All Products
Search
Document Center

Cloud Backup:Before you begin (on-premises VMware)

Last Updated:Dec 26, 2023

You can use Cloud Backup to back up on-premises VMware virtual machines (VMs) and restore VMs as needed.

(Recommended) Create an AccessKey pair for a RAM user

Resource Access Management (RAM) is an Alibaba Cloud service that allows you to manage user identities and control access to resources. RAM allows you to create and manage multiple identities associated with an Alibaba Cloud account and grant different permissions to a single identity or a group of identities. This way, you can authorize different identities to access different Alibaba Cloud resources.

An AccessKey pair is required when you activate a disaster recovery gateway. The AccessKey pair is an identity credential. If an AccessKey pair of your Alibaba Cloud account is used, all cloud resources that belong to the account are exposed to risks. Therefore, we recommend that you use an AccessKey pair of a RAM user to activate the disaster recovery gateway. Before you back up data, make sure that a RAM user is created and an AccessKey pair is created for the RAM user. For more information, see Create a RAM user and Create an AccessKey pair.

Step 1: Create a backup account

To ensure that Cloud Backup can back up on-premises VMware VMs as expected, you must create a VMware username and password for Cloud Backup to access vCenter Server and its resources. In vCenter Server, you can create a VMware role and VMware user and then assign the VMware role to the VMware user.

  1. Log on to the vSphere Web Client.

  2. Create a VMware role.

    1. Click Menu and select Administration.

      administrator

    2. On the Roles tab, click the Add icon.

      role

    3. In the New Role dialog box, select the required permissions for the role based on the following tables. Click NEXT.

      Note

      The category and location of the required permissions vary with the vCenter version. We recommend that you find the required permissions based on the following tables.

