All Products
Search
Document Center

Cloud Backup:Before you begin (on-premises VMware)

Last Updated:May 26, 2026

Install and activate the disaster recovery gateway in your on-premises VMware environment. After activation, create backup and restore jobs from the Cloud Backup console. Cloud Backup backs up and restores on-premises VMware virtual machines.

(Recommended) Use a RAM user AccessKey for disaster recovery

Resource Access Management (RAM) is an Alibaba Cloud service that lets you create and manage multiple identities under one account with different permissions.

To activate a disaster recovery gateway, you need an AccessKey. Your Alibaba Cloud account AccessKey grants full access to all resources — if exposed, all resources are at risk. Use a RAM user AccessKey instead. Create a RAM user and AccessKey before starting: Create a RAM user, Create an AccessKey pair.

Prerequisites

  • You have activated the Alibaba Cloud Cloud Backup service. While activating Cloud Backup is free, using the VMware backup and disaster recovery feature of Cloud Backup incurs fees for Cloud Backup storage capacity and VMware backup software. VMware backup and disaster recovery fees.

  • You have the credentials for a VMware account with permissions to access vCenter Server and its resources.

Notes

Step 1: Create a backup account

Create a VMware role and user in vCenter Server, then assign the role to the user. This account allows Cloud Backup to access vCenter Server resources.

  1. Log in to the vSphere Web Client.

  2. Create a VMware role.

    1. Click Menu > Administration.

      administrator

    2. On the Roles tab, click the plus icon.

      role

    3. In the New Role dialog box, select the required permissions from the following table, and then click NEXT.

      Note

      The locations and categories of permissions can differ between vCenter versions. Be sure to verify them carefully.

