backups and delegates them to the base vault. Please deactivate bypass mode so that the satellite can accept backups.<br>
<br>
<br>
[[File:Bypass deaktivieren2.png|border|800px|Disable Bypass]]<br>
[[Datei:Backup-DE-Bootable Media Creator-15.png|700px|border]]<br>
<br>
<br>
'''Activate Support Connect:'''<br>
[[Datei:Backup-DE-Bootable Media Creator-16.png|700px|border]]<br>
With this switch you allow TERRA CLOUD support to access the satellite via remote maintenance.<br>
<br>
[[Datei:Backup-DE-Bootable Media Creator-17.png|700px|border]]<br>
<br>
[[Datei:Backup-DE-Bootable Media Creator-18.png|700px|border]]<br>
<br>
[[Datei:Backup-DE-Bootable Media Creator-19.png|700px|border]]<br>
<br>
[[Datei:Backup-DE-Bootable Media Creator-20.png|700px|border]]<br>
<br>
[[Datei:Backup-DE-Bootable Media Creator-21.png|700px|border]]<br>
<br>
[[Datei:Backup-DE-Bootable Media Creator-22.png|700px|border]]<br>
<br>
The image can be created very easily after installation. <br>
First, launch the Bootable Media Creator and simply select a destination directory at the bottom. <br>
[[Datei:Build Image.png|700px|border|Create new Image]]<br>
<br>
In this step, you can add drivers exported via [https://wiki.terracloud.de/index.php/Backup/en#Export_drivers_of_a_secured_system Exporting drivers] by selecting the driver directory using the "add" button.<br>
Now click "Continue" to create the image. <br>
[[Datei:Add Drivers.PNG|border|Treiber hinzufügen]]<br>
<br>
[[Datei:Backup-DE-Bootable Media Creator-23.png|700px|border]]<br>
<br>
[[Datei:Backup-DE-Bootable Media Creator-24.png|700px|border]]<br>
<br>
[[Datei:Backup-DE-Bootable Media Creator-25.png|700px|border]]<br>
<br>
The image can now, for example, be burned to a CD or attached to a virtual machine. <br>
<br />
<span id="Restore_durchführen"></span>
=== Perform restore ===


===== Branding =====
The following instructions demonstrate a typical BMR restore within a virtual machine.<br>
 
The BMR restore ISO must be mounted to the virtual machine beforehand.<br>
This function allows you to adapt the satellite interface to your company's CI. The configuration only needs to be carried out on one satellite, as you can export it and import it on other satellites.<br>
Legacy network adapters must be used for both VMware and Hyper-V.<br>
There is also the option to add your own logo.<br>
After restarting the machine, you must connect to it via the console.<br>
[[File:Branding.png|800px|border|Branding]] <br>
The following screen will then appear:<br>
<span id="Wartung"></span>
[[Datei:Press_any_key_to_boot_from_CD_or_DVD.PNG|border|800px|boot from CD or DVD]]<br>
===== Maintenance =====
<br>
 
First, configure the time zone and desired language, then click "Next".<br>
Vault maintenance checks the satellite's data stock every day at 9:23 a.m. for safesets that have exceeded their retention period; the number of retention days and copies must be exceeded. Expired safesets are deleted from the satellite.
[[Datei:Restore sprache.jpg|border|Select language]]<br>
You can adjust the start time of this maintenance if necessary.<br>
<br>
[[File:Wartung.png|800px|border]]<br>
In the next window, accept the license terms and click "Next".<br>
===== Updates =====
[[Datei:Backup-DE-BMR Restore-01.png|border]]<br>
<br>
By default, the "System Restore" process obtains an IP address from a DHCP server.<br>
If no DHCP server is available, or if you wish to assign the IP address manually, click "Settings" in the main menu.<br>
Select the network interface and then click "Properties". Assign an IP address and confirm by clicking "Apply". <br>
[[File:Backup-DE-BMR Restore-02.png|border]]<br>
<br>
[[File:Backup-DE-BMR Restore-03.png|border]]<br>
<br>
[[File:Backup-DE-BMR Restore-04.png|border]]<br>
<br>
We recommend subsequently pinging the vault via the command prompt to ensure it is reachable.<br>
The command prompt can then be minimized so that it remains available for further adjustments (e.g., diskpart) during the rest of the restore process if needed.
<br>
<br>
To perform a restore operation, click "Restore My System" in the main menu. Click "Next" in the wizard. <br>
[[File:Backup-DE-BMR Restore-05.png|border]]<br>
<br>
On the following page, enter your vault (data storage) details and confirm by clicking "Next". The system restore process will now attempt to establish a connection to the vault. <br>
[[File:Backup-DE-BMR Restore-06.png|border]]<br>
<br>
On the following page, you will see all computers associated with your account. Select the computer you wish to restore. Then click "Next". <br>
[[File:Backup-DE-BMR Restore-07.png|border]]<br>
<br>
On the following page, you will see all backup jobs associated with this computer. Select the job you wish to restore. Then click "Next". <br>
[[File:Backup-DE-BMR Restore-08.png|border]]<br>
<br>
In the next step, you can select which safeset to restore. Select the desired safeset and then click "Next". <br>
Next, enter the encryption password and click OK to confirm. <br>
[[Datei:Backup-DE-BMR Restore-09.png|border]]<br>
<br>
[[Datei:Backup-DE-BMR Restore-10.png|border]]<br>
<br>
In the next step, you can select the volumes to be restored.<br>
You can drag the individual partitions down into the "Destination" field or use the AutoMap button. <br>
Then click "Next". <br>
<br>
Note:<br>
You can only drag down the light blue partitions; the gray partitions are created automatically.<br>
[[Datei:Backup-DE-BMR Restore-11.png|border]]<br>
<br>
[[Datei:Backup-DE-BMR Restore-12.png|border]]<br>
<br>
In the final step, you can review the settings. Then, check the box next to "Click here to confirm the restore plan" and click "Next". <br>
[[Datei:Backup-DE-BMR Restore-13.png|border]]<br>
<br>
The restore process begins. <br>
[[Datei:Backup-DE-BMR Restore-14.png|border]]<br>
<br>
[[Datei:Backup-DE-BMR Restore-15.png|border]]<br>
<br>
[[Datei:Backup-DE-BMR Restore-16.png|border]]<br>
<br>
Once the restore process has successfully completed, click "Next" to close the window and launch the Repair Wizard. <br>
[[File:Backup-DE-BMR Restore-17.png|border]]<br>
<br>
Here, you can check whether any software components requiring an additional driver have been detected.<br>
If the status is "OK" and a green checkmark is visible for each item, you can close the wizard by clicking **Close**.
<br>
[[File:Backup-DE-BMR Restore-18.png|border]]<br>
= '''Linux Agent''' =


You can search the satellite interface directly for current updates and import them.<br>
<span id="Dokumentation_Linux_Agent"></span>
[[File:Updates.png|800px|border]]<br>
== Documentation Linux Agent ==
<span id="XML-Ansicht"></span>
===== XML View =====


This menu item will take you to the XML output of the satellite in a new tab. This output lists all relevant information of the satellite and can be monitored.<br>
You can find extensive documentation and further information in [https://drive.terracloud.de/getlink/fiWfB9v89MHuWyK9a63FQJRc/Linux%20Agent Linux Agent User Guide].
You can incorporate this link into your own monitoring solution or use ready-made sensors. You can find ready-made sensors for Server-Eye and PRTG Network Monitor, the sensors can be found under the search term “Terra Cloud Backup”. <br>
<span id="Vorbereitung_der_Installation_für_eine_Bare_Metal_Sicherung"></span>
[https://www.server-eye.de/ Homepage Server-Eye] <br>
== Preparing the installation for a bare metal backup ==
[[File:XML-Ansicht.png|border|500px]]<br>
<br />
<span id="Replikation"></span>
==== Replication ====


<span id="Konnektivität"></span>
The bare metal backup of the TERRA CLOUD Backup Linux agent requires the software [https://relax-and-recover.org Relax and Recover], in a supported version, on the system to be backed up.<br>
===== Connectivity =====
We recommend installing the software via the package manager of the respective distribution and, if necessary, updating it to the supported version. <br>
The currently supported version of Relax and Recover can be found in the release notes of the TERRA CLOUD Backup Linux agent.<br>
<br>
<font color="red">Please note that TERRA CLOUD cannot provide support for the installation or commissioning of the Relax and Recover software.</font>
== Installation ==
 
'''Step 1:''' Please download the TERRA Backup Agent. <br>
To do so, log in to the TERRA CLOUD Backup Portal and copy the link address of the required agent (32 or 64 bit) from the download area. <br>
Please download the agent setup, e.g., using the ''wget'' command and the copied link address.
[[Datei:Linux-Agent-Download.png|ohne]]
<br>
'''Step 2:''' Unpack the archive with ''tar -xzvf PACKAGE-NAME.tar.gz''. <br>
[[Datei:Linux Agent unzip-2neu.png|ohne]]
<br>
'''Step 3:''' Then change to the unzipped agent directory and start the installer shell script using ''./install.sh''
<br>
[[Datei:Linux Agent install.sh.png|1500px|ohne]]
<br>
'''Step 4:''' Please first read and confirm the license agreement and follow the instructions of the installation wizard to configure the installation. <br>
In the screenshot of the example installation, the default settings for the following queries have been selected:
#Installation directory ''/opt/BUAgent''
#Language Email notification ''(deprecated agent email notification)''
#Encryption method
You can accept the default values ​​by confirming the queries with ENTER. <br>
[[Datei:Linux Agent Installation.png|ohne]]
<br>
'''Step 5:''' Indicate whether a Bare Metal Restore backup is desired. <br>
If you answer YES, please note that a supported version of [https://wiki.terracloud.de/index.php/Backup/en#Preparing_the_installation_for_a_bare_metal_backup Relax and Recover] must already be installed on the system. <br>
The default value for the Relax and Recover directory is ''/usr/sbin/rear''. <br>
[[Datei:Linux Agent enable BMR.png|ohne]]
'''Step 6:''' Register the Linux Agent on the TERRA CLOUD Backup Portal: <br>
#Portal address = backup.terracloud.de
#Portal connection port = 8086 ''(default value)''
#Portal username = [https://wiki.terracloud.de/index.php/Backup/en#Create_user User] of the end customer's site
#Portal password = Password of the user on the end customer's site
<br>
[[Datei:Linux Agent Portal Registrierung.png|ohne]]
'''Step 7:''' Please check the TERRA CLOUD Backup Portal to see if the Agent has been successfully registered on your end customer's site. <br>
[[Datei:Linux Agent im Portal.png|ohne]]
<span id="Wiederherstellung_eines_Backup-Jobs"></span>
== Restore a backup job ==


This overview shows you the status of the connection to the Basevault. The satellite transmits a "heartbeat" to the basevault at regular intervals.<br>
After backing up data from a system, you can select “Restore” under “Actions” in the backup jobs.
In addition, the connection to the backup portal and the base vault is checked via ping and Telnet. This ensures that all necessary [https://wiki.terracloud.de/index.php/Backup#Networkconfiguration ports] are activated for the satellite.< br>
<span id="Wiederherstellung_von_einem_File_Level_Job"></span>
During replication, for example, the outgoing network traffic rate can also be monitored.<br>
==== Recovery from a file-level job ====
[[File:Satellit Konnektivität.jpg|framed|ohne|100px|]]<br>
<span id="Replikationsstatus"></span>
===== Replication Status =====


This overview shows you which safesets are still outstanding for replication to the data center; these are processed as if in a queue. <br>
[[Datei:1 Linux-Wiederherstellung.png|border|filebasierte Wiederherstellung]] <br>
On the right side you can click through the satellite's current inventory and view more detailed information about individual safe sets, such as the compressed <br>
<br>
Size or whether this safeset has already been replicated.<br>
Use the calendar button to select the safeset from which you wish to restore data. <br>
Enter the job's encryption password. Clicking the "Hint" button displays your password hint. <br>
You can select the folders and files to be restored using checkboxes and then include them in the recovery process by clicking "Include". <br>
The search function allows you to search for specific files without having to look up the file path. <br>
Wildcard characters are supported: * (for any number of characters) and ? (for a single character). <br>
However, the question mark cannot be used for a German umlaut (ö, ä, ü). <br>
Select the relevant files and add them to the recovery selection by clicking "Include selected". <br>
To search for files within a specific folder in the backup, enter the desired path in the "Search path" field. <br>
When you include a folder in a recovery, its subdirectories and files are also included by default. <br>
If you wish to restore only a portion of the subdirectories or files within a folder, you can add filters to the inclusion set. <br>
For example, you can add a filter to restore only files with a .txt or .log extension from a folder. <br>
When you exclude a folder from a recovery, its subdirectories and files are also excluded by default. <br>
If you wish to exclude only specific subdirectories or files within a folder, you can add filters to the exclusion set. <br>
For example, you can add a filter to exclude only files with the .sh extension within a folder from the restore process. <br>
<br>
[[Datei:2 Linux-Nach Dateien suchen.png|border|Nach Dateien suchen]]<br>
<br>
<br>
[[File:Replikation.png|border|900px|ReplicationStatus]]<br>
You have the option to restore the files to their original location or to an alternative location. <br>
<span id="Bandbreitenlimitierung"></span>
If you choose an alternative location, you can select the desired destination using the folder button.<br>
===== Bandwidth limitation =====
You also have options to overwrite existing files, not overwrite them (in which case a numeric extension, e.g., .0001, is added), rename incoming files, or rename existing files.<br>
 
<br />
You can configure a bandwidth limit for satellite replication.
<span id="Vorhandene_Daten_überschreiben"></span>
Please note that after an adjustment, the replication service restarts and ongoing replications are aborted. <br>
==== Overwrite existing data ====
If the connection is weaker, we recommend configuring the "Quality of Service" on the firewall for the satellite and assigning it a low priority.<br>
This setting on the firewall ensures that, for example, on a holiday, the <br>. can be replicated with full bandwidth
Bandwidth allocation is therefore more flexible than a fixed bandwidth limit. <br>
[[File:Bandbreitenlimitierung.png|border|800px]]<br>
<span id="Replikationszeitplan"></span>
===== Replication Schedule =====


The replication schedule allows you to control whether to replicate immediately after a newly created backup and after <br>
If you attempt to restore multiple files with the same name to an alternate location and select the option to overwrite existing files, only the last file restored will be retained.<br>
defined schedule or exclusively according to a configured replication schedule. This option is particularly recommended if <br>
Other files with the same name will be overwritten. To add a numeric extension (e.g., .0001) to a restored filename, select the option not to overwrite existing files.<br>
should be backed up during your customer's working hours, but replication should only start after working hours. <br>
For example, if you restore a file named "filename.txt" to a location where a file with the same name already exists, an extension (such as "filename.txt.0001") will be added to the restored filename.<br>
In this image you can see the configuration for a replication schedule that initiates a replication operation every day around 8 p.m.:<br>
<p style="color: #FF0000;">
[[File:Replikationszeitplan.png|border|800px]]<br>
Do not, under any circumstances, select the entire root volume and allow it to overwrite the existing volume. Doing so will cause severe system corruption!
===== Safeset Management =====
</p>
<span id="Vorhandene_Dateien_umbenennen"></span>
==== Rename existing files ====


Special configurations can be made on the satellite via Safeset Management; if configured incorrectly, these can affect the function of the satellite.<br>
To add a numeric extension (e.g., .0001) to an existing filename, select "Rename existing files." <br>
Changes can only be made after activation via the slider and '''may only be made after consultation with support'''.<br>
For example, if you restore a file named "filename.txt" to a location where a file with the same name already exists, an extension is added to the existing filename (e.g., "filename.txt.0001"). <br>
[[File:Safeset-management.png|border|800px]]<br>
The name of the restored file remains "filename.txt". <br>
<span id="Backup_Daten"></span>
<br />
==== Backup data ====
<span id="Erweiterte_Wiederherstellungsoptionen"></span>
==== Advanced recovery options ====


You can use the satellite interface to delete entire systems, jobs or individual backup sets (safesets). <br>
The deletion only applies to satellites; the data in the data center on the respective base vault remains unaffected. <br>
Safe sets are displayed online; they are highlighted in black and can be selected by clicking in the checkbox. <br>
Online safesets are characterized by the fact that they are stored locally on the satellite and are directly available there.<br>
Safesets that are grayed out and cannot be selected are offline safesets. <br>
An offline safeset represents a backup that does not exist on the Vault, but still exists on the Basevault. <br>
Only meta information about these safesets is stored on the satellite. <br>
<br>
<br>
'''Procedure for deletion:'''<br>
[[Datei:3 Erweiterte Wiederherstellungsoptionen.png|border|Advanced recovery options]]<br>
<br>
<br>
'''System level deletion:'''<br>
[[Datei:4 Erweiterte Wiederherstellungsoptionen.png|border|Advanced recovery options Part 2]]<br>
a) Check in the interface's job monitor that no process is running for the affected system. (If the Job Monitor tab is not available, update to the latest interface version)<br>
<br />
b) Select the systems to be deleted and carry out the “Delete marked entries” action
<span id="Optionen_für_gesperrte_Dateien"></span>
c) Wait until the affected system is grayed out from the overview. (It may take some time) <br>
==== Options for locked files ====
d) Check the capacity of the satellite and start a quick storage optimization <br>
 
When restoring data from a local job, you can specify whether locked files should be overwritten by restored files with the same name. <br>
To do this, select one of the following options:<br>
<br>
<br>
'''Job level deletion:'''<br>
*''' "Yes, overwrite locked files" '''<br>
a) Check in the interface's job monitor that no process is running for the affected job. (If the Job Monitor tab is not available, update to the latest interface version)<br>
System files that are locked during the restore process will be overwritten by the restored files upon restart. This option must be enabled for System State or system volume restores. <br>
b) Mark the job to be deleted by selecting it and carry out the “Delete marked entries” action <br>
c) Wait until the affected job has disappeared from the overview/grayed out. (It may take some time)<br>
d) Check satellite capacity. If unchanged, start quick memory optimization <br>
<br>
<br>
'''Safeset level deletion:'''<br>
*''' "No, do not overwrite locked files" '''<br>
a) Check in the interface's job monitor that no process is running for the affected job. (If the Job Monitor tab is not available, update to the latest interface version)<br>
System files that are locked during the restore process will not be overwritten by the restored files with the same name upon restart.
b) Select the safe sets to be deleted and carry out the “Delete marked entries” action
<br />
c) Wait until all affected safe sets have disappeared from the overview/grayed out. (Depending on the size, the process can take a lot of time) <br>
==== Streams ====
d) As soon as all safesets have disappeared/grayed out, start quick storage optimization <br>
 
When performing backups, information from your files is captured in various streams. <br>
The original data created by a user is referred to as the data stream. <br>
Other information—such as security settings, data for other operating systems, file references, and attributes—is stored in separate streams. <br>
When restoring data from a local job, you have the following options: <br>
<br>
<br>
*'''"Restore all streams"''' <br>
Restores all information streams. Use this option when restoring files to a system with an identical platform.<br>
<br>
<br>
[[File:Backupdaten.png|border|800px|Backup data on the satellite]]<br>
*'''"Restore data streams only"''' <br>
==== Job Monitor ====
Select this option for cross-platform restores. This option avoids conflicts caused by system-specific data streams.
<br />
<span id="Protokolloptionen"></span>
==== Protocol Options ====


You can view open or already completed processes in the Job Monitor.<br>
Select one of the following logging levels from the list:
Backups or restores can be monitored, as can replication processes.<br>
*Files: Provides more detailed information and is typically used for troubleshooting. Provides information about files being restored. <br>
The following screenshot shows a satellite that currently has no open jobs:<br>
*Directory: Provides less detailed information than the "Files" logging level. Provides information about folders being restored. <br>
[[File:Jobmonitor.png|800px|border]]<br>
*Summary: Provides high-level information, including the vault/agent version and backup size. <br>
<br>
*Minimal: Provides high-level information, including the vault/agent version. <br>
'''Jobs on the screenshot:'''<br>
Changing the logging level affects only log files created after the change. Existing log files are not affected by this change. <br>
Maintenance Host = This process represents maintenance on the satellite, this process should always be displayed <br>
<br />
Satellite Replication Service = Behind this process is the active replication service, this process should always be displayed <br>
<span id="Leistungsoptionen"></span>
Satellite Replication - Upload Satellite Statistics = In the screenshot, this process is set to "Inactive" because it was completed successfully. In this job, the satellite passed information to the basevault.
==== Performance Options ====
<span id="Benutzerverwaltung"></span>
==== User management ====


Within the user management you can define passwords for a total of two users. Which users are stored in total?<br>
To use the entire available bandwidth for recovery, select "Use all available bandwidth." <br>
#Admin: This user has full access and is intended for administration of the satellite.
Bandwidth throttling determines the amount of bandwidth an agent is permitted to use for backups and recoveries.<br>
#User: This user only has read permission and can be issued to the end customer as required.
For example, you can limit data traffic to avoid impacting online users, while allowing unrestricted usage at night so that scheduled backups or recoveries can complete as quickly as possible. <br>
<br>
Bandwidth throttling values ​​are configured at the computer (or agent) level and apply to both backups and recoveries. <br>
[[File:Benutzerverwaltung.png|border|800px|User Management]]<br>
If three jobs run simultaneously on a computer, each job receives one-third of the specified maximum bandwidth. <br>
Available bandwidth settings: Maximum bandwidth (upper limit) in MB per second that the agent may use for all backups and recoveries. <br>
Daytime period during which throttling is active. Only one time window can be specified. <br>
No throttling occurs outside this time window. The days of the week on which throttling is active. <br>
If the bandwidth throttling time window begins while a backup or recovery is in progress, the maximum bandwidth limit is dynamically applied to the running process. <br>
If the throttling time window ends while a backup or recovery is in progress, bandwidth throttling is lifted. <br>
If you modify an agent's bandwidth settings while a backup or recovery is running, the new settings do not affect the active process. <br>
Bandwidth settings are applied when the backup or recovery starts and are not modified subsequently. <br>
<br />
<br />
<span id="Netzwerkkonfiguration"></span>
== Bare Metal Restore ==
==== Network configuration ====
 
<span id="Vorbereitung"></span>
=== Preparation ===


You can use the network configuration to pass on your desired settings directly to the satellite or use the “Activate DHCP” function. <br>
To perform a bare-metal restore, the `Bare_Metal_Restore_Image_xxxxx.iso` file—created during the BMR backup—is required.<br>
As soon as DHCP has been activated, the network configuration assigned by the DHCP server will be displayed. <br>
You can find this file in the system's root directory (/).<br>
If the ISO is not visible, the [https://wiki.terracloud.de/index.php/Backup/en#Installation_2 of the Relax and Recover tool] or the BMR backup was unsuccessful.
<br>
<br>
[[File:Netzwerkverwaltung.png|border|800px|Satellite Network Management]]<br>
<span id="Durchführung"></span>
<br/>
=== Implementation ===
<span id="Initialsicherung_FTP_Upload_/_Datenträger_einsenden"></span>
== '''Initial backup FTP upload / send data carrier''' ==


<span id="Buchung"></span>
* Boot the target system from the mentioned ISO and select '''Recover ''Systemname'' '''.
=== Booking ===
[[File:Backup-DE-Linux-BMR-1.png|none]]<br>
* Log in as the '''root''' user; no password is required.
[[File:Backup-DE-Linux-BMR-2.png|none]]<br>
* Next, start the BMR restore agent by running '''./bmragent'''.
[[File:Backup-DE-Linux-BMR-3.png|none]]<br>
* Enter your '''vault (data storage) details'''. The system restore process will now attempt to establish a connection to the vault.
[[File:Backup-DE-Linux-BMR-5.png|none]]<br>
* Select the '''computer''' you wish to restore.
[[File:Backup-DE-Linux-BMR-6.png|none]]<br>
* Select the '''job''' you wish to restore.
[[File:Backup-DE-Linux-BMR-7.png|none]]<br>
* In the next step, you can choose which '''safeset''' to restore. Select the desired safeset.
[[File:Backup-DE-Linux-BMR-8.png|none]]<br>
* Then, enter the '''encryption password''' and set the prompt to '''yes''' using the left arrow key.
[[File:Backup-DE-Linux-BMR-9.png|none]]<br>
* Next, confirm the '''disk mapping'''. Option 1 is selected by default.
[[File:Backup-DE-Linux-BMR-10.png|none]]<br>
* Finally, confirm the '''disk layout'''. Option 1 is selected by default.
[[File:Backup-DE-Linux-BMR-11.png|none]]<br>
* Next, you must confirm the '''Disk Recreation Script'''. Option 1 is selected by default.
[[File:Backup-DE-Linux-BMR-12.png|none]]<br>
* In the next step, you must confirm that the '''storage on the target system will be wiped'''. Option 1 is selected by default.
[[File:Backup-DE-Linux-BMR-13.png|none]]<br>
* Finally, you will receive a '''summary''' of the changes to the target system's storage, which you must confirm. Option 1 is selected by default.
[[File:Backup-DE-Linux-BMR-14.png|none]]<br>
* The '''BMR recovery process''' now begins. Depending on the amount of data, bandwidth, and vault load, this may take some time.
[[File:Backup-DE-Linux-BMR-15.png|none]]<br>
* Once the recovery is complete, you must confirm the '''recovery of the initrd and the reinstallation of the bootloader'''. Option 1 is selected by default.
[[File:Backup-DE-Linux-BMR-16.png|none]]<br>
* This completes the BMR restore.
[[File:Backup-DE-Linux-BMR-18.png|none]]
<span id="Alternative_statische_IP_bei_einer_BMR-Rücksicherung_vergeben"></span>
== Assign alternative static IP for a BMR restore ==


The two processes can be added when initially booking a backup package or later in the order.
By default, a BMR restore restores the original network configuration. <br>
<span id="Empfohlener_Weg"></span>
If you would like to assign an alternative configuration, for example to carry out a test restore, we recommend starting the system without network access first. <br>
=== Recommended way ===
With a Hyper-V, for example, you could initially boot into the recovery ISO without a connected external vSwitch. After adjusting the network configuration, you can connect the VM to the vSwitch. This ensures that the system never goes online with the old IP address.
Please follow these steps to adjust the network configuration before restoring:
#Boot into the Restore ISO and initiate the restore until the step where you are asked to run ''./bmragent''.
#Find the name and configuration of the network interface using ''ip address show''
#Take the interface offline by e.g. ''ip link set name of network interface down''
#Delete the old IP address that you determined in the first step, e.g. ''ip address del 172.29.4.24/22 dev name of the network interface''
#Configure a new IP address using, for example, the following command ''ip address add 172.29.4.29/22 dev name of the network interface''
#Take the network interface back online after customization
#Finally, configure the default gateway using, for example, ''ip route del default'' and then ''ip route add default via 172.29.4.1 dev name of the network interface''
In this screenshot you can see an example of step 1 from the instructions:
[[File:Linux BMR.jpg|framed|ohne]]<br>
= '''vSphere Recovery Agent''' =


The [https://backup.terracloud.de/Download/TERRA%20CLOUD%20Backup%20Assistant.exe Backup Assistant] was equipped with the TERRA CLOUD initial backup tool.<br>
<span id="Dokumentation_vSphere_Recovery_Agent"></span>
How the initial backup tool works is explained in the following short video: [https://www.wortmann.de/content/files/content/Externe_Dokumente_Ablage/Video/cloud/TERRA-CLOUD-Backup_Initialbackup.mp4 TERRA Cloud Initialbackup Tool] <br>
== vSphere Recovery Agent Documentation==
<br>
Please select a locally connected volume that was not included in the backup set as the destination for the initial backup. Also make sure that the affected volume does not end up in the backup set using the “Entire Server” option. <br>
<br>
Network shares are not supported as a destination path. <br>
<br>
After the initial backup has been created, it is recommended to check the backup log file. If no warnings/errors are visible here, this can be made available either via an external data carrier or by uploading it to our FTP server. <br>
<span id="Manueller_Weg"></span>
=== Manual way ===


As an alternative to the Backup Assistant, the initial backup can also be created manually. The following points should be taken care of in advance:
You can find extensive documentation and further information in [https://drive.terracloud.de/getlink/fi17zn1o2vUrkUJLgCQEYL/vSphere%20Agent vSphere Recovery Agent User Guide].
*Backup Agent installed on the desired system and registered on the portal.
== Installation ==
*Backup job and schedule configured as desired.
*Schedule disabled so that the agent does not automatically attempt to backup to the vault.<br>
<br>
'''Method'''<br>
1.) '''Start backup for metadata transfer against the vault.''' This involves transmitting information required by the vault that is necessary for the import process. As soon as the status “Processing in progress” is visible, the process can be stopped. <br>
<br>
2.) '''Create a folder structure in the target directory.''' To ensure smooth identification, we ask you to create the following folder structure: <br>
<br>
''\$ACCOUNT NAME$\$COMPUTER NAME$\$JOB NAME$'' <br>
<br>
Example path:
''D:\00000-EXAMPLE\srv-terracloud\bmrjob'' <br>
<br>
<p style="color: #FF0000;"> Since this always involves encrypted data, an insufficient folder structure would result in a written query and thus a delay in the process. </p>
<br>
3.) '''Start backup to the previously created path.''' The procedure in the portal looks like this:<br>
<br>
[[File:Verzeichnis_auf_Datentraeger.png|border|Destination: Directory on data carrier]] <br>
<br>
[[File:Ordner_auswaehlen.png|border|Select previously created folder structure]] <br>
<br>
[[File:Initialbackup_auf_Datentraeger.png|border|Start backup]] <br>


=== FTP Upload ===
Please run the vSphere Recovery Agent setup on a Windows Server system with access to the VMware environment (vCenter or standalone ESXi host). Please note the recommendations from the section [[Backup/en#Best_Practice|Best Practice]]. Please follow the instructions in the vSphere Recovery Agent InstallShield. In the last step of the installation, you register the system using the user and password entered in your end customer's created site. You can find a detailed description of the installation process in the User Guide linked above.
 