      • Required permissions in vCenter 7.0

        Category

        vCenter 7.0

        Datastore

        Datastore > Configure datastore

        Datastore > Allocate space

        Datastore > Browse datastore

        Datastore > Low level file operations

        Global

        Global > Disable methods

        Global > Enable methods

        Global > Licenses

        Global > Log event

        Global > Manage custom attributes

        Global > Set custom attribute

        Host

        Host > Local operations > Create virtual machine

        Network

        Network > Assign network

        Resource

        Resource > Assign virtual machine to resource pool

        vApp

        vApp > Add virtual machine

        vApp > Assign resource pool

        vApp > Unregister

        VirtualMachine

        VirtualMachine > Configuration > Add or remove Device

        Virtual machine > Configuration > Acquire disk lease

        Virtual machine > Configuration > Add new disk

        Virtual machine > Configuration > Advanced configuration

        Virtual machine > Configuration > Toggle disk change tracking

        Virtual machine > Configuration > Configure Host USB device

        Virtual machine > Configuration > Extend virtual disk

        Virtual machine > Configuration > Query unowned files

        Virtual machine > Configuration > Change Swapfile placement

        Virtual machine > Guest Operations > Guest operation program execution

        Virtual machine > Guest Operations > Guest operation modifications

        Virtual machine > Guest Operations > Guest operation queries

        Virtual machine > Interaction > Connect devices

        Virtual machine > Interaction > Guest operating system management by VIX API

        Virtual machine > Interaction > Power Off

        Virtual machine > Inventory > Create new

        Virtual machine > Inventory > Remove

        Virtual machine > Inventory > Register

        Virtual machine > Provisioning > Allow disk access

        Virtual machine > Provisioning > Allow file access

        Virtual machine > Provisioning > Allow read-only disk access

        Virtual machine > Provisioning > Allow virtual machine download

        Virtual machine > Snapshot management > Create snapshot

        Virtual machine > Snapshot management > Remove Snapshot

        Virtual machine > Snapshot management > Revert to snapshot

      • Required permissions in vCenter 6.7

        Category

        vCenter 6.7

        Datastore

        Datastore > Configure datastore

        Datastore > AllocateSpace

        Datastore > Browse datastore

        Datastore > Low-level file operations

        Global

        Global > Disable methods

        Global > Enable methods

        Global > Licenses

        Global > Log event

        Global > Manage custom attributes

        Global > Set custom attribute

        Host

        Host > Local operations > Create virtual machine

        Network

        Network > Assign network

        Resource

        Resource > Assign virtual machine to resource pool

        vApp

        vApp > Add virtual machine

        vApp > Assign resource pool

        vApp > Unregister

        VirtualMachine

        VirtualMachine > Configuration > Add Or Remove Device

        Virtual machine > Configuration > Acquire disk lease

        Virtual machine > Configuration > Add new disk

        Virtual machine > Configuration > Advanced configuration

        Virtual machine > Configuration > Toggle disk change tracking

        Virtual machine > Configuration > Configure Host USB device

        Virtual machine > Configuration > Extend virtual disk

        Virtual machine > Configuration > Query unowned files

        Virtual machine > Configuration > Change Swapfile placement

        Virtual machine > Guest Operations > Guest Operation Program Execution

        Virtual machine > Guest Operations > Guest Operation Modifications

        Virtual machine > Guest Operations > Guest Operation Queries

        Virtual machine > Interaction > Device connection

        Virtual machine > Interaction > Guest operating system management by VIX API

        Virtual machine > Interaction > Power Off

        Virtual machine > Inventory > Create new

        Virtual machine > Inventory > Remove

        Virtual machine > Inventory > Register

        Virtual machine > Provisioning > Allow disk access

        Virtual machine > Provisioning > Allow file access

        Virtual machine > Provisioning > Allow read-only disk access

        Virtual machine > Provisioning > Allow virtual machine download

        Virtual machine > Snapshot management > Create snapshot

        Virtual machine > Snapshot management > Remove Snapshot

        Virtual machine > Snapshot management > Revert to snapshot

      • Required permissions in vCenter 6.5

        Category

        vCenter 6.5

        Datastore cluster

        Datastore cluster > Configure a datastore cluster

        Datastore

        Datastore > AllocateSpace

        Datastore > Browse datastore

        Datastore > Low-level file operations

        Global

        Global > Disable methods

        Global > Enable methods

        Global > Licenses

        Global > Log event

        Global > Manage custom attributes

        Global > Set custom attribute

        Host

        Host > Local operations > Create virtual machine

        Network

        Network > Assign network

        Resource

        Resource > Assign virtual machine to resource pool

        vApp

        vApp > Add virtual machine

        vApp > Assign resource pool

        vApp > Unregister

        VirtualMachine

        VirtualMachine > Configuration > Add Or Remove Device

        Virtual machine > Configuration > Disk lease

        Virtual machine > Configuration > Add new disk

        Virtual machine > Configuration > Advanced

        Virtual machine > Configuration > Disk change tracking

        Virtual machine > Configuration > Host USB device

        Virtual machine > Configuration > Extend virtual disk

        Virtual machine > Configuration > Query unowned files

        Virtual machine > Configuration > Swapfile placement

        Virtual machine > Guest Operations > Guest Operation Program Execution

        Virtual machine > Guest Operations > Guest Operation Modifications

        Virtual machine > Guest Operations > Guest Operation Queries

        Virtual machine > Interaction > Device connection

        Virtual machine > Interaction > Guest operating system management by VIX API

        Virtual machine > Interaction > Power Off

        Virtual machine > Inventory > Create new

