TruenNAS: Backup Immutability & Hardening

Ғылым және технология

How To Secure TrueNAS Core
• How To Lock Down And S...
TrueNAS Document on "Hardened Backup Repository for Veeam"
www.truenas.com/docs/scale/sc...
MINIO Object Lock and Immutablity Guide
docs.min.io/docs/minio-bucket...
How S3 Object Lock works
docs.aws.amazon.com/AmazonS3/...
The Best Diagramming Tool "Diagrams.net"
• These New Features Mak...
Connecting With Us
---------------------------------------------------
+ Hire Us For A Project: lawrencesystems.com/hire-us/
+ Tom Twitter 🐦 / tomlawrencetech
+ Our Web Site www.lawrencesystems.com/
+ Our Forums forums.lawrencesystems.com/
+ Instagram / lawrencesystems
+ Facebook / lawrencesystems
+ GitHub github.com/lawrencesystems/
+ Discord / discord
Lawrence Systems Shirts and Swag
---------------------------------------------------
►👕 lawrence.video/swag
AFFILIATES & REFERRAL LINKS
---------------------------------------------------
Amazon Affiliate Store
🛒 www.amazon.com/shop/lawrences...
UniFi Affiliate Link
🛒 store.ui.com?a_aid=LTS
All Of Our Affiliates that help us out and can get you discounts!
🛒 lawrencesystems.com/partners-...
Gear we use on Kit
🛒 kit.co/lawrencesystems
Use OfferCode LTSERVICES to get 10% off your order at
🛒 lawrence.video/techsupplydirect
Digital Ocean Offer Code
🛒 m.do.co/c/85de8d181725
HostiFi UniFi Cloud Hosting Service
🛒 hostifi.net/?via=lawrencesystems
Protect you privacy with a VPN from Private Internet Access
🛒 www.privateinternetaccess.com...
Patreon
💰 / lawrencesystems
⏱️ Timestamps ⏱️
00:00 TrueNAS Hardening Backups
02:14 Backups and Protecting the Transport Layer
05:44 Snapshots and Replication
09:00 Cloud Backups
10:26 Hardening TrueNAS
12:18 MINIO S3 Object Locking

Пікірлер: 49

  • @LAWRENCESYSTEMS
    @LAWRENCESYSTEMS2 жыл бұрын

    How To Secure TrueNAS Core kzread.info/dash/bejne/oqeKsNBmerm6abQ.html TrueNAS Document on "Hardened Backup Repository for Veeam" www.truenas.com/docs/scale/communityrecommends/hardened-backup-repository-for-veeam/ MINIO Object Lock and Immutablity Guide docs.min.io/docs/minio-bucket-object-lock-guide.html How S3 Object Lock works docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock-overview.html The Best Diagramming Tool "Diagrams.net" kzread.info/dash/bejne/n6R6k8tyo8mrepM.html ⏱ Timestamps ⏱ 00:00 TrueNAS Hardening Backups 02:14 Backups and Protecting the Transport Layer 05:44 Snapshots and Replication 09:00 Cloud Backups 10:26 Hardening TrueNAS 12:18 MINIO S3 Object Locking

  • @cpadesignuk
    @cpadesignuk2 жыл бұрын

    This is very helpful Tom, thank you.

  • @jimwillhite816
    @jimwillhite8162 жыл бұрын

    Backups are a good start but you must also periodically test and verify the restore process. Any suggestions on how to implement a practical test procedure to verify that the backup/restore will work when needed?

  • @mmobini1803
    @mmobini18032 жыл бұрын

    Thank you Tom!

  • @Neo8019
    @Neo8019 Жыл бұрын

    I use 2 NAS servers for backup. The first one is on the AD where only admins and the backup software have RW. The second NAS is read only for ANY AD user, including admins and the only way it mirrors NAS No.1 is by doing a pull replication/rsync. Any deletion can only be done by logging on to the machine directly with a different user and password, with a local cron job or with something like winscp but only from specific machines and again with a different account that is not part of the AD. Not sure if its an ideal solution or I have missed something, but at the time of setting it up to my mind it was. 😁 Once again, good video and as always informative.👍

  • @uncommonamerican
    @uncommonamerican2 жыл бұрын

    Thank you good sir ..

  • @adam872
    @adam8728 ай бұрын

    I achieve immutable and air-gapped backups that can be stored offsite by using tape. With the right backup technology and processes you can make this pretty secure and able to recover from any number of different scenarios.

  • @lucienzerger
    @lucienzerger2 жыл бұрын

    second! and TrueNAS is awesome!

  • @dfgdfg_
    @dfgdfg_2 жыл бұрын

    Be great to see borgbase or something setup on Scale.

  • @blender_wiki
    @blender_wiki Жыл бұрын

    Long-term cloud archival is so cheap that is not a big issue having 2 or more full copy and snap shots in 2 or more Differents locations. Many insurance (especially in nowadays with CCPA or GDPR Hiden rules to backup private data) require you save your backup encrypted in at least 3 location separated by at leas 100miles. In 2023 I highly suggest for any bussines that handle valuable data to have at least one employee with the ISO 27001. certification.

  • @maxmustermann9858
    @maxmustermann98582 жыл бұрын

    I use Borge backup and an Storage Box from Hetzner. Borge has the permission to delete his own backups but the Hetzner Storage Box is based on ZFS and makes Daily Snapshots which only can be deleted via web Interface. And my backup user has no permission to read or whatever the backups. So I think this is a pretty good approach. What are you guys thinking?