<span id="Konfiguration_des_Agenten"></span>
'''Please make sure that the data is complete. Each job is divided into backup fragments, which are incremented numerically and are 1,048,576 KB in size except for the last fragment. Only the first fragment (Safesetnummer.SSI or 00000001.SSI) differs in name from the remaining files.''' <br>
== Agent configuration ==
<br>
The initial backup created, whether manually or via the Assistant, can be uploaded to the TERRA Cloud FTP server. <br>
<br>
For the upload you can e.g. B. the [https://filezilla-project.org/download.php?type=client FileZilla Client] can be used. <br>
<br>
The necessary access data will be provided by us in the center after receipt of the booking. <br>
<br>
Once the upload has been completed and checked, you can send us a short confirmation of the previously submitted information. <br>
<br>
You will then receive a response from us as soon as there is news about the import.
<br>
<span id="Datenträger_einsenden"></span>
=== Send in data carrier ===


'''Please make sure that the data is complete. Each job is divided into backup fragments, which are incremented numerically and are 1,048,576 KB in size except for the last fragment. Only the first fragment (Safesetnummer.SSI or 00000001.SSI) differs in name from the remaining files.''' <br>
After successful installation and registration on the TERRA CLOUD Backup Portal, you can now add the system to the vault as described in [[Backup/en#Associate_Agent_with_Vault|Add system to the vault]].
<br>
<span id="Verbindung_zu_der_vSphere-Umgebung"></span>
The data carrier can be sent together with the completed [https://downloads.terracloud.de/files/Formulare%20&%20Zertifikate/terra%20CLOUD_Einsendeformular.pdf submission form] to the following address: <br>
=== Connection to the vSphere environment ===
<br>
'''TERRA CLOUD GmbH''' <br>
'''Hankamp 2''' <br>
'''32609 Hüllhorst''' <br>
<br>
Notifications about the import status / shipping status of the data carrier are carried out via automated business processes. <br>
<br>
<p style="color: #FF0000;"> Please do not send us unencrypted raw data from your end customer under any circumstances! </p>
<p style="color: #FF0000;"> These will be sent back to the sender unprocessed. </p>
== '''Backup Export''' ==


To get data e.g. For example, if you want to store your data on a local medium for long-term backup, we can export your backups.
Please enter and save the access data for the vSphere environment (vCenter or standalone ESXi host) in the “credentials” fields. You will receive immediate feedback as to whether the access data provided is correct or whether the area can be reached.
The export is encrypted and in the so-called vault format, so that the exported data must be read in with additional software before an agent can process and restore it.<br>
[[File:VRA-1.png|framed|ohne]]<br>
<br>
=== Changed Block Tracking ===
Please note that this is a paid process. Further information about the process (offer, process, etc.) can be obtained from our cloud sales department: cloud@wortmann.de <br>
As soon as you have received the desired data set, you can use the following steps. Continue steps. <br>
<br>
You can find the required software at:<br>
[https://backup.terracloud.de/Download/SecondaryRestoreServer-8-70-0266.exe Secondary Restore Server]<br>
=== Secondary Restore Server ===


The Secondary Restore Server reads the exported data and presents it as a virtual vault in the existing network.<br>
This agent function is already activated after installation and allows quick and efficient delta backup of the virtual machines. <br>
*Please navigate to the folder structure of the exported data in the Secondary Restore Server
For more information about this technology, see VMware's [https://kb.vmware.com/s/article/1020128 Knowledge Base]. <br>
*Store the data of the exported vault account, e.g. B. (45814-END CUSTOMER), as well as the vault account password
[[File:VRA-CBT.png|framed|ohne]]<br>
*Start sharing via the Secondary Restore Server (Start)
<span id="Automatisierte_Wiederherstellungstests"></span>
*Agents can then access the share as if it were a normal vault.
=== Automated recovery tests ===
[[File:Secondaryrestoreserver.png|border|Secondary Restore Server]]<br>
 
Enabling the Verify backup on completion option will perform a recovery test via quick VM restore after each backup completes.
After the virtual machine boots, a screenshot of the login mask is created and saved in the TERRA CLOUD Backup Portal.
To use this feature, the [[Backup/en#Rapid_VM_Recovery|rapid VM recovery]] requirements must be met.
Please store the temporary data store on which the VM can be started for the test recovery and the desired ESXi host. <br>
<br>
<br>
<span id="Wiederherstellung_von_einzelnen_Dateien(Secondary_Restore_Server)"></span>
'''Example configuration:''' <br>
=== Restore individual files (Secondary Restore Server) ===
[[File:VRA-2.png|framed|ohne]]<br>
<span id="vSphere_Backup_Job_erstellen"></span>
== Create vSphere Backup Job ==


Once the data has been presented on the network, you can proceed as follows:<br>
Once you have finished installing and configuring the agent, you can create a new "Job for VMware vSphere".<br>
[[File:CrossRestore-1.PNG|border|1500px|CrossRestore Step 1]]<br>
The following screenshot shows an example of a new job for a vSphere environment. Please enter a job name and optionally a description and the encryption password.<br>
You can either include all virtual machines in the backup by selecting the "Virtual Machines" level, so all virtual machines are included recursively. This option offers the advantage that new virtual machines are automatically added to the backup job.<br>
Alternatively, you can select individual VMs and add them to the backup set.<br>
[[Datei:VRA-3.png|gerahmt|ohne]]<br>
<br>
<br>
[[File:CrossRestore-2.PNG|border|CrossRestore Step 2]]<br>
'''Optional:Advanced Settings:''' <br>
<br>
<span id="Anwendungskonsistente_Sicherung_aktivieren"></span>
[[File:CrossRestore-3.PNG|border|CrossRestore Step 3]]<br>
=== Enable application consistent backup ===
<br>
 
[[File:CrossRestore-4.PNG|border|1500px|CrossRestore Step 4]]<br>
As soon as you "enable application consistent backup" an application consistent snapshot can be created based on a Microsoft VSS snapshot.<br>
<br>
We recommend enabling this option for all virtual machines with a Windows guest operating system.
[[File:CrossRestore-5.PNG|border|CrossRestore Step 5]]<br>
<span id="Protokolle_der_Datenbanktransaktionen_kürzen"></span>
=== Truncate database transaction logs ===
 
In addition to application-consistent backup, transaction logs from Microsoft Exchange or SQL Server instances can be truncated.
<span id="Bedrohungserkennung_aktivieren"></span>
=== Enable Threat Detection ===
 
When backing up active virtual machines with Windows guest operating systems, the vSphere Recovery Agent can scan the system for active ransomeware.<br>
We recommend enabling this option for all virtual machines with a Windows guest operating system.<br>
The Enable Threat Detection option requires guest operating system credentials.
<span id="Diesen_Sicherungsjob_bei_Fertigstellung_überprüfen"></span>
=== Verify this backup job upon completion ===
 
Following the backup, a recovery test of the virtual machines is performed via fast VM recovery.<br>
Please note that this function must be set up in the [https://wiki.terracloud.de/index.php/Backup/en#Automated_recovery_tests Agent Configuration].<br>
Furthermore, this option is only visible if the [https://wiki.terracloud.de/index.php/Backup/en#Rapid_VM_Recovery prerequisites for Rapid VM Recovery] are met.
<span id="Globale_VM-Anmeldeinformationen"></span>
=== Global VM Credentials ===
 
The entered access data will be used for all virtual machines in the backup set.
<span id="Gast-BS-Anmeldeinformationen"></span>
=== Guest OS Credentials ===
 
If you would like to assign access data individually for each virtual machine, you can enter these in the backup set below the virtual machine by displaying the input field using the blue arrow.
[[Datei:VRA-3.png|gerahmt|ohne]]<br>
<span id="Rapid_VM_Recovery_(schnelle_VM-Wiederherstellung)"></span>
== Rapid VM Recovery ==
 
The Rapid VM Recovery option allows you to start a VM directly from the backup.<br>
Downtime can be drastically reduced thanks to this rapid access; additionally, the feature is suitable for performing a recovery test in just a few minutes.<br>
<br>
<br>
[[File:CrossRestore-6.PNG|border|1500px|CrossRestore Step 6]]<br>
'''Prerequisites:'''
* Available only in conjunction with a TERRA CLOUD Backup Satellite or TERRA CLOUD Backup Enterprise Vault.
* Each ESXi host must have a software iSCSI adapter.
* The datastore where the VM is started can be located on local, iSCSI, or vSAN storage.
* A datastore intended as the migration target for a VM can be located on an NFS share, in addition to the storage types mentioned above.
* A minimum of two datastores must be available in total.
* vSphere Recovery Agent 8.82 or higher.
* The Windows Server hosting the VRA must have the "iSCSI Target Server" Windows feature installed.<br>
<br>
<br>
[[File:CrossRestore-7.PNG|border|CrossRestore Step 7]]<br>
'''Example configuration of an ESXi host for Rapid VM Recovery:''' <br>
<br>
In the screenshot below, an iSCSI software adapter has been added via vCenter using the "Add Software Adapter" option. [[File:ISCSI Software Adapter.png|none|1500px]]<br>
<span id="BMR_Wiederherstellung(Secondary_Restore_Server)"></span>
Additionally, a VMkernel adapter without the service role enabled was added, as shown in the following screenshot:
=== BMR Restore(Secondary Restore Server) ===
[[File:VMkerneladapter.png|none|1500px]]<br>
'''Procedure:'''
Once all prerequisites are met, an additional option—"Virtual Machine option using Rapid VM Recovery"—becomes available under "Restore": <br>
[[File:RVMR.png|framed|none]]<br>
You then proceed to the recovery configuration.<br>
Here, in addition to selecting which VM to restore, you can also define which datastore should be used.<br>
The following screenshot shows the "Rapid VM Recovery Datastore," which was configured specifically for tasks such as recovery and functional testing.<br>
During the recovery process, you can migrate the VM to a different datastore—for example, the one hosting your production systems.
[[File:RVMR1.png|framed|none]]<br>
== Best Practice ==


For instructions on how to initiate a BMR, see: [[Backup/en#Bare_Metal_Restore| Bare Metal Restore]]
* Install the vSphere Recovery Agent in its own Windows Server VM; if possible, this will only be used for management or backup
Once the data has been presented on the network, you can proceed as follows:<br>
* Keep the vSphere Recovery Agent VM highly available via vSphere HA
[[File:BMR-1.PNG|border|BMR Step 1]]<br>
* Use a satellite for TERRA CLOUD backup to be able to use Rapid VM Recovery
* Place the vSphere Recovery Agent VM on the same subnet as the vCenter Server Appliance
* Enable the "Application Aware Backup" option in the backup job
* Use Change Block Tracking to back up virtual machines; this setting can be found under the "vCenter Settings" tab.
= '''Hyper-V Agent''' =
 
<span id="Dokumentation_Hyper-V_Agent"></span>
== Documentation Hyper-V Agent ==
 
The following sections contain, among other things, information about setting up and configuring the TERRA CLOUD Backup Hyper-V agent. <br>
You can find extensive documentation and further information in the [https://drive.terracloud.de/getlink/fiVpa5RWivf6onxsGi6bsfPW/Hyper-V%20Agent Hyper-V Agent User Guide ]
== Installation ==
 
The following concise guide outlines the essential steps for setting up the TERRA CLOUD Backup Hyper-V Agent. <br>
<br>
'''Setup sequence:'''<br>
1. Install TERRA CLOUD Backup Hyper-V Agent Management <br>
2. Configure the Management Agent in the Backup Portal (establish connection to the Hyper-V environment, add the computer to the vault) <br>
3. Install TERRA CLOUD Backup Hyper-V Agent Host <br>
<br>
'''Single-host Hyper-V systems: <br>'''
In this scenario, you can install both the TERRA CLOUD Backup Hyper-V Management Agent and the Host Agent directly on the Hyper-V host ("root"/"parent" partition). <br>
However, please still observe the setup sequence listed above.<br>
<br>
'''Hyper-V clusters:''' <br>
Because the TERRA CLOUD Backup Hyper-V Agent is split into two software components (Management and Host), it is ideally suited for use in a cluster environment.<br>
We recommend installing the Management Agent in an administrative VM within the Hyper-V cluster; this allows it to run on different hosts and ensures high availability via the failover cluster. <br>
After completing setup steps 1 and 2, you can proceed to step 3 and install the TERRA CLOUD Backup Hyper-V Agent Host on all nodes of the Hyper-V cluster.<br>
<br>
<br>
[[File:BMR-2.PNG|border|BMR Step 2]]<br>
'''TERRA CLOUD Backup Hyper-V Agent Management:''' <br>
<br>
<br>
[[File:BMR-3.PNG|border|BMR Step 3]]<br>
'''Setup step 1''' <br>
Please run the installer on the desired system and follow the on-screen instructions.<br>
In the final step—as with all other TERRA CLOUD Backup agents—you configure the registration with the TERRA CLOUD Backup Portal.<br>
You can either select a user within the site who has sufficient permissions, or register the system to your parent site and move it later. <br>
<br>
<br>
[[File:BMR-4.PNG|border|BMR Step 4]]<br>
'''Setup Step 2''' <br>
Once installation is successfully completed, the system should appear under the selected site in the backup portal.<br>
Please follow the instructions in the backup portal to establish a connection to the Hyper-V environment and subsequently add the computer to the vault.<br>
<br>
<br>
[[File:BMR-5.PNG|border|BMR Step 5]]<br>
'''Installing the TERRA CLOUD Backup Hyper-V Agent Host:''' <br>
<br>
<br>
= '''Agent Skripting''' =
'''Setup Step 3''' <br>
After successfully configuring the Hyper-V agent in Step 2, you can install the host agent on all nodes of the Hyper-V cluster or on the standalone host.<br>
For a cluster installation, specify the FQDN of the system where the management agent is active in order to establish a connection to it.<br>
Once installation is successful, the respective node should appear as "online" under the "Hosts" tab in the backup portal.
<span id="Wiederherstellung_eines_Backup-Jobs"></span>
== Restoring a Backup Job ==


== Windows Agent ==
The Hyper-V Agent allows you to restore either individual files and folders from a virtual machine or the entire virtual machine.<br>
When restoring files, the virtual machine is mounted as a read-only file share.<br>
This enables you to copy the desired files and folders directly from the backup without having to restore the entire virtual machine.<br>
<br>
'''Note:'''<br>
Restoring individual files and folders is supported exclusively for '''Windows VMs'''.<br>
This feature is not available for '''Linux VMs'''.<br>
For Linux VMs, only the complete virtual machine can be restored.<br>
<br>
First, navigate to '''Computers''' in the Backup Portal and select your Hyper-V server.<br>
[[Datei:Backup-DE-Hyper-V Agent-Restore (1).png|ohne|1500px]]<br>
Next, switch to the '''Virtual Machines''' tab and click '''Select action → Restore''' for the desired VM.<br>
[[Datei:Backup-DE-Hyper-V Agent-Restore (2).png|ohne|1500px]]<br>
Various restore options are available in the subsequent dialog.<br>
[[Datei:Backup-DE-Hyper-V Agent-Restore (3).png|ohne|900px]]
<br>
<span id="Wiederherstellung_von_VMs"></span>
=== VM Recovery ===


In addition to the portal, the Windows agent can also be started via command line or script.<br>
To restore a complete virtual machine, please select '''Virtual Machines'''.<br>
Agent scripting is recommended, for example, to stop non-VSS-capable databases before backup (MySQL, MariaDB, etc.)<br>
[[Datei:Backup-DE-Hyper-V Agent-VM wiederherstellen (4).png|none|900px]]<br>
<br />
The following information is required for the subsequent steps:
<span id="Windows_Agent_per_Kommandozeile_ansprechen"></span>
* '''New VM Name'''
=== Address Windows Agent via command line ===
** Specify the name for the virtual machine to be restored.<br>If the original VM still exists on the host, please provide a new name that differs from the existing VM's name.<br>If it no longer exists, please leave the field blank; in this case, the virtual machine's original name will be used automatically.
* '''Backup Set'''
** Select the desired backup set and then enter the encryption password you assigned.
* '''Destination'''
** Select the destination drive where the virtual machine is to be restored.<br>We recommend using the root directory of a disk (without a subpath) initially and moving the VM to the desired directory via Hyper-V Manager after the restore is complete.
* '''VM Identity'''
** Specify how the VM ID of the virtual machine to be restored should be handled.<br>You can retain the original VM ID, generate a new VM ID, or have a new VM ID generated automatically if the original VM ID already exists on the target system.<br>We recommend retaining the original VM ID. This allows the existing backup chain to continue seamlessly after the restore.
* '''Host'''
** Select the Hyper-V host or cluster node where the virtual machine is to be restored.<br>If no Hyper-V cluster is used, only the local host is available for selection. Additionally, you can specify whether the restored virtual machine should start automatically after the restore is complete and whether the VM should be connected directly to the network.<br>
[[Datei:Backup-DE-Hyper-V Agent-VM wiederherstellen (12).png|none|900px]]<br>
The restore process then begins.<br>
[[Datei:Backup-DE-Hyper-V Agent-VM wiederherstellen (13).png|none|900px]]<br><br>
Upon successful completion, you will find the restored VM both on the selected target drive and in the Hyper-V Manager of the target Hyper-V server.
[[Datei:Backup-DE-Hyper-V Agent-VM wiederherstellen (16).png|none|900px]]<br>
[[Datei:Backup-DE-Hyper-V Agent-VM wiederherstellen (17).png|none|900px]]
<br>
<span id="Wiederherstellung_von_Dateien_und_Ordner"></span>
=== Recovery of files and folders ===


Please first change to the agent's installation directory in CMD or PowerShell, by default this is 'C:\Program Files\TERRA Cloud Backup\Agent\'<br>
To restore files and folders, please select '''Files and folders'''.<br>
To start a backup, the following parameters must be passed to VV.exe:
[[Datei:Backup-DE-Hyper-V Agent-Dateien und Ordner wiederherstellen (4).png|none|900px]]<br>
*VV.exe backup JOBNAME /retention=RetentionName (CMD) <br>
You will then need to provide the following information:
*.\VV.exe backup JOBNAME /retention=RetentionName (PowerShell)<br>
* '''Backup set'''
** Select the desired backup set and then enter the encryption password you assigned.
* '''Inactivity duration'''
** Use this value (in minutes) to specify how long the file share should remain active during periods of inactivity.<br>We recommend setting this value to 90 minutes.
<br>
[[Datei:Backup-DE-Hyper-V Agent-Dateien und Ordner wiederherstellen (7).png|none|500px]]<br>
The next window displays the status of the file share.<br>
As soon as the status changes to **Processing...**, the release becomes available.<br>
[[Datei:Backup-DE-Hyper-V Agent-Dateien und Ordner wiederherstellen (9).png|none|900px]]<br>
By default, the file share is mounted at '''C:\RestoreMount'''.<br>
[[Datei:Backup-DE-Hyper-V Agent-Dateien und Ordner wiederherstellen (10).png|none|900px]]<br>
[[Datei:Backup-DE-Hyper-V Agent-Dateien und Ordner wiederherstellen (11).png|none|900px]]<br>
If you wish to change this default path, you can find further information in the following wiki article:<br>
[https://wiki.terracloud.de/index.php/Backup/en#Changing_the_mount_point_for_data_recovery Link]
<br>
<br>
You can use the /retention=RetentionName parameter to determine which retention type should be used.<br>
<span id="Rapid_VM_Recovery_(schnelle_VM-Wiederherstellung)"></span>
Please replace "RetentionName" with the name of the retention period, which you can view in the [[Backup/en#Advanced_Agent_Configuration|Advanced Agent Settings]].<br>
== Rapid VM Recovery ==
<br />
 
<span id="Windows_Agent_per_Skript_ansprechen"></span>
The '''Instant VM Recovery''' option allows you to start a VM directly from the backup.<br>
=== Address Windows Agent via script ===
Downtime can be drastically reduced thanks to this rapid access; additionally, the feature is suitable for performing a recovery test in just a few minutes.
<span id="Voraussetzungen"></span>
=== Requirements ===
 
# Hybrid TERRA CLOUD backup with a TERRA CLOUD Backup satellite or TERRA CLOUD Backup Enterprise
# Hyper-V Checkpoints must be enabled for the secured VMs (for more information, see: [https://docs.microsoft.com/en-us/windows-server/virtualization/hyper-v/manage/enable-or-disable-checkpoints-in-hyper-v Hyper-V Checkpoints])
<span id="Durchführung"></span>
=== Implementation ===


The desired commands can be stored in a script.<br>
First, navigate to '''Computers''' in the Backup Portal and select your Hyper-V server.<br>
Recommended formats are '''.bat''' and '''.cmd'''<br>
[[Datei:Backup-DE-Hyper-V Agent-Restore (1).png|none|1500px]]<br>
Next, switch to the '''Virtual Machines''' tab and click '''Select Action → Restore''' for the desired VM.<br>
[[Datei:Backup-DE-Hyper-V Agent-Restore (2).png|none|1500px]]<br>
Various restore options are available in the subsequent dialog.<br>
For a quick restore of the virtual machine, please select '''Virtual machine using rapid VM restore'''.<br>
[[Datei:Backup-DE-Hyper-V Agent-VM wiederherstellen-Rapid (5).png|none|900px]]<br>
The following information is required for the subsequent steps:<br>
* '''Backup set and encryption password'''
** Select the desired backup set and then enter the encryption password you assigned.<br>
* '''Restore VM name'''
** Specify the name for the virtual machine to be restored here.<br>If the original VM is still on the host, please provide a new name that differs from the existing VM's name.<br>If it is no longer present, please leave the field blank. In this case, the virtual machine's original name will be used automatically.<br>
* '''Volume'''
** Here you can select the target drive where the virtual machine is to be temporarily mounted.<br>
* '''Target host'''
** Select the Hyper-V host or cluster node where the virtual machine is to be restored.<br>If no Hyper-V cluster is used, only the local host is available for selection.<br> <br>
Additionally, you can specify whether the restored virtual machine should automatically start and connect directly to the network once the restoration is complete.<br>
[[File:Backup-DE-Hyper-V Agent-VM wiederherstellen-Rapid (7).png|none|500px]]<br>
The virtual machine restoration process then begins.<br>
[[File:Backup-DE-Hyper-V Agent-VM wiederherstellen-Rapid (9).png|none|900px]]<br>
Once the restoration status changes to '''Rapid VM recovery in progress''', the new virtual machine becomes visible on the target host in Hyper-V Manager and is ready for immediate use.<br>
[[File:Backup-DE-Hyper-V Agent-VM wiederherstellen-Rapid (11).png|none|900px]]<br>
In our example, the new VM appears as '''VM01-rvmr-2026-Aug-05-09-35-34'''.<br>
[[File:Backup-DE-Hyper-V Agent-VM wiederherstellen-Rapid (10).png|none|900px]]<br>
If you no longer need the provisioned VM, you can cancel the rapid VM recovery by clicking '''Cancel rapid VM recovery''' in the process details window within the Backup Portal.
[[File:Backup-DE-Hyper-V Agent-VM wiederherstellen-Rapid (11).png|none|900px]]
<br>
<br>
Scripts can be extended as desired, e.g. to store pre- and post-commands, i.e. commands before or after the backup.
<span id="Migration_der_VM"></span>
Example script:
=== VM Migration ===
@echo off<br>
cd "C:\Program Files\TERRA Cloud Backup\Agent"<br>
echo "Start backup" >> backuplog.txt<br>
VV.exe backup BMR /retention=Daily <br>
echo "Backup performed" >> backuplog.txt<br>
[[File:Backupskript.png|none]]<br>
<span id="Skript_vor_dem_Herunterfahren_ausführen"></span>
=== Run script before shutdown ===


You can integrate your created script into the system's pre-shutdown event with the following configuration. This is particularly recommended for client systems that are not consistently in use.<br>
Optionally, you can migrate the virtual machine to the target storage—and thus permanently to the target host—during the recovery process.<br>
Please carry out the following steps to store a script: <br>
To do this, select the '''Migrate VM''' option within the process details in the Backup Portal.<br>
# Open Local Group Policy Editor (WIN + R "gpedit.msc")<br>
The migration settings will then open; select the '''Permanent Volume''' there.<br>
# Store your created script under "Computer Configuration -> Windows Settings -> Scripts (Startup/Shutdown)<br>
We recommend initially using the root directory of a storage drive (without a sub-path) and moving the VM to the desired directory via Hyper-V Manager after the migration is complete.
# Click "Shutdown" and add your script via "Add". <br>
<br>Then, start the migration by clicking '''Start migration'''.<br>
# Please adjust the following registry key: ''HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gpsvc\PreshutdownTimeout''<br>
[[File:Backup-DE-Hyper-V Agent-VM wiederherstellen-Rapid (14).png|none|300px]]<br>
# This key defines the length of the pre-shutdown event, which is set to 15 minutes by default. Please increase this value so that a backup can be created during this time.
[[File:Backup-DE-Hyper-V Agent-VM wiederherstellen-Rapid (15).png|none|900px]]<br>
# In the Local Group Policy Editor, please navigate to "Computer Configuration -> Administrative Templates -> System -> Scripts <br>
During the migration, the status of the virtual machine in Hyper-V Manager indicates that it is being moved to local storage.<br>
# Adjust the "Specify maximum wait time for Group Policy scripts" setting. You can enter a value of up to 32,000 seconds or 0 for an infinite waiting time.
[[File:Backup-DE-Hyper-V Agent-VM wiederherstellen-Rapid (17).png|none|900px]]<br>
# Please note that you have adjusted the rights accordingly. <br>
Once the status '''Restored VM has been migrated''' appears in the Backup Portal process details, the migration is complete.<br>
::We have described further information about this in the following Wiki article: [https://wiki.terracloud.de/index.php/Backup_Fehlerdiagnose/en#PreshutdownTimeout_Value PreshutdownTimeout Value Authorization]
[[File:Backup-DE-Hyper-V Agent-VM wiederherstellen-Rapid (18).png|none|900px]]<br>
[[File:Preshutdown.png|gerahmt|left]] [[File:Maximale Wartezeit für Gruppenrichtlinienskripts angeben.png|boxed|ohne]]<br>
This is also visible in Hyper-V Manager, as the virtual machine's migration status is no longer displayed.<br>
<span id="Neuen_benutzerdefinierten_Befehl_erstellen"></span>
[[File:Backup-DE-Hyper-V Agent-VM wiederherstellen-Rapid (19).png|none|900px]]
=== Create new custom command ===
<br>
<span id="Anzahl_der_VMs_pro_Sicherungsdurchlauf_reduzieren"></span>
== Reduce number of VMs per backup run ==  


This option gives you the opportunity to add a schedule to scripts that have already been created via the backup portal.
The TERRA CLOUD Backup Hyper-V Agent backs up up to 16 virtual machines per Hyper-V host simultaneously within a single job.<br>
[[File:Neuer benutzerdefinierter Befehl.png|framed|ohne]]<br>
<br>
<br>
When you create a new custom command, the agent checks whether there are scripts stored in the agent directory in the "ScheduleScripts" batch files subfolder.
'''Preparation:'''<br>
The standard path to this directory in which a script for this function can be stored:
# Stop the "TERRA CLOUD Backup Hyper-V Agent Management Service"
''C:\Program Files\TERRA Cloud Backup\Agent\ScheduleScripts''
# Stop the "TERRA CLOUD Backup Hyper-V Agent Host Service" on all hosts managed by the management component
In the following screenshot you can see a selected script with a configured schedule:
# Navigate to the following directory of the management component ''(default path: C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Management\Data\Configuration)''
[[File:Benutzerdefinierter Befehlt.jpg|framed|ohne]]<br>
# Create a backup copy of the file "''AgentCoordinator.cfg''" and save it outside the agent directory
# Navigate to the following directory of the host component (default path: ''C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Host\Data\Configuration'')
# Create a backup copy of the file "''AgentWorker.cfg''" and save it outside the agent directory
# Repeat step 6 for all host agents connected to the management agent
'''Editing the configuration:'''<br>
# Open the management agent's configuration file "''AgentCoordinator.cfg''" ''(default path: C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Management)''
# Add the [Advanced] section with the parameter MaximumConcurrency and the desired value, e.g. ...5 in JSON format (see screenshot below) and save the file.
# Open the host agent configuration file "AgentWorker.cfg" (default path: "C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Host\Data\Configuration").
# Change the value of the setting "MaximumConcurrency": 16, to the value specified in step 1 within AgentCoordinator.cfg.
# Repeat steps 3–4 for all host agents connected to the management agent.
# Start the "TERRA CLOUD Backup Hyper-V Agent Management Service".
# Start the "TERRA CLOUD Backup Hyper-V Agent Host Service" on all connected hosts.
'''Screenshot for editing step 2:'''
[[File:AgentCoordinator.cfg.png|framed|none]]
<br>
<br>
'''Recommendation:'''
'''Note:'''<br>
A custom command's schedule can only be created as a single-line schedule.
Please note that the value must not be configured higher than the default value of 16. <br>
Please check our [[Backup/en#Agent_Skripting_Best_Practice|Best Practice]] for agent scripting to avoid this disadvantage.
If the services fail to start after these adjustments, please perform a rollback using the backups you created. <br>
=== Agent Skripting Best Practice ===
<span id="Ändern_des_Mountpoints_für_Dateiwiederherstellungen"></span>
== Changing the mount point for data recovery ==
 
The Hyper-V agent allows you to restore not only entire virtual machines but also individual files and folders.<br>
For file-level recovery, the selected virtual machine is mounted as a network share.<br>
This enables you to conveniently browse its file system using Windows File Explorer and restore the desired files or folders.<br>
By default, the network share is mounted at '''C:\RestoreMount'''.<br>
You can change this path to a different folder or drive via the Windows Registry.<br>
<br>
'''Procedure:'''
* Open the Registry Editor with administrative privileges.
* Navigate to the following registry path: '''HKEY_LOCAL_MACHINE\SOFTWARE\EVault\InfoStage\Agent'''
* Create a new String Value named '''MountAlternatePath'''.
* Enter the desired target path as the value, for example:<br>'''E:\RestoreMount'''
* Restart both TERRA CLOUD services.
'''Note:'''<br>
If the specified folder does not yet exist, it will be created automatically during the recovery process.
<span id="Konfigurationsübertragung_auf_einen_anderen_Hyper-V_Host"></span>
== Transferring configuration to another Hyper-V host ==
 
Use this guide if a Hyper-V host has been replaced and existing backup jobs need to be transferred to the new host.
<span id="Voraussetzungen"></span>
=== Prerequisites ===
 
* The original Hyper-V host appears as '''Offline''' in the backup portal.
** This is the case, for example, if the Hyper-V agent components have been uninstalled.
* The Hyper-V management component is installed on the new Hyper-V host.
* The new Hyper-V host has already been registered with the TERRA CLOUD backup portal.
[[Datei:Backup-DE-Hyper-V-Crossrestore-1.png|1500px]]
<span id="Falls_der_ursprüngliche_Hyper-V-Host_bereits_gelöscht_wurde"></span>
==== If the original Hyper-V host has already been deleted ====


The backup agent can be tailored to individual application scenarios through the use of scripts.
If you have already deleted the original Hyper-V host '''visually''' from the backup portal, it must first be restored.<br>
We recommend that you use the following instructions as a basis for your scenario.<br>
To do this, open the '''Computers''' section, right-click on '''Online & Offline''', and then select '''Deleted'''.<br>
<br>
[[Datei:Backup-DE-Hyper-V-wiederherstellen-1.png|1500px]]<br>
<br>
<br>
'''Preparation:''' <br>
The deleted Hyper-V host should now be visible.<br>
What should be prepared before using the following scripts?
Select it and restore it using '''Actions → Restore selected Hyper-V computer'''.<br>
#Installing the agent on the system to be protected
#Link the system to the vault in the backup portal
#Create backup job(s), without a schedule<br>
<br>
<br>
'''Step 1: Create batch file''' <br>
[[Datei:Backup-DE-Hyper-V-wiederherstellen-2.png|1500px]]<br>
Create a batch file (.bat) with the following structure
''powershell.exe -ExecutionPolicy Bypass -File "Path to PowerShell script\agentscripting_retention.ps1"''
Please adapt this batch file later to the path and name of the PowerShell script you specified.
Copy the created batch script to the following folder in the agent installation directory: <br>
''C:\Program Files\TERRA Cloud Backup\Agent\ScheduleScripts (default)''
In the Backup Portal for the system in question, under "Select job task" click [[Backup/en#Create_new_custom_command|"New_custom_command"]]. <br>
You can use this function to select a stored batch script and provide it with a schedule. Please configure the desired time. (e.g. 10 p.m.)<br>
<br>
<br>
'''Function:''' <br>
[[Datei:Backup-DE-Hyper-V-wiederherstellen-3.png|1500px]]<br>
This batch file will later be started on a schedule by the backup agent itself. The batch file starts PowerShell and the second script.
<span id="Durchführung"></span>
Since PowerShell is much more extensive and flexible, the first script is only used to call PowerShell.<br>
=== Implementation ===
 
* If you have not already done so, install the Hyper-V management component on the new Hyper-V host and register it with the TERRA CLOUD Backup Portal.
* In the Backup Portal, go to '''Computers''' and open the settings for the new Hyper-V host.
[[Datei:Backup-DE-Hyper-V-Crossrestore-2.png|1500px]]
<br>
* Select the option '''Restore a previous Hyper-V agent'''.
[[Datei:Backup-DE-Hyper-V-Crossrestore-3.png|1500px]]
<br>
<br>
'''Step 2: Create PowerShell script''' <br>
* Under '''Select an offline agent for restoration''', choose the original Hyper-V host.
In this step you create the PowerShell script which is controlled by the batch script from '''Step 1'''.
[[Datei:Backup-DE-Hyper-V-Crossrestore-4.png|1500px]]
This script is used to contact the backup agent to carry out a backup.
It is also possible to use different retention periods and to install pre- and postcommands.<br>
<br>
<br>
'''Content:''' <br>
[[Datei:Backup-DE-Hyper-V-Crossrestore-5.png|1500px]]
Please create a PowerShell script (.ps1) with, for example, the following content:
''Set Location "C:\Program Files\TERRA Cloud Backup\Agent"''
  ''$date = GetDate
  $currentday = $date.Day
  $lastday = [DateTime]::DaysInMonth($date.Year, $date.Month)
  if ($lastday -eq $currentday){
    '''Placeholder for pre-commands'''
    .\VV.exe backup '''NamedesBackupJobs''' /quickscan=true /retention=Monthly
    '''Placeholder for post commands'''
  }
  else{
    '''Placeholder for pre-commands'''
    .\VV.exe backup '''NamedesBackupJobs''' /quickscan=true /retention=Daily
    '''Placeholder for post commands'''
  }''<br>
<br>
<br>
'''Function:'''
* Enter or correct the login credentials for the new Hyper-V host and save the settings.
This PowerShell script goes to the agent installation directory and checks the current date.
** Make sure to enter '''localhost''' in the '''Address''' field. This ensures the host remains accessible even if its IP address changes.
If the date equals the total number of days of the month (the dynamic last day of the month), a backup with the Monthly retention type is performed.
[[Datei:Backup-DE-Hyper-V-Crossrestore-6.png|1500px]]
On all other days, the retention type "Daily" is used.<br>
<span id="Wichtige_Nacharbeiten"></span>
=== Important Rework ===
 
{{Hinweis|type=terra|
'''After restoration, some settings must be re-entered or verified for security reasons.'''<br>
If these steps are not performed, backup jobs will not execute correctly.
* Re-enter the password for each vault registration.
* Re-enter the encryption password for each backup job.
* Reactivate scheduled jobs via the agent's action menu if necessary.
}}
<br>
<br>
'''Advantages of this implementation:'''
Once all passwords have been entered and communication has been successfully verified, please install the '''Hyper-V host component''' on the new Hyper-V host.
# You can use the full functionality of PowerShell and customize this basic script as desired for your customers
<span id="Abschluss"></span>
# The schedule can be created via the Backup Portal and does not have to be implemented via the script
=== Conclusion ===
# You can use pre- and post-commands to stop databases before the backup that cannot be brought into a consistent state using VSS technology
 
Finally, verify the following points:
* The Hyper-V agent appears as Online in the backup portal.
* The Hyper-V host appears as Online on the Hosts tab.
* All backup jobs have been successfully imported.
* All required passwords have been re-entered.
* Communication between the Agent Host Service and the Agent Management Service is working.
* Scheduled backup jobs are enabled (if desired).
<span id="Backup_Satelliten"></span>
= '''Backup satellites''' =


== Linux Agent  ==
<span id="Beschreibung_und_Vorteile"></span>
== Description and Benefits ==


In addition to the portal, the Linux agent can also be accessed via created scripts. <br>
The backup satellite is a hardware appliance or a virtual machine that is used in your end customer's network and can receive backups via the local network.<br>
You can contact the agents directly via a created script. As in the following example script (CustomScript.sh):<br>
The satellite provides you with all vault functions, e.g. providing volumes from an image backup.<br>
''nano CustomScript.sh''
The rental devices or virtual machines are made available to you by the TERRA Cloud and are billed monthly, depending on their size and performance, in addition to the required backup packages.<br>
''cd /opt/BUagent''<br>
By using a satellite, you can implement a hybrid cloud backup solution, as backups are stored locally on a satellite and subsequently replicated to a data center.<br>
''./VV backup RootDir''<br>
This backup concept offers the following advantages:
In the example, RootDir is the backup job name.<br>
* Fast backup and restore, thanks to a locally connected vault system (satellite)
The script (e.g.: CustomScript.sh) must then be given the appropriate rights. To do this, please execute the following command: <br>
* No acquisition costs, as the hardware is provided to you
''chmod +x CustomScript.sh''<br>
* Time decoupling between backup and replication is possible
<br>
* Restoration is possible independently of the data center
Optionally, you can schedule scripts via the Backup Portal by completing the following steps:<br>
* Initial backup can be carried out directly against the satellite
*Under Linux, by default, no folder called "ScheduleScripts" is created in the installation directory. Please create this with e.g. ''mkdir ScheduleScripts''<br>
* Your customer's bandwidth can be used optimally
*Place the created script (.bat or .cmd) in the agent directory in the newly created ScheduledScripts folder
* Fast VM restore of the Hyper-V agent or vSphere recovery agent
*In the Backup Portal, select "Create a new custom command" via "Select job task" and select your script
<span id="Inbetriebnahme"></span>
*Create a schedule for the script
== Commissioning ==
[[File:Neuen-benutzerdefinierten-Befehl.png|none]]<br>
<br />
= '''vSphere Recovery Agent''' =