        Virtual machine > Inventory > Remove

        Virtual machine > Inventory > Register

        Virtual machine > Provisioning > Allow disk access

        Virtual machine > Provisioning > Allow file access

        Virtual machine > Provisioning > Allow read-only disk access

        Virtual machine > Provisioning > Allow virtual machine download

        Virtual machine > Snapshot management > Create snapshot

        Virtual machine > Snapshot management > Remove Snapshot

        Virtual machine > Snapshot management > Revert to snapshot

      • Required permissions in vCenter 6.0

        Category

        vCenter 6.0

        Datastore

        Datastore > AllocateSpace

        Global

        Global > Manage custom attributes

        Global > Set custom attribute

        Host

        Host > Local operations > Create virtual machine

        Network

        Network > Assign network

        Resource

        Resource > Assign virtual machine to resource pool

        Virtual machine

        Virtual machine > Configuration > Add new disk

        Virtual machine > Configuration > Advanced

        Virtual machine > Configuration > Disk change tracking

        Virtual machine > Configuration > Host USB device

        Virtual machine > Configuration > Query unowned files

        Virtual machine > Configuration > Swapfile placement

        Virtual machine > Interaction > Power Off

        Virtual machine > Inventory > Create new

        Virtual machine > Provisioning > Allow disk access

        Virtual machine > Provisioning > Allow read-only disk access

        Virtual machine > Snapshot management > Create snapshot

        Virtual machine > Snapshot management > Remove Snapshot

      • Required permissions in vCenter 5.5

        Category

        vCenter 5.5

        Network

        Network > Assign

        Datastore

        Datastore > AllocateSpace

        VirtualMachine

        VirtualMachine > Config > ChangeTracking

        VirtualMachine > State > RemoveSnapshot

        VirtualMachine > State > CreateSnapshot

        VirtualMachine > Provisioning > DiskRandomRead

        VirtualMachine > Interact > PowerOff

        VirtualMachine > Inventory > Create

        VirtualMachine > Config > AddNewDisk

        VirtualMachine > Config > HostUSBDevice

        VirtualMachine > Config > AdvancedConfig

        VirtualMachine > Config > SwapPlacement

        Global

        Global > ManageCustomFields

    4. Enter the role name and description, and then click Finish.

      We recommend that you specify an informative name to identify the role, for example, HBRBackupAdminRole. role name

  3. Create a VMware user.

    1. Click Menu and select Administration.

    2. On the Users and Groups tab, select a local domain name from the Domain drop-down list and click ADD USER.

      add user

    3. In the Add User dialog box, enter the username and password, and then click ADD.

      We recommend that you specify an informative name to identify the user, for example, BackupAdmin.

      Important

      You must remember the username and password and keep them confidential. When you add a vCenter Server in the Cloud Backup console, you must specify the username and password.

  4. Assign the VMware role to the VMware user.

    1. Click Menu and select Administration.

    2. On the Global Permissions tab, click the Add icon.

      global permissions

    3. In the Add Permission dialog box, configure the following parameters and click OK.

      add permission

      Parameter

      Description

      Domain

      Select a local domain name.

      User/Group

      Select the VMware user that you created in Step 3.

      Role

      Select the VMware role that you created in Step 2.

      Propagate to children

      Select the check box.

Step 2: Create a disaster recovery gateway

A disaster recovery gateway helps you back up and restore data. To configure a disaster recovery gateway and download the gateway to the server where the vSphere Client is deployed, perform the following steps:

  1. On the server on which the vSphere Client is deployed, log on to the Cloud Backup console.

  2. In the left-side navigation pane, choose Backup > VMware Backup & Disaster Recovery.

  3. In the top navigation bar, select a region.

  4. In the VMware Backup & Disaster Recovery page, click Create Backup & Disaster Recovery Gateway.

  5. In the Create Backup & Disaster Recovery Gateway panel, configure the parameters and click Create.

    The following table describes the parameters.

    Parameter

    Description

    Backup Vault

    The backup vault to which you want to store the backup data. Valid values:

    • Create Vault: If you select this option, specify a name for the vault in the Vault Name field. If you do not configure this parameter, a random name is specified for the backup vault.

    • Select Vault: If you select this option, select a backup vault from the Vault Name drop-down list.

    Important

    After you create a backup vault and store backup data, you are charged for the usage of the backup vault. For more information, see Billing methods and billable items.

    To maximize the redundancy of your backup data, Cloud Backup uses ZRS-enabled backup vaults by default in regions that support ZRS-enabled backup vaults. If only LRS-enabled backup vaults are available in the region where the backup vaults are located, Cloud Backup uses LRS-enabled backup vaults. You do not need to manually select a backup vault type.

    Vault Name

    The name of the backup vault.

    Vault Resource Group

    This parameter is required only if you set the Backup Vault parameter to Create Vault. This parameter specifies the resource group to which the backup vault belongs.

    You can use resource groups to manage resources owned by your Alibaba Cloud account. Resource groups help you simplify the resource and permission management of your Alibaba Cloud account. For more information, see Create a resource group.

    Gateway Name

    The name of the gateway. The name must be 1 to 64 characters in length.

    VMware Platform

    The VMware platform on which the VM is deployed. In this example, select On-premise vSphere.

    • On-premise vSphere: The VM is deployed in a VMware environment on the on-premises server.

    • Alibaba Cloud VMware Service (ACVS): The VM is deployed on Alibaba Cloud VMware Service (ACVS).

    Network Type

    The network type. In this example, select Internet.

    • VPC: If the VM that you want to back up resides in a virtual private cloud (VPC) and the VPC is in the same region as the backup vault, select this option.