      • Required permissions for vCenter 8.0

        Category

        vCenter 8.0

        Datastore

        Datastore > Configure datastore

        Datastore > Allocate space

        Datastore > Browse datastore

        Datastore > Low level file operations

        Global

        Global > Disable methods

        Global > Enable methods

        Global > Licenses

        Global > Log event

        Global > Manage custom attributes

        Global > Set custom attribute

        Host

        Host > Local operations > Create virtual machine

        Network

        Network > Assign network

        Resource

        Resource > Assign virtual machine to resource pool

        vApp

        vApp > Add virtual machine

        vApp > Assign resource pool

        vApp > Unregister

        Virtual machine

        Virtual machine > Configuration > Add or remove device

        Virtual machine > Configuration > Acquire disk lease

        Virtual machine > Configuration > Add new disk

        Virtual machine > Configuration > Advanced configuration

        Virtual machine > Configuration > Toggle disk change tracking

        Virtual machine > Configuration > Configure Host USB device

        Virtual machine > Configuration > Extend virtual disk

        Virtual machine > Configuration > Query unowned files

        Virtual machine > Configuration > Change Swapfile placement

        Virtual machine > Guest Operations > Guest operation program execution

        Virtual machine > Guest Operations > Guest operation modifications

        Virtual machine > Guest Operations > Guest operation queries

        Virtual machine > Interaction > Connect devices

        Virtual machine > Interaction > Guest operating system management by VIX API

        Virtual machine > Interaction > Power Off

        Virtual machine > Inventory > Create new

        Virtual machine > Inventory > Remove

        Virtual machine > Inventory > Register

        Virtual machine > Provisioning > Allow disk access

        Virtual machine > Provisioning > Allow file access

        Virtual machine > Provisioning > Allow read-only disk access

        Virtual machine > Provisioning > Allow virtual machine download

        Virtual machine > Snapshot management > Create snapshot

        Virtual machine > Snapshot management > Remove snapshot

        Virtual machine > Snapshot management > Revert to snapshot

      • vCenter 7.0 permissions

        Category

        vCenter 7.0

        Datastore

        Datastore > Configure datastore

        Datastore > Allocate space

        Datastore > Browse datastore

        Datastore > Low-level file operations

        Global

        Global > Disable methods

        Global > Enable methods

        Global > licenses

        Global > Log event

        Global > Manage custom attributes

        Global > Set custom attribute

        Host

        Host > Local operations > Create virtual machine

        Network

        Network > Assign network

        Resource

        Resource > Assign virtual machine to resource pool

        vApp

        vApp > Add virtual machine

        vApp > Assign resource pool

        vApp > Unregister

        Virtual machine

        Virtual machine > Configuration > Add or remove device

        Virtual machine > Configuration > Acquire disk lease

        Virtual machine > Configuration > Add new disk

        Virtual machine > Configuration > Advanced configuration

        Virtual machine > Configuration > Toggle disk change tracking

        Virtual machine > Configuration > Configure host USB device

        Virtual machine > Configuration > Extend virtual disk

        Virtual machine > Configuration > Query unowned files

        Virtual machine > Configuration > Change swapfile placement

        Virtual machine > Guest operations > Guest operation program execution

        Virtual machine > Guest operations > Guest operation modifications

        Virtual machine > Guest operations > Guest operation queries

        Virtual machine > Interaction > Connect devices

        Virtual machine > Interaction > Guest operating system management by VIX API

        Virtual machine > Interaction > Power off

        Virtual machine > Inventory > Create new

        Virtual machine > Inventory > Remove

        Virtual machine > Inventory > Register

        Virtual machine > Provisioning > Allow disk access

        Virtual machine > Provisioning > Allow file access

        Virtual machine > Provisioning > Allow read-only disk access

        Virtual machine > Provisioning > Allow virtual machine download

        Virtual machine > Snapshot management > Create snapshot

        Virtual machine > Snapshot management > Remove snapshot

        Virtual machine > Snapshot management > Revert to snapshot

      • vCenter 6.7 permissions

        Category

        vCenter 6.7

        Datastore

        Datastore > Configure datastore

        Datastore > Allocate space

        Datastore > Browse datastore

        Datastore > Low-level file operations

        Global

        Global > Disable methods

        Global > Enable methods

        Global > licenses

        Global > Log event

        Global > Manage custom attributes

        Global > Set custom attribute

        Host

        Host > Local operations > Create virtual machine

        Network

        Network > Assign network

        Resource

        Resource > Assign virtual machine to resource pool

        vApp

        vApp > Add virtual machine

        vApp > Assign resource pool

        vApp > Unregister

        Virtual machine

        Virtual machine > Configuration > Add or remove device

        Virtual machine > Configuration > Acquire disk lease

        Virtual machine > Configuration > Add new disk

        Virtual machine > Configuration > Advanced configuration

        Virtual machine > Configuration > Toggle disk change tracking

        Virtual machine > Configuration > Configure host USB device

        Virtual machine > Configuration > Extend virtual disk

        Virtual machine > Configuration > Query unowned files

        Virtual machine > Configuration > Change swapfile placement

        Virtual machine > Guest operations > Guest operation program execution

        Virtual machine > Guest operations > Guest operation modifications

        Virtual machine > Guest operations > Guest operation queries

        Virtual machine > Interaction > Connect devices

        Virtual machine > Interaction > Guest operating system management by VIX API

        Virtual machine > Interaction > Power off

        Virtual machine > Inventory > Create new

        Virtual machine > Inventory > Remove

        Virtual machine > Inventory > Register

        Virtual machine > Provisioning > Allow disk access

        Virtual machine > Provisioning > Allow file access

        Virtual machine > Provisioning > Allow read-only disk access

        Virtual machine > Provisioning > Allow virtual machine download

        Virtual machine > Snapshot management > Create snapshot

        Virtual machine > Snapshot management > Remove snapshot

        Virtual machine > Snapshot management > Revert to snapshot

    4. Enter a role name and description, and then click Finish.

      Use an easily identifiable name, such as HBRBackupAdminRole.role name

  3. Create a VMware user.

    1. Click Menu and select Administrator.

    2. On the Users and Groups tab, from the Domain drop-down list, select the local domain and click ADD USER.

      add user

    3. In the Add User dialog box, enter the User name and Password, and click ADD.

      Use an easily identifiable name, for example, BackupAdmin.