  • @Wayk123

    @Wayk123

    7 ай бұрын

    Thanks for the idea, I didn't know about Hetzner storage boxes. Looks really nice!

  • @HelloHelloXD
    @HelloHelloXD2 жыл бұрын

    14:37 do you connect it directly to your TrueNas server or connect the usb drive to your pc and copy the data over ssh?

  • @shadownet_nft

    @shadownet_nft

    2 жыл бұрын

    I have a 5TB pool to backup, my home network is only gigabit ethernet so direct usb should be faster? I think it's a replication task source > destination but I'll let an expert confirm that

  • @JPEaglesandKatz
    @JPEaglesandKatz2 жыл бұрын

    @Lawrense Systems, Tom, thanks for the video.. Very clarifying... btw.. your link to TrueNAS Document on "Hardened Backup Repository for Veeam" does not appear to be valid anymore...

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    2 жыл бұрын

    Updated

  • @JPEaglesandKatz

    @JPEaglesandKatz

    2 жыл бұрын

    @@LAWRENCESYSTEMS Thank you!! Keep on rocking ! Your videos are invaluable!

  • @teachonlywhatiseasy
    @teachonlywhatiseasy2 жыл бұрын

    root smb share is broken for anyone who set it up in version 11?

  • @urzalukaskubicek9690
    @urzalukaskubicek96902 жыл бұрын

    What do you use to encrypt your external sandisk?

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    2 жыл бұрын

    LUKS

  • @shadownet_nft
    @shadownet_nft2 жыл бұрын

    I have just set up TrueNAS 12.0-U3 and trying to set up a one off backup to external USB drive on the same system, I think it's a replication task?

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    2 жыл бұрын

    The UI does not offer setting up with USB backup devices, you will have to do some custom scripts to get that working.

  • @shadownet_nft

    @shadownet_nft

    2 жыл бұрын

    @@LAWRENCESYSTEMS thank you

  • @rolling_marbles
    @rolling_marbles2 жыл бұрын

    Immutable means the data only can be written once and never changed. It can be deleted, but never changed. Think of the old WORM systems, Write Once Read Many. Folks do mix up immutability and retention.

  • @cvmagic404
    @cvmagic4042 жыл бұрын

    In the example provided, why not have the cloud backup performed by the replicated truenas server, and have it access the first server via SSH using a key pair, that way even if the first truenas server is compromised that they then would not have access to the cloud provider nor would they have an avenue to retrieve the credentials to the second server. You could even add a cron script to check for a canary file with a known MD5 hash to prevent replications.

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    2 жыл бұрын

    That could work as well.

  • @moelassus

    @moelassus

    2 жыл бұрын

    Compartmentalization is a good thing.

  • @sanjeev2003
    @sanjeev20032 жыл бұрын

    What a good April fools video 🤣

  • @NickF1227
    @NickF12272 жыл бұрын

    If you want immutable backups...tapes have been around for decades? :P

  • @PrimalNaCl

    @PrimalNaCl

    2 жыл бұрын

    Correct! There's even support for WORM tapes. Very odd he didn't mention any of this.

  • @marcogenovesi8570

    @marcogenovesi8570

    2 жыл бұрын

    Tape backups aren't automated (unless you have the fancy bot stations) so now it's down to human error. They also wear out

  • @NickF1227

    @NickF1227

    2 жыл бұрын

    @@marcogenovesi8570 a tape library from someone like HP coupled with A backup suite like Veeam is 100% automated…. And the amount of hours the drive can do is not dissimilar to the amount of hours a spinning hard drive can do before failure rates grow exponentially

  • @marcogenovesi8570

    @marcogenovesi8570

    2 жыл бұрын

    @@NickF1227 if it's automated then it is just cold storage with extra steps, if it's not isolated correctly then you can delete the backups, just like with a normal cold storage appliance. I have some horror stories about tape libraries. The amount of hours and/or writes is so different you can't even compare it to hard drives, tapes aren't meant to be written all the time, again, plenty of horror stories about people that kept reusing the same tapes for backups well past their end of life and were hosed when tried to restore backups

  • @samsampier7147

    @samsampier7147

    2 жыл бұрын

    I think Tom covered that in the external hard drive storage. You need good people processes, so the drives or tapes are swapped. And tested on a regular basis.

  • @curmudgeoniii9762
    @curmudgeoniii97622 жыл бұрын

    What is the diff between TrueNas and TruenNAS?

  • @mitchellsmith4601
    @mitchellsmith46012 жыл бұрын

    Consultants who know what they are doing configure only full-automated backup solutions, no user involvement required.

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    2 жыл бұрын

    Yup

  • @GameCyborgCh
    @GameCyborgCh Жыл бұрын

    cron job to print the data on paper every now and then

  • @shaunlavoie6183
    @shaunlavoie61832 жыл бұрын

    First!

  • @TechySpeaking
    @TechySpeaking2 жыл бұрын

    First

  • @alan.norbauer
    @alan.norbauer2 жыл бұрын

    Are you all using TrueNAS’ snapshot replication (zettarepl) successfully? I spent months trying to get it to work and just kept hitting bug after bug while trying to replicate ~40TB. I eventually gave up and switched to zrepl.

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    2 жыл бұрын

    I use replication via the web interface and it works well.

Келесі