      Note

      VM backup clients must be connected to VPCs by using routes. You must also make sure that you can use a VM backup client to access one of the following CIDR blocks from an on-premises VM: 100.64.0.0/10, 100.64.0.0/11, and 100.96.0.0/11.

    • Internet: If no VPCs are available, select this option.

    Use HTTPS

    Specifies whether to use HTTPS to transmit encrypted data that is stored in the backup vault. If you use HTTPS to transmit data, the performance of data transmission is degraded. If you modify the setting of this switch, the modification takes effect on the next backup or restore job.

  6. In the Create Backup & Disaster Recovery Gateway panel, click Download Gateway and Download Certificate.

    Note

    The disaster recovery gateway is used to connect your VM to Cloud Backup, and the certificate is used to activate the disaster recovery gateway. On the Backup & Disaster Recovery Gateway tab, you can download and deploy a disaster recovery gateway at any time.

Step 3: Install the disaster recovery gateway

After you download the gateway and certificate, you need to install the gateway in your VMware environment. After the gateway is installed, you can run backup and restore jobs in the Cloud Backup console. To install the gateway, perform the following steps:

  1. Log on to the vSphere Web Client.

    • Cloud Backup supports only vCenter Server 5.5, 6.0, 6.5, 6.7, and 7.0.

    • You can use a browser to log on to the Flash-based or HTML5-based vSphere Web Client.

  2. In the left-side navigation pane, right-click the VM and select Deploy OVF Template from the shortcut menu.

    For more information, see Deploying OVF and OVA Templates.

    1. In the Deploy OVF Template dialog box, select Local file. Click UPLOAD FILES, select the gateway package that you downloaded, and then click NEXT.

      Note

      To reduce the download time, Cloud Backup provides a client package in the Open Virtual Appliance (OVA) format. You can use the client package to deploy Open Virtual Format (OVF) templates on the vSphere Web Client.

    2. Enter the name of the VM, select the location where you want to deploy the VM, and then click NEXT.

    3. Select the location where you want to run the deployed template and click NEXT.

    4. Verify the template details and click NEXT.

    5. Select the format of the virtual disk, select a storage resource to which you want to store the files of the deployed template, and then click NEXT.

    6. Select a destination network for each source network and click NEXT.

    7. Configure the required deployment properties for the software solution and click NEXT.

      • If you use DHCP to obtain an IP address, you do not need to specify the Gateway, IP, and Netmask parameters. If you use a static IP address, you must specify the preceding parameters based on the obtained IP address.

      • You must make sure that the specified primary DNS server and secondary DNS server can resolve to domain names such as Cloud Backup, vCenter, and ESXi.

      • Set the Admin User Name and Admin User Password parameters to the username and password of the gateway VM that you created. This user has root permissions and can be used to log on to the VM.

    8. Verify the configurations and click FINISH.

  3. View the progress of each deployment task in the Recent Tasks section.

  4. View the progress of each deployment task in the Recent Tasks section.

  5. After the deployment tasks are completed, start the VM on which the OVF template is deployed.

  6. Open a browser, and enter http://hostname:8011 in the address bar.

    The value of hostname is the IP address of the VM on which the OVF template is deployed.

FAQ

  • Why am I unable to upload an OVA template?

    You may be unable to upload an OVA template because the vCenter Server version of the vSphere Web Client is not supported, the browser is not supported by the vCenter Server, or the language of the browser is not supported. Perform the following steps to troubleshoot the error:

    • Check whether the vCenter Server version of the vSphere Web Client is supported by Cloud Backup. Only the following vCenter Server versions are supported: 5.5, 6.0, 6.5, 6.7, or 7.0.

    • If you use vCenter Server 6.0, use an earlier version of Firefox, for example, Firefox 38.0, to deploy the OVA template.

    • If a message appears to remind you of a common error when you deploy an OVA template, we recommend that you change the language of your browser to English and then deploy the OVA template again.

  • Why am I unable to add a vCenter Server instance to the Cloud Backup gateway even if the IP address, username, and password are correct?

    A vCenter Server may fail to be added if the password contains the following special characters:

    ` ^ ~ = ; ! / ( [ ] { } @ $ \ & # % +

    Note

    We recommend that you create a vCenter Server account that is dedicated for backup. The account must have the permissions of the administrator role. We recommend that you use periods (.) instead of other special characters in the password of the account.

What to do next

Back up VMware VMs