      Important

      Save the username and password in a secure location. You will need these credentials to add a vCenter Server in the Cloud Backup console.

  4. Assign the VMware role to the VMware user.

    1. Click Menu and select Administration.

    2. On the Global Permissions tab, click the plus icon.

      global permissions

    3. In the Add Permission dialog box, configure the following parameters and click OK.

      add permissions

      Parameter

      Description

      Domain

      Select the local domain.

      User/Group

      Select the VMware user created in Step 3.

      Role

      Select the VMware role created in Step 2.

      Propagate to children

      Select this checkbox.

Step 2: Add a disaster recovery gateway

A disaster recovery gateway runs backup and restore jobs. Configure and download the gateway on the server where vSphere Client is deployed.

  1. On the server where the vSphere Client is deployed, sign in to the Cloud Backup console.

  2. In the left-side navigation pane, choose Back Up > VMware Backup & Disaster Recovery.

  3. In the upper-left corner of the top menu bar, select a region.

  4. In the upper-right corner of the VMware Backup & Disaster Recovery page, click Create Backup & Disaster Recovery Gateway.

  5. In the Create Backup & Disaster Recovery Gateway panel, configure the parameters and click Create.

    Parameter

    Description

    Backup Vault

    Configure the backup vault for storing backups.

    • Create backup vault: Enter a name for the new backup vault, or leave it blank to have a name automatically assigned.

    • Select backup vault: Select an existing backup vault.

    Important

    After you create a backup vault and store data, Cloud Backup charges for resources such as storage capacity. Billing methods and billable items.

    To maximize data redundancy, Cloud Backup uses zone-redundant storage (ZRS) vaults by default where available. In regions with only locally redundant storage (LRS), Cloud Backup uses an LRS vault. You do not need to select the vault type manually.

    Vault Name

    The name of the backup vault.

    Vault Resource Group

    This parameter is required only when Backup Vault is set to Create backup vault. It specifies the resource group to which the backup vault belongs.

    Resource groups let you manage and authorize resources in logical groups. Create a resource group.

    Gateway name

    Gateway name. Maximum 64 characters.

    VMware environment

    The VMware platform where the VM is deployed. For this tutorial, select On-premise vSphere.

    • On-premise vSphere: The VM is deployed on a server in your local data center.

    • Alibaba Cloud VMware Service (ACVS): The VM is deployed within Alibaba Cloud VMware Service.

    Network type

    The network type. For this tutorial, select Internet.

    • VPC: Select this option for VMs that use a VPC in the same region as the backup vault.

      Note

      The VMware backup client must have a network route to the Alibaba Cloud VPC. The route from your on-premises network to the cloud must allow traffic to the service CIDR blocks: 100.64.0.0/10, 100.64.0.0/11, or 100.96.0.0/11.

    • Internet: Select this option if a VPC connection is not available.

    Use HTTPS for data transfer

    Transfers data over HTTPS. May reduce performance. Data is always encrypted before storage. Takes effect on the next backup or restore job.

  6. In the Create Backup & Disaster Recovery Gateway panel, click Download Gateway and Download Certificate.

    The downloaded disaster recovery gateway package is the OVF template required for Step 3: Install the disaster recovery gateway.

    Note

    The installation package connects the gateway to Cloud Backup, and the certificate activates it. You can download and deploy the gateway from the client list at any time.

Step 3: Install the disaster recovery gateway

After downloading the gateway and certificate, install the gateway in your VMware environment.

  1. Log on to the vSphere Web Client.

    • Cloud Backup supports only vCenter Server 6.7 and later.

    • Use a browser to access the vSphere Web Client (Flash or HTML5).