<span id="Dokumentation_vSphere_Recovery_Agent"></span>
After ordering your backup package including satellites, you will receive an email with the access data as soon as the vault account has been provided on the Basevault. <br>
== vSphere Recovery Agent Documentation==
You will receive a separate notification after the satellite has been deployed and shipped to you.<br>
After receiving the satellite, the following steps must be carried out (hardware satellites):<br>
* Set up and launch satellite in your end customer's network
* You can reach the satellite interface via the local address of the satellite (either static IP or DHCP)
* Please note that the satellite interface can be accessed via HTTPS and may need to be enabled in the browser first
* You can use the interface to change the access data in the user administration and, if necessary, adjust the network configuration
* Please deactivate the bypass mode using the Deactivate bypass mode function [https://wiki.terracloud.de/index.php/Backup/en#Features 10.3.1.3]
* The satellite is now prepared for productive use and must be saved as a backup target in the agents' vault settings (local IP of the satellite)
* Initial backups can optionally be carried out directly against the satellite
Commissioning a satellite VM:<br>
* You will receive a Hyper-V VM container from TERRA Cloud Support, which you can import and virtualize under Hyper-V
** '''''Please note that only Hyper Hosts are compatible with the Windows Server 2022 operating system or higher!'''''
* Disk/network allocation must be done via Hyper-V Manager / VM Connect
* The remaining steps of commissioning a satellite VM are similar to commissioning a normal satellite
<span id="Satelliteninterface"></span>
== Satellite interface ==


You can find extensive documentation and further information in [https://drive.terracloud.de/dl/fiLpZboTGRPeqzW1cqwS6yin/Documentation%20and%20Release%20Notes/Documentation/DE/vSphere%20Recovery%20Agent%20v9.1%20-%20User%20Guide.pdf?inline vSphere Recovery Agent User Guide].
=== System ===
== Installation ==


Please run the vSphere Recovery Agent setup on a Windows Server system with access to the VMware environment (vCenter or standalone ESXi host). Please note the recommendations from the section [[Backup/en#Best_Practice|Best Practice]]. Please follow the instructions in the vSphere Recovery Agent InstallShield. In the last step of the installation, you register the system using the user and password entered in your end customer's created site. You can find a detailed description of the installation process in the User Guide linked above.
<span id="Anmeldung"></span>
<span id="Konfiguration_des_Agenten"></span>
==== Registration ====
== Agent configuration ==


After successful installation and registration on the TERRA CLOUD Backup Portal, you can now add the system to the vault as described in [[Backup/en#Associate_Agent_with_Vault|Add system to the vault]].
You can access the following interface in your browser using the satellite's IP address.<br>
<span id="Verbindung_zu_der_vSphere-Umgebung"></span>
There are two different users available, the image shows the administrative user who has <br> unrestricted access.<br>
=== Connection to the vSphere environment ===
In addition, there is a user who only has read rights; you can set the access data at a later date.<br>
The default login details for the admin user are:<br>
<br>
''User = admin''<br>
''Password = terra''<br>
<br>
[[File:AnmeldungSat.png|border|800px|Registration in the satellite interface]]<br>
<br />
<span id="Informationen"></span>
==== Informations ====


Please enter and save the access data for the vSphere environment (vCenter or standalone ESXi host) in the “credentials” fields. You will receive immediate feedback as to whether the access data provided is correct or whether the area can be reached.
The Information item shows you the dashboard with all the important vital indicators of the hardware, e.g. CPU, RAM or hard drive utilization.<br>
[[File:VRA-1.png|framed|ohne]]<br>
The satellite mode is also visible. A distinction is made between two modes, the active and inactive bypass mode.<br>
=== Changed Block Tracking ===
With active bypass, the satellite rejects all agent requests, so communication for backups, restores, synchronizations or job creation takes place via the basevault. Accordingly, the Basevault address must be stored in the portal under the Vault Settings tab.<br>
 
With the inactive bypass, the satellite is activated and accepts all agent requests, thereby enabling communication for backups, restores, synchronizations
This agent function is already activated after installation and allows quick and efficient delta backup of the virtual machines. <br>
or job creation takes place via the satellite. Accordingly, the IP address of the satellite must be stored in the portal under the Vault Settings tab.<br>
For more information about this technology, see VMware's [https://kb.vmware.com/s/article/1020128 Knowledge Base]. <br>
<br>
[[File:VRA-CBT.png|framed|ohne]]<br>
'''Hard disk capacity:'''<br>
<span id="Automatisierte_Wiederherstellungstests"></span>
Green = Between 0% and 85% <br>
=== Automated recovery tests ===
Orange = From 85% to 95% <br>
 
Red = From 95% to 99.99% <br>
Enabling the Verify backup on completion option will perform a recovery test via quick VM restore after each backup completes.
<br>
After the virtual machine boots, a screenshot of the login mask is created and saved in the TERRA CLOUD Backup Portal.
[[File:Warnung Speicher.png|border|800px|Storage warning in the overview]]<br>
To use this feature, the [[Backup/en#Rapid_VM_Recovery|rapid VM recovery]] requirements must be met.
<br>
Please store the temporary data store on which the VM can be started for the test recovery and the desired ESXi host. <br>
[[File:Warnung.png|border|Message Storage Warning]]<br>
<br>
[[File:Speicher Alarm de.png|border|800px|Storage Alarm in the overview]]<br>
<br>
[[File:95%-DE.png|border|Storage Alert]]<br>
<br>
<br>
'''Example configuration:''' <br>
<span id="Funktionen"></span>
[[File:VRA-2.png|framed|ohne]]<br>
==== Features ====
<span id="vSphere_Backup_Job_erstellen"></span>
== Create vSphere Backup Job ==


Once you have finished installing and configuring the agent, you can create a new "Job for VMware vSphere".
'''System functions:'''<br>
The following screenshot shows an example of a new job for a vSphere environment. Please enter a job name and optionally a description and the encryption password.
Under Functions you will find a list of the relevant services stored on the satellite. Please check whether all services are running.<br>
You can either include all virtual machines in the backup by selecting the "Virtual Machines" level, so all virtual machines are included recursively. This option offers the advantage that new virtual machines are automatically added to the backup job.
If a service is stopped, you can start it using the Play symbol. Please do not restart any services while the satellite is running.<br>
Alternatively, you can select individual VMs and add them to the backup set.<br>
<br>
<br>
'''Optional:Advanced Settings:''' <br>
'''Satellite functions:'''<br>
<span id="Anwendungskonsistente_Sicherung_aktivieren"></span>
You can use this interface to shut down the satellite, restart it, or manually start a replication process.<br>
=== Enable application consistent backup ===
<br>
 
'''Disable bypass:'''<br>
As soon as you "enable application consistent backup" an application consistent snapshot can be created based on a Microsoft VSS snapshot.
A satellite with bypass mode activated cannot accept backups and delegates them to the base vault. Please deactivate bypass mode so that the satellite can accept backups.<br>
We recommend enabling this option for all virtual machines with a Windows guest operating system.
<br>
<span id="Protokolle_der_Datenbanktransaktionen_kürzen"></span>
[[File:Bypass deaktivieren2.png|border|800px|Disable Bypass]]<br>
=== Truncate database transaction logs ===
<br>
'''Activate Support Connect:'''<br>
With this switch you allow TERRA CLOUD support to access the satellite via remote maintenance.<br>
==== Branding ====


In addition to application-consistent backup, transaction logs from Microsoft Exchange or SQL Server instances can be truncated.
This function allows you to adapt the satellite interface to your company's CI.<br>
<span id="Bedrohungserkennung_aktivieren"></span>
The configuration only needs to be carried out on one satellite, as you can export it and import it on other satellites.<br>
=== Enable Threat Detection ===
There is also the option to add your own logo.<br>
[[File:Branding.png|800px|border|Branding]] <br>
<span id="Wartung"></span>
==== Maintenance ====


When backing up active virtual machines with Windows guest operating systems, the vSphere Recovery Agent can scan the system for active ransomeware.
Vault maintenance checks the satellite's data stock every day at 9:23 a.m. for safesets that have exceeded their retention period; the number of retention days and copies must be exceeded. Expired safesets are deleted from the satellite.
We recommend enabling this option for all virtual machines with a Windows guest operating system.
You can adjust the start time of this maintenance if necessary.<br>
The Enable Threat Detection option requires guest operating system credentials.
[[File:Wartung.png|800px|border]]<br>
<span id="Diesen_Sicherungsjob_bei_Fertigstellung_überprüfen"></span>
==== Updates ====
=== Verify this backup job upon completion ===


Following the backup, a recovery test of the virtual machines is performed via fast VM recovery.
You can search the satellite interface directly for current updates and import them.<br>
Please note that this function must be set up in the [[https://wiki.terracloud.de/index.php/Backup#Automatisierte_Wiederherstellungstests|Agent Configuration]].
[[File:Updates.png|800px|border]]<br>
<span id="Globale_VM-Anmeldeinformationen"></span>
<span id="XML-Ansicht"></span>
=== Global VM Credentials ===
==== XML View ====
 
This menu item will take you to the XML output of the satellite in a new tab. This output lists all relevant information of the satellite and can be monitored.<br>
You can incorporate this link into your own monitoring solution or use ready-made sensors. You can find ready-made sensors for Server-Eye and PRTG Network Monitor, the sensors can be found under the search term “Terra Cloud Backup”. <br>
[https://www.server-eye.de/ Homepage Server-Eye] <br>
[[File:XML-Ansicht.png|border|500px]]<br>
<br />
<span id="Replikation"></span>
=== Replication ===


The entered access data will be used for all virtual machines in the backup set.
<span id="Konnektivität"></span>
<span id="Gast-BS-Anmeldeinformationen"></span>
==== Connectivity ====
=== Guest OS Credentials ===


If you would like to assign access data individually for each virtual machine, you can enter these in the backup set below the virtual machine by displaying the input field using the blue arrow.
This overview shows you the status of the connection to the Basevault. The satellite transmits a "heartbeat" to the basevault at regular intervals.<br>
[[File:VRA-3.png|framed|ohne]]<br>
In addition, the connection to the backup portal and the base vault is checked via ping and Telnet. This ensures that all necessary [https://wiki.terracloud.de/index.php/Backup/en#Network_configuration ports] are activated for the satellite.< br>
<span id="Rapid_VM_Recovery_(schnelle_VM-Wiederherstellung)"></span>
During replication, for example, the outgoing network traffic rate can also be monitored.<br>
== Rapid VM Recovery ==
[[File:Satellit Konnektivität.jpg|framed|ohne|100px|]]<br>
<span id="Replikationsstatus"></span>
==== Replication Status ====


The quick VM restore recovery option gives you the option to start a VM from the backup.<br>
This overview shows you which safesets are still outstanding for replication to the data center; these are processed as if in a queue. <br>
Downtime can be drastically reduced thanks to quick access, and the function is also suitable for carrying out a recovery test in just a few minutes.<br>
On the right side you can click through the satellite's current inventory and view more detailed information about individual safe sets, such as the compressed <br>
Size or whether this safeset has already been replicated.<br>
<br>
<br>
'''Requirement:'''
[[File:Replikation.png|border|900px|ReplicationStatus]]<br>
* Only available in conjunction with a TERRA CLOUD Backup Satellite or TERRA CLOUD Backup Enterprise Vault
<span id="Bandbreitenlimitierung"></span>
* Every ESXi host must have a software ISCSI adapter
==== Bandwidth limitation ====
* The datastore on which the VM is started can be either on local, ISCSI or vSAN storage
* A datastore to which a VM is to be migrated can also be located on an NFS share in addition to the storage types mentioned above
* There must be at least two datastores in total
* vSphere Recovery Agent 8.82 or later
* The Windows server on which the VRA is installed has the Windows feature "iSCSI Target Server"<br>
<br>
'''Example configuration of an ESXi host for Rapid VM Recovery:''' <br>
In the following screenshot, an iSCSI software adapter was added via the vCenter via "Add Software Adapter".
[[File:ISCSI Software Adapter.png|ohne|1500px]]<br>
<br>
Additionally, a VMkernel adapter without an activated service role has been added, as shown in the following screenshot:
[[File:VMkerneladapter.png|ohne|1500px]]<br>
<br>
'''Method:'''
Once all prerequisites are met, under "Restore" you will see an additional "Virtual machine option that uses fast VM restore": <br>
[[File:RVMR.png|framed|ohne]]<br>
<br>
You will then be taken to the recovery configuration, where you can decide which VM should be restored and also define which datastore should be used.
In the following screenshot you can see the datastore "Rapid VM Recovery Datastore", which was specifically configured for e.g. recovery and functional testing. During the recovery you can migrate the VM to another datastore on which your productive systems are located, for example.
[[File:RVMR1.png|framed|ohne]]<br>
== Best Practice ==


* Install the vSphere Recovery Agent in its own Windows Server VM; if possible, this will only be used for management or backup
You can configure a bandwidth limit for satellite replication.
* Keep the vSphere Recovery Agent VM highly available via vSphere HA
Please note that after an adjustment, the replication service restarts and ongoing replications are aborted. <br>
* Use a satellite for TERRA CLOUD backup to be able to use Rapid VM Recovery
If the connection is weaker, we recommend configuring the "Quality of Service" on the firewall for the satellite and assigning it a low priority.<br>
* Place the vSphere Recovery Agent VM on the same subnet as the vCenter Server Appliance
This setting on the firewall ensures that, for example, on a holiday, the <br>. can be replicated with full bandwidth
* Enable the "Application Aware Backup" option in the backup job
Bandwidth allocation is therefore more flexible than a fixed bandwidth limit. <br>
* Use Change Block Tracking to back up virtual machines; this setting can be found under the "vCenter Settings" tab.
[[File:Bandbreitenlimitierung.png|border|800px]]<br>
= '''Hyper-V Agent''' =
<span id="Replikationszeitplan"></span>
==== Replication Schedule ====


<span id="Dokumentation_Hyper-V_Agent"></span>
The replication schedule allows you to control whether to replicate immediately after a newly created backup and after <br>
== Documentation Hyper-V Agent ==
defined schedule or exclusively according to a configured replication schedule. This option is particularly recommended if <br>
should be backed up during your customer's working hours, but replication should only start after working hours. <br>
In this image you can see the configuration for a replication schedule that initiates a replication operation every day around 8 p.m.:<br>
[[File:Replikationszeitplan.png|border|800px]]<br>
==== Safeset Management ====


The following sections contain, among other things, information about setting up and configuring the TERRA CLOUD Backup Hyper-V agent. <br>
Special configurations can be made on the satellite via Safeset Management; if configured incorrectly, these can affect the function of the satellite.<br>
You can find extensive documentation and further information in the [https://drive.terracloud.de/dl/fi6M3VBEW7DmdZmCXYazF9L2/Hyper-V%20Agent%20v9.1%20-%20User%20Guide.pdf?inline Hyper-V Agent User Guide ]
Changes can only be made after activation via the slider and '''may only be made after consultation with support'''.<br>
== Installation ==
[[File:Safeset-management.png|border|800px]]<br>
<span id="Backup_Daten"></span>
=== Backup data ===


The following compact instructions describe the essential steps for setting up the TERRA CLOUD Backup Hyper-V agent. <br>
You can use the satellite interface to delete entire systems, jobs or individual backup sets (safesets). <br>
<br>
The deletion only applies to satellites; the data in the data center on the respective base vault remains unaffected. <br>
'''Setup order:'''<br>
Safe sets are displayed online; they are highlighted in black and can be selected by clicking in the checkbox. <br>
1. Install TERRA CLOUD Backup Hyper-V Agent Management <br>
Online safesets are characterized by the fact that they are stored locally on the satellite and are directly available there.<br>
2. Setting up the management agent in the backup portal (establishing a connection to the Hyper-V environment, adding computers to the vault) <br>
Safesets that are grayed out and cannot be selected are offline safesets. <br>
3. Install TERRA CLOUD Backup Hyper-V Agent Host <br>
An offline safeset represents a backup that does not exist on the Satellite, but still exists on the Basevault. <br>
Only meta information about these safesets is stored on the satellite. <br>
<br>
<br>
'''Single Host Hyper-V Systems: <br>'''
'''Procedure for deletion:'''<br>
In this scenario, you can install both the TERRA CLOUD Backup Hyper-V Management Agent and the Host Agent directly on the Hyper-V host ("Root"/"Parent" partition). <br>
Please still follow the setup sequence listed above.<br>
<br>
<br>
'''Hyper-V Cluster:''' <br>
'''System level deletion:'''<br>
Because it is split into two software components (management and host), the TERRA CLOUD Backup Hyper-V Agent is ideal for use in a cluster.
a) Check in the interface's job monitor that no process is running for the affected system. (If the Job Monitor tab is not available, update to the latest interface version)<br>
We recommend installing the management agent in an administrative VM within the Hyper-V cluster, so it can be operated on different hosts and kept highly available via the failover cluster.
b) Select the systems to be deleted and carry out the “Delete marked entries” action
After completing setup steps 1 and 2, you can install the TERRA CLOUD Backup Hyper-V Agent Host on all nodes of the Hyper-V cluster in the third step.<br>
c) Wait until the affected system is grayed out from the overview. (It may take some time) <br>
d) Check the capacity of the satellite and start a quick storage optimization <br>
<br>
<br>
'''TERRA CLOUD Backup Hyper-V Agent Management:''' <br>
'''Job level deletion:'''<br>
a) Check in the interface's job monitor that no process is running for the affected job. (If the Job Monitor tab is not available, update to the latest interface version)<br>
b) Mark the job to be deleted by selecting it and carry out the “Delete marked entries” action <br>
c) Wait until the affected job has disappeared from the overview/grayed out. (It may take some time)<br>
d) Check satellite capacity. If unchanged, start quick memory optimization <br>
<br>
<br>
'''Step 1 of Setup''' <br>
'''Safeset level deletion:'''<br>
Please install the setup on the desired system and follow the instructions within the setup.
a) Check in the interface's job monitor that no process is running for the affected job. (If the Job Monitor tab is not available, update to the latest interface version)<br>
In the last step, registration on the TERRA CLOUD backup portal is configured, analogous to all other TERRA CLOUD backup agents. You can either directly select a user within the site with sufficient authorization or register the system in your parent site and then move it.<br>
b) Select the safe sets to be deleted and carry out the “Delete marked entries” action
c) Wait until all affected safe sets have disappeared from the overview/grayed out. (Depending on the size, the process can take a lot of time) <br>
d) As soon as all safesets have disappeared/grayed out, start quick storage optimization <br>
<br>
<br>
'''Setup Step 2''' <br>
After successfully completing the installation, the system should appear in the selected site in the portal. Please follow the instructions in the Backup Portal to establish a connection to the Hyper-V environment and then add the computer to the vault.<br>
<br>
<br>
'''Installation TERRA CLOUD Backup Hyper-V Agent Host:''' <br>
[[File:Backupdaten.png|border|800px|Backup data on the satellite]]<br>
<br>
=== Job Monitor ===
'''Step 3 of Setup''' <br>
After successfully configuring the Hyper-V agent in step 2, you can install the host agent on all nodes of the Hyper-V cluster or on the single host.
For a cluster installation, the FQDN of the system on which the management agent is active should be specified in order to establish a connection to it.
After the successful installation, the respective node should be displayed as online under the “Hosts” tab in the backup portal.


<span id="Rapid_VM_Recovery_(schnelle_VM-Wiederherstellung)"></span>
You can view open or already completed processes in the Job Monitor.<br>
== Rapid VM Recovery ==
Backups or restores can be monitored, as can replication processes.<br>
The following screenshot shows a satellite that currently has no open jobs:<br>
[[File:Jobmonitor.png|800px|border]]<br>
<br>
'''Jobs on the screenshot:'''<br>
Maintenance Host = This process represents maintenance on the satellite, this process should always be displayed <br>
Satellite Replication Service = Behind this process is the active replication service, this process should always be displayed <br>
Satellite Replication - Upload Satellite Statistics = In the screenshot, this process is set to "Inactive" because it was completed successfully. In this job, the satellite passed information to the basevault.
<span id="Benutzerverwaltung"></span>
=== User management ===


The quick VM restore recovery option gives you the option to start a VM from the backup.<br>
Within the user management you can define passwords for a total of two users.<br>
Downtime can be drastically reduced thanks to quick access, and the function is also suitable for carrying out a recovery test in just a few minutes.
Which users are stored in total?<br>
<span id="Voraussetzungen"></span>
#Admin: This user has full access and is intended for administration of the satellite.
=== Requirements ===
#User: This user only has read permission and can be issued to the end customer as required.
<br>
[[File:Benutzerverwaltung.png|border|800px|User Management]]<br>
<br />
<span id="Netzwerkkonfiguration"></span>
=== Network configuration ===


# Hybrid TERRA CLOUD backup with a TERRA CLOUD Backup satellite or TERRA CLOUD Backup Enterprise
You can use the network configuration to pass on your desired settings directly to the satellite or use the “Activate DHCP” function. <br>
# Hyper-V Checkpoints must be enabled for the secured VMs (for more information, see: [https://docs.microsoft.com/en-us/windows-server/virtualization/hyper-v/manage/enable-or-disable-checkpoints-in-hyper-v Hyper-V Checkpoints])
As soon as DHCP has been activated, the network configuration assigned by the DHCP server will be displayed. <br>
<br>
[[File:Netzwerkverwaltung.png|border|800px|Satellite Network Management]]<br>
<br/>
<span id="Initialsicherung_FTP_Upload_/_Datenträger_einsenden"></span>
= '''Initial backup FTP upload / send data carrier''' =


<span id="Anzahl_der_VMs_pro_Sicherungsdurchlauf_reduzieren"></span>
<span id="Buchung"></span>
== Reduce number of VMs per backup run ==  
== Booking ==


The TERRA CLOUD Backup Hyper-V Agent backs up up to 16 virtual machines per Hyper-V host in one job at the same time.
The two processes can be added when initially booking a backup package or later in the order.
<br>
<span id="Durchführung"></span>
'''Instructions'''<br>
== Implementation ==
 
'''Prerequisites:'''
*The backup agent is installed on the target system and registered in the portal.
*The backup job and schedule are configured as desired.
*To prevent the external storage medium from being included in the backup, the "Entire Server" option has been temporarily removed from the job configuration.<br>Instead, the backup is performed by manually selecting the individual drives. The external storage medium must not be selected.
*The backup job schedule is disabled to prevent the agent from automatically attempting to back up to the vault.<br>
<br>
'''Procedure:'''<br>
1.) '''Start the backup to the vault to transfer metadata.'''<br>
This transmits information required by the vault for the import process.<br>
The process can be stopped as soon as the status "Processing" appears. <br>
<br>
2.) '''Create the folder structure in the target directory.''' <br>
To ensure smooth identification, please create the following folder structure: <br>
'''\$ACCOUNTNAME$\$COMPUTERNAME$\$JOBNAME$''' <br>
<br>
<br>
'''Preparation:'''<br>
Example path:<br>
# Stop the "TERRA CLOUD Backup Hyper-V Agent Management Service" service
'''E:\45814-ENDKUNDE\WIN-VKEE7ONL8FG\BMR''' <br>
# Stop the "TERRA CLOUD Backup Hyper-V Agent Host Service" service on all hosts managed by the management component
<p style="color: #FF0000;"> As the data involved is always encrypted, an incorrect folder structure would result in a written inquiry and, consequently, a delay in the process. </p>
# Navigate to the installation path of the management component ''(default path: C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Management)''
3.) '''Start the backup to the previously created path.'''<br>
# Make a backup copy of the file "''AgentCoordinator.cfg''" and store it outside the agent directory
The procedure in the portal is as follows:<br>
# Navigate to the installation path of the host component (default path: ''C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Host\Data\Configuration'')
# Make a backup copy of the file "''AgentWorker.cfg''" and store it outside the agent directory
# Repeat step 6 for all host agents connected to the management agent
<br>
<br>
'''Editing the configuration:'''<br>
[[File:Verzeichnis_auf_Datentraeger.png|350px|border|Target: Directory on storage medium]] <br>
# Open the management agent configuration file "''AgentCoordinator.cfg''" ''(Default path: C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Management)''
# Add the Advanced section with the MaximumConcurrency parameter and the desired value e.g. For example, enter 5 in JSON format (see screenshot below) and save the file
# Open the host agent configuration file ''AgentWorker.cfg'' (default path: ''C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Host\Data\Configuration'')
# Lower the value of the setting "''"MaximumConcurrency": 16,''" to the value stored in step 1 in AgentCoordinator.cfg
# Repeat steps 3-4 for all host agents connected to the management agent
# Start the service "TERRA CLOUD Backup Hyper-V Agent Management Service"
# Start the "TERRA CLOUD Backup Hyper-V Agent Host Service" service on all connected hosts
<br>
<br>
'''Screenshot of step 2 of editing:'''
[[File:Ordner_auswaehlen.png|350px|border|Select the previously created folder structure]] <br>
[[Datei:AgentCoordinator.cfg.png|gerahmt|ohne]]
<br>
<br>
'''Note:'''<br>
[[File:Initialbackup_auf_Datentraeger.png|350px|border|Start backup]] <br>
Please note that the value cannot be configured higher than the default value of 16. <br>
== FTP Upload ==
If the services do not start after the adjustments, please perform a rollback using the created backup copies. <br>


= '''A'''utomatic '''B'''are Metal '''S'''ystem '''R'''estore '''T'''est (ABSRT-Tool) =
'''Please ensure that the dataset is complete.'''<br>
 
'''Each job is divided into backup fragments that are numbered sequentially; all fragments except the last one are 1,048,576 KB in size.'''<br>
<span id="Allgemeines"></span>
'''Only the first fragment (SafesetNumber.SSI or 00000001.SSI) differs in its filename from the remaining files.''' <br>
== General ==
<br>
 
[[Datei:Backup-DE-Initialsicherung-Fragmente.PNG|350px|border]]<br>
Regular BMR test restores are a necessity for the quality management of a backup concept. <br>
<br>
However, manual tests are time-consuming and therefore cost-intensive; automation can help here and reduce the time spent on configuration and control.<br>
Before uploading, check the initial backup log for any anomalies.<br>
If you encounter irregularities or have questions, please contact our support team before sending or uploading the dataset.<br>
<br>
<br>
The ABSRT tool creates virtual machines based on Microsoft Hyper-V; these have a prepared restore ISO. <br>
The created initial backup can then be uploaded to the TERRA Cloud FTP server.<br>
All data that would have to be entered during a manual restore, such as the system name or the address of the vault system, is read from a CSV file and entered in the restore process. <br>
The most current safeset is dynamically used for the recovery test. <br>
After the automated configuration has been completed, a complete restore is carried out, including the system start after successful completion.<br>
<br>
<br>
To further increase efficiency, you can also parallelize the restore by storing the data from several BMR backup jobs in the CSV file.<br>
For example, the [https://filezilla-project.org/download.php?type=client FileZilla Client] can be used for the upload. <br>
The necessary access credentials will be provided by us after the booking has been received in the Center. <br>
<br>
<br>
'''The current version of ABSRT is only supported on Windows Server operating systems due to compatibility issues.'''
Once the upload is complete and has been verified, please send us a brief confirmation regarding the previously transmitted information. <br>
<span id="Voraussetzungen"></span>
== Requirements ==
 
# Participation in the [https://b2b.wortmann.de/de-de/productlist/2996422/schulungen/nav-campus.aspx TERRA CLOUD Backup Certified Specialist Training]
# At least one Microsoft Hyper-V host with corresponding free capacity for the test VMs
# The test VMs require access to a DHCP server
# An external vSwitch must be available
# Activated Windows Server license
# Certified Specialist ABSRT license (available upon request from [mailto:support@terracloud.de Support])
<span id="Einrichtung"></span>
== Setup ==
 
When you start the ABSRT tool for the first time, the tool will ask you for a Certified Specialist ABSRT license:<br>
[[File:Lizenz.PNG|framed|ohne]]<br>
<br>
<br>
After you have entered a valid license, the installation path selection appears:<br>
Following successful verification, we will notify you as soon as there are updates regarding the import.
[[File:Install Path.PNG|framed|ohne]]<br>
<br>
<br>
The following required components are then checked/installed:<br>
<span id="Datenträger_einsenden"></span>
# Hyper-V installation
== Send in data carrier ==
# Bootable Media Creator
# Windows Assessment and Deployment Kit
# If configured, VeraCrypt
If software components are missing or not up to date, they will be automatically installed by the tool.<br>
If the Hyper-V component is installed, a restart must be carried out.<br>
[[File:Preparation.PNG|framed|ohne]] <br>
<span id="Vorbereitung_der_CSV_Datei"></span>
=== Preparation of the CSV file ===


Please navigate to the tool's installation directory and open the "CSV" folder (e.g. under C:\ABSRT\CSV). <br>
'''Please ensure that the dataset is complete.'''<br>
This folder contains the "Backups.csv" file, which you can use as the basis for your configuration. <br>
'''Each job is divided into backup fragments that are numbered sequentially; all fragments except the last one are 1,048,576 KB in size.'''<br>
'''Only the first fragment (SafesetNumber.SSI or 00000001.SSI) differs in its filename from the remaining files.''' <br>
<br>
[[Datei:Backup-DE-Initialsicherung-Fragmente.PNG|350px|border]]<br>
<br>
<br>
'''Important! The first line serves as a legend and may not be adjusted!'''<br>
Before shipping, check the initial backup log for any anomalies.<br>
If you encounter irregularities or have questions, please contact our support team before sending in the storage medium.<br>
<br>
<br>
Example:<br>
If the initial backup completed successfully but an error message appears in the log file after the successful completion notice, we recommend consulting the following Wiki article:<br>
<code>Vaultaddress,Vaultaccount,Vaultaccountpassword,Computername,Jobname,EncryptionPassword,VHDXCapacity,VMGeneration,VHDXStorage,VSwitchName,AmountOfPhysicalDisks,SendEmail</code><br>
[[Backup_Fehlerdiagnose#SSET-E-04104 Die Anforderung ist fehlgeschlagen. Der Remote-Server meldete folgenden Fehler: RPC-E-FAILED, allgemeiner RPC-Fehler / UTIL-W-05229 Konfigurationsdateien konnten nicht hochgeladen werden: Datei konnte nicht hochgeladen werden. C:\Program Files\TERRA CLOUD Backup\Agent\Jobname.status.cfg|SSET-E-04104 The request failed. The remote server reported the following error: RPC-E-FAILED, general RPC error / UTIL-W-05229 Configuration files could not be uploaded: File could not be uploaded. C:\Program Files\TERRA CLOUD Backup\Agent\Jobname.status.cfg]]<br>
==> vault-wmh1-wp01.terracloud.de,00000-RESELLER,RtHKha451!HjioplÖ03,DC,BMR,hdakzeogsz1,300,2,D,extern,3,n<br>
<br>
<br>
'''Note:'''<br>
Once all outstanding questions and issues have been resolved, the storage medium can be sent to the following address, together with the completed [https://downloads.terracloud.de/files/Formulare%20&%20Zertifikate/terra%20CLOUD_Einsendeformular.pdf submission form]: <br>
If there is a comma in the encryption password, the entire encryption password must be enclosed in double quotation marks.<br>
<br>
<br>
'''Example of the encryption password with the special character comma:''' <br>
'''TERRA CLOUD GmbH''' <br>
"Ghgui385as,"
'''Hankamp 2''' <br>
'''32609 Hüllhorst''' <br>
<br>
<br>
You can save the CSV file under any name. We recommend creating a separate CSV file for each end customer.<br>
Notifications regarding the import or shipping status of the storage medium are handled via automated business processes. <br>
<span id="Erklärung_der_Parameter"></span>
=== Explanation of parameters ===
 
''Vaultaddress'' = FQDN of the vault system
''Vaultaccount'' = Vault account, you can take this from your Vault profile, for example
''Vaultaccountpassword'' = This is the password you received in the deployment confirmation
''Computer name'' = computer name on the vault system, this does not necessarily have to correspond to the name displayed in the backup portal, if in doubt, please check your reseller report
''Jobname'' = Name of the backup job
''EncryptionPassword'' = The encryption password of the selected backup job
''VHDXCapacity'' = Please enter the size of the restored volume here. If the system has several volumes, please enter the value of the largest in GB.
''VMGeneration'' = Please note that the generation of the VM matches the source system. Specifying the generation in the CSV determines the algorithm for allocating volumes in the restore process.
''VHDXStorage'' = Please enter the drive letter for the storage location of the VHDX
''VSwitchName'' = Name of the external vSwitch, you can find this in the virtual switch manager
''AmountOfPhysicalDisks'' = Please enter the number of hard drives the system has
''SendEmail'' = An optional switch that allows you to configure an email notification (n = no, y = yes)
If you want to restore multiple systems at the same time, simply add more lines starting from line 3. The legend line does not need to be copied.<br>
<span id="Durchführung"></span>
== Implementation ==
 
After you have prepared one or more CSV files, you can start the tool again. Here you just have to select the CSV file to start a restore.<br>
[[File:Selection of the CSV.PNG|framed|ohne]]<br>
<br>
<br>
You can find a short demonstration at: [https://drive.terracloud.de/getlink/fi7SiA69jnYZAeuhtkkkuSXV/ABSRT.mp4 Demo video] <br>
<p style="color: #FF0000;"> Under no circumstances should you send us unencrypted raw data belonging to your end customer! </p>
== Monitoring ==
<p style="color: #FF0000;"> Such data will be returned to the sender unprocessed. </p>
= '''Backup Export''' =


