# HI GIO Cloud Help Center

From February 12, 2025, HI GIO Cloud powered by FPT & IIIJ has changed the user guide UI platform. The content remains unchanged and continues to be updated in the new UI.

<figure><img src="/files/1qTsGeBSXbOp3IUw4bXS" alt=""><figcaption></figcaption></figure>

### Welcome!

The User Manual contains all the essential information for using the **HI GIO Cloud's system**.  Use graphics where possible in this manual. The manual format may be altered if another format is more suitable for the project.

### Purpose and Scope

This manual includes a description of the system functions and capabilities, contingencies and alternate modes of operation, and step-by-step procedures for system access and use.

Search our essential information.

<table data-header-hidden><thead><tr><th width="301"></th><th></th></tr></thead><tbody><tr><td><strong>COMPUTE</strong></td><td><ol start="1"><li><a href="/pages/bsv65grkGJohZT9Ut5iM">Working with VM</a></li><li><a href="/pages/ASfVFiFTtW7Ogdl1zxyV">Working with vAPP</a></li><li><a href="/pages/KfOeS0ZuqdvtLmCgz5ut">HI GIO Auto Scale</a></li><li><a href="/pages/oXP7ZTJDMfjL8Xzyjx9P">HI GIO API</a></li><li><a href="/pages/pDcK64ZlrrW4PF7v3doi">HI GIO KMS Service</a></li><li><a href="/pages/DbKXha1lYf7jJQIijhto">Encryption Management Service</a></li></ol></td></tr><tr><td><strong>STORAGE</strong></td><td><ul><li><a href="/pages/Z5yLEWl2eSl970TuGCYJ">HI GIO S3 Storage</a></li></ul></td></tr><tr><td><strong>BACK-UP AS A SERVICE</strong></td><td><ol start="1"><li><a href="/pages/FYNzG5JNMUahviWhxt5I">HI GIO BaaS</a></li><li><a href="/pages/53vC5CNrrnrhirr45X1k">HI GIO Backup</a></li><li><a href="/pages/X9tVOK0TSs5JPlMAWnuf">HI GIO M365 BaaS</a></li></ol></td></tr><tr><td><strong>DISASTER AS A SERVICE</strong></td><td><ul><li><a href="/pages/lwEtQ0YJyx3p3utNZnbS">HI GIO DRaaS</a></li></ul></td></tr><tr><td><strong>NETWORK</strong></td><td><ol start="1"><li><a href="/pages/JGuEPbmEq8xUmVjpuXab">Working with Network</a></li><li><a href="/pages/5KpiUmm5oFGpvkUNVtz8">VPN</a></li><li><a href="/pages/fP7JCNR7ai4bEFVcZWZm">Load Balancer</a></li></ol></td></tr><tr><td><strong>MANAGEMENT</strong></td><td><ol start="1"><li><a href="/pages/rF1ZeW7KKbTeD1UJRmCS">IAM Portal</a></li><li><a href="/pages/Ad7gZ7ukDybZRD6VFFmB">Create a Catalog</a></li></ol></td></tr><tr><td><strong>CONTAINER</strong></td><td><ul><li><a href="/spaces/bvay7AR0CH8vZKgD3dSy">HI GIO kubernetes</a></li></ul></td></tr><tr><td><strong>DATABASE</strong></td><td><ul><li>HI GIO DBaaS <em>(coming soon)</em></li></ul></td></tr></tbody></table>

### Organization

* FPT Telecom International Co., Ltd
* IIJ Global Solutions Vietnam Co., Ltd

### Points of Contact

* Help desk: <fti.support@fpt.com>
* Telephone assistance: **1900 6973**


# COMPUTE

## <mark style="color:green;">Introduction</mark>

This technical manual provides a comprehensive guide to understanding and handling **COMPUTE**. It includes detailed descriptions, step-by-step instructions, and necessary resources for effective utilization. Please follow the procedures and recommendations outlined in this manual to ensure the smooth functioning of IT infrastructure.

## <mark style="color:green;">Overview</mark>

HI GIO CLOUD is the first full-scale public cloud service in Vietnam and the unique product of a powerful collaboration between two leading technology companies, FPT Telecom and Internet Initiative Japan (IIJ). This platform offers high-performance computing resources, enabling businesses to seamlessly deploy, manage, and scale applications.

## <mark style="color:green;">Guideline</mark>

* [Working with VM](/compute/1.-working-with-vm)
  * [Create a New Virtual Machine from ISO](https://docs.higiocloud.vn/)
  * [Create a Virtual Machine from a Template](/compute/1.-working-with-vm/create-a-virtual-machine-from-a-template)
  * [Install VMware Tools in a Virtual Machine](/compute/1.-working-with-vm/install-vmware-tools-in-a-virtual-machine)
  * [View VM](/