  2. In the left navigation pane, right-click the virtual machine where you want to deploy the gateway, and then select Deploy OVF Template.

    deploy ovfFull OVF deployment instructions: Deploy OVF template.

    1. On the Deploy OVF Template page, select Local file. Click UPLOAD FILES, select the downloaded disaster recovery gateway installation package, and then click NEXT.

      upload

      Note

      Cloud Backup provides the client package in OVA format for simplified downloads. This package deploys directly as an OVF template in the Web Client.

    2. Enter a name for the virtual machine, select a deployment location, and then click NEXT.

      vmname

    3. Select a compute resource for the deployed template and click NEXT.

      ziyuan

    4. Verify the template details and click NEXT.

      yanzheng

    5. Select a virtual disk format, select a storage location for the deployed template files, and then click NEXT.

      storage

    6. Select a destination network for each source network and click NEXT.

      network

    7. Customize the deployment properties and click NEXT.

      • If you use DHCP, you do not need to specify Gateway, IP, and Netmask. For a static IP, specify these values.

      • Ensure the Primary DNS and Secondary DNS servers can resolve domain names for Cloud Backup, vCenter Server, and ESXi.

      • The Admin User Name and Admin User Password set the credentials for the gateway VM. This user has root permissions for VM login.

      zidingyi

    8. Review the configuration data and click FINISH.

      check

  3. In the Recent Tasks pane, monitor the task until it completes.

    recenttask

Step 4: Activate disaster recovery gateway

Note

The system automatically deletes a VMware disaster recovery gateway if it is not activated within 48 hours of its creation.

  1. After the deployment, start the VM deployed from the OVF template.

  2. Open a browser and enter http://hostname:8011 in the address bar.

    The hostname is the IP address of the gateway VM deployed from the OVF template.

  3. On the Register page, configure the parameters and click Register to log on to the disaster recovery gateway. The following table describes the parameters.

    register

    Parameter

    Description

    AccessKey ID

    Obtain the AccessKey ID and AccessKey Secret of a RAM user from the Alibaba Cloud account with Cloud Backup activated. Create an AccessKey pair for a RAM user.

    Note

    The gateway AccessKey can expire or be rotated. If rotated, reactivate the gateway or backup jobs will fail. How do I reset a VMware backup gateway (change the AccessKey pair)?.

    AccessKey Secret

    Password

    Gateway login password. Minimum 6 characters.

    Certificate file

    Select the certificate downloaded from the console. If the gateway is powered off for more than five days after activation, the certificate expires and you must download a new one to reactivate.

    After you activate the gateway, its status changes to Activated on the Backup & Disaster Recovery Gateway tab of the VMware Backup & Disaster Recovery page. You can also perform the following operations in the Actions column:

    • Throttle Bandwidth: Set traffic limits for different time periods to prevent backup jobs from consuming excessive VMware resources.

    • <hd> More </hd>:

      • Download Gateway: Download the disaster recovery gateway installation package.

      • Download Certificate: Download the activation certificate for the disaster recovery gateway.

      • Delete: Deletes the client and all its backup data. Running backup or restore jobs will fail. Ensure you no longer need the data and no jobs are in progress.

      • Gateway Settings: Configure HTTPS for data transfer, maximum worker threads, and CPU cores.

FAQ

Error deploying an OVA template?

To deploy an OVA template, use a vSphere Web Client managed by vCenter Server 6.7 or later. If an error occurs, perform the following checks:

  • Verify that Cloud Backup supports your vCenter Server version.

  • If a "general error" message appears during deployment, change your browser's language to English and deploy the template again.

Failed to add a vCenter Server?

This operation can fail if the password contains any of the following special characters:

` ^ ~ = ; ! / ( [ ] { } @ $ \ & # % +

Note

As a best practice, create a dedicated vCenter Server backup account with the administrator role. Use only periods (.) as special characters in the password to prevent authentication failures. Create a backup account.

Next steps

Backing up VMware virtual machines