During the restore, another process is started that checks the status of the restore based on the heartbeat of the virtual machine. <br>
In order to save data on a local medium, for example for long-term backup, we can export your backups.
As soon as a heartbeat is present, a screenshot of the connection window is created and stored in the ABSRT directory under "Screenshots". <br>
The export is encrypted and in the so-called vault format, so that the exported data must be read in with additional software before an agent can process and restore it.<br>
If the ''SendEmail'' option was selected, the screenshot will also be sent to the specified email address.<br>
[[File:Monitoring neu.png|framed|ohne]] <br>
<br>
<br>
[[File:ABSRT-Monitoring.jpg|framed|ohne]] <br>
Please note that this is a paid process. Further information about the process (offer, procedure, etc.) is available from our cloud sales department: [mailto:cloud@wortmann.de cloud@wortmann.de] <br>
<span id="E-Mail_Benachrichtigung_ABSRT"></span>
As soon as you have received the desired data set, you can continue with the steps below. <br>
=== Email notification ABSRT ===
It should also be noted that it is '''not''' possible to export backups via the Hyper-V agent. <br>
 
To use email notification, you must edit and fill out the file C:\ABSRT\smtp.xml:<br>
[[File:Mailabsrt.png|border|C:\ABSRT\smtp.xml]]<br>
<br>
<br>
The script checks in advance whether the required fields have been filled out. If an entry has not been completed, the notification will be skipped.<br>
The required software can be found at:<br>
== VeraCrypt ==
[https://backup.terracloud.de/Download/SecondaryRestoreServer-8-70-0266.exe Secondary Restore Server]<br>
== Secondary Restore Server ==


'''Activate function later:''' <br>
The Secondary Restore Server reads the exported data and presents it as a virtual vault in the existing network.<br>
Remove VeraCrypt REG key under HKEY_LOCAL_MACHINE\SOFTWARE\ABSRT\
*Please navigate to the folder structure of the exported data in the Secondary Restore Server
Start ABSRT.exe again and activate VeraCrypt<br>
*Store the data of the exported vault account, e.g. B. (45814-END CUSTOMER), as well as the vault account password
*Start sharing via the Secondary Restore Server (Start)
*Agents can then access the share as if it were a normal vault.
[[File:Secondaryrestoreserver.png|border|Secondary Restore Server]]<br>
<br>
<br>
'''Deactivate the function later:''' <br>
<span id="Wiederherstellung_von_einzelnen_Dateien(Secondary_Restore_Server)"></span>
If necessary, remove containers under C:\ABSRT\VeraCrypt
== Restore individual files (Secondary Restore Server) ==
Remove VeraCrypt REG key under HKEY_LOCAL_MACHINE\SOFTWARE\ABSRT\
 
Start ABSRT.exe again and say no to VeraCrypt<br>
Once the data has been presented on the network, you can proceed as follows:<br>
[[File:CrossRestore-1.PNG|border|1500px|CrossRestore Step 1]]<br>
<br>
<br>
'''Rebuild CSV Container:''' <br>
[[File:CrossRestore-2.PNG|border|CrossRestore Step 2]]<br>
Remove container under C:\ABSRT\VeraCrypt
Start ABSRT.exe again and enter the password for the new container
<span id="Skriptbasierter_Umgang_ABSRT"></span>
== Script-based handling ABSRT ==
 
The following parameters can be used '''only via PowerShell''':<br>
<br>
<br>
'''''-Install [Switch]''' - "C:\Users\Administrator\Desktop\ABSRT.exe -Install -DebitorNumber 12345 -License D133763385BAEFBFF9673C63Ab [-Vera Terra001!]"''<br>
[[File:CrossRestore-3.PNG|border|1500px|CrossRestore Step 3]]<br>
-> Performs an automated installation of the ABSRT tool. The -Vera parameter is optional. <br>
<br>
<br>
'''IMPORTANT:''' If the Hyper-V role has not yet been installed, an automatic restart will occur after the installation is complete! <br>
[[File:CrossRestore-4.PNG|border|1500px|CrossRestore Step 4]]<br>
<br>
<br>
'''''-Password [String]''' - "C:\Users\Administrator\Desktop\ABSRT.exe -Password Terra001!"<br>''
[[File:CrossRestore-5.PNG|border|CrossRestore Step 5]]<br>
-> Ensures that the VeraCrypt container is mounted automatically. If the password is incorrect, a manual query will be made.<br>
<br>
<br>
'''''-CSV [String]''' - "C:\Users\Administrator\Desktop\ABSRT.exe -Password Terra001! -CSV V:\CSV\TestCSV.csv [-NoPause]"''<br >
[[File:CrossRestore-6.PNG|border|1500px|CrossRestore Step 6]]<br>
-> Ensures that the CSV file is automatically selected. Please always provide the complete path of the CSV + file extension. (Shift + right click -> "Copy as path" can be used for this)<br>
<br>
<br>
'''''-Uninstall [Switch]''' - "C:\Users\Administrator\Desktop\ABSRT.exe -Uninstall"''<br>
[[File:CrossRestore-7.PNG|border|CrossRestore Step 7]]<br>
-> Performs a complete uninstallation of the ABSRT tool. However, the Hyper-V role is not uninstalled. Please ensure that you only perform the uninstallation once no VM created by ABSRT exists in the Hyper-V Manager. <br>
<br>
<br>
'''''-Manual [Switch]''' - "C:\Users\Administrator\Desktop\ABSRT.exe -Manual -Vaultaddress vault-wmh1-0002.terracloud.de -Vaultaccount 00000-RESTORE -Vaultaccountpassword wD5c9mP7-3bL1337l1th8W7xaB0T0m -Computername RESTORE -Jobname RESTORE -EncryptionPassword Terra001! -VHDXCapacity 1000 -VMGeneration 2 -VHDXStorage D -VSwitchName vSwitch -AmountOfPhysicalDisks 4 -SendEmail n"'' <br>
<span id="BMR_Wiederherstellung(Secondary_Restore_Server)"></span>
-> Can be used as an alternative to CSV selection. All parameters are required.
== BMR Restore(Secondary Restore Server) ==
<span id="ABSRT_Upgrade_auf_Version_9.30"></span>
== ABSRT upgrade to version 9.30 ==


1. Make sure that no VM is accessing the following ISOs: <br>
For instructions on how to initiate a BMR, see: [[Backup/en#Bare_Metal_Restore| Bare Metal Restore]]
[[File:NP 9.20.png|800px]] <br>
Once the data has been presented on the network, you can proceed as follows:<br>
<br>
[[File:BMR-1.PNG|border|BMR Step 1]]<br>
[[File:OS 9.20.png|800px]] <br>
<br>
<br>
2. Remove ISOs from the affected folders. <br>
[[File:BMR-2.PNG|border|BMR Step 2]]<br>
3. Remove the current Bootable Media Creator setup from the install directory and store the new version. <br>
Before: <br>
[[File:Install vorher.png|800px]] <br> <br>
After: <br>
[[File:Install nachher.png|800px]] <br>
<br>
<br>
'''Important: There may only be one setup in the install directory.''' <br>
[[File:BMR-3.PNG|border|BMR Step 3]]<br>
4. You can then start the ABSRT application. The first thing to do here would be to recreate it
of the Restore ISO and the subsequent editing of the Restore ISO can be seen.
='''Backup Assistant'''=
 
The TERRA CLOUD Backup Assistant is an in-house development of TERRA CLOUD. This tool is intended to support you in using the TERRA CLOUD backup solution.
== Status ==
 
On the right side of the tool you will find information about the "Connections" and "Software" versions.<br>
If a connection to the portal servers is not possible, please check the corresponding [https://wiki.terracloud.de/index.php/Backup/en#Network_configuration Ports].<br>
You can also install or update the TERRA CLOUD Backup Windows Agent using the Backup Assistant.<br>
<br>
<br>
<span id="Agenten_Installation"></span>
[[File:BMR-4.PNG|border|BMR Step 4]]<br>
== Agent Installation ==
 
If the backup agent is not yet installed on the affected system, you can download and install it using the tool.<br>
Please first enter the access data of a Backup Portal user who is located on the corresponding customer site.<br>
If you would like an automatic job setup, you can check this directly there. All you need is an encryption password, which should be assigned.<br>
Further information about automatic agent configuration can be found [https://wiki.terracloud.de/index.php/Backup/en#Automatic_agent_configuration here]. <br>
<br>
<br>
[[File:Agenten Installation BackupAssistant.png|border]]<br>
[[File:BMR-5.PNG|border|BMR Step 5]]<br>
<br>
<br>
After you have selected the required plugins and accepted the license agreement, the latest backup agent will be downloaded and installed in the background.<br>
= '''Agent Skripting''' =
<br>
[[File:Agent wird installiert Backup Assistant.png|border]]<br>
<span id="Initiale_Sicherung"></span>
== Initial backup ==


This feature represents the same options that are available for the initial backup tool. This tool is presented in the following [https://www.wortmann.de/content/files/content/Externe_Dokumente_Ablage/Video/cloud/TERRA-CLOUD-Backup_Initialbackup.mp4 Video]<br>
== Windows Agent ==
<br>
<span id="Agenten_Funktionen"></span>
== Agent functions ==


The "Agent Functions" function offers you the opportunity to run backup jobs that have already been created by the installed Windows agent and to view information about backups that have already been created, such as the size or backup status. <br>
=== Installation ===
[[File:Agenten Funktionen Backup Assistant.png|border]]<br>
=== Backup Reset ===


This function removes metadata (e.g. the delta information) from the job directory of the selected backup job. <br>
<span id="Windows_Agent_per_Kommandozeile_ansprechen"></span>
After deletion, the tool performs a synchronization to recreate the removed metadata.
=== Address Windows Agent via command line ===
This process may take some time.<br>
 
This process may be necessary to resolve various error patterns. <br>
Please first change to the agent's installation directory in CMD or PowerShell, by default this is 'C:\Program Files\TERRA Cloud Backup\Agent\'<br>
To start a backup, the following parameters must be passed to VV.exe:
*VV.exe backup JOBNAME /retention=RetentionName (CMD) <br>
*.\VV.exe backup JOBNAME /retention=RetentionName (PowerShell)<br>
You can use the /retention=RetentionName parameter to determine which retention type should be used.<br>
Please replace "RetentionName" with the name of the retention period, which you can view in the [[Backup/en#Advanced_Agent_Configuration|Advanced Agent Settings]].
<span id="Windows_Agent_per_Skript_ansprechen"></span>
=== Address Windows Agent via script ===
 
The desired commands can be stored in a script.<br>
Recommended formats are '''.bat''' and '''.cmd'''<br>
<br>
<br>
'''Example:'''<br>
Scripts can be extended as desired, e.g. to store pre- and post-commands, i.e. commands before or after the backup.<br>
[https://wiki.terracloud.de/index.php/Backup_Fehlerdiagnose/en#Invalid_file_format_or_delta_map_file_is_corrupted delta assignment file is damaged]<br>
<br>
<br>
== Support Bundle ==
Example script: <br>
@echo off<br>
cd "C:\Program Files\TERRA Cloud Backup\Agent"<br>
echo "Start backup" >> backuplog.txt<br>
VV.exe backup BMR /retention=Daily <br>
echo "Backup performed" >> backuplog.txt<br>
[[File:Backupskript.png|none]]
<span id="Skript_vor_dem_Herunterfahren_ausführen"></span>
=== Run script before shutdown ===


With the support bundle, all necessary information and logs such as VSS logs, system event logs and backup job logs are brought together and packed into a .zip file. <br>
You can integrate your created script into the system's pre-shutdown event with the following configuration. This is particularly recommended for client systems that are not consistently in use.<br>
This can help us find the cause in various support cases.<br>
Please carry out the following steps to store a script: <br>
<br />
# Open Local Group Policy Editor (WIN + R "gpedit.msc")<br>
<span id="Überwachung"></span>
# Store your created script under "Computer Configuration -> Windows Settings -> Scripts (Startup/Shutdown)<br>
='''Monitoring'''=
# Click "Shutdown" and add your script via "Add". <br>
# Please adjust the following registry key: ''HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gpsvc\PreshutdownTimeout''<br>
# This key defines the length of the pre-shutdown event, which is set to 15 minutes by default. Please increase this value so that a backup can be created during this time.
# In the Local Group Policy Editor, please navigate to "Computer Configuration -> Administrative Templates -> System -> Scripts <br>
# Adjust the "Specify maximum wait time for Group Policy scripts" setting. You can enter a value of up to 32,000 seconds or 0 for an infinite waiting time.
# Please note that you have adjusted the rights accordingly. <br>
::We have described further information about this in the following Wiki article: [https://wiki.terracloud.de/index.php/Backup_Fehlerdiagnose/en#PreshutdownTimeout_Value PreshutdownTimeout Value Authorization]
[[File:Preshutdown.png|gerahmt|left]] [[File:Maximale Wartezeit für Gruppenrichtlinienskripts angeben.png|boxed|ohne]]<br>
<span id="Neuen_benutzerdefinierten_Befehl_erstellen"></span>
=== Create new custom command ===


<span id="Reiter_&quot;Überwachung&quot;_im_TERRA_CLOUD_Backup_Portal"></span>
This option gives you the opportunity to add a schedule to scripts that have already been created via the backup portal.
== “Monitoring” tab in the TERRA CLOUD Backup Portal ==
[[File:Neuer benutzerdefinierter Befehl.png|framed|ohne]]
When you create a new custom command, the agent checks whether there are scripts stored in the agent directory in the "ScheduleScripts" batch files subfolder.<br>
The standard path to this directory in which a script for this function can be stored:<br>
''C:\Program Files\TERRA Cloud Backup\Agent\ScheduleScripts''<br>
In the following screenshot you can see a selected script with a configured schedule:
[[File:Benutzerdefinierter Befehlt.jpg|framed|ohne]]
'''Recommendation:'''
A custom command's schedule can only be created as a single-line schedule.
Please check our [[Backup/en#Agent_Skripting_Best_Practice|Best Practice]] for agent scripting to avoid this disadvantage.
=== Agent Skripting Best Practice ===


This function of the TERRA CLOUD backup portal offers you a comprehensive overview of the status of all backup jobs. <br>
The backup agent can be tailored to specific application scenarios through the use of scripts.
In addition, open agent processes are displayed (ongoing backups, restores, etc.). <br>
We recommend using the following guide as a basis for your scenario.<br>
This overview can be accessed across customers via the parent site or within a created site and thus for a specific end customer.
In addition to the backup status, the value of the '''last backup completed''' is particularly important because you can compare this date with the date of the '''last backup'''.
From the combination of this information, you can estimate whether a failed backup is critical because, for example, the date of the last completed backup is too far in the past.<br>
<br>
<br>
'''Open Processes''':<br>
'''Preparation:''' <br>
You can recognize open processes by the circle consisting of two arrows and the number next to it. If you click on the symbol you will be taken directly to the overview of the process.
What needs to be prepared before using the following scripts?
[[File:Überwachung.png|1300 px|ohne]]<br>
#Install the agent on the system to be protected
<span id="Export_der_Überwachungsübersicht_per_Mail"></span>
#Link the system to the vault in the Backup Portal
=== Export of the monitoring overview by email ===
#Create backup job(s) without a schedule
 
'''Step 1: Create a batch file''' <br>
You can schedule regular export in various file formats for the monitoring view using the 'Email/Schedule' drop-down menu. <br>
Create a batch file (.bat) with the following structure:<br>
For an automatic evaluation of a monitoring or ticket system, you can e.g. B. select the file format 'CSV'. <br>
''powershell.exe -ExecutionPolicy Bypass -File "Path to PowerShell script\agentscripting_retention.ps1"''<br>
If you want an export for a single end customer, you can configure this via a site user with the "Administrator" role.<br>
Please adjust this batch file later to match the path and name you have assigned to the PowerShell script.<br>
To do this, please log in to the backup portal with the site user and configure the export within this end customer.
Copy the created batch script into the following folder within the agent's installation directory: <br>
The export from the following example includes the backup jobs of all sites/end customers.
''C:\Program Files\TERRA Cloud Backup\Agent\ScheduleScripts (default)''<br>
[[File:Export-Überwachung.png|600 px|ohne]]<br>
In the Backup Portal, for the relevant system, click on [https://wiki.terracloud.de/index.php/Backup/en#Create_new_custom_command "New custom command"] under "Select job task".<br> <br>
<span id="Jobstatus_in_XML-Datei_auswerten"></span>
Using this function, you can select a stored batch script and assign a schedule to it; please configure the desired time (e.g., 10 PM).<br>
== Evaluate job status in XML file ==
<br>
 
'''Function:''' <br>
The Windows, Linux and vSphere Recovery Agent store information about the last backup status and e.g. B. the backup size in an XML file.
This batch file will subsequently be launched by the backup agent itself according to the schedule. <br>
The following paths refer to the default installation directory.<br>
The batch file launches PowerShell and the second script.<br>
Since PowerShell is significantly more extensive and flexible, the first script serves solely to invoke PowerShell.<br>
<br>
'''Step 2: Create PowerShell script''' <br>
In this step, you create the PowerShell script that is triggered by the batch script from '''Step 1'''.<br>
This script calls the backup agent to perform a backup.<br>
Additionally, it allows for the use of different retention periods and the inclusion of pre- and post-commands.<br>
<br>
<br>
'''Linux Agent:'''<br>
'''Content:''' <br>
<code>/opt/BUAgent/<JOBNAME>/BackupStatus.xml</code><br>
Please create a PowerShell script (.ps1) with, for example, the following content:
''Set-Location "C:\Program Files\TERRA Cloud Backup\Agent"''
''$date = Get-Date
$currentday = $date.Day
$lastday = [DateTime]::DaysInMonth($date.Year, $date.Month)
if ($lastday -eq $currentday){
'''Placeholder for pre-commands'''
.\VV.exe backup '''NameOfBackupJob''' /quickscan=true /retention=Monthly
'''Placeholder for post-commands'''
}
else{
'''Placeholder for pre-commands'''
.\VV.exe backup '''NameOfBackupJob''' /quickscan=true /retention=Daily
'''Placeholder for post-commands'''
}''
'''Function:'''<br>
This PowerShell script switches to the agent's installation directory and checks the current date.<br>
If the date matches the total number of days in the month (the dynamic last day of the month), a backup with the retention type "Monthly" is performed.<br>
On all other days, the retention type "Daily" is used.<br>
<br>
<br>
'''Windows Agent:'''<br>
'''Advantages of this implementation:'''
<code>C:\Program Files\TERRA Cloud Backup\Agent\<JOBNAME>\BackupStatus.xml</code><br>
# You can utilize the full range of PowerShell functions and customize this base script as desired customize for your customers
# The schedule can be created via the Backup Portal and does not need to be implemented via the script
# You can use pre- and post-commands to stop databases prior to the backup if they cannot be brought into a consistent state using VSS technology
== Linux Agent ==
 
In addition to the portal, the Linux agent can also be accessed via created scripts. <br>
You can contact the agents directly via a created script. As in the following example script (CustomScript.sh):<br>
''nano CustomScript.sh''<br>
''cd /opt/BUAgent''<br>
''./VV backup RootDir''<br>
In the example, RootDir is the backup job name.<br>
The script (e.g.: CustomScript.sh) must then be given the appropriate rights. To do this, please execute the following command: <br>
''chmod +x CustomScript.sh''<br>
<br>
<br>
'''vSphere Recovery Agent:'''<br>
Optionally, you can schedule scripts via the Backup Portal by completing the following steps:<br>
<code>C:\Program Files\vSphere Recovery Agent\<JOBNAME>\BackupStatus.xml</code><br>
*Under Linux, by default, no folder called "ScheduleScripts" is created in the installation directory. Please create this with e.g. ''mkdir ScheduleScripts''<br>
<br>
*Place the created script (.bat or .cmd) in the agent directory in the newly created ScheduledScripts folder
Possible results for "<agentdata:result></agentdata:result>":<br>
*In the Backup Portal, select "Create a new custom command" via "Select job task" and select your script
*UNKNOWN: The job status is currently unknown.<br>
*Create a schedule for the script
*COMPLETED: The job is completed or completed with errors/warnings.<br>
[[File:Neuen-benutzerdefinierten-Befehl.png|none]]<br>
*CANCELLED: The job was canceled manually.<br>
*FAILED: The job failed, please check the log files.<br>
*NO_FILES: No backup could be performed because no files are protected by this job.<br>
<br />
<br />
<span id="Verbrauchsberichte"></span>
= '''A'''utomatic '''B'''are Metal '''S'''ystem '''R'''estore '''T'''est (ABSRT-Tool) =
='''Consumption Reports'''=


The TERRA CLOUD provides you with various reports to monitor the consumption values relevant to the license model.
<span id="Allgemeines"></span>
==TERRA CLOUD Backup Reseller Report==
== General ==


This report shows you the consumption values of all your end customers' backup accounts. <br>
Regular BMR test restores are essential for the quality management of a backup strategy. <br>
The data refers to the 15th calendar day of a month and forms the billing basis for the respective month.
However, manual tests are time-consuming and therefore costly; automation offers a solution here, reducing the required effort to configuration and monitoring.<br>
The report is sent to the Backup Master Account / Cloud Master Account (TERRA CLOUD Center) from the 16th calendar day of a month.<br>
<br>
The ABSRT tool creates virtual machines using Microsoft Hyper-V, equipped with a prepared restore ISO. <br>
Data that would normally need to be entered during a manual restore—such as the system name or the vault system address—is read from a CSV file and applied during the recovery process. <br>
<br>
The most recent safeset is dynamically selected for the recovery test. <br>
Once the automated configuration is complete, a full restore is performed, including booting up the system after successful completion.<br>
<br>
<br>
'''Example excerpt from the Reseller Report''' <br>
To further increase efficiency, you can parallelize the recovery process by including data for multiple BMR backup jobs in the CSV file.<br>
[[File:Reseller-Report.png|ohne]]<br>
==TERRA CLOUD Backup Billing Report==
 
In addition to the '''TERRA CLOUD Backup Reseller Report''', you will receive the '''TERRA CLOUD Backup Billing Report''' in CSV file format. <br>
The consumption values for billing the TERRA CLOUD backup are summarized for you in this report for each end customer. <br>
We recommend this report as the basis for automated billing, e.g. B. also for the TERRA CLOUD Backup Enterprise license model.<br>
<br>
<br>
'''Content of the report:''' <br>
'''Due to compatibility issues, the current version of ABSRT is supported only on Windows Server operating systems.'''
''Active vault Vault'': The name of the active vault <br>
<span id="Voraussetzungen"></span>
''account Native protected data in GB'': The sum of the end customer's natively protected data volume <br>
== Requirements ==
''Computer amount'': The sum of the device licenses <br>
''Additional safesets'': The sum of the additional paid safesets <br>
==TERRA CLOUD Backup Customer Report==


Optionally, you can add an end customer report to your TERRA CLOUD backup order in the TERRA CLOUD Center. <br>
# Participation in the [https://b2b.wortmann.de/de-de/productlist/2996422/schulungen/nav-campus.aspx TERRA CLOUD Backup Certified Specialist Training]
In this report, you or your end customer will receive a weekly consumption overview and the status of the backups. <br>
# At least one Microsoft Hyper-V host with corresponding free capacity for the test VMs
The presentation corresponds to the reseller report, but only includes the data records for the respective end customer.
# The test VMs require access to a DHCP server
= '''FAQ''' =
# An external vSwitch must be available
# Certified Specialist ABSRT license (available upon request from [mailto:support@terracloud.de Support])
<span id="Einrichtung"></span>
== Setup ==


== VSS ==
When you start the ABSRT tool for the first time, the tool will ask you for a Certified Specialist ABSRT license:<br>
[[File:Lizenz.PNG|gerahmt|ohne]]
After you have entered a valid license, the installation path selection appears:<br>
[[File:Install Path.PNG|gerahmt|ohne]]
The following required components are then checked/installed:<br>
# Hyper-V Installation
# If configured, VeraCrypt
If software components are missing, they are installed automatically by the tool.<br>
If the Hyper-V component is installed, a restart must be performed.<br>
[[File:Preparation.PNG|gerahmt|ohne]]
<span id="Vorbereitung_der_CSV_Datei"></span>
=== Preparation of the CSV file ===


Here is a small explanation about VSS: <br>
You can create the CSV file via our [https://manage.terracloud.de/login TERRA CLOUD Technical Center].<br>
<span id="Was_ist_eigentlich_VSS?"></span>
Please feel free to consult the following wiki article for details: [https://wiki.terracloud.de/index.php/Technical_Center/en#Automatic_Restore Link]<br>
=== What exactly is VSS? ===
<br>
 
If you do not currently have access to the Technical Center, you can also create the CSV file manually.<br>
*VSS is the abbreviation is a derivation of "'''V'''olume '''S'''napshot '''S'''service"
To do this, locate the "Backups.csv" file in the "CSV" folder (e.g., at C:\ABSRT\CSV); you can use this file as the basis for your configuration.<br>
*Translated: Volume Shadow Copy Service
<br>
*implemented since Windows XP / Windows Server 2003, used to create versions (snapshots)
'''Important! The first line serves as a legend and must not be modified!'''<br>
*A snapshot is a snapshot of a volume (read-only)
<br>
*VSS works at block level
'''Example:'''<br>
*VSS technology is used in most backup solutions that back up Windows systems
<code>Vaultaddress,Vaultaccount,Vaultaccountpassword,Computername,Jobname,EncryptionPassword,VHDXCapacity,VMGeneration,OSVersion,VHDXStorage,VSwitchName,AmountOfPhysicalDisks,SendEmail</code><br>
*VSS errors are the main source of disruption in these backup solutions
==> vault-wmh1-wp01.terracloud.de,00000-RESELLER,RtHKha451!HjioplÖ03,DC,BMR,hdakzeogsz1,300,2,2019,D,extern,3,n<br>
<br />
<br>
<span id="Bestandteile_der_VSS-Technik"></span>
'''Note:'''<br>
=== Components of VSS technology ===
If the encryption password contains a comma, the entire password must be enclosed in double quotation marks.<br>
 
<br>
'''VSS Writer:'''<br>
'''Example of an encryption password containing a comma:''' <br>
*each VSS-capable application installs its own VSS writer on the system, which is required to bring its application into a consistent state
"Ghgui385as,"
<br />
<br>
'''VSS requestor:'''<br>
<span id="Erklärung_der_Parameter"></span>
*Any program that needs consistent data can become a requestor, in our case the backup agent
=== Explanation of parameters ===
<br />
'''VSS Provider:'''<br>
*The provider creates and manages the shadow copies of data in the system
<span id="Verschlüsselungskennwort_eines_Backup_Jobs_vergessen"></span>
== Forgot encryption password of a backup job ==


The backup job's encryption password cannot be reset by TERRA CLOUD support.<br>
'''Vaultaddress'''<br>
Please check whether a password hint has been stored for the job.
FQDN of the vault system <br>
<br />
<br>
 
'''Vaultaccount'''<br>
<span id="Verschlüsselungskennwort_eines_Backup_Jobs_ändern"></span>
Vault account; you can find this in your vault profile, for example <br>
== Change encryption password of a backup job ==
<br>
 
'''Vaultaccountpassword'''<br>
You have the option to reset the encryption password. To do this, go to the corresponding backup job in the backup portal and then click “Edit job”. <br>
You received this password in the provisioning confirmation <br>
You can now set a new password on the left. It should be noted that backups that were created with the old encryption password can only be restored with this one.<br>
<br>
Here our recommendation would be to delete the backup job and create a new backup job with the new encryption password. <br>
'''Computername'''<br>
<br />
Computer name on the vault system; this does not necessarily have to match the name displayed in the Backup Portal—please check your reseller report if in doubt <br>
<span id="Granular_Restore_Tool_-_Lizenz"></span>
== Granular Restore Tool - License ==
 
During the installation of the Granular Restore Tool you will be asked for a license.<br>
<br>
<br>
Please send us an email including your customer number with the subject “Granular Restore License” to [mailto:support@terracloud.de support@terracloud.de] <br>
'''Jobname'''<br>
We will then provide you with a corresponding license.<br>
Name of the backup job <br>
<br />
<span id="Erneut_registrieren"></span>
== Register again ==
 
The “Re-register” function makes it possible to replace the agent’s locally stored configuration with a computer configuration stored on the Vault or to supplement the existing one. This is necessary, for example, after a new installation of the agent, as the agent is not configured after a new installation. <br>
The current configuration can e.g. For example, this function can be added if you have removed a backup job in the portal and thus from the agent, but the data and configuration are still available on the vault. After re-registration, the missing backup job will be displayed again in the portal. <br>
<br>
<br>
'''Procedure:''' <br>
'''EncryptionPassword'''<br>
1. Please select the affected agent in the backup portal. Under the “Vault Settings” tab you will find the “Re-register” action. <br>
The encryption password for the selected backup job <br>
2. Now load the Vault profile created for the customer site here, then the “Load computer” action can be carried out. <br>
3. All systems located on the affected vault are now displayed on the right side. <br>
4. After you have selected the affected system and executed the "Save" action, the configuration is restored. <br>
5. Now edit the existing jobs and enter the encryption password for each. Each affected job must then be synchronized. <br>
6. Once the synchronization has completed successfully, you can run the affected jobs. <br>
<br />
<span id="Sicherung_einer_DATEV_SQL_Datenbank"></span>
== Backup of a DATEV SQL database ==
 
When backing up a DATEV SQL database, there are some special features compared to a “normal” SQL database backup. As a rule, the administrator does not have full access to the database and therefore the SQL plug-in cannot be used. In addition, problems can occur with a file-based backup because the timestamp of the database file (MDF file) is partially reset.<br>
Transaction logs do not need to be truncated because circular logging is configured for the DATEV SQL database.<br>
<br>
<br>
'''Recommended backup concept:'''<br>
'''VHDXCapacity'''<br>
The system should be protected using an image-based BMR backup, as the timestamp of the database file is irrelevant with this partition-based backup method. <br>
Enter the size of the restored volume here; if the system has multiple volumes, please enter the size of the largest one in GB. <br>
<span id="Wie_läuft_die_Migration_der_Backups_von_Bestandskunden_auf_einen_TERRA_CLOUD_Backup_Enterprise_Vault_ab?"></span>
== How does the migration of backups from existing customers to a TERRA CLOUD Backup Enterprise Vault work? ==
 
'''Initial situation''': <br>
You have currently booked Backup Standard or Backup Basic packages for your customers and would like to have your customers' backups moved to a new TERRA CLOUD Backup Enterprise Vault.
<p style="color: #FF0000;"><br>
<br>
<br>
'''Satellites:'''<br>
'''VMGeneration'''<br>
Please note that TERRA CLOUD Hybrid Backup packages in conjunction with a satellite cannot be moved to a TERRA CLOUD Backup Enterprise Vault.
Please ensure that the VM generation matches that of the source system.<br>
</p>
The generation specified in the CSV determines the algorithm used to assign volumes during the recovery process. <br>
<br>
<br>
'''Preparation:'''<br>
'''OSVersion'''<br>
Please prepare the following steps for the migration process:
As of agent version 9.40, there are two recovery media options, selected via the OSVersion entry.<br>
#Order the TCBE vault system in the desired location for your company (please note the delivery time of up to 10 working days)
This refers to the operating system version of the source system. The following values ​​are permitted: 7|10|11|2008|2012|2016|2019|2022|2025 <br>
#After deploying your new vault system, place an order for a vault account for each of your customers (you can key the vault accounts to the respective customers)
#Create a comparison in e.g. Microsoft Excel with the old Vault account (e.g. 12345-DRMEY) and the newly ordered Vault account, on your TCBE Vault e.g. (12345-DRMEYER)
#When your vault system is deployed, a support ticket for the migration process is automatically created. Please discuss the time period for the migration in this<br>
<br>
<br>
'''Procedure during migration:'''<br>
'''VHDXStorage'''<br>
On the morning of migration day, the process is started by the TERRA CLOUD team. You will receive an email notification of which accounts have been started for migration.
Please specify the drive letter for the VHDX storage location. <br>
Immediately after starting the migration, you can store the new backup destinations for the agents, as described in [[https://wiki.terracloud.de/index.php/Backup/en#Migration_of_data_to_a_new_vault_account|Instructions for making adjustments in the backup portal]].
Please note that backups cannot be performed during the migration as both accounts are locked by the migration.
Typically, migrations complete on the same business day, allowing scheduled backup agents to be backed up against the migrated dataset on the dedicated vault.<br>
<br>
<br>
'''How does the migration work technically?'''<br>
'''VSwitchName'''<br>
The migration process starts a copy process that transfers the stored computers / backup jobs / safesets from the old account from the shared vault to the account on the TCBE vault system.<br>
Name of the external vSwitch; you can find this in the Virtual Switch Manager. <br>
If only one external vSwitch exists, you can also use the value <default>. <br>
<br>
<br>
'''How many end customers can be moved per migration day?'''<br>
'''AmountOfPhysicalDisks'''<br>
As a rule, around 5 end customers can be moved per day; this depends on the size of the respective accounts from around 1.5 TB (natively protected data volume)<br>
Please specify the number of physical or virtual disks the source system has. <br>
Note: ABSRT currently supports systems with a maximum of four disks. <br>
<br>
<br>
'''What happens to the old accounts after the migration?'''<br>
'''SendEmail'''<br>
<p style="color: #FF0000;">
An optional switch used to configure email notifications (n ​​= no, y = yes). <br> <br>
After the entire migration process has been completed, you still have to cancel the old accounts, otherwise double billing may occur.
If you wish to restore multiple systems simultaneously, simply add further lines starting from line 3. The legend line does not need to be copied. <br>
</p>
<span id="Durchführung"></span>
Of course, a support team member will be available to answer any questions you may have during the migration process.
== Implementation ==


<span id="Gibt_es_Kennworteinschränkungen_für_den_Backup_Agent?"></span>
After launching ABSRT and preparing the environment, you can choose between a "standard" execution on the Hyper-V host<br>
== Are there password restrictions for the Backup Agent? ==
or preparing configuration ISOs to automate recovery at a different location (e.g., in our IaaS environment):<br>
<br>
[[Datei:Backup-DE-ABSRT.png|gerahmt|ohne]]
=== Convert ===


There is a 31 character length limit for all passwords with the TERRA Cloud Backup Agent. This includes:<br>
First, you are prompted to specify the storage location for the ISO files.<br>
<br>
Since the ISOs are very small, C:\temp\ is set as the default destination path:<br>
*Encryption passwords
[[File:Backup-DE-ABSRT-C-1.png|framed|none]]
*Password hints
Next, you must select the desired CSV file:<br>
*SQL credentials
[[File:Backup-DE-ABSRT-C-2.png|framed|none]]
*VRA credentials
Once the conversion is complete, you will find the ISO files at the selected location:<br>
*Oracle credentials
[[File:Backup-DE-ABSRT-C-3.png|framed|none]]
*SMTP credentials
[[File:Backup-DE-ABSRT-C-4.png|framed|none]]
*Vault credentials password
=== Recovery Test ===
*Etc...
Only these characters are allowed for use in the encryption password and hint fields: '''a-z, A-Z, Á-ÿ, 0-9, space, !@#$%^&*()_-+=[]{ }|'":;,<.>?~`´'''
<span id="Pflichtupdate:_Wie_nehme_ich_veraltete_Agenten_wieder_in_die_Sicherung_auf?"></span>
== Mandatory update: How do I add deprecated agents back to backup? ==


As of April 1, 2024, it is no longer possible to use outdated agent versions. See [https://wiki.terracloud.de/index.php/Backup/en#Supported_Agent_Versions Supported agent versions] <br>
The standard recovery test begins directly with the selection of a CSV file:
[[Datei:Backup-DE-ABSRT-R-1.png|framed|none]]
<br>
<br>
If one of your agents is no longer able to backup due to the mandatory update, you can make it functional again with the following steps: <br>
Subsequently, the VMs are created and started based on the CSV parameters so that the automatic recovery takes place:<br>
#Perform a software update to the latest available version. If offered, the Agent Upgrade Center can be used for this. <br>Alternatively, the update can be carried out manually via setup. <br>
[[Datei:Backup-DE-ABSRT-R-2.png|framed|none]]
#:
=== Restoration outside the ABSRT environment ===
#Once the new version is visible in the portal, you need to get the agent to contact our vault. <br>The actions “Execute Job” or “Synchronize” can be used for this. <br>'''Important! Without contact, our vault cannot know anything about the update that has been carried out, so the data remains locked.'''<br>
#:
#Every hour on the hour we carry out a check during which we release the data from updated agents. <br>As soon as the next full hour has been reached, a backup should be possible again. <br>
<br>
If the backup is still not possible after about 2 hours, we ask you to check the following article:<br>
[https://wiki.terracloud.de/index.php/Backup_Fehlerdiagnose/en#SSET-E-04104_The_request_failed._The_remote_server_reported_the_following_error:_RPC-E-AUTHERROR,_authentication_failure SSET-E-04104 The request failed. The remote server reported the following error: RPC-E-AUTHERROR, authentication failure]


= '''Backup Troubleshooting''' =
Once you have created the config ISOs using the Convert function, you can create a new VM shell at your chosen destination.<br>
Importantly, a DHCP server is also required in the network of the target VM shell for the restoration to proceed.<br>
The VM shell must have two DVD drives; the standard restore ISO is required in one drive, and the config ISO in the other:<br>
[[Datei:Backup-DE-ABSRT-R-3.png|framed|none]]
Booting from the restore ISO initiates the automatic restoration process.<br>
Once the restoration is complete, the process pauses at the driver overview screen.<br>
Before restarting, ensure that both ISO files are removed from the DVD drives.<br>
== Monitoring ==
 
During the recovery, another process is started which checks the status of the recovery based on the heartbeat of the virtual machine. <br>
As soon as a heartbeat is present, a screenshot of the connection window is created and stored in the ABSRT directory under "Screenshots". <br>
If the ''SendEmail'' option has been selected, the screenshot is also sent to the specified email address.<br>
[[Datei:Monitoring neu.png|gerahmt|ohne]]
[[Datei:ABSRT-Monitoring.jpg|gerahmt|ohne]]
<span id="E-Mail_Benachrichtigung_ABSRT"></span>
=== Email notification ABSRT ===
 
To use the email notification, you must edit and fill out the file C:\ABSRT\smtp.xml:<br>
[[Datei:Mailabsrt.png|border|C:\ABSRT\smtp.xml]]<br>
The script checks in advance whether the required fields have been filled in. If an entry has not been filled in, the notification is skipped.<br>
== VeraCrypt ==
 
'''Activate function later:''' <br>
Remove VeraCrypt REG key under HKEY_LOCAL_MACHINE\SOFTWARE\ABSRT\
Start ABSRT.exe again and activate VeraCrypt<br>
<br>
'''Deactivate the function later:''' <br>
If necessary, remove containers under C:\ABSRT\VeraCrypt
Remove VeraCrypt REG key under HKEY_LOCAL_MACHINE\SOFTWARE\ABSRT\
Start ABSRT.exe again and say no to VeraCrypt<br>
<br>
'''Rebuild CSV Container:''' <br>
Remove container under C:\ABSRT\VeraCrypt
Start ABSRT.exe again and enter the password for the new container
<span id="Skriptbasierter_Umgang_ABSRT"></span>
== Script-based handling ABSRT ==


* [[Backup Fehlerdiagnose/en | Backup Troubleshooting]]
The following parameters can '''only be used via PowerShell''':<br>
<br>
'''''-Install [Switch]''' - "C:\Users\Administrator\Desktop\ABSRT.exe -Install -DebitorNumber 12345 -License D133763385BAEFBFF9673C63Ab [-Vera Terra001!]"''<br>
-> Performs an automated installation of the ABSRT tool. The -Vera parameter is optional. <br>
<br>
'''IMPORTANT:''' If the Hyper-V role has not yet been installed, an automatic restart will occur after the installation is complete! <br>
<br>
'''''-Password [String]''' - "C:\Users\Administrator\Desktop\ABSRT.exe -Password Terra001!"<br>''
-> Ensures that the VeraCrypt container is mounted automatically. If the password is incorrect, a manual query is made.<br>
<br>
''''-CSV [String]''' - "C:\Users\Administrator\Desktop\ABSRT.exe -Password Terra001! -CSV V:\CSV\TestCSV.csv [-NoPause]"''<br>
-> Ensures that the CSV file is selected automatically. Please always specify the complete path of the CSV + file extension. (Shift + right click -> "Copy as path" can be used for this)<br>
<br>
'''''-Uninstall [Switch]''' - "C:\Users\Administrator\Desktop\ABSRT.exe -Uninstall"''<br>
-> Performs a complete uninstallation of the ABSRT tool. However, the Hyper-V role is not uninstalled. Please make sure that you only perform the uninstallation once no VM created by ABSRT exists in the Hyper-V Manager. <br>
<br>
'''''-Manual [Switch]''' - "C:\Users\Administrator\Desktop\ABSRT.exe -Manual -Vaultaddress vault-wmh1-0002.terracloud.de -Vaultaccount 00000-RESTORE -Vaultaccountpassword wD5c9mP7-3bL1337l1th8W7xaB0T0m -Computername RESTORE -Jobname RESTORE -EncryptionPassword Terra001! -VHDXCapacity 1000 -VMGeneration 2 -OSVersion 2019 -VHDXStorage D -VSwitchName <default> -AmountOfPhysicalDisks 4 -SendEmail n"'' <br>
-> Can be used as an alternative to the CSV selection. All parameters are required.<br>
<br>
'''''-ConvertCsvToIso [Switch]''''' - "C:\Users\Administrator\Desktop\ABSRT.exe -ConvertCsvToIso -ISODestination C:\temp\ -CSV C:\Users\Administrator\Desktop\RESTORETEST.csv [-NoPause]"<br>
-> Performs the conversion of CSV files to configuration ISOs.
='''Backup Assistant'''=
 
The TERRA CLOUD Backup Assistant is a proprietary development by TERRA CLOUD.<br>
<br>
'''Note:'''<br>
Please note that the tool is no longer being maintained as of the end of 2025.
== Status ==
 
On the right side of the tool you will find information about the "Connections" and "Software" versions.<br>
If a connection to the portal servers is not possible, please check the corresponding [https://wiki.terracloud.de/index.php/Backup/en#Network_configuration Ports].<br>
You can also install or update the TERRA CLOUD Backup Windows Agent using the Backup Assistant.<br>
<br>
<span id="Agenten_Installation"></span>
== Agent Installation ==
 
If the Backup Agent is not yet installed on the affected system, it can be downloaded and installed using the tool.<br>
Please first enter the login credentials of a Backup Portal user located on the corresponding customer site.<br>
If you would like automatic job setup, you can check this box directly there. All you need to do is enter an encryption password.<br>
Further information on automatic agent configuration can be found [https://wiki.terracloud.de/index.php/Backup/en#Automatic_agent_configuration here]. <br>
<br>
[[Datei:Agenten Installation BackupAssistant.png|border]]<br>
<br>
After you have selected the required plugins and accepted the license agreement, the latest Backup Agent will be downloaded and installed in the background.<br>
<br>
<span id="Initiale_Sicherung"></span>
== Initial backup ==
 
This feature represents the same options that are available for the initial backup tool. This tool is presented in the following [https://www.wortmann.de/content/files/content/Externe_Dokumente_Ablage/Video/cloud/TERRA-CLOUD-Backup_Initialbackup.mp4 Video]<br>
<br>
<span id="Agenten_Funktionen"></span>
== Agent functions ==
 
The "Backup Jobs" function allows you to execute previously created backup jobs of the installed Windows Agent and to view the log files of the performed backups.. <br>
[[File:Agenten Funktionen Backup Assistant.png|border]]<br>
=== Backup Reset ===
 
This function removes metadata (e.g. the delta information) from the job directory of the selected backup job. <br>
After deletion, the tool performs a synchronization to recreate the removed metadata.
This process may take some time.<br>
This process may be necessary to resolve various error patterns. <br>
<br>
'''Example:'''<br>
[https://wiki.terracloud.de/index.php/Backup_Fehlerdiagnose/en#Invalid_file_format_or_delta_map_file_is_corrupted delta assignment file is damaged]<br>
<br>
== Support Bundle ==
 
With the support bundle, all necessary information and logs such as VSS logs, system event logs and backup job logs are brought together and packed into a .zip file. <br>
This can help us find the cause in various support cases.<br>
<br />
<span id="Überwachung"></span>
='''Monitoring'''=
 
<span id="Reiter_&quot;Überwachung&quot;_im_TERRA_CLOUD_Backup_Portal"></span>
== “Monitoring” tab in the TERRA CLOUD Backup Portal ==
 
This feature of the TERRA CLOUD Backup Portal provides a comprehensive overview of the status of all backup jobs. <br>
Additionally, active agent processes (ongoing backups, restores, etc.) are displayed. <br>
This overview can be accessed across all customers via the parent site or within a specific site, thereby focusing on a particular end customer.<br>
In addition to the backup status, the '''Last completed backup''' column is particularly useful for sorting backup jobs based on the time of the last successful backup.<br>
This makes it easy to quickly identify jobs for which no backup has been successfully completed for an extended period.<br>
<br>
A new addition is the '''Backup History Graph''', a visual representation of the backup history over the past 28 days.<br>
This view displays 28 colored status bars visualizing the backup status for each day, providing a quick overview of the backup history.<br>
Hovering your mouse cursor over a bar allows you to view further details regarding the backups performed on that specific day.<br>
<br>
'''Note:'''<br>
Please note that only '''past days''' are displayed; i.e., the first bar on the far right shows the status from yesterday.<br>
<br>
The colors indicate the following:
* <span style="color:#D3DE85">'''Green'''</span><br>At least one backup started on that day completed successfully without any warnings or errors.
* <span style="color:#F9E073">'''Yellow'''</span><br>At least one backup started on that day completed with warnings or was deferred.<br>However, no backup completed successfully without warnings or errors.
* <span style="color:#C84C28">'''Red'''</span><br>At least one backup started on this day finished with errors, failed, was aborted, or could not back up any data.<br>No backup was successfully completed on this day.
* <span style="color:#C7C7C7">'''Gray'''</span><br>No backup was performed for the relevant backup job on this day; scheduled backups were skipped, are still in progress, or no backup activity took place.<br>In some cases, this status may also appear briefly if a backup has just successfully completed but the status information in the portal has not yet fully updated.
<br>
'''Active processes''':<br>
You can identify active processes by the circle consisting of two arrows and the adjacent number; clicking the icon takes you directly to the process overview.
[[Datei:Überwachung.png|1300 px|none]]<br>
<span id="Export_der_Überwachungsübersicht_per_Mail"></span>
=== Export of the monitoring overview by email ===
 
You can schedule regular export in various file formats for the monitoring view using the 'Email/Schedule' drop-down menu. <br>
For an automatic evaluation of a monitoring or ticket system, you can e.g. B. select the file format 'CSV'. <br>
If you want an export for a single end customer, you can configure this via a site user with the "Administrator" role.<br>
To do this, please log in to the backup portal with the site user and configure the export within this end customer.
The export from the following example includes the backup jobs of all sites/end customers.<br>
[[File:Export-Überwachung.png|600 px|ohne]]<br>
<span id="Jobstatus_in_XML-Datei_auswerten"></span>
== Evaluate job status in XML file ==
 
The Windows, Linux and vSphere Recovery Agent store information about the last backup status and e.g. B. the backup size in an XML file.<br>
The following paths refer to the default installation directory.<br>
<br>
'''Linux Agent:'''<br>
<code>/opt/BUAgent/<JOBNAME>/BackupStatus.xml</code><br>
<br>
'''Windows Agent:'''<br>
<code>C:\Program Files\TERRA Cloud Backup\Agent\<JOBNAME>\BackupStatus.xml</code><br>
<br>
'''vSphere Recovery Agent:'''<br>
<code>C:\Program Files\vSphere Recovery Agent\<JOBNAME>\BackupStatus.xml</code><br>
<br>
Possible results for "<agentdata:result></agentdata:result>":<br>
*UNKNOWN: The job status is currently unknown.<br>
*COMPLETED: The job is completed or completed with errors/warnings.<br>
*CANCELLED: The job was canceled manually.<br>
*FAILED: The job failed, please check the log files.<br>
*NO_FILES: No backup could be performed because no files are protected by this job.<br>
<br />
<span id="Verbrauchsberichte"></span>
='''Consumption Reports'''=
 
The TERRA CLOUD provides you with various reports to monitor the consumption values relevant to the license model.
==TERRA CLOUD Backup Reseller Report==
 
This report shows you the consumption values of all your end customers' backup accounts. <br>
The data refers to the 15th calendar day of a month and forms the billing basis for the respective month.<br>
The report is sent to the Backup Master Account / Cloud Master Account (TERRA CLOUD Center) from the 16th calendar day of a month.<br>
<br>
'''Example excerpt from the Reseller Report''' <br>
[[File:Reseller-Report.png|800px|ohne]]
==TERRA CLOUD Backup Billing Report==
 
In addition to the '''TERRA CLOUD Backup Reseller Report''', you will receive the '''TERRA CLOUD Backup Billing Report''' in CSV file format. <br>
The consumption values for billing the TERRA CLOUD backup are summarized for you in this report for each end customer. <br>
We recommend this report as the basis for automated billing, e.g. B. also for the TERRA CLOUD Backup Enterprise license model.<br>
<br>
'''Content of the report:''' <br>
''Active vault Vault'': The name of the active vault <br>
''account Native protected data in GB'': The sum of the end customer's natively protected data volume <br>
''Computer amount'': The sum of the device licenses <br>
''Additional safesets'': The sum of the additional paid safesets <br>
==TERRA CLOUD Backup Customer Report==
 
Optionally, you can add an end customer report to your TERRA CLOUD backup order in the TERRA CLOUD Center. <br>
In this report, you or your end customer will receive a weekly consumption overview and the status of the backups. <br>
The presentation corresponds to the reseller report, but only includes the data records for the respective end customer.

Aktuelle Version vom 24. September 2026, 09:17 Uhr

Introduction

What characterizes the TERRA CLOUD backup solution?

TERRA CLOUD Backup is a comprehensive data backup solution. All necessary components are provided by TERRA CLOUD.
This gives you a single point of contact for any questions or issues.

Communication between all components involved is always encrypted. Only a single agent needs to be installed on the server to be backed up.
It then connects to our data center via ports 8086 and 8087.
Since the connection originates from the server being backed up, no inbound firewall rules or NAT configurations are required.

Administration is handled via the multi-tenant TERRA CLOUD Backup Portal.
In this portal, you can view all servers linked to your account through agent registration.

The backup solution essentially consists of three components: Agent, Portal, and Vault:
The Agent is the software component that performs the backup on the system being protected. The Portal is used to administer and monitor these agents and to initiate restores. The Vault is the secure storage repository that receives and safely stores the backups. All backups are stored redundantly across two different data centers, distinguishing between a primary and a secondary vault.

Function overview

TERRA CLOUD Backup - Functional Overview
Fuse Windows Agent Linux Agent vSphere Agent Hyper-V Agent
Bare-Metal Restore*
Alterable backups (WORM)
Hybrid Cloud Backup (Satellite)
Backup of virtual systems (servers, VDI)
Backup deferral (initial backup)
Renewed Backup Attempts
Initialbackup ext. HDD/FTP
Protocol truncation (MS Exchange and MS SQL)
Microsoft VSS Support
Backup of physical systems (servers, clients)
Backup of network shares
Backup/Excluding Files and Folders
Threat Detection
Windows_Backup_Event_Triggers
High Frequent Backup - Hourly Backups
Restore
Bare-Metal Restore
Restore files and folders
Restore from another computer
Recovery to IaaS Cloud (DRaaS)
Rapid VM Recovery (Satellite Vault)
Rapid VM Recovery (Enterprise Vault)
Storage
Storage of backups for up to one year
Storage of backups for up to ten years
Automation
Script-based control
Automated BMR test restores
Fully Automated Setup
Patch management of the backup software
Monitoring
Interface for ext. Backup sensors
Mail notification via the backup portal
Backup History Graph
Included in TERRA CLOUD Backup Basic/Standard
Additionally included in TERRA CLOUD Backup Enterprise
Bare-metal restore (BMR) backups using a Windows agent on a Hyper-V host are not supported.
For further information, please see here
*

Product presentation and initial setup

To make getting started with TERRA CLOUD Backup as clear as possible, the following diagram illustrates the complete setup process—ranging from the installation of the agent and its automatic configuration via the Backup Portal to the final installation of the TERRA CLOUD Backup agent.
It highlights the stages where the process can be significantly accelerated and standardized through features such as automatic agent configuration.

Following the diagram, we recommend familiarizing yourself with the fundamental concepts and functions of TERRA CLOUD Backup.
A good supplement to this is the recordings of the TERRA CASTs, which you can find here.

Requirements

Supported operating systems

Windows Agent

Windows Server:

  • Windows Server 2025: Standard, Datacenter, Server Core
  • Windows Server 2022: Essentials, Standard, Datacenter, Server Core
  • Windows Server 2019: Essentials, Standard, Datacenter, Server Core
  • Windows Server 2016: Essentials, Standard, Datacenter, Server Core

Windows Client:

  • Windows 11: Home, Pro, Enterprise (Version 25H2)
  • Windows 10: Home, Pro, Enterprise (Version 22H2)

Plug-ins:
Please refer to the supported platforms and applications of the respective plug-ins in the Agent Doku/Release Notes

Linux Agent

  • Debian 13 (up to Update 2)
  • Debian 12 (up to Update 12)
  • Debian 11 (up to Update 11)
  • Debian 10 (up to Update 13)
  • openSUSE Linux 16 (up to Service Pack 0) A) B)
  • openSUSE Linux 15 (up to Service Pack 6) A) B)
  • Oracle Linux 10 (up to Update 1)
  • Oracle Linux 9 (up to Update 7)
  • Oracle Linux 8 (up to Update 10)
  • Oracle Linux 7 (up to Update 9)
  • Red Hat Enterprise Linux Server 10 (up to Update 1)
  • Red Hat Enterprise Linux Server 9 (up to Update 7)
  • Red Hat Enterprise Linux Server 8 (up to Update 10)
  • Red Hat Enterprise Linux Server 7 (up to Update 9)
  • Rocky Linux 10 (up to Update 1)
  • Rocky Linux 9 (up to Update 7)
  • Rocky Linux 8 (up to Update 10)
  • SUSE Linux Enterprise Server 16 (up to Service Pack 0) A)
  • SUSE Linux Enterprise Server 15 (up to Service Pack 7) A)
  • SUSE Linux Enterprise Server 12 (up to Service Pack 5) A)
  • Ubuntu Server 24.04
  • Ubuntu Server 22.04
  • Ubuntu Server 20.04
  • Ubuntu Server 18.04


Notes:
Since CentOS Stream is a pre-release version of RHEL and does not have long-term stable releases, the Linux agent on CentOS Stream is not supported.

A) This platform is not supported when the BTRFS file system is used.
B) The Agent is supported on this platform, but BMR backups are not supported for an openSUSE 16.0 UEFI or openSUSE 15.6 UEFI system with a FAT16 EFI boot partition.

Supported file systems on Linux:

  • ext2
  • ext3
  • ext4
  • XFS
  • GFS
  • ReiserFS
  • JFS

The BTRFS file system is not supported.

Supported Agent Versions

Windows Agent
Operating system Agent version x86 Agent version x64 A notice
Windows Server 2003 7.34.4009a 7.34.4009a EOL
Windows Server 2008 + R2 9.10.1013 9.30.1009 EOL
Windows Server 2012 + R2 - 9.30.1009 EOL
Windows Server 2016 - 9.50.6732 -
Windows Server 2019 - 9.50.6732 -
Windows Server 2022 - 9.50.6732 -
Windows Server 2025 - 9.50.6732 -
Windows 7 9.10.1013 9.30.1009 EOL
Windows 8 + 8.1 9.10.1013 9.30.1009 EOL
Windows 10 9.10.1013 9.50.6732 -
Windows 11 - 9.50.6732 -

Any operating system marked "EOL" can still be backed up using the corresponding agent version. However, neither Microsoft nor our software vendor offers support for these platforms. Please note that TERRA CLOUD can only provide "best-effort support." In the event of an error, we cannot rely on the software manufacturer for assistance.
It is strongly recommended to keep operating systems up to date. If an update is not possible, regular test restores should be performed.

Hyper-V Agent
Operating System Agent Version x86 Agent Version x64 Note
Windows Server >= 2012 R2 - 9.40.1009 -


vSphere Agent
Operating System Agent Version x86 Agent Version x64 Note
Windows Server from 2012 R2 to 2022 - 9.22.1011 -


Linux Agent
Operating system Agent version x86 Agent version x64 A notice
Supported Linux distributions 8.90.1020 9.41.1020 See Release Notes for supported Linux distributions

Network configuration

Port overview TERRA CLOUD Backup
Protocol Port Source Goal Function A notice
TCP 443 Agent Portal Automatic agent updates 185.35.13.210/32
TCP 2546 Agent Vault Connection to the Vault for data backup, synchronization and restore *
TCP 8086 Agent Portal Registering an agent on the portal 185.35.13.210/32
TCP 8087 Agent AMP Management of agents via the portal 195.4.212.128/25


Port overview TERRA CLOUD Hybrid Backup
Protocol Port Source Goal Function A notice
UDP 123 Satellite Internet NTP time synchronization -
TCP 443 Satellite Portal Interface updates and Support Connect function -
TCP 2547 Satellite Basevault Heartbeat / Management OLD Satellite-Vault version <= 8.62*
TCP 12546 Satellite Basevault Heartbeat / Management NEW Satellite-Vault version > 8.62*
TCP 12547 Satellite Basevault Data transfer for backup replication *

* Note:
Access must be enabled for both the primary and secondary Vaults using their respective FQDNs and IP addresses.
You can find the public IP address of each Vault via the Vault Finder in the backup portal:
backup.terracloud.de → Quick Links → Vault-Finder

Vault

A vault is a virtual system that is operated in the TERRA CLOUD or a partner data center.
This system communicates with the backup agents and receives backups and stores them according to the defined retention periods.
Backup packages include access to a shared backup platform in the form of a Vault account.

Vault-Account

A Vault Account is a unique organizational unit on a Vault system; it is required for authenticating a Backup Agent with the Vault.
The Vault Account name is composed of your customer number at Wortmann AG and the name of your end customer in the TERRA CLOUD Center, written in capital letters.

Example:
12345-ENDKUNDEXY

You require the Vault Account—for instance, when creating a new Vault Profile—so that the Agent can use the data from the profile to authenticate itself with the Vault system.
The Vault Account is entered into the "Account" and "Username" fields.


General

Retention periods

TERRA CLOUD Backup offers you a data backup retention period of up to 365 days in the Standard license model.
The retention period of a data backup on the Vault is determined by the selected retention type.

Retention Types

A retention type consists of two parameters that determine the retention time of a data backup.

Online storage(days):
This parameter specifies the minimum number of days the data backup must be stored on the Vault.

Online copies:
This parameter specifies the minimum number of backup copies required for this backup job.

Important: Linking the parameters
In order for a data backup to be considered expired and to be removed, BOTH parameters must be exceeded.
The safeset must therefore be at least the defined X days old AND there must be at least Y data backups for the backup job.

Preconfigured retention types

The following retention types are pre-configured and automatically created during agent installation.
Please note that 50 safesets are included free of charge per backup job; additional backup points can be added for an extra charge.

Note:
Starting April 1, 2024, 50 safesets can be configured free of charge per backup job.

24-Hour (Hourly Backup):
This retention type is automatically created by a "Sub-Day" schedule and cannot be edited.
It is required for the function High Frequent Backup.
Backups are retained for a maximum of 24 hours.
48-Hour (Hourly Backup):
This retention type is automatically created by a "Sub-Day" schedule and cannot be edited.
It is required for the function High Frequent Backup.
Backups are retained for a maximum of 48 hours.

Daily (daily backup):
This retention type is suitable for one backup per day.
Backups are retained for a total of 30 days each, and the job must contain at least 30 backups.

4xDaily (four daily backups):
This retention type is suitable for four backups per day.
Backups are retained for a total of 10 days each, and the job must contain at least 40 backups.

Monthly (monthly backups):
This retention type is suitable for one backup per month.
The backups are retained for a total of 365 days each, and there must be at least 12 backups in the job.

Yearly (annual backup):
This retention type is suitable for one backup per year and must be used for Retention of backups for 10 years.
The backups are retained for a total of 3653 days each, and there must be at least 10 backups in the job.

Former default retention types

The following standard retention types have been used in the past for TERRA CLOUD backup and may still be stored on the systems:

Daily (7/7 Version):
This retention type is suitable for one backup per day.
In total, the data backups are kept for 7 days each and there must be at least 7 data backups in the job.

Weekly(weekly backup):
This retention type is suitable for one backups per week.
In total, the data backups are kept for 31 days each and there must be at least 5 data backups in the job.

Create individual retention types

If you do not want to use or add to the standard retention types, you have the option of defining your own retention types using the agent's advanced settings:

Consumption values for licensing

The consumption values of a TERRA CLOUD backup account consist of:

  • Natively protected data set of backup jobs
  • Number of protected systems
  • Number of active safesets of the backup jobs

On the 15th calendar day of a month, the above-mentioned consumption values are determined and made available to you in the form of the consumption report on the 16th calendar day.

Consumption values of the active safe sets

50 active safe sets are included in the inclusive quota per backup job and can be distributed depending on the retention scheme and Schedule configuration.
In order for a safeset to be considered expired and to be deleted, the retention parameters “Online storage (days)” and “Online copies” must be exceeded.
This can result in more than 50 safesets being present in the vault at the time of consumption measurement because expired backups have not yet been removed from the vault.
The TERRA CLOUD backup license model therefore includes a free buffer zone of 10 safe sets.
If 61 or more safe sets are used, all safe sets above the inclusive quota will be invoiced.

Safeset consumption zones
Zone Safe set number
Inclusive quota 01 - 50 safe sets
Buffer zone 51 - 60 safe sets
Additional consumption 61 - ∞ Safe sets

Portal

The configuration is carried out as an example as documented in the following sections. The administrator account “backupadmin@terracloud.de” was used for this configuration.
This corresponds to your specialist dealer administrator account (backup master account).

Structure of TERRA CLOUD Backup Portal

Description:
This diagram shows the structure of the Backup Portal. The upper level consists of the parent site, which you can recognize by its name consisting of your Wortmann AG customer number and your company name. Through this level, you can administer (child) sites and centrally access all portal functions. You can create users for both levels; these are shown in the diagram in green for the parent site and in blue for the end customer sites. Please create a separate site for your company, as indicated in the diagram with the NFR site.
You can then move the agents for your systems to this site or register them directly via a user within the site.

Note:
Please only register agents in the parent site if they will subsequently be moved to the associated customer site for further configuration.

Site

A "Site" is an administrative area within the TERRA CLOUD Backup Portal that represents an end-customer organization.
Sites enable the separation of your tenants and simplify the management of backed-up systems.
As soon as you book a backup package for a customer, we automatically create a (child) site for you, along with a registration user.
This user can be used exclusively to register new agents with the backup portal; logging into the backup portal itself is not possible with these credentials.
You can find the access details for this registration user under the "Users" tab within the respective site.

Manually create site

Should you ever need to create a site manually, you will find a button for this under the "Sites" tab.
This launches the site creation wizard.



Site name assigned

The first step is to assign a name to the new site.
We recommend, for example, combining your customer's name with their customer number from your ERP system (12345-EndCustomer).
Then click "Next".



Create user

Optionally, you can then create an additional user with admin rights for the customer's site; this user will also be able to log in to the backup portal.

Note:
You can find further information on the various user roles in the permissions concept. The screenshot below shows the configuration for a user with the "Admin" role.
Please note that you must assign agents to users who do not have the "Admin" user role.



Vault Profile

Once a TERRA CLOUD Backup package has been provisioned, you will receive the access credentials for your tenant's vault account.
These credentials are required for authentication between the agents and the vault (storage destination).
These credentials must be saved into a vault profile within the wizard.

Vault Name:
The vault name is the display name for the vault profile.
Recommendation:
For simplicity, we recommend using the vault's FQDN (e.g., vault-wmh2-P001.terracloud.de) as the vault name.
The chosen vault name serves only as a label and has no technical function.

Address:
Enter the vault's FQDN here (e.g., vault-wmh1-P001.terracloud.de).
Account:
Enter the provided vault account (e.g., 45814-ENDKUNDE).

Username:
Enter the provided vault account here as well (e.g., 45814-ENDKUNDE).
The account and username have been set up identically to simplify the setup process.

Password:
Enter the provided password; this vault password is used to authenticate the vault account and is not used to encrypt user data.



Automatic Agent Configuration

Finally, you have the option to enable automatic agent configuration so that new agents are configured automatically.

Prerequisites:
To have a backup job created fully automatically, an encryption password must be defined.
With automatic agent configuration, the encryption password is passed as the default encryption password during the installation process itself.

Please select a vault profile and a job template.
If you are logged in as a parent site user, you can choose from all the job templates you have previously created and saved at other (child) sites.



Summary

In the final step, you will receive a summary of the information entered.



Configure notification

You can subsequently configure email notifications for the site via the "Notifications" tab.
The specified address will receive a notification as soon as the selected events occur.

Please note that portal-based email notification is currently not available for all agents. See Function Overview

"Encryption password changed" option:
This can alert you, for example, in the event of unauthorized access—such as when an attacker attempts to gain access to future backups by changing the encryption password.
The encryption password cannot be changed retroactively for existing safesets.

Note:
Changes to the encryption password are also displayed in the "Status Feed".

The basic configuration for the (child) site is now complete.
You can subsequently review all settings made in the site creation wizard within the individual tabs of the respective (child) site and adjust them separately if necessary.

Create additional users

Just as in the Site Creation Wizard, you can also create additional portal users later from within the site via the "Users" tab.
In addition to creating another administrator, you have the option here to select other user roles.

Note:
You can find further information on the various user roles in the permissions concept.
The following screenshot shows the configuration for a user with the "User" role.
Please note that you can still assign agents to users who do not have the "Administrator" role.
User anlegen

Create job template for automatic agent configuration

You can create your own job templates by opening the "Automatic Agent Configuration" tab for the respective site.
Click "View" next to the existing job template and then create an editable copy of the template.
You can customize this copy as desired and use it for automatic agent configuration after saving it.



Note:
The start time for the data backup is randomly selected within the time windows of 18:00 – 21:00 and 02:00 – 06:00.
Example of a custom job template:


Multi-Factor Authentication (MFA)

Multi-factor authentication (MFA) must be enabled to protect access to the TERRA CLOUD Backup Portal.

MFA Process

  • TOTP (Time-based One-Time Password)
    • The user employs an authenticator app, such as Microsoft Authenticator or Google Authenticator.
      The app generates time-based one-time codes that are entered during login.

Configure MFA

When creating a new user, the mandatory multi-factor authentication (MFA) requirement is enabled by default.
Consequently, the user is prompted to set up MFA upon their first login.


Since multi-factor authentication (MFA) was not previously mandatory, there may be user accounts where it has not yet been enabled.
These users must set up MFA subsequently.
To do this, the user first logs in to the TERRA CLOUD Backup Portal without having MFA set up.
Then, the Edit my profile entry is opened via the menu in the top right corner (three dots).


Multi-factor authentication can then be set up in the Two-factor configuration section.



Reset MFA

To reset two-factor authentication (MFA), please proceed as follows:

  • If you haven't already done so, create a second user with administrator rights in the Backup Portal under Users.
  • Then, log in using this second administrator account and, under Users, open the administrator account for which the MFA needs to be reset.
  • Enable the option highlighted in red in the screenshot.


The next time this user logs in, two-factor authentication will need to be set up again.
You can remove the additional administrator account if desired once MFA has been successfully set up.

Authorization concept

This table shows the four different roles that can be assigned to a user, as well as the registration user automatically created by the TERRA CLOUD.
You can create users either within a site or at the reseller level in your parent site.
For further information, please refer to the diagram showing the structure of the TERRA CLOUD Backup Portal.

User and Portal Management Read Only* Execute Only* User** Administrator Registration User***
Can assign agents to other users*
Move computers to another site
Delete backup jobs and computers from the vault
Agent Upgrade Center
Report function
Create additional users
Handling potential threats
Agent and backup management Read Only* Execute Only* User** Administrator Registration User***
Register agents on the portal
Configure agents on the portal
Create and view schedules
Create and edit backup jobs
Advanced Agent Configuration***
Backup jobs and computers from the portal interface delete
Backup operation and recovery Read Only* Execute Only* User** Administrator Registration User***
Start backup manually
Recovery carry out
Monitoring and information Read Only* Execute Only* User** Administrator Registration User***
View last backup status
View/download log files
Statusfeed view
View backup job configuration
* Assignment required to administer the agent based on the role.
** Assignment of the respective agent is not necessary
if it was registered on the portal by the user.
*** This user is automatically created when ordering a backup package.
**** Agent description, retention types, email notification,
bandwidth limitation, Agent logs.

Computer

All registered systems are displayed in a table on the Computer tab. If you open the overview while logged in to a site, only the computers of the respective site (end customers) will be displayed.
This part of the portal offers you the opportunity to fully administrate, configure and much more with the agents in a multi-client capable manner.

Skipped backups

This function shows you whether and how many data backups were skipped.

A high rate of skipped backups can result from the following circumstances:

  1. The intervals between data backups are too short and the next data backup is started during runtime.
  2. A very long data backup duration ensures that the subsequent data backup is skipped.

Data backups may be skipped if the following two conditions are met together:

  1. The backup job is executed more frequently than once per day, through multiple backups per day or the High-Frequent Backup.
  2. A data backup is already in progress or the Vault is performing important maintenance work on the backup job.

Through the use of e.g. B. High-frequency backups, with up to 24 backups per day, the vault only has a short time window for maintaining the backup job.
To ensure that outdated data backups can be removed despite the high backup frequency, the agent is allowed to skip backups.

Skipped backup rate:
You will be shown the percentage of data backups skipped in the last 48 hours.
In this example, due to a misconfiguration, backups were made almost every minute to illustrate how this display works.

If you click on the value, you will be shown an overview of the data backups with information about whether they were skipped:

Move computer to another site

You can move as many computers as you want to another site using the Move Computers action.
This function makes it possible, for example, to assign systems that were accidentally registered in the Parent-Site to the end customer's site.
Please select the desired site for the selected computers:

Assign agents to users

Users who do not have the "Administrator" role must be assigned to agents who can be managed by them.
You can do this either via the user configuration within the site or via the Sites tab within your parent site.
In this example, only SERVER01 and SERVER02 have been assigned to the user for management.

Deletion of data backups

Delete computers from the portal and vault

You can have a computer's data backups completely deleted as an administrative user via the Backup Portal.

This type of deletion includes:

  1. Deletion of the computer from the portal (online or offline computer)
  2. Delete the backup of all backup jobs of this computer on the primary and secondary vault
  3. Delete the registered computer on the Vault

Procedure for deleting a computer:

  1. Select the desired system using the checkbox on the left side of the backup portal.
  2. Under Actions, select Delete selected computer(s).
  3. Switch to the “Completely Wipe Computer” option.
  4. Enter "CONFIRM" in the input field of the dialog to confirm the deletion.

The deletion job will be executed after a quarantine period of 24 hours.

Cancel deletion job:
Within the quarantine period of 24 hours, you can select the computer as described above and cancel the deletion request using the "Cancel deletion of the selected computer(s)" action.

Delete backup jobs from the portal and vault

You can have the data backups of a backup job completely deleted as an administrative user via the Backup Portal.

This type of deletion includes:

  1. Delete the backup job from the portal
  2. Delete all data backups of the backup job on the primary and secondary vault
  3. Delete the registered backup job on the Vault

Procedure for deleting a backup job:

  1. Open the "Select Action" drop-down menu for the desired job under the "Job" tab of the respective computer.
  2. Choose the “Delete Job” option.
  3. Switch to the “Delete Job Completely” option (screenshot below).
  4. Enter "CONFIRM" in the input field of the dialog to confirm the deletion.

The deletion job will be executed after a quarantine period of 24 hours.

Cancel deletion job:
Within the quarantine period of 24 hours, you can select the backup job as described above and cancel the deletion job using the "Cancel deletion" action.

Delete individual data backups (safesets) from the vault

As an administrative user, you can completely delete selected backups from a backup job via the Backup Portal.

This type of deletion includes:

  1. Deleting the selected backup(s) from the backup job on the primary and secondary vaults, and if applicable, the satellite.

Procedure for deleting individual backups (safesets):

  1. Open the "Select Action" drop-down menu for the desired job under the "Job" tab of the respective computer.
  2. Select the "Delete Backup" option.
  3. Select the safesets to be deleted and click "Delete" (image below).
  4. Enter "CONFIRM" in the dialog box to confirm the deletion.


Note:

The deletion of individual backups (safesets) is executed immediately and cannot be stopped after confirmation. become!


Adjustment in the backup portal after a data migration

After migrating the data/backups to, for example, a dedicated vault system, the configuration must be adjusted in the backup portal.
After the migration, the backup agent should connect to another vault system and, if necessary, also use other access data for authentication.
The procedure differs slightly depending on the migration method. Please make the following adjustments after consultation in the migration process (support ticket).

Vault account migration

With this variant, the entire vault account is moved to another vault system. A vault account is an organizational unit for an end customer.
You will receive the access data and the name of the vault account when you provide the account, e.g. 12345-DEMO.
Please carry out the following steps after successfully moving the account:

  1. For each agent, access the "Vault Settings" in the Backup Portal.
  2. Edit the current vault connection and swap the FQDN of the old vault system with that of the new vault system.
  3. Also customize the vault profile for this site.

The following screenshot shows the current vault connection that needs to be edited.


Migration of data to a new vault account

The prerequisite for this method is a new vault account, e.g. B. on a TCBE vault system. With this variant, only the affected computers and their backup jobs are moved.
Since authentication will now take place via the new account, all positions in the vault connection must be changed.

  1. For each agent, access the "Vault Settings" in the Backup Portal.
  2. Edit the current vault connection and replace all vault credentials with those of the new vault account.
  3. Also adjust the vault profile of the affected site.


Reports

The reporting function gives you access to various data sets from the TERRA CLOUD backup via various preconfigured reports.
The underlying database receives new records twice a day through the TERRA CLOUD Vaults.
Please note that in connection with a TERRA CLOUD backup satellite, only data sets for the existing safe sets and consumption as of the base vault are available.
TERRA CLOUD backup satellites are not connected to the reporting function.

Requirements:
In order to view reports, the “Vault account” must be synchronized with the respective site.
Automatic synchronization of the Vault account – How it works:

  • Below the “Vault Settings” is the Vault Registration (1)
  • the “Vault Account” (2) will be transferred to the site (3)


ReportFunction(BETA)

For the synchronization to work, the following requirements must be met:

  1. The Vault account may NOT be used across sites (same Vault account in different sites)
  2. The agent was registered in a self-created site (https://backup.terracloud.de/Sites).

Different Vault accounts can be used within a site as long as they are not used in other sites.

Necessary permission of the user:
To access the Reports page, you must be logged in as a user with the Administrator role.
Reports can be scheduled and automatically sent by email (PDF, XLS, CSV).

Backup Verification Report

This report provides you with an overview of the most recently performed automated Recovery Tests by your vSphere Recovery Agents.
On the one hand, you have the option of exporting this view as a PDF document, and on the other hand, you can configure a regular export including email delivery using the "E-mail/Schedule" menu item.



Agent Upgrade Center

The Agent Upgrade Center offers you the opportunity to upgrade Windows agents from version 8.7x via the portal.

Update Individual Agents
You can select single systems via the “Computer” tab and initiate the agent update under “Actions”.



Status display
In addition to the current version, you can use the icon to see whether the agent can be updated (purple dot) or is currently being updated. As soon as an agent has been successfully updated, a checkmark will be displayed next to the version number. If you move the cursor to the symbol next to the version number, the respective meaning will be displayed, e.g. "New agent version available".
In the following screenshot you can see an agent that is currently being updated.



Update Agents for Entire Sites
To do this, access the Agent Upgrade Center via your master login and select the desired agent and then the respective sites.



Then select whether you want the agents to be updated automatically or immediately:


Backup Jobs

File-based backup

How it works

The backup software accesses the file system of the system to be backed up. The files are read and divided into 32KB blocks; a checksum is calculated for each of these blocks.
The delta can be determined in subsequent backups using the checksums. The blocks identified for backup are compressed and encrypted.

Fast File Scan

The "Quick File Scan" or "QFS Quick File Scanning" function allows the Windows agent to pre-filter files based on the timestamp (modified date) in the file system to determine the delta.
Files whose modification date is newer than the last backup are read in and compared with the delta file of the last backup using the calculated checksums of the 32KB blocks.
Only blocks that have not yet been backed up will be included in the backup.

Advantages and disadvantages file-based

Advantages:

  1. BMR backup possible
  2. Included as standard with the agent, no additional plugin is required
  3. No reboot required after installation
  4. Granular troubleshooting possible
  5. Files/directories can be excluded
  6. Can be administered from the agent console without portal access
  7. Script-based restore possible via VPR file


Disadvantages:

  1. Slower with lots of small files
  2. Navigation via portal when restoring individual files
  3. The OneDrive folder cannot currently be backed up.

Best Practice

1.In the best case scenario, use a file-based backup job only to back up individual files and folders.
2.Add the “Entire Server” option to existing file-based BMR backup jobs.
3.Use an image-based job to configure new BMR backups.
4. File-based backup jobs are only recommended for up to a million files; above a million files we recommend an image backup job.

Configure complex exclusions/inclusions in file-based jobs

The following instructions can be used for both local file-based backup jobs and UNC jobs (network shares).
When configuring one of the job types mentioned above, the portal can only be excluded or included to a limited extent.
Using the Backup Portal, you can only select one directory per exclusion entry in the job configuration and exclude folders and/or files in the respective subdirectory. This means that the entry only applies to the level below.

Example complex exclusion:
You want to exclude all directories that end with _Backup in a backup job because they Contains data backups that should not be included in the TERRA CLOUD backup.
D:\Data\*\*\*_Backup\*.*
In this exclusion there are two levels of different directories, each containing subdirectories ending in _Backup.
These directories and their contents are excluded using the syntax shown.
However, this complex exclusion expression cannot be configured in the portal and must therefore be copied manually into the job's configuration file.

Deposit exclusion in the job configuration:
1. Configure any exclusion
for the job 2. Stop both TERRA CLOUD Backup Agent
services 3. Open the JOBNAME.vvc file in the agent installation directory
4. Swap the exclusion created by step 1 with the one you want as in the following example
Exclude = "D:\*\*\*_Backup\*.*"
5. Start both services again
6. In the Backup Portal, check the job configuration and schedule and save it again if necessary 7. If you modify it manually, you will receive a warning in the Backup Portal, which you can simply confirm
8. After confirming the warning, please check whether the configuration has been applied as desired
For a complex inclusion, you can use these instructions analogously.

Ransomware Threat Detection

This file-based backup option allows the agent to scan the system for potential threats during backup.
If a possible threat is detected, the data backup is marked as a “potential threat”.
The current and all subsequent backups will retain this flag until one of the actions is taken.

Note:
The agent does not check for possible errors in a seed backup or the first backup Ransomware threats when threat detection is enabled in a job.

Handling potential threats

When ransomware threat detection is triggered, the following options are available via the "Manage potential threat" action:


1. Using the "Restore" option, you can configure a granular restore and—after the restore is complete—delete the flagged backup from the backup chain.


2. In the event of a false positive, you can select the "Delete potential threat warning" option and confirm the deletion of the warning.


Image-based backup

How it works

In contrast to a file-based backup job, which protects individual files and folders when backing up, an image job backs up all blocks of a selected volume.
It is possible to set up a BMR backup if all system-relevant volumes are backed up.

Changed Block Tracking

The image plug-in installs a changed block tracking driver, which requires a restart after installation. This can be used to determine which blocks have changed in relation to the last backup.

Advantages and Disadvantages Image-based

Advantages:

  1. BMR backup possible
  2. Faster for lots of small files
  3. Recommended for natively protected data volumes of 1TB or more
  4. Requires less processing power than file-based backup
  5. Convenient Restore (Image is attached)
  6. Navigation via Explorer when restoring
  7. The OneDrive folder can be included in the backup


Disadvantages:

  1. Exclusion of individual files and folders is not possible
  2. Restore only possible on disks of the same size/larger
  3. Restart required after plugin installation
  4. No granular troubleshooting possible
  5. ReFS is not supported

Best Practice

1. The restart can be done at a later point in time (usually after the end of work). The agent can be configured without restarting.
2. To protect the entire system, including the possibility of a bare metal restore, select the "Entire Server" and "BMR" options.
3. If data (such as local backups / dumps) needs to be excluded, you can move it to a separate volume and explicitly not include this volume in the backup set.
The "Entire Server" option cannot be used in this case.

UNC-Backup Job

Documentation

Complete setup instructions can be found in Chapter 5.4 of the Windows Agent User Guide at Agents Doku/ Release Notes (Documentation -> EN -> Windows Agent -> User Guide )

How it works

The Windows agent connects to the stored network share and saves the selected files. For authentication, a user must be provided with read and write permissions.

Best Practice

1. A UNC backup job should protect a maximum of 500,000 files or 1 TB of native data. If more data needs to be backed up, we recommend distributing it across several UNC backup jobs.
2. Since backing up a network share via a DFS namespace is not supported, we recommend backing up the server share directly without using the namespace.
3. Recommended backup method for files stored on NAS systems (e.g. from Synology, QNAP).

Schedule Recommendations

The schedule determines when a data backup should be started and with which retention type it should be saved.
The following articles go into more detail about various recommended schedule configurations.

Renewed backup attempts

The “Automatic restart for time-controlled backup” function offers the option of restarting an incorrect or failed data backup.
This can be particularly helpful if, for example, in the first backup attempt. B. a Microsoft VSS shadow copy cannot be created.
We recommend waiting a few minutes between backup attempts so that e.g. B. Load peaks can be avoided.

Daily and Monthly Backup

This schedule runs one backup per day, using a Daily or Monthly retention type.
The last calendar day uses the Monthly retention type, and all other days use the Daily retention type.
The time was configured identically due to the priority, so that every day except the last calendar day, line 1 does not apply and line 2 must be checked.
Since the conditions in line 2 are met on any other day, this is executed.
This configuration prevents daily and monthly backups from being created on the last calendar day.

Example configuration:
Create schedule

Four daily backups

This schedule runs four backups per day, with retention type "4xDaily".
The backup times were set at the beginning and end of the working day plus two additional backups within the working day.
In the example configuration below, the backup is performed on the hour at 6 a.m., 9 a.m., 12 p.m. and 3 p.m.
If the system data is changed 24/7, it is recommended to distribute it at equal intervals, e.g. E.g. 0/6/12/18

Example configuration:




Backing up clients using the Windows backup event triggers

Unlike a scheduled server backup, a client system's usage time can vary, making a fixed backup schedule less suitable.
The Windows backup event triggers, which start the data backup dynamically depending on the time of triggering, are suitable for these purposes.
The following Windows events can be selected as triggers:

Event:
1. Shutdown
Before the system is shut down or restarted, the user receives a message asking whether the data backup should be performed before shutdown.

2. Login
A user login starts the data backup.



Waiting time between backups:
The triggering can be limited to once or twice a day, for example. B. If you restart multiple times, you won't be asked for a backup every time you restart.

TERRA CLOUD BACKUP Enterprise: High Frequent Backup - Hourly backups

The High Frequency Backups feature enables hourly backups and thus an RPO of 60 minutes.
Hourly backups must be created with retention types Retention Types "24-Hours" and "48-Hours" using the "Intraday" schedule view.
In the example shown below, all 50 safesets of the inclusive quota are scheduled.
It was assumed that most changes to the data set are made between 9 a.m. and 5 p.m.

This schedule performs a total of eleven backups per day in the following distribution:

  • Nine backups are performed hourly between 9 a.m. and 5 p.m. with the retention type "24-Hours"
  • One backup at 8 p.m. with the retention type "Daily" or on the last calendar day "Monthly"


Note:
Please note that the hourly backups may only be used in conjunction with a TERRA CLOUD Backup Enterprise Vault.

Example configuration:

  1. Please add a new line to your schedule using "Add schedule"
  2. Select the "Intraday" schedule view for this line
  3. Configure how often the high-frequency backup should back up within a day, e.g. every full hour between 9 a.m. and 5 p.m. (see screenshot)
  4. Confirm the configuration with "OK".
  5. Finally, you can decide how long the data backups should be kept using the two new retention types available, 24-hours and 48-hours



Full schedule:


TERRA CLOUD BACKUP Enterprise: 10 years retention

The sample schedule shown below includes all 50 safesets of the Included quota.
It is assumed that all documents to be archived will be stored on the system and backed up by December 31st.
This schedule performs one data backup per day at 11:30 PM with the following retention types:

  • Daily on all days of the month except the last day
  • Monthly on the last day of the month, from January to November
  • Yearly on the last day of the year

Note on the Yearly Retention Type
The "Yearly" retention type was added as the default retention type in February 2026.

Sample Schedule:

Run job manually

If you wish, you can also run jobs manually.
Run job manually

Click “Start Backup”.
Run job

Completed backup process:
Process Details

Since the agent is able to compress, in this case only 14.27 GB of data was transferred and stored in the vault for a complete Windows Server 2025 VM. The original size of the system is 33.95 GB.
This is an initial backup, as 33.95 GB is also stored under Changed.
We can also see under the “Jobs” tab that the backup process was completed successfully:
Backup Status Completed Successfully

Further details can be viewed by clicking on “Completed” in the middle.

Defering function

The deferral function allows you to split the initial backup into multiple backup stages.
After the specified time window (e.g., 8 hours) has elapsed, an incomplete safeset is created.
The blocks not yet backed up are "deferred" and can be backed up in the next backup stage.
You will receive a warning at the end of the backup that the deferral is still active.
Please select the "Use deferral" option and specify a backup time window of at least 15 minutes to a maximum of 48 hours.
This function can be used for both manual and scheduled execution.




Important:
A backup with the resume function enabled results in an incomplete backup if interrupted.
For file-based backups, data successfully backed up prior to the interruption can be restored.
For image-based backups, however, restoration is only possible if the backup has been fully completed.


Recommendation:
The deferral function can be used exclusively for the initial backup. You can select the deferral during manual execution or specify it in the schedule. We recommend adding a reminder in the agent description that the deferral function is active in the schedule. After the first successful backup without deferral, you can remove the function from the schedule and the reminder from the agent description.



The deferral can be used to split the initial backup or seed backup into multiple backup operations. You will receive a warning in the log file until the backup job has completed completely. For a BMR job, BMR protection is only provided after the first successful completion without deferral.

Example:

Day 1:
The backup job is started with a deferral for the first time and completes the backup after a defined period of 8 hours, and Safeset 1 has been created.

Day 2:
The backup is started again and creates Safeset 2 after 8 hours.

Day 3:
On the third run, the backup job completes before the 8-hour period, Safeset 3 is created, and the seed backup is successfully completed.
The status of the backup job changes from "Deferred with Warnings" to "OK".

Windows Agent

Documentation Windows Agent

You can find extensive documentation and further information in Windows Agent User Guide.

Installation

Installation via Setup

Please download TERRA Backup Agent. To do this, log in to your portal and select the appropriate version under Downloads on the right.
Select language

Now start the installation on the server to be backed up. First select the desired language in which you would like to be guided through the installation.
Click Next

On the "Support Information and Release Notes" page, click Next
Support Notes

Accept the license terms and click Next.
Confirm License Terms

In the next installation step, select “Custom” and click Next.
Setup type

The local logon credentials can usually be adopted. Click on Continue.
Logon Credentials

Select the desired installation directory. Then click Next.
Select path

In addition to the actual backup agent, other plug-ins can be installed. Depending on the type of server, individual Microsoft SQL database instances or Exchange mailboxes can be backed up.
Select the plug-ins you want and then click Next.
Plugins

In the dialog box that follows, you can specify how the agent should encrypt the data. You can retain the default settings here.
Data encryption

Enter the email address and password of the registration users or the user created in 5.2.1. Confirm with Next.
Enter login information

In the next step, you can set a default encryption password. This is required if you wish to use automatic agent configuration.
Encryption password

Confirm with Install.
Install

If you are then redirected back to agent registration, the access data you entered is probably incorrect or you are having problems with the
Network connection. First try pinging backup.terracloud.de. If this works, you can use Telnet to check whether port 8086 can be reached.
Complete installation

After 5 minutes at the latest, the server you just registered should appear under “Computer” within your portal.
List of computers in the portal

On the right side under “Site Name” you can read “End Customer1” in our case. This is because we registered the agent with the user backupkunde@endkunde1.de,
which belongs to the “End Customer1” subsite. This way we can now filter for computers that belong to the “End Customer1” subsite. This allows you to quickly list all computers in an organizational unit.

Silent installation under Windows

The agent can also be installed in silent mode. This is helpful if the agent is to be rolled out automatically on multiple systems.

An example of the silent installation including the image plug-in:
Agent-Windows-x64-x-xx-xxxx.exe /s /v" REGISTERWITHWEBCC=True AMPNWADDRESS=backup.terracloud.de AMPUSERNAME=backupkunde@firmaXYZ.de AMPPASSWORD=password FEATUREVOLUMEIMAGE=ON /qn"

Explanation:
Agent-Windows-x64-x-xx-xxxx.exe: The agent (x64) setup is called.
REGISTERWITHWEBCC=True: The agent should be registered on the backup portal.
AMPNWADDRESS=backup.terracloud.de: The address of the backup portal is passed.
AMPUSERNAME=backupkunde@firmaXYZ.de: The user of the customer site is transferred.
AMPPASSWORD=password: The password you assigned for the customer site user.

Parameters for plugins:
Plug-ins can be added after the AMPPASSWORD separated by a space as in the example above. Image Plugin: FEATUREVOLUMEIMAGE=ON
Exchange Plugin (Legacy): FEATUREEXCHANGE=ON
Exchange Plug-in (From 2010): FEATUREEXCHANGE2010=ON
SQL Plugin: FEATURESQL=ON
Cluster plugin: FEATURECLUSTER=ON
Oracle Plugin: FEATUREORACLE=ON

Installation in another directory:
If required, please specify the following parameter directly after /s /v" to install in another directory:
SILENTINSTALDIR=\"Path Example:
SILENTINSTALLDIR=\"C:\Program Files\Example\

Silent Agent Registration

The following PowerShell command is sufficient to re-register the agent with the portal:
& "C:\Program Files\TERRA Cloud Backup\Agent\buagent.exe" -cmdline --reregister --amplogin 'backupkunde@firmaXYZ.de' --amppassword 'USERPW' --ampserver 'backup.terracloud.de' --ampport 8086 Note:
Please replace the placeholder values ​​with your actual TERRA CLOUD Backup portal login credentials.

Afterwards, the TERRA Cloud Backup services must be restarted once.
To do this, launch PowerShell with administrator privileges and enter the following command:
Get-Service -DisplayName "TERRA Cloud Backup*" | Restart-Service

Installation via PowerShell script

To achieve a fully automated installation of the TERRA CLOUD Backup Windows Agent, we developed the following PowerShell script and made it available in the download area of ​​the TERRA CLOUD Backup portal:

Install-TCBWindowsAgent

Functions:

  • Port check TCP 8086/8087
  • Check for pending restarts
  • Download the current setup
  • Install the agent and register it with the portal
  • Initiate automatic agent configuration, if configured in the portal

Administrator rights in PowerShell are required to run this script. It may also be necessary to unlock the script file after downloading by right-clicking and selecting Properties.

Parameters:
SiteUser: Site username
SiteUserPassword: Site user password
JobEncryptionKey: Encryption password for jobs to be created, provided automatic agent configuration has been configured on the customer site

Plug-in Parameters:
ExchangeLegacy: Exchange Plug-in (Legacy)
Exchange: Exchange Plug-in (2010 and later)
SQL: SQL Plug-in
Cluster: Cluster Plug-in
Oracle: Oracle Plug-in

Execution via PowerShell (without plug-ins):
.\Install-TCBWindowsAgent.ps1 -SiteUser "register@terracloud.de" -SiteUserPassword "Password123!" -JobEncryptionKey "Terra456#"

Execution via PowerShell (with plugins):
.\Install-TCBWindowsAgent.ps1 -SiteUser "register@terracloud.de" -SiteUserPassword "Password123!" -JobEncryptionKey "Terra456#" -SQL
.\Install-TCBWindowsAgent.ps1 -SiteUser "register@terracloud.de" -SiteUserPassword "Password123!" -JobEncryptionKey "Terra456#" -Exchange

Associate Agent with Vault

Every newly registered computer is initially displayed as “Not configured” in the portal. First, at least one vault (data safe) must be assigned to the computer.
Click on the server you want to configure (DC in this example). This will open the settings for this computer. Then click on “Configure manually” on the right.
Manual Configuration

Now click on “Add Vault” on the right.
Then select the Vault profile created in 4.2.1 under “Vault profile”, in our case this is “Vault_Endkunden1”. All fields should then be automatically filled with the set values.
Vault Settings

The agent establishes a test connection to the vault.
If the connection cannot be established, for example because incorrect access data was entered, you will receive an error message.
If everything is OK, the vault will now appear under the “Vault Settings”.
Overview
In addition to the portal, the Windows agent can also be started via command line or script.
Agent scripting is recommended, for example, to stop non-VSS-capable databases before backup (MySQL, MariaDB, etc.)

Create job

Create file-based backup job

Click on the “Jobs” tab. Then click “Create new job for local system”.
Create new job for local system

The “Create new job” window opens.



Please first give the job a name. The name “BMR” (for Bare Metal Restore) is used in the example.
The default encryption algorithm is AES 256 bit, which is considered very secure.

Then enter an encryption password (maximum 31 characters). Resetting an encryption password is not possible!
In the middle area you will find the directory structure that the agent transmits to the portal.
Here you can easily select all the directories and folders you want to back up.
In this example, the BMR and Entire Server options have been configured.
This not only backs up the actual system files, but also the bootloader. This means you can restore an entire server later.
With the “Bare Metal Restore” the entire c:\ system partition is backed up in addition to the data required for booting.
On the right you will then see the backup set.
Objects marked with “+” are saved.
If you would like to exclude individual data from the backup,
select the file and click “Exclude”. Objects marked with “-” are excluded from the backup.
Confirm the setting by clicking on “Create job”.
A window will then automatically open to configure the schedule.

Create image-based backup job

Requirement:
The image plug-in must be installed on the system. If the plug-in is not yet installed, you can run the agent setup again and use the "change" option to install the plug-in later.

Create job:
In the backup portal, please select the image job under "Select job task" as shown in the following screenshot:



Configure job:
In this screenshot you can see an example configuration from an image job. In this, the “Bare Metal Restore” and “Entire Server” options were selected and included in the backup set.
Instead of showing the file system, the agent only shows individual volumes.



Application Aware Backup' option:
In addition to a BMR backup, this option also enables the transaction logs of a Microsoft SQL Server to be truncated and backed up. In order to use this, you must provide the access data required for the SQL instance. We recommend not using this option and using your own SQL job for a comprehensive backup of a SQL instance.

Entire Server' option:
If you add this option to the backup set, all partitions (volumes) of a system will be included in the backup. This excludes removable storage media (e.g. external hard drives or USB sticks). Partitions (volumes) added later are automatically included; there is no need to adjust the configuration.

Note:

For an image-based backup job, BMR protection is automatically provided by the "Entire Server" option, but in order to be able to offer a standard configuration for file- and image-based backup jobs, the option was changed BMR additionally added in the screenshot above. 

Create UNC Backup Job

In the TERRA CLOUD Backup Portal, first navigate to Computers and select the relevant computer.
Then, switch to the Jobs tab and select Select job task → Create UNC file job.


In the window that follows, enter the required access credentials to establish a connection to the UNC share.
The Domain field is optional and is only required if a domain is needed for authentication.


Once the connection is successfully established, you will proceed to the actual job configuration.
Assign a Name for the backup job and enter the desired Encryption password.
You can optionally provide a Password hint.
Next, you can define the desired Backup set.
To do this, expand the previously entered UNC share in the central area and select the folders or files to be backed up.
Then click Include to add the selected data to the backup set.
If necessary, you can also define Exclusions to omit specific files or folders from the backup.


You can use the UNC credentials button to modify the previously entered access credentials for the UNC share if needed.
Additional UNC shares can be added to the backup job using the Add UNC share button.

Advanced Agent Configuration

Individual settings can be configured for each computer. These include, for example: B. Mail notification and bandwidth limitation.
Go to “Computer” in the portal. Select a server and then click on “Advanced” to make specific settings.
Overview of Advanced Agent Configuration

Options:
Under this point you can add a description to the system, for example: B. to store the ticket number in the description in a support case.
We recommend the option “Log errors and stop backup” for current Windows agents; this is the default setting after installation or update.
The option "Log errors and continue backup" offers the advantage that backups can also be carried out if, for example, B. VSS problems can sometimes go through.
The files not backed up in this job will result in an increased delta afterwards.

Retention Types:
The currently stored retention types are displayed here; after installation, "4xDaily", "Daily", "Monthly" and "Yearly" are stored by default.
You can use this tab to create your own storage types, which you can then choose from in the schedule.
When configuring, please note that 50 safe sets per job are included free of charge.

Notifications (agent side):
As of August 2021, the “Notifications” tab is only available if an agent-side mail notification is already configured.
This agent function has been replaced by the Notification via the TERRA CLOUD Backup Portal.

Enable agent-side notification manually:
If you want to continue using agent-side notification, you can configure it using the following steps.
1. Stop the "TERRA Cloud Backup Agent" and "TERRA Cloud Backup BUAgent"
services on the desired system. 2. Open the "global.vvc" file in the TERRA CLOUD Backup Agent
installation directory. 3. Please add the following lines, if they are not present, after the curly braces of the "OpenFile" block:

  notification {
  MailOnError = True
  MailOnFailure = True
  MailOnSuccess = True
  }

4. Start the services "TERRA Cloud Backup Agent" and "TERRA Cloud Backup BUAgent"
on the desired system. 5. Open the TERRA CLOUD Backup Portal and update your browser if necessary. 6. Complete the configuration using the “Notification” tab, which is now visible again.
Performance:
Bandwidth limitation and execution priority can be configured under this point.
According to current knowledge, changing the execution priority has no noticeable effect, so we recommend keeping the default value.
Bandwidth limitation is particularly recommended for weak connections during your customer's working hours.
At least 1.5 Mbps should be allocated for a backup.

Agent log files:
Under this tab you can view all global (cross-job) log files of the agent, which can be helpful for troubleshooting.
For example, log files of the BUAgent can be viewed; this service (TERRA Cloud Backup BUAgent) is responsible for the agent's communication with the backup portal.

Agent Update

The TERRA CLOUD Backup Agent can be updated as follows:
Windows (manually):

  • Starting with agent version 8, the agent can be updated directly via the setup of the newer agent version.
  • When you start a setup of a newer agent, you will be asked if you want to perform an update.
Update durchführen


Windows (Agent Upgrade Center):
You can update multiple agents centrally via the TERRA CLOUD Backup Portal. Instructions can be found at:
Agent Upgrade Center

Restoring a Backup Job

Restore from a file-based backup


file-based recovery

You can use the calendar button to select the safe set from which you wish to restore data.
Then, enter the job's encryption password.
Clicking the "Hint" button displays your password hint.

You can select the folders and files to be restored using the checkboxes—choosing either entire folders or individual files.
Clicking "Include" then adds them to the restoration process.

The search function allows you to look for specific files without having to manually locate the full file path.
This supports the wildcard characters * (representing any number of characters) and ? (for a single character).
However, the question mark cannot be used for umlauts (ö, ä, ü).

Select the desired files and add them to the recovery operation by clicking "Include selected".
To search for files in a specific folder within the backup, enter the desired path into the "Search path" field.

When you include a folder in a recovery operation, its subdirectories and files are included by default as well.
If you wish to recover only a portion of the subdirectories or files, you can add filters to the inclusion set.
For example, it is possible to recover only files with the .doc or .docx extension from a folder.

When you exclude a folder from a recovery operation, its subdirectories and files are excluded by default as well.
If you wish to exclude only a portion of the subdirectories or files, you can add filters to the exclusion set.
For instance, you can set a filter to exclude only files with the .exe extension within a folder from the recovery.

Search for files

You have the options to restore the files to the original location or to an alternative location.
If you decide to use an alternative storage location, you can use the folder button to select the desired storage location.
You also have the options to overwrite existing files, not overwrite (this adds a numeric extension, e.g. .0001), rename incoming files and rename existing files.

Overwrite existing data

If you try to restore multiple files with the same name to an alternate location and select Overwrite Existing Files, only the last file restored will be retained.
Other files with the same name will be overwritten. To add a numeric extension (e.g. .0001) to a recovered filename, select Do not overwrite existing files.
For example, if you restore a file named "filename.txt" to a location where there is a file with the same name, an extension is added to the restored file name (for example, "filename.txt.0001").

Under no circumstances should you select the entire C: volume and let it overwrite the existing volume. This will result in serious damage to the system!

Rename existing files

To add a numeric extension (e.g. .0001) to an existing filename, select Rename Existing Files.
For example, if you restore a file named "filename.txt" to a location where there is a file with the same name, an extension is added to the existing file name (for example, "filename.txt.0001").
The name of the restored file is still “filename.txt”.

Advanced Recovery Options


Advanced Recovery Options

Advanced Recovery Options Part 2

Locked File Options

When restoring data from a local job, you can specify whether locked files should be overwritten by restored files with the same name.
To do this, select one of the following options:

  • "Yes, overwrite locked files"

Files in the system that are locked during recovery will be overwritten with the recovered files upon reboot. This option must be enabled for system state or system volume restores.

  • "No, do not overwrite locked files"

Files in the system that are locked during recovery will not be overwritten with the recovered files with the same name upon reboot.

Streams

When you run backups, information from your files is captured in different streams.
The original data created by a user is called a data stream.
Other information such as security settings, data for other operating systems, file references and attributes are stored in separate streams.
When restoring data from a local job, you have the following options to choose from:

  • "Restore all streams"

Restores all information streams. Use this option when restoring files to a system with an identical platform.

  • "Restore data streams only"

Select this option for cross-platform restores. With this option, conflicts do not arise due to system-specific data streams.

Protocol options

From the list, select one of the following logging levels:

  • Files: Provides more detailed information and is typically used for troubleshooting. Provides information about files that are being restored.
  • Directory: Provides less detailed information than the Files logging level. Provides information about folders that will be restored.
  • Summary: Provides top-level information including Vault/Agent version and backup size.
  • Minimal: Provides top-level information including Vault/Agent version.

Changing the logging level only affects log files that are created afterwards. Log files that have already been created are not affected by this change.

Performance options

To use all available bandwidth for recovery, select "Use all available bandwidth."
Bandwidth throttling determines how much bandwidth an agent can consume for backups and restores.
For example, you can limit traffic so that online users are not impacted and allow unrestricted usage at night so that scheduled backups or restores can occur as quickly as possible.
Bandwidth throttling values are set at the machine (or agent) level and apply to backups and restores.
When three jobs are running simultaneously on a computer, each job receives 1/3 of the specified maximum bandwidth.
Possible bandwidth settings: Maximum bandwidth (upper limit) in MB per second that the agent is allowed to consume for all backups and restores.
Period of time during the day when throttling is activated. Only one time window can be specified.
There is no throttling outside the time window. The days of the week that throttling is enabled.
Once the bandwidth throttling window begins during an ongoing backup or restore, the maximum bandwidth is dynamically applied to the running process.
If the throttling window ends while a backup or restore is in progress, bandwidth throttling is removed.
If you change an agent's bandwidth settings while a backup or restore is in progress, the new settings do not affect the ongoing process.
The bandwidth settings are applied when the backup or restore starts and are not changed afterwards.

Restore from another computer (file based)

It is possible to restore some or all of the data backed up on one computer to another computer with the same characteristics.
To restore the data from another computer, you can redirect the data from a backup job in the Vault to another computer.
If the data was backed up with a plug-in, the same plug-in and the corresponding installation (e.g. Microsoft SQL) must also be present on the target computer.
The new computer then downloads information from the vault to restore the data to the new computer.
Example: Computer A backs up its data with Job A, Computer B restores Job A's data (Computer A's data) to Computer B.

recover from another computer

recovery

Restore from an image-based backup


Select items to restore

You can choose whether you want to restore a complete partition or individual files or folders.
Select the manufacturing you want and click “Configure Source Next”.

Volume Recovery


Recovery

Select the desired volume to be restored.

Select Volume

Next, select an existing volume to restore to.
Click “OK” and then click “Run Restore” to start the restore process.

File or folder recovery


Restore to Volume

Select the volume from which individual files or folders should be restored and assign a valid drive letter. (Please do not use A & B)
Now click on “Mount Volumes”. The backed up volume is mounted on the affected agent and you can restore the required files or folders to a local volume by dragging and dropping them.
Under “Duration of inactivity”, set a generous time limit for how long the drive should be mounted. By default we recommend the value 60 minutes.

Restore from another computer (image based)

You can restore successfully backed up data to another computer with the same agent configuration.
To do this, you can transfer/copy existing backup jobs in the Vault to another computer.
Since an image job is a plugin job, the image plugin must exist on the target agent.

Example: Computer A is down/no longer in use, but now you need to restore data from Computer A. To do this, copy the job from computer A to computer B to perform a restore.

Select Computer B in the backup portal.
From the Select Job Task menu, click Restore from Another Computer.
The Restore from Another Computer dialog box opens.
recover from another computer

In the "Vaults" list, select the vault in which the backup of Computer A was stored. If the restore is to be carried out across vaults, the agent must first be registered with the source vault.
Once the correct vault is selected, you will find Computer A in the Computers tab.
After computer A is selected, you will find its job in the Jobs tab.
Confirm with OK once a selection has been made.
The portal attempts to download required job information to Computer B. Once these are downloaded, the job will appear in Computer B's Jobs tab.
A recovery process will start automatically. Once you have selected the desired restore here and entered the encryption password to decrypt required information, you can proceed with a normal image-based restore.
Selecting the recovery type

Password is required

If an error occurs while downloading the job information, the restore cannot continue.
This can happen if the job information is not available or a required plugin is not installed on the target computer.
Make sure the required plugin is installed on the target computer before repeating the process. (Change installation via Agent Setup or via the "Select job task" action)

Bare Metal Restore

A "bare metal restore" is a complete restoration of a backed up system, including all components required for the boot process (e.g. the bootloader).

Disaster recovery options

The following flow chart shows you possible workflows and recommendations for action for various Disaster Recovery scenarios.

Export drivers of a secured system

You can export all drivers of a system using the following instructions:

  1. Create a directory in which the drivers should be stored, e.g. (C:\Drivers)
  2. Run this command with administrative permission in CMD:
dism /online /export-driver /destination:"C:\Driver"

You can add the exported drivers when creating a new restore iso. If complications arise during a BMR test restore, we recommend exporting the drivers of the protected system as described above and adding them to the restore ISO. Please keep this ISO or drivers separately.

Create Restore ISO

To perform a bare-metal restore, you need a restore ISO (.iso file). The restore ISO is based on Windows PE and includes the recovery software for the TERRA CLOUD backup solution; this software launches automatically once the system boots from the ISO. You can create this ISO yourself and use it for the bare-metal restore of all your systems.

Download:
Please download the Bootable Media Creator from the backup portal.

Installation:
Install the Bootable Media Creator; this also requires the Windows Assessment and Deployment Kit (ADK).
The Bootable Media Creator setup guides you through the installation of the ADK components by default.












































The image can be created very easily after installation.
First, launch the Bootable Media Creator and simply select a destination directory at the bottom.
Create new Image

In this step, you can add drivers exported via Exporting drivers by selecting the driver directory using the "add" button.
Now click "Continue" to create the image.
Treiber hinzufügen







The image can now, for example, be burned to a CD or attached to a virtual machine.

Perform restore

The following instructions demonstrate a typical BMR restore within a virtual machine.
The BMR restore ISO must be mounted to the virtual machine beforehand.
Legacy network adapters must be used for both VMware and Hyper-V.
After restarting the machine, you must connect to it via the console.
The following screen will then appear:
boot from CD or DVD

First, configure the time zone and desired language, then click "Next".
Select language

In the next window, accept the license terms and click "Next".


By default, the "System Restore" process obtains an IP address from a DHCP server.
If no DHCP server is available, or if you wish to assign the IP address manually, click "Settings" in the main menu.
Select the network interface and then click "Properties". Assign an IP address and confirm by clicking "Apply".






We recommend subsequently pinging the vault via the command prompt to ensure it is reachable.
The command prompt can then be minimized so that it remains available for further adjustments (e.g., diskpart) during the rest of the restore process if needed.

To perform a restore operation, click "Restore My System" in the main menu. Click "Next" in the wizard.


On the following page, enter your vault (data storage) details and confirm by clicking "Next". The system restore process will now attempt to establish a connection to the vault.


On the following page, you will see all computers associated with your account. Select the computer you wish to restore. Then click "Next".


On the following page, you will see all backup jobs associated with this computer. Select the job you wish to restore. Then click "Next".


In the next step, you can select which safeset to restore. Select the desired safeset and then click "Next".
Next, enter the encryption password and click OK to confirm.




In the next step, you can select the volumes to be restored.
You can drag the individual partitions down into the "Destination" field or use the AutoMap button.
Then click "Next".

Note:
You can only drag down the light blue partitions; the gray partitions are created automatically.




In the final step, you can review the settings. Then, check the box next to "Click here to confirm the restore plan" and click "Next".


The restore process begins.






Once the restore process has successfully completed, click "Next" to close the window and launch the Repair Wizard.


Here, you can check whether any software components requiring an additional driver have been detected.
If the status is "OK" and a green checkmark is visible for each item, you can close the wizard by clicking **Close**.

Linux Agent

Documentation Linux Agent

You can find extensive documentation and further information in Linux Agent User Guide.

Preparing the installation for a bare metal backup

The bare metal backup of the TERRA CLOUD Backup Linux agent requires the software Relax and Recover, in a supported version, on the system to be backed up.
We recommend installing the software via the package manager of the respective distribution and, if necessary, updating it to the supported version.
The currently supported version of Relax and Recover can be found in the release notes of the TERRA CLOUD Backup Linux agent.

Please note that TERRA CLOUD cannot provide support for the installation or commissioning of the Relax and Recover software.

Installation

Step 1: Please download the TERRA Backup Agent.
To do so, log in to the TERRA CLOUD Backup Portal and copy the link address of the required agent (32 or 64 bit) from the download area.
Please download the agent setup, e.g., using the wget command and the copied link address.


Step 2: Unpack the archive with tar -xzvf PACKAGE-NAME.tar.gz.


Step 3: Then change to the unzipped agent directory and start the installer shell script using ./install.sh


Step 4: Please first read and confirm the license agreement and follow the instructions of the installation wizard to configure the installation.
In the screenshot of the example installation, the default settings for the following queries have been selected:

  1. Installation directory /opt/BUAgent
  2. Language Email notification (deprecated agent email notification)
  3. Encryption method

You can accept the default values ​​by confirming the queries with ENTER.


Step 5: Indicate whether a Bare Metal Restore backup is desired.
If you answer YES, please note that a supported version of Relax and Recover must already be installed on the system.
The default value for the Relax and Recover directory is /usr/sbin/rear.

Step 6: Register the Linux Agent on the TERRA CLOUD Backup Portal:

  1. Portal address = backup.terracloud.de
  2. Portal connection port = 8086 (default value)
  3. Portal username = User of the end customer's site
  4. Portal password = Password of the user on the end customer's site


Step 7: Please check the TERRA CLOUD Backup Portal to see if the Agent has been successfully registered on your end customer's site.

Restore a backup job

After backing up data from a system, you can select “Restore” under “Actions” in the backup jobs.

Recovery from a file-level job

filebasierte Wiederherstellung

Use the calendar button to select the safeset from which you wish to restore data.
Enter the job's encryption password. Clicking the "Hint" button displays your password hint.
You can select the folders and files to be restored using checkboxes and then include them in the recovery process by clicking "Include".
The search function allows you to search for specific files without having to look up the file path.
Wildcard characters are supported: * (for any number of characters) and ? (for a single character).
However, the question mark cannot be used for a German umlaut (ö, ä, ü).
Select the relevant files and add them to the recovery selection by clicking "Include selected".
To search for files within a specific folder in the backup, enter the desired path in the "Search path" field.
When you include a folder in a recovery, its subdirectories and files are also included by default.
If you wish to restore only a portion of the subdirectories or files within a folder, you can add filters to the inclusion set.
For example, you can add a filter to restore only files with a .txt or .log extension from a folder.
When you exclude a folder from a recovery, its subdirectories and files are also excluded by default.
If you wish to exclude only specific subdirectories or files within a folder, you can add filters to the exclusion set.
For example, you can add a filter to exclude only files with the .sh extension within a folder from the restore process.

Nach Dateien suchen

You have the option to restore the files to their original location or to an alternative location.
If you choose an alternative location, you can select the desired destination using the folder button.
You also have options to overwrite existing files, not overwrite them (in which case a numeric extension, e.g., .0001, is added), rename incoming files, or rename existing files.

Overwrite existing data

If you attempt to restore multiple files with the same name to an alternate location and select the option to overwrite existing files, only the last file restored will be retained.
Other files with the same name will be overwritten. To add a numeric extension (e.g., .0001) to a restored filename, select the option not to overwrite existing files.
For example, if you restore a file named "filename.txt" to a location where a file with the same name already exists, an extension (such as "filename.txt.0001") will be added to the restored filename.

Do not, under any circumstances, select the entire root volume and allow it to overwrite the existing volume. Doing so will cause severe system corruption!

Rename existing files

To add a numeric extension (e.g., .0001) to an existing filename, select "Rename existing files."
For example, if you restore a file named "filename.txt" to a location where a file with the same name already exists, an extension is added to the existing filename (e.g., "filename.txt.0001").
The name of the restored file remains "filename.txt".

Advanced recovery options


Advanced recovery options

Advanced recovery options Part 2

Options for locked files

When restoring data from a local job, you can specify whether locked files should be overwritten by restored files with the same name.
To do this, select one of the following options:

  • "Yes, overwrite locked files"

System files that are locked during the restore process will be overwritten by the restored files upon restart. This option must be enabled for System State or system volume restores.

  • "No, do not overwrite locked files"

System files that are locked during the restore process will not be overwritten by the restored files with the same name upon restart.

Streams

When performing backups, information from your files is captured in various streams.
The original data created by a user is referred to as the data stream.
Other information—such as security settings, data for other operating systems, file references, and attributes—is stored in separate streams.
When restoring data from a local job, you have the following options:

  • "Restore all streams"

Restores all information streams. Use this option when restoring files to a system with an identical platform.

  • "Restore data streams only"

Select this option for cross-platform restores. This option avoids conflicts caused by system-specific data streams.

Protocol Options

Select one of the following logging levels from the list:

  • Files: Provides more detailed information and is typically used for troubleshooting. Provides information about files being restored.
  • Directory: Provides less detailed information than the "Files" logging level. Provides information about folders being restored.
  • Summary: Provides high-level information, including the vault/agent version and backup size.
  • Minimal: Provides high-level information, including the vault/agent version.

Changing the logging level affects only log files created after the change. Existing log files are not affected by this change.

Performance Options

To use the entire available bandwidth for recovery, select "Use all available bandwidth."
Bandwidth throttling determines the amount of bandwidth an agent is permitted to use for backups and recoveries.
For example, you can limit data traffic to avoid impacting online users, while allowing unrestricted usage at night so that scheduled backups or recoveries can complete as quickly as possible.
Bandwidth throttling values ​​are configured at the computer (or agent) level and apply to both backups and recoveries.
If three jobs run simultaneously on a computer, each job receives one-third of the specified maximum bandwidth.
Available bandwidth settings: Maximum bandwidth (upper limit) in MB per second that the agent may use for all backups and recoveries.
Daytime period during which throttling is active. Only one time window can be specified.
No throttling occurs outside this time window. The days of the week on which throttling is active.
If the bandwidth throttling time window begins while a backup or recovery is in progress, the maximum bandwidth limit is dynamically applied to the running process.
If the throttling time window ends while a backup or recovery is in progress, bandwidth throttling is lifted.
If you modify an agent's bandwidth settings while a backup or recovery is running, the new settings do not affect the active process.
Bandwidth settings are applied when the backup or recovery starts and are not modified subsequently.

Bare Metal Restore

Preparation

To perform a bare-metal restore, the `Bare_Metal_Restore_Image_xxxxx.iso` file—created during the BMR backup—is required.
You can find this file in the system's root directory (/).
If the ISO is not visible, the of the Relax and Recover tool or the BMR backup was unsuccessful.

Implementation

  • Boot the target system from the mentioned ISO and select Recover Systemname .


  • Log in as the root user; no password is required.


  • Next, start the BMR restore agent by running ./bmragent.


  • Enter your vault (data storage) details. The system restore process will now attempt to establish a connection to the vault.


  • Select the computer you wish to restore.


  • Select the job you wish to restore.


  • In the next step, you can choose which safeset to restore. Select the desired safeset.


  • Then, enter the encryption password and set the prompt to yes using the left arrow key.


  • Next, confirm the disk mapping. Option 1 is selected by default.


  • Finally, confirm the disk layout. Option 1 is selected by default.


  • Next, you must confirm the Disk Recreation Script. Option 1 is selected by default.


  • In the next step, you must confirm that the storage on the target system will be wiped. Option 1 is selected by default.


  • Finally, you will receive a summary of the changes to the target system's storage, which you must confirm. Option 1 is selected by default.


  • The BMR recovery process now begins. Depending on the amount of data, bandwidth, and vault load, this may take some time.


  • Once the recovery is complete, you must confirm the recovery of the initrd and the reinstallation of the bootloader. Option 1 is selected by default.


  • This completes the BMR restore.

Assign alternative static IP for a BMR restore

By default, a BMR restore restores the original network configuration.
If you would like to assign an alternative configuration, for example to carry out a test restore, we recommend starting the system without network access first.
With a Hyper-V, for example, you could initially boot into the recovery ISO without a connected external vSwitch. After adjusting the network configuration, you can connect the VM to the vSwitch. This ensures that the system never goes online with the old IP address. Please follow these steps to adjust the network configuration before restoring:

  1. Boot into the Restore ISO and initiate the restore until the step where you are asked to run ./bmragent.
  2. Find the name and configuration of the network interface using ip address show
  3. Take the interface offline by e.g. ip link set name of network interface down
  4. Delete the old IP address that you determined in the first step, e.g. ip address del 172.29.4.24/22 dev name of the network interface
  5. Configure a new IP address using, for example, the following command ip address add 172.29.4.29/22 dev name of the network interface
  6. Take the network interface back online after customization
  7. Finally, configure the default gateway using, for example, ip route del default and then ip route add default via 172.29.4.1 dev name of the network interface

In this screenshot you can see an example of step 1 from the instructions:


vSphere Recovery Agent

vSphere Recovery Agent Documentation

You can find extensive documentation and further information in vSphere Recovery Agent User Guide.

Installation

Please run the vSphere Recovery Agent setup on a Windows Server system with access to the VMware environment (vCenter or standalone ESXi host). Please note the recommendations from the section Best Practice. Please follow the instructions in the vSphere Recovery Agent InstallShield. In the last step of the installation, you register the system using the user and password entered in your end customer's created site. You can find a detailed description of the installation process in the User Guide linked above.

Agent configuration

After successful installation and registration on the TERRA CLOUD Backup Portal, you can now add the system to the vault as described in Add system to the vault.

Connection to the vSphere environment

Please enter and save the access data for the vSphere environment (vCenter or standalone ESXi host) in the “credentials” fields. You will receive immediate feedback as to whether the access data provided is correct or whether the area can be reached.


Changed Block Tracking

This agent function is already activated after installation and allows quick and efficient delta backup of the virtual machines.
For more information about this technology, see VMware's Knowledge Base.


Automated recovery tests

Enabling the Verify backup on completion option will perform a recovery test via quick VM restore after each backup completes. After the virtual machine boots, a screenshot of the login mask is created and saved in the TERRA CLOUD Backup Portal. To use this feature, the rapid VM recovery requirements must be met. Please store the temporary data store on which the VM can be started for the test recovery and the desired ESXi host.

Example configuration:


Create vSphere Backup Job

Once you have finished installing and configuring the agent, you can create a new "Job for VMware vSphere".
The following screenshot shows an example of a new job for a vSphere environment. Please enter a job name and optionally a description and the encryption password.
You can either include all virtual machines in the backup by selecting the "Virtual Machines" level, so all virtual machines are included recursively. This option offers the advantage that new virtual machines are automatically added to the backup job.
Alternatively, you can select individual VMs and add them to the backup set.



Optional:Advanced Settings:

Enable application consistent backup

As soon as you "enable application consistent backup" an application consistent snapshot can be created based on a Microsoft VSS snapshot.
We recommend enabling this option for all virtual machines with a Windows guest operating system.

Truncate database transaction logs

In addition to application-consistent backup, transaction logs from Microsoft Exchange or SQL Server instances can be truncated.

Enable Threat Detection

When backing up active virtual machines with Windows guest operating systems, the vSphere Recovery Agent can scan the system for active ransomeware.
We recommend enabling this option for all virtual machines with a Windows guest operating system.
The Enable Threat Detection option requires guest operating system credentials.

Verify this backup job upon completion

Following the backup, a recovery test of the virtual machines is performed via fast VM recovery.
Please note that this function must be set up in the Agent Configuration.
Furthermore, this option is only visible if the prerequisites for Rapid VM Recovery are met.

Global VM Credentials

The entered access data will be used for all virtual machines in the backup set.

Guest OS Credentials

If you would like to assign access data individually for each virtual machine, you can enter these in the backup set below the virtual machine by displaying the input field using the blue arrow.


Rapid VM Recovery

The Rapid VM Recovery option allows you to start a VM directly from the backup.
Downtime can be drastically reduced thanks to this rapid access; additionally, the feature is suitable for performing a recovery test in just a few minutes.

Prerequisites:

  • Available only in conjunction with a TERRA CLOUD Backup Satellite or TERRA CLOUD Backup Enterprise Vault.
  • Each ESXi host must have a software iSCSI adapter.
  • The datastore where the VM is started can be located on local, iSCSI, or vSAN storage.
  • A datastore intended as the migration target for a VM can be located on an NFS share, in addition to the storage types mentioned above.
  • A minimum of two datastores must be available in total.
  • vSphere Recovery Agent 8.82 or higher.
  • The Windows Server hosting the VRA must have the "iSCSI Target Server" Windows feature installed.


Example configuration of an ESXi host for Rapid VM Recovery:

In the screenshot below, an iSCSI software adapter has been added via vCenter using the "Add Software Adapter" option.


Additionally, a VMkernel adapter without the service role enabled was added, as shown in the following screenshot:


Procedure: Once all prerequisites are met, an additional option—"Virtual Machine option using Rapid VM Recovery"—becomes available under "Restore":


You then proceed to the recovery configuration.
Here, in addition to selecting which VM to restore, you can also define which datastore should be used.
The following screenshot shows the "Rapid VM Recovery Datastore," which was configured specifically for tasks such as recovery and functional testing.
During the recovery process, you can migrate the VM to a different datastore—for example, the one hosting your production systems.


Best Practice

  • Install the vSphere Recovery Agent in its own Windows Server VM; if possible, this will only be used for management or backup
  • Keep the vSphere Recovery Agent VM highly available via vSphere HA
  • Use a satellite for TERRA CLOUD backup to be able to use Rapid VM Recovery
  • Place the vSphere Recovery Agent VM on the same subnet as the vCenter Server Appliance
  • Enable the "Application Aware Backup" option in the backup job
  • Use Change Block Tracking to back up virtual machines; this setting can be found under the "vCenter Settings" tab.

Hyper-V Agent

Documentation Hyper-V Agent

The following sections contain, among other things, information about setting up and configuring the TERRA CLOUD Backup Hyper-V agent.
You can find extensive documentation and further information in the Hyper-V Agent User Guide

Installation

The following concise guide outlines the essential steps for setting up the TERRA CLOUD Backup Hyper-V Agent.

Setup sequence:
1. Install TERRA CLOUD Backup Hyper-V Agent Management
2. Configure the Management Agent in the Backup Portal (establish connection to the Hyper-V environment, add the computer to the vault)
3. Install TERRA CLOUD Backup Hyper-V Agent Host

Single-host Hyper-V systems:
In this scenario, you can install both the TERRA CLOUD Backup Hyper-V Management Agent and the Host Agent directly on the Hyper-V host ("root"/"parent" partition).
However, please still observe the setup sequence listed above.

Hyper-V clusters:
Because the TERRA CLOUD Backup Hyper-V Agent is split into two software components (Management and Host), it is ideally suited for use in a cluster environment.
We recommend installing the Management Agent in an administrative VM within the Hyper-V cluster; this allows it to run on different hosts and ensures high availability via the failover cluster.
After completing setup steps 1 and 2, you can proceed to step 3 and install the TERRA CLOUD Backup Hyper-V Agent Host on all nodes of the Hyper-V cluster.

TERRA CLOUD Backup Hyper-V Agent Management:

Setup step 1
Please run the installer on the desired system and follow the on-screen instructions.
In the final step—as with all other TERRA CLOUD Backup agents—you configure the registration with the TERRA CLOUD Backup Portal.
You can either select a user within the site who has sufficient permissions, or register the system to your parent site and move it later.

Setup Step 2
Once installation is successfully completed, the system should appear under the selected site in the backup portal.
Please follow the instructions in the backup portal to establish a connection to the Hyper-V environment and subsequently add the computer to the vault.

Installing the TERRA CLOUD Backup Hyper-V Agent Host:

Setup Step 3
After successfully configuring the Hyper-V agent in Step 2, you can install the host agent on all nodes of the Hyper-V cluster or on the standalone host.
For a cluster installation, specify the FQDN of the system where the management agent is active in order to establish a connection to it.
Once installation is successful, the respective node should appear as "online" under the "Hosts" tab in the backup portal.

Restoring a Backup Job

The Hyper-V Agent allows you to restore either individual files and folders from a virtual machine or the entire virtual machine.
When restoring files, the virtual machine is mounted as a read-only file share.
This enables you to copy the desired files and folders directly from the backup without having to restore the entire virtual machine.

Note:
Restoring individual files and folders is supported exclusively for Windows VMs.
This feature is not available for Linux VMs.
For Linux VMs, only the complete virtual machine can be restored.

First, navigate to Computers in the Backup Portal and select your Hyper-V server.


Next, switch to the Virtual Machines tab and click Select action → Restore for the desired VM.


Various restore options are available in the subsequent dialog.


VM Recovery

To restore a complete virtual machine, please select Virtual Machines.


The following information is required for the subsequent steps:

  • New VM Name
    • Specify the name for the virtual machine to be restored.
      If the original VM still exists on the host, please provide a new name that differs from the existing VM's name.
      If it no longer exists, please leave the field blank; in this case, the virtual machine's original name will be used automatically.
  • Backup Set
    • Select the desired backup set and then enter the encryption password you assigned.
  • Destination
    • Select the destination drive where the virtual machine is to be restored.
      We recommend using the root directory of a disk (without a subpath) initially and moving the VM to the desired directory via Hyper-V Manager after the restore is complete.
  • VM Identity
    • Specify how the VM ID of the virtual machine to be restored should be handled.
      You can retain the original VM ID, generate a new VM ID, or have a new VM ID generated automatically if the original VM ID already exists on the target system.
      We recommend retaining the original VM ID. This allows the existing backup chain to continue seamlessly after the restore.
  • Host
    • Select the Hyper-V host or cluster node where the virtual machine is to be restored.
      If no Hyper-V cluster is used, only the local host is available for selection. Additionally, you can specify whether the restored virtual machine should start automatically after the restore is complete and whether the VM should be connected directly to the network.


The restore process then begins.



Upon successful completion, you will find the restored VM both on the selected target drive and in the Hyper-V Manager of the target Hyper-V server.



Recovery of files and folders

To restore files and folders, please select Files and folders.


You will then need to provide the following information:

  • Backup set
    • Select the desired backup set and then enter the encryption password you assigned.
  • Inactivity duration
    • Use this value (in minutes) to specify how long the file share should remain active during periods of inactivity.
      We recommend setting this value to 90 minutes.



The next window displays the status of the file share.
As soon as the status changes to **Processing...**, the release becomes available.


By default, the file share is mounted at C:\RestoreMount.



If you wish to change this default path, you can find further information in the following wiki article:
Link

Rapid VM Recovery

The Instant VM Recovery option allows you to start a VM directly from the backup.
Downtime can be drastically reduced thanks to this rapid access; additionally, the feature is suitable for performing a recovery test in just a few minutes.

Requirements

  1. Hybrid TERRA CLOUD backup with a TERRA CLOUD Backup satellite or TERRA CLOUD Backup Enterprise
  2. Hyper-V Checkpoints must be enabled for the secured VMs (for more information, see: Hyper-V Checkpoints)

Implementation

First, navigate to Computers in the Backup Portal and select your Hyper-V server.


Next, switch to the Virtual Machines tab and click Select Action → Restore for the desired VM.


Various restore options are available in the subsequent dialog.
For a quick restore of the virtual machine, please select Virtual machine using rapid VM restore.


The following information is required for the subsequent steps:

  • Backup set and encryption password
    • Select the desired backup set and then enter the encryption password you assigned.
  • Restore VM name
    • Specify the name for the virtual machine to be restored here.
      If the original VM is still on the host, please provide a new name that differs from the existing VM's name.
      If it is no longer present, please leave the field blank. In this case, the virtual machine's original name will be used automatically.
  • Volume
    • Here you can select the target drive where the virtual machine is to be temporarily mounted.
  • Target host
    • Select the Hyper-V host or cluster node where the virtual machine is to be restored.
      If no Hyper-V cluster is used, only the local host is available for selection.

Additionally, you can specify whether the restored virtual machine should automatically start and connect directly to the network once the restoration is complete.


The virtual machine restoration process then begins.


Once the restoration status changes to Rapid VM recovery in progress, the new virtual machine becomes visible on the target host in Hyper-V Manager and is ready for immediate use.


In our example, the new VM appears as VM01-rvmr-2026-Aug-05-09-35-34.


If you no longer need the provisioned VM, you can cancel the rapid VM recovery by clicking Cancel rapid VM recovery in the process details window within the Backup Portal.


VM Migration

Optionally, you can migrate the virtual machine to the target storage—and thus permanently to the target host—during the recovery process.
To do this, select the Migrate VM option within the process details in the Backup Portal.
The migration settings will then open; select the Permanent Volume there.
We recommend initially using the root directory of a storage drive (without a sub-path) and moving the VM to the desired directory via Hyper-V Manager after the migration is complete.
Then, start the migration by clicking Start migration.



During the migration, the status of the virtual machine in Hyper-V Manager indicates that it is being moved to local storage.


Once the status Restored VM has been migrated appears in the Backup Portal process details, the migration is complete.


This is also visible in Hyper-V Manager, as the virtual machine's migration status is no longer displayed.


Reduce number of VMs per backup run

The TERRA CLOUD Backup Hyper-V Agent backs up up to 16 virtual machines per Hyper-V host simultaneously within a single job.

Preparation:

  1. Stop the "TERRA CLOUD Backup Hyper-V Agent Management Service"
  2. Stop the "TERRA CLOUD Backup Hyper-V Agent Host Service" on all hosts managed by the management component
  3. Navigate to the following directory of the management component (default path: C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Management\Data\Configuration)
  4. Create a backup copy of the file "AgentCoordinator.cfg" and save it outside the agent directory
  5. Navigate to the following directory of the host component (default path: C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Host\Data\Configuration)
  6. Create a backup copy of the file "AgentWorker.cfg" and save it outside the agent directory
  7. Repeat step 6 for all host agents connected to the management agent

Editing the configuration:

  1. Open the management agent's configuration file "AgentCoordinator.cfg" (default path: C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Management)
  2. Add the [Advanced] section with the parameter MaximumConcurrency and the desired value, e.g. ...5 in JSON format (see screenshot below) and save the file.
  3. Open the host agent configuration file "AgentWorker.cfg" (default path: "C:\Program Files\TERRA CLOUD Backup\Hyper-V Agent Host\Data\Configuration").
  4. Change the value of the setting "MaximumConcurrency": 16, to the value specified in step 1 within AgentCoordinator.cfg.
  5. Repeat steps 3–4 for all host agents connected to the management agent.
  6. Start the "TERRA CLOUD Backup Hyper-V Agent Management Service".
  7. Start the "TERRA CLOUD Backup Hyper-V Agent Host Service" on all connected hosts.

Screenshot for editing step 2:


Note:
Please note that the value must not be configured higher than the default value of 16.
If the services fail to start after these adjustments, please perform a rollback using the backups you created.

Changing the mount point for data recovery

The Hyper-V agent allows you to restore not only entire virtual machines but also individual files and folders.
For file-level recovery, the selected virtual machine is mounted as a network share.
This enables you to conveniently browse its file system using Windows File Explorer and restore the desired files or folders.
By default, the network share is mounted at C:\RestoreMount.
You can change this path to a different folder or drive via the Windows Registry.

Procedure:

  • Open the Registry Editor with administrative privileges.
  • Navigate to the following registry path: HKEY_LOCAL_MACHINE\SOFTWARE\EVault\InfoStage\Agent
  • Create a new String Value named MountAlternatePath.
  • Enter the desired target path as the value, for example:
    E:\RestoreMount
  • Restart both TERRA CLOUD services.

Note:
If the specified folder does not yet exist, it will be created automatically during the recovery process.

Transferring configuration to another Hyper-V host

Use this guide if a Hyper-V host has been replaced and existing backup jobs need to be transferred to the new host.

Prerequisites

  • The original Hyper-V host appears as Offline in the backup portal.
    • This is the case, for example, if the Hyper-V agent components have been uninstalled.
  • The Hyper-V management component is installed on the new Hyper-V host.
  • The new Hyper-V host has already been registered with the TERRA CLOUD backup portal.

If the original Hyper-V host has already been deleted

If you have already deleted the original Hyper-V host visually from the backup portal, it must first be restored.
To do this, open the Computers section, right-click on Online & Offline, and then select Deleted.



The deleted Hyper-V host should now be visible.
Select it and restore it using Actions → Restore selected Hyper-V computer.




Implementation

  • If you have not already done so, install the Hyper-V management component on the new Hyper-V host and register it with the TERRA CLOUD Backup Portal.
  • In the Backup Portal, go to Computers and open the settings for the new Hyper-V host.


  • Select the option Restore a previous Hyper-V agent.


  • Under Select an offline agent for restoration, choose the original Hyper-V host.



  • Enter or correct the login credentials for the new Hyper-V host and save the settings.
    • Make sure to enter localhost in the Address field. This ensures the host remains accessible even if its IP address changes.

Important Rework

Hinweis

After restoration, some settings must be re-entered or verified for security reasons.
If these steps are not performed, backup jobs will not execute correctly.

  • Re-enter the password for each vault registration.
  • Re-enter the encryption password for each backup job.
  • Reactivate scheduled jobs via the agent's action menu if necessary.


Once all passwords have been entered and communication has been successfully verified, please install the Hyper-V host component on the new Hyper-V host.

Conclusion

Finally, verify the following points:

  • The Hyper-V agent appears as Online in the backup portal.
  • The Hyper-V host appears as Online on the Hosts tab.
  • All backup jobs have been successfully imported.
  • All required passwords have been re-entered.
  • Communication between the Agent Host Service and the Agent Management Service is working.
  • Scheduled backup jobs are enabled (if desired).

Backup satellites

Description and Benefits

The backup satellite is a hardware appliance or a virtual machine that is used in your end customer's network and can receive backups via the local network.
The satellite provides you with all vault functions, e.g. providing volumes from an image backup.
The rental devices or virtual machines are made available to you by the TERRA Cloud and are billed monthly, depending on their size and performance, in addition to the required backup packages.
By using a satellite, you can implement a hybrid cloud backup solution, as backups are stored locally on a satellite and subsequently replicated to a data center.
This backup concept offers the following advantages:

  • Fast backup and restore, thanks to a locally connected vault system (satellite)
  • No acquisition costs, as the hardware is provided to you
  • Time decoupling between backup and replication is possible
  • Restoration is possible independently of the data center
  • Initial backup can be carried out directly against the satellite
  • Your customer's bandwidth can be used optimally
  • Fast VM restore of the Hyper-V agent or vSphere recovery agent

Commissioning

After ordering your backup package including satellites, you will receive an email with the access data as soon as the vault account has been provided on the Basevault.
You will receive a separate notification after the satellite has been deployed and shipped to you.
After receiving the satellite, the following steps must be carried out (hardware satellites):

  • Set up and launch satellite in your end customer's network
  • You can reach the satellite interface via the local address of the satellite (either static IP or DHCP)
  • Please note that the satellite interface can be accessed via HTTPS and may need to be enabled in the browser first
  • You can use the interface to change the access data in the user administration and, if necessary, adjust the network configuration
  • Please deactivate the bypass mode using the Deactivate bypass mode function 10.3.1.3
  • The satellite is now prepared for productive use and must be saved as a backup target in the agents' vault settings (local IP of the satellite)
  • Initial backups can optionally be carried out directly against the satellite

Commissioning a satellite VM:

  • You will receive a Hyper-V VM container from TERRA Cloud Support, which you can import and virtualize under Hyper-V
    • Please note that only Hyper Hosts are compatible with the Windows Server 2022 operating system or higher!
  • Disk/network allocation must be done via Hyper-V Manager / VM Connect
  • The remaining steps of commissioning a satellite VM are similar to commissioning a normal satellite

Satellite interface

System

Registration

You can access the following interface in your browser using the satellite's IP address.
There are two different users available, the image shows the administrative user who has
unrestricted access.
In addition, there is a user who only has read rights; you can set the access data at a later date.
The default login details for the admin user are:

User = admin
Password = terra

Registration in the satellite interface

Informations

The Information item shows you the dashboard with all the important vital indicators of the hardware, e.g. CPU, RAM or hard drive utilization.
The satellite mode is also visible. A distinction is made between two modes, the active and inactive bypass mode.
With active bypass, the satellite rejects all agent requests, so communication for backups, restores, synchronizations or job creation takes place via the basevault. Accordingly, the Basevault address must be stored in the portal under the Vault Settings tab.
With the inactive bypass, the satellite is activated and accepts all agent requests, thereby enabling communication for backups, restores, synchronizations or job creation takes place via the satellite. Accordingly, the IP address of the satellite must be stored in the portal under the Vault Settings tab.

Hard disk capacity:
Green = Between 0% and 85%
Orange = From 85% to 95%
Red = From 95% to 99.99%

Storage warning in the overview

Message Storage Warning

Storage Alarm in the overview

Storage Alert

Features

System functions:
Under Functions you will find a list of the relevant services stored on the satellite. Please check whether all services are running.
If a service is stopped, you can start it using the Play symbol. Please do not restart any services while the satellite is running.

Satellite functions:
You can use this interface to shut down the satellite, restart it, or manually start a replication process.

Disable bypass:
A satellite with bypass mode activated cannot accept backups and delegates them to the base vault. Please deactivate bypass mode so that the satellite can accept backups.

Disable Bypass

Activate Support Connect:
With this switch you allow TERRA CLOUD support to access the satellite via remote maintenance.

Branding

This function allows you to adapt the satellite interface to your company's CI.
The configuration only needs to be carried out on one satellite, as you can export it and import it on other satellites.
There is also the option to add your own logo.
Branding

Maintenance

Vault maintenance checks the satellite's data stock every day at 9:23 a.m. for safesets that have exceeded their retention period; the number of retention days and copies must be exceeded. Expired safesets are deleted from the satellite. You can adjust the start time of this maintenance if necessary.

Updates

You can search the satellite interface directly for current updates and import them.

XML View

This menu item will take you to the XML output of the satellite in a new tab. This output lists all relevant information of the satellite and can be monitored.
You can incorporate this link into your own monitoring solution or use ready-made sensors. You can find ready-made sensors for Server-Eye and PRTG Network Monitor, the sensors can be found under the search term “Terra Cloud Backup”.
Homepage Server-Eye


Replication

Connectivity

This overview shows you the status of the connection to the Basevault. The satellite transmits a "heartbeat" to the basevault at regular intervals.
In addition, the connection to the backup portal and the base vault is checked via ping and Telnet. This ensures that all necessary ports are activated for the satellite.< br> During replication, for example, the outgoing network traffic rate can also be monitored.


Replication Status

This overview shows you which safesets are still outstanding for replication to the data center; these are processed as if in a queue.
On the right side you can click through the satellite's current inventory and view more detailed information about individual safe sets, such as the compressed
Size or whether this safeset has already been replicated.

ReplicationStatus

Bandwidth limitation

You can configure a bandwidth limit for satellite replication. Please note that after an adjustment, the replication service restarts and ongoing replications are aborted.
If the connection is weaker, we recommend configuring the "Quality of Service" on the firewall for the satellite and assigning it a low priority.
This setting on the firewall ensures that, for example, on a holiday, the
. can be replicated with full bandwidth Bandwidth allocation is therefore more flexible than a fixed bandwidth limit.

Replication Schedule

The replication schedule allows you to control whether to replicate immediately after a newly created backup and after
defined schedule or exclusively according to a configured replication schedule. This option is particularly recommended if
should be backed up during your customer's working hours, but replication should only start after working hours.
In this image you can see the configuration for a replication schedule that initiates a replication operation every day around 8 p.m.:

Safeset Management

Special configurations can be made on the satellite via Safeset Management; if configured incorrectly, these can affect the function of the satellite.
Changes can only be made after activation via the slider and may only be made after consultation with support.

Backup data

You can use the satellite interface to delete entire systems, jobs or individual backup sets (safesets).
The deletion only applies to satellites; the data in the data center on the respective base vault remains unaffected.
Safe sets are displayed online; they are highlighted in black and can be selected by clicking in the checkbox.
Online safesets are characterized by the fact that they are stored locally on the satellite and are directly available there.
Safesets that are grayed out and cannot be selected are offline safesets.
An offline safeset represents a backup that does not exist on the Satellite, but still exists on the Basevault.
Only meta information about these safesets is stored on the satellite.

Procedure for deletion:

System level deletion:
a) Check in the interface's job monitor that no process is running for the affected system. (If the Job Monitor tab is not available, update to the latest interface version)
b) Select the systems to be deleted and carry out the “Delete marked entries” action c) Wait until the affected system is grayed out from the overview. (It may take some time)
d) Check the capacity of the satellite and start a quick storage optimization

Job level deletion:
a) Check in the interface's job monitor that no process is running for the affected job. (If the Job Monitor tab is not available, update to the latest interface version)
b) Mark the job to be deleted by selecting it and carry out the “Delete marked entries” action
c) Wait until the affected job has disappeared from the overview/grayed out. (It may take some time)
d) Check satellite capacity. If unchanged, start quick memory optimization

Safeset level deletion:
a) Check in the interface's job monitor that no process is running for the affected job. (If the Job Monitor tab is not available, update to the latest interface version)
b) Select the safe sets to be deleted and carry out the “Delete marked entries” action c) Wait until all affected safe sets have disappeared from the overview/grayed out. (Depending on the size, the process can take a lot of time)
d) As soon as all safesets have disappeared/grayed out, start quick storage optimization


Backup data on the satellite

Job Monitor

You can view open or already completed processes in the Job Monitor.
Backups or restores can be monitored, as can replication processes.
The following screenshot shows a satellite that currently has no open jobs:


Jobs on the screenshot:
Maintenance Host = This process represents maintenance on the satellite, this process should always be displayed
Satellite Replication Service = Behind this process is the active replication service, this process should always be displayed
Satellite Replication - Upload Satellite Statistics = In the screenshot, this process is set to "Inactive" because it was completed successfully. In this job, the satellite passed information to the basevault.

User management

Within the user management you can define passwords for a total of two users.
Which users are stored in total?

  1. Admin: This user has full access and is intended for administration of the satellite.
  2. User: This user only has read permission and can be issued to the end customer as required.


User Management

Network configuration

You can use the network configuration to pass on your desired settings directly to the satellite or use the “Activate DHCP” function.
As soon as DHCP has been activated, the network configuration assigned by the DHCP server will be displayed.

Satellite Network Management

Initial backup FTP upload / send data carrier

Booking

The two processes can be added when initially booking a backup package or later in the order.

Implementation

Prerequisites:

  • The backup agent is installed on the target system and registered in the portal.
  • The backup job and schedule are configured as desired.
  • To prevent the external storage medium from being included in the backup, the "Entire Server" option has been temporarily removed from the job configuration.
    Instead, the backup is performed by manually selecting the individual drives. The external storage medium must not be selected.
  • The backup job schedule is disabled to prevent the agent from automatically attempting to back up to the vault.


Procedure:
1.) Start the backup to the vault to transfer metadata.
This transmits information required by the vault for the import process.
The process can be stopped as soon as the status "Processing" appears.

2.) Create the folder structure in the target directory.
To ensure smooth identification, please create the following folder structure:
\$ACCOUNTNAME$\$COMPUTERNAME$\$JOBNAME$

Example path:
E:\45814-ENDKUNDE\WIN-VKEE7ONL8FG\BMR

As the data involved is always encrypted, an incorrect folder structure would result in a written inquiry and, consequently, a delay in the process.

3.) Start the backup to the previously created path.
The procedure in the portal is as follows:

Target: Directory on storage medium

Select the previously created folder structure

Start backup

FTP Upload

Please ensure that the dataset is complete.
Each job is divided into backup fragments that are numbered sequentially; all fragments except the last one are 1,048,576 KB in size.
Only the first fragment (SafesetNumber.SSI or 00000001.SSI) differs in its filename from the remaining files.



Before uploading, check the initial backup log for any anomalies.
If you encounter irregularities or have questions, please contact our support team before sending or uploading the dataset.

The created initial backup can then be uploaded to the TERRA Cloud FTP server.

For example, the FileZilla Client can be used for the upload.
The necessary access credentials will be provided by us after the booking has been received in the Center.

Once the upload is complete and has been verified, please send us a brief confirmation regarding the previously transmitted information.

Following successful verification, we will notify you as soon as there are updates regarding the import.

Send in data carrier

Please ensure that the dataset is complete.
Each job is divided into backup fragments that are numbered sequentially; all fragments except the last one are 1,048,576 KB in size.
Only the first fragment (SafesetNumber.SSI or 00000001.SSI) differs in its filename from the remaining files.



Before shipping, check the initial backup log for any anomalies.
If you encounter irregularities or have questions, please contact our support team before sending in the storage medium.

If the initial backup completed successfully but an error message appears in the log file after the successful completion notice, we recommend consulting the following Wiki article:
SSET-E-04104 The request failed. The remote server reported the following error: RPC-E-FAILED, general RPC error / UTIL-W-05229 Configuration files could not be uploaded: File could not be uploaded. C:\Program Files\TERRA CLOUD Backup\Agent\Jobname.status.cfg

Once all outstanding questions and issues have been resolved, the storage medium can be sent to the following address, together with the completed submission form:

TERRA CLOUD GmbH
Hankamp 2
32609 Hüllhorst

Notifications regarding the import or shipping status of the storage medium are handled via automated business processes.

Under no circumstances should you send us unencrypted raw data belonging to your end customer!

Such data will be returned to the sender unprocessed.

Backup Export

In order to save data on a local medium, for example for long-term backup, we can export your backups. The export is encrypted and in the so-called vault format, so that the exported data must be read in with additional software before an agent can process and restore it.

Please note that this is a paid process. Further information about the process (offer, procedure, etc.) is available from our cloud sales department: cloud@wortmann.de
As soon as you have received the desired data set, you can continue with the steps below.
It should also be noted that it is not possible to export backups via the Hyper-V agent.

The required software can be found at:
Secondary Restore Server

Secondary Restore Server

The Secondary Restore Server reads the exported data and presents it as a virtual vault in the existing network.

  • Please navigate to the folder structure of the exported data in the Secondary Restore Server
  • Store the data of the exported vault account, e.g. B. (45814-END CUSTOMER), as well as the vault account password
  • Start sharing via the Secondary Restore Server (Start)
  • Agents can then access the share as if it were a normal vault.

Secondary Restore Server

Restore individual files (Secondary Restore Server)

Once the data has been presented on the network, you can proceed as follows:
CrossRestore Step 1

CrossRestore Step 2

CrossRestore Step 3

CrossRestore Step 4

CrossRestore Step 5

CrossRestore Step 6

CrossRestore Step 7

BMR Restore(Secondary Restore Server)

For instructions on how to initiate a BMR, see: Bare Metal Restore Once the data has been presented on the network, you can proceed as follows:
BMR Step 1

BMR Step 2

BMR Step 3

BMR Step 4

BMR Step 5

Agent Skripting

Windows Agent

Installation

Address Windows Agent via command line

Please first change to the agent's installation directory in CMD or PowerShell, by default this is 'C:\Program Files\TERRA Cloud Backup\Agent\'
To start a backup, the following parameters must be passed to VV.exe:

  • VV.exe backup JOBNAME /retention=RetentionName (CMD)
  • .\VV.exe backup JOBNAME /retention=RetentionName (PowerShell)

You can use the /retention=RetentionName parameter to determine which retention type should be used.
Please replace "RetentionName" with the name of the retention period, which you can view in the Advanced Agent Settings.

Address Windows Agent via script

The desired commands can be stored in a script.
Recommended formats are .bat and .cmd

Scripts can be extended as desired, e.g. to store pre- and post-commands, i.e. commands before or after the backup.

Example script:
@echo off
cd "C:\Program Files\TERRA Cloud Backup\Agent"
echo "Start backup" >> backuplog.txt
VV.exe backup BMR /retention=Daily
echo "Backup performed" >> backuplog.txt

Run script before shutdown

You can integrate your created script into the system's pre-shutdown event with the following configuration. This is particularly recommended for client systems that are not consistently in use.
Please carry out the following steps to store a script:

  1. Open Local Group Policy Editor (WIN + R "gpedit.msc")
  2. Store your created script under "Computer Configuration -> Windows Settings -> Scripts (Startup/Shutdown)
  3. Click "Shutdown" and add your script via "Add".
  4. Please adjust the following registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gpsvc\PreshutdownTimeout
  5. This key defines the length of the pre-shutdown event, which is set to 15 minutes by default. Please increase this value so that a backup can be created during this time.
  6. In the Local Group Policy Editor, please navigate to "Computer Configuration -> Administrative Templates -> System -> Scripts
  7. Adjust the "Specify maximum wait time for Group Policy scripts" setting. You can enter a value of up to 32,000 seconds or 0 for an infinite waiting time.
  8. Please note that you have adjusted the rights accordingly.
We have described further information about this in the following Wiki article: PreshutdownTimeout Value Authorization
boxed
boxed


Create new custom command

This option gives you the opportunity to add a schedule to scripts that have already been created via the backup portal.

When you create a new custom command, the agent checks whether there are scripts stored in the agent directory in the "ScheduleScripts" batch files subfolder.
The standard path to this directory in which a script for this function can be stored:
C:\Program Files\TERRA Cloud Backup\Agent\ScheduleScripts
In the following screenshot you can see a selected script with a configured schedule:

Recommendation: A custom command's schedule can only be created as a single-line schedule. Please check our Best Practice for agent scripting to avoid this disadvantage.

Agent Skripting Best Practice

The backup agent can be tailored to specific application scenarios through the use of scripts. We recommend using the following guide as a basis for your scenario.

Preparation:
What needs to be prepared before using the following scripts?

  1. Install the agent on the system to be protected
  2. Link the system to the vault in the Backup Portal
  3. Create backup job(s) without a schedule

Step 1: Create a batch file
Create a batch file (.bat) with the following structure:
powershell.exe -ExecutionPolicy Bypass -File "Path to PowerShell script\agentscripting_retention.ps1"
Please adjust this batch file later to match the path and name you have assigned to the PowerShell script.
Copy the created batch script into the following folder within the agent's installation directory:
C:\Program Files\TERRA Cloud Backup\Agent\ScheduleScripts (default)
In the Backup Portal, for the relevant system, click on "New custom command" under "Select job task".

Using this function, you can select a stored batch script and assign a schedule to it; please configure the desired time (e.g., 10 PM).

Function:
This batch file will subsequently be launched by the backup agent itself according to the schedule.
The batch file launches PowerShell and the second script.
Since PowerShell is significantly more extensive and flexible, the first script serves solely to invoke PowerShell.

Step 2: Create PowerShell script
In this step, you create the PowerShell script that is triggered by the batch script from Step 1.
This script calls the backup agent to perform a backup.
Additionally, it allows for the use of different retention periods and the inclusion of pre- and post-commands.

Content:
Please create a PowerShell script (.ps1) with, for example, the following content:

Set-Location "C:\Program Files\TERRA Cloud Backup\Agent"
$date = Get-Date
$currentday = $date.Day
$lastday = [DateTime]::DaysInMonth($date.Year, $date.Month)
if ($lastday -eq $currentday){
Placeholder for pre-commands
.\VV.exe backup NameOfBackupJob /quickscan=true /retention=Monthly
Placeholder for post-commands
}
else{
Placeholder for pre-commands
.\VV.exe backup NameOfBackupJob /quickscan=true /retention=Daily
Placeholder for post-commands
}

Function:
This PowerShell script switches to the agent's installation directory and checks the current date.
If the date matches the total number of days in the month (the dynamic last day of the month), a backup with the retention type "Monthly" is performed.
On all other days, the retention type "Daily" is used.

Advantages of this implementation:

  1. You can utilize the full range of PowerShell functions and customize this base script as desired customize for your customers
  2. The schedule can be created via the Backup Portal and does not need to be implemented via the script
  3. You can use pre- and post-commands to stop databases prior to the backup if they cannot be brought into a consistent state using VSS technology

Linux Agent

In addition to the portal, the Linux agent can also be accessed via created scripts.
You can contact the agents directly via a created script. As in the following example script (CustomScript.sh):
nano CustomScript.sh
cd /opt/BUAgent
./VV backup RootDir
In the example, RootDir is the backup job name.
The script (e.g.: CustomScript.sh) must then be given the appropriate rights. To do this, please execute the following command:
chmod +x CustomScript.sh

Optionally, you can schedule scripts via the Backup Portal by completing the following steps:

  • Under Linux, by default, no folder called "ScheduleScripts" is created in the installation directory. Please create this with e.g. mkdir ScheduleScripts
  • Place the created script (.bat or .cmd) in the agent directory in the newly created ScheduledScripts folder
  • In the Backup Portal, select "Create a new custom command" via "Select job task" and select your script
  • Create a schedule for the script



Automatic Bare Metal System Restore Test (ABSRT-Tool)

General

Regular BMR test restores are essential for the quality management of a backup strategy.
However, manual tests are time-consuming and therefore costly; automation offers a solution here, reducing the required effort to configuration and monitoring.

The ABSRT tool creates virtual machines using Microsoft Hyper-V, equipped with a prepared restore ISO.
Data that would normally need to be entered during a manual restore—such as the system name or the vault system address—is read from a CSV file and applied during the recovery process.

The most recent safeset is dynamically selected for the recovery test.
Once the automated configuration is complete, a full restore is performed, including booting up the system after successful completion.

To further increase efficiency, you can parallelize the recovery process by including data for multiple BMR backup jobs in the CSV file.

Due to compatibility issues, the current version of ABSRT is supported only on Windows Server operating systems.

Requirements

  1. Participation in the TERRA CLOUD Backup Certified Specialist Training
  2. At least one Microsoft Hyper-V host with corresponding free capacity for the test VMs
  3. The test VMs require access to a DHCP server
  4. An external vSwitch must be available
  5. Certified Specialist ABSRT license (available upon request from Support)

Setup

When you start the ABSRT tool for the first time, the tool will ask you for a Certified Specialist ABSRT license:

After you have entered a valid license, the installation path selection appears:

The following required components are then checked/installed:

  1. Hyper-V Installation
  2. If configured, VeraCrypt

If software components are missing, they are installed automatically by the tool.
If the Hyper-V component is installed, a restart must be performed.

Preparation of the CSV file

You can create the CSV file via our TERRA CLOUD Technical Center.
Please feel free to consult the following wiki article for details: Link

If you do not currently have access to the Technical Center, you can also create the CSV file manually.
To do this, locate the "Backups.csv" file in the "CSV" folder (e.g., at C:\ABSRT\CSV); you can use this file as the basis for your configuration.

Important! The first line serves as a legend and must not be modified!

Example:
Vaultaddress,Vaultaccount,Vaultaccountpassword,Computername,Jobname,EncryptionPassword,VHDXCapacity,VMGeneration,OSVersion,VHDXStorage,VSwitchName,AmountOfPhysicalDisks,SendEmail
==> vault-wmh1-wp01.terracloud.de,00000-RESELLER,RtHKha451!HjioplÖ03,DC,BMR,hdakzeogsz1,300,2,2019,D,extern,3,n

Note:
If the encryption password contains a comma, the entire password must be enclosed in double quotation marks.

Example of an encryption password containing a comma:
"Ghgui385as,"

Explanation of parameters

Vaultaddress
FQDN of the vault system

Vaultaccount
Vault account; you can find this in your vault profile, for example

Vaultaccountpassword
You received this password in the provisioning confirmation

Computername
Computer name on the vault system; this does not necessarily have to match the name displayed in the Backup Portal—please check your reseller report if in doubt

Jobname
Name of the backup job

EncryptionPassword
The encryption password for the selected backup job

VHDXCapacity
Enter the size of the restored volume here; if the system has multiple volumes, please enter the size of the largest one in GB.

VMGeneration
Please ensure that the VM generation matches that of the source system.
The generation specified in the CSV determines the algorithm used to assign volumes during the recovery process.

OSVersion
As of agent version 9.40, there are two recovery media options, selected via the OSVersion entry.
This refers to the operating system version of the source system. The following values ​​are permitted: 7|10|11|2008|2012|2016|2019|2022|2025

VHDXStorage
Please specify the drive letter for the VHDX storage location.

VSwitchName
Name of the external vSwitch; you can find this in the Virtual Switch Manager.
If only one external vSwitch exists, you can also use the value <default>.

AmountOfPhysicalDisks
Please specify the number of physical or virtual disks the source system has.
Note: ABSRT currently supports systems with a maximum of four disks.

SendEmail
An optional switch used to configure email notifications (n ​​= no, y = yes).

If you wish to restore multiple systems simultaneously, simply add further lines starting from line 3. The legend line does not need to be copied.

Implementation

After launching ABSRT and preparing the environment, you can choose between a "standard" execution on the Hyper-V host
or preparing configuration ISOs to automate recovery at a different location (e.g., in our IaaS environment):

Convert

First, you are prompted to specify the storage location for the ISO files.
Since the ISOs are very small, C:\temp\ is set as the default destination path:

Next, you must select the desired CSV file:

Once the conversion is complete, you will find the ISO files at the selected location:

Recovery Test

The standard recovery test begins directly with the selection of a CSV file:


Subsequently, the VMs are created and started based on the CSV parameters so that the automatic recovery takes place:

Restoration outside the ABSRT environment

Once you have created the config ISOs using the Convert function, you can create a new VM shell at your chosen destination.
Importantly, a DHCP server is also required in the network of the target VM shell for the restoration to proceed.
The VM shell must have two DVD drives; the standard restore ISO is required in one drive, and the config ISO in the other:

Booting from the restore ISO initiates the automatic restoration process.
Once the restoration is complete, the process pauses at the driver overview screen.
Before restarting, ensure that both ISO files are removed from the DVD drives.

Monitoring

During the recovery, another process is started which checks the status of the recovery based on the heartbeat of the virtual machine.
As soon as a heartbeat is present, a screenshot of the connection window is created and stored in the ABSRT directory under "Screenshots".
If the SendEmail option has been selected, the screenshot is also sent to the specified email address.

Email notification ABSRT

To use the email notification, you must edit and fill out the file C:\ABSRT\smtp.xml:
C:\ABSRT\smtp.xml
The script checks in advance whether the required fields have been filled in. If an entry has not been filled in, the notification is skipped.

VeraCrypt

Activate function later:
Remove VeraCrypt REG key under HKEY_LOCAL_MACHINE\SOFTWARE\ABSRT\ Start ABSRT.exe again and activate VeraCrypt

Deactivate the function later:
If necessary, remove containers under C:\ABSRT\VeraCrypt Remove VeraCrypt REG key under HKEY_LOCAL_MACHINE\SOFTWARE\ABSRT\ Start ABSRT.exe again and say no to VeraCrypt

Rebuild CSV Container:
Remove container under C:\ABSRT\VeraCrypt Start ABSRT.exe again and enter the password for the new container

Script-based handling ABSRT

The following parameters can only be used via PowerShell:

-Install [Switch] - "C:\Users\Administrator\Desktop\ABSRT.exe -Install -DebitorNumber 12345 -License D133763385BAEFBFF9673C63Ab [-Vera Terra001!]"
-> Performs an automated installation of the ABSRT tool. The -Vera parameter is optional.

IMPORTANT: If the Hyper-V role has not yet been installed, an automatic restart will occur after the installation is complete!

-Password [String] - "C:\Users\Administrator\Desktop\ABSRT.exe -Password Terra001!"
-> Ensures that the VeraCrypt container is mounted automatically. If the password is incorrect, a manual query is made.

'-CSV [String] - "C:\Users\Administrator\Desktop\ABSRT.exe -Password Terra001! -CSV V:\CSV\TestCSV.csv [-NoPause]"
-> Ensures that the CSV file is selected automatically. Please always specify the complete path of the CSV + file extension. (Shift + right click -> "Copy as path" can be used for this)

-Uninstall [Switch] - "C:\Users\Administrator\Desktop\ABSRT.exe -Uninstall"
-> Performs a complete uninstallation of the ABSRT tool. However, the Hyper-V role is not uninstalled. Please make sure that you only perform the uninstallation once no VM created by ABSRT exists in the Hyper-V Manager.

-Manual [Switch] - "C:\Users\Administrator\Desktop\ABSRT.exe -Manual -Vaultaddress vault-wmh1-0002.terracloud.de -Vaultaccount 00000-RESTORE -Vaultaccountpassword wD5c9mP7-3bL1337l1th8W7xaB0T0m -Computername RESTORE -Jobname RESTORE -EncryptionPassword Terra001! -VHDXCapacity 1000 -VMGeneration 2 -OSVersion 2019 -VHDXStorage D -VSwitchName <default> -AmountOfPhysicalDisks 4 -SendEmail n"
-> Can be used as an alternative to the CSV selection. All parameters are required.

-ConvertCsvToIso [Switch] - "C:\Users\Administrator\Desktop\ABSRT.exe -ConvertCsvToIso -ISODestination C:\temp\ -CSV C:\Users\Administrator\Desktop\RESTORETEST.csv [-NoPause]"
-> Performs the conversion of CSV files to configuration ISOs.

Backup Assistant

The TERRA CLOUD Backup Assistant is a proprietary development by TERRA CLOUD.

Note:
Please note that the tool is no longer being maintained as of the end of 2025.

Status

On the right side of the tool you will find information about the "Connections" and "Software" versions.
If a connection to the portal servers is not possible, please check the corresponding Ports.
You can also install or update the TERRA CLOUD Backup Windows Agent using the Backup Assistant.

Agent Installation

If the Backup Agent is not yet installed on the affected system, it can be downloaded and installed using the tool.
Please first enter the login credentials of a Backup Portal user located on the corresponding customer site.
If you would like automatic job setup, you can check this box directly there. All you need to do is enter an encryption password.
Further information on automatic agent configuration can be found here.



After you have selected the required plugins and accepted the license agreement, the latest Backup Agent will be downloaded and installed in the background.

Initial backup

This feature represents the same options that are available for the initial backup tool. This tool is presented in the following Video

Agent functions

The "Backup Jobs" function allows you to execute previously created backup jobs of the installed Windows Agent and to view the log files of the performed backups..

Backup Reset

This function removes metadata (e.g. the delta information) from the job directory of the selected backup job.
After deletion, the tool performs a synchronization to recreate the removed metadata. This process may take some time.
This process may be necessary to resolve various error patterns.

Example:
delta assignment file is damaged

Support Bundle

With the support bundle, all necessary information and logs such as VSS logs, system event logs and backup job logs are brought together and packed into a .zip file.
This can help us find the cause in various support cases.

Monitoring

“Monitoring” tab in the TERRA CLOUD Backup Portal

This feature of the TERRA CLOUD Backup Portal provides a comprehensive overview of the status of all backup jobs.
Additionally, active agent processes (ongoing backups, restores, etc.) are displayed.
This overview can be accessed across all customers via the parent site or within a specific site, thereby focusing on a particular end customer.
In addition to the backup status, the Last completed backup column is particularly useful for sorting backup jobs based on the time of the last successful backup.
This makes it easy to quickly identify jobs for which no backup has been successfully completed for an extended period.

A new addition is the Backup History Graph, a visual representation of the backup history over the past 28 days.
This view displays 28 colored status bars visualizing the backup status for each day, providing a quick overview of the backup history.
Hovering your mouse cursor over a bar allows you to view further details regarding the backups performed on that specific day.

Note:
Please note that only past days are displayed; i.e., the first bar on the far right shows the status from yesterday.

The colors indicate the following:

  • Green
    At least one backup started on that day completed successfully without any warnings or errors.
  • Yellow
    At least one backup started on that day completed with warnings or was deferred.
    However, no backup completed successfully without warnings or errors.
  • Red
    At least one backup started on this day finished with errors, failed, was aborted, or could not back up any data.
    No backup was successfully completed on this day.
  • Gray
    No backup was performed for the relevant backup job on this day; scheduled backups were skipped, are still in progress, or no backup activity took place.
    In some cases, this status may also appear briefly if a backup has just successfully completed but the status information in the portal has not yet fully updated.


Active processes:
You can identify active processes by the circle consisting of two arrows and the adjacent number; clicking the icon takes you directly to the process overview.


Export of the monitoring overview by email

You can schedule regular export in various file formats for the monitoring view using the 'Email/Schedule' drop-down menu.
For an automatic evaluation of a monitoring or ticket system, you can e.g. B. select the file format 'CSV'.
If you want an export for a single end customer, you can configure this via a site user with the "Administrator" role.
To do this, please log in to the backup portal with the site user and configure the export within this end customer. The export from the following example includes the backup jobs of all sites/end customers.


Evaluate job status in XML file

The Windows, Linux and vSphere Recovery Agent store information about the last backup status and e.g. B. the backup size in an XML file.
The following paths refer to the default installation directory.

Linux Agent:
/opt/BUAgent/<JOBNAME>/BackupStatus.xml

Windows Agent:
C:\Program Files\TERRA Cloud Backup\Agent\<JOBNAME>\BackupStatus.xml

vSphere Recovery Agent:
C:\Program Files\vSphere Recovery Agent\<JOBNAME>\BackupStatus.xml

Possible results for "<agentdata:result></agentdata:result>":

  • UNKNOWN: The job status is currently unknown.
  • COMPLETED: The job is completed or completed with errors/warnings.
  • CANCELLED: The job was canceled manually.
  • FAILED: The job failed, please check the log files.
  • NO_FILES: No backup could be performed because no files are protected by this job.


Consumption Reports

The TERRA CLOUD provides you with various reports to monitor the consumption values relevant to the license model.

TERRA CLOUD Backup Reseller Report

This report shows you the consumption values of all your end customers' backup accounts.
The data refers to the 15th calendar day of a month and forms the billing basis for the respective month.
The report is sent to the Backup Master Account / Cloud Master Account (TERRA CLOUD Center) from the 16th calendar day of a month.

Example excerpt from the Reseller Report

TERRA CLOUD Backup Billing Report

In addition to the TERRA CLOUD Backup Reseller Report, you will receive the TERRA CLOUD Backup Billing Report in CSV file format.
The consumption values for billing the TERRA CLOUD backup are summarized for you in this report for each end customer.
We recommend this report as the basis for automated billing, e.g. B. also for the TERRA CLOUD Backup Enterprise license model.

Content of the report:
Active vault Vault: The name of the active vault
account Native protected data in GB: The sum of the end customer's natively protected data volume
Computer amount: The sum of the device licenses
Additional safesets: The sum of the additional paid safesets

TERRA CLOUD Backup Customer Report

Optionally, you can add an end customer report to your TERRA CLOUD backup order in the TERRA CLOUD Center.
In this report, you or your end customer will receive a weekly consumption overview and the status of the backups.
The presentation corresponds to the reseller report, but only includes the data records for the respective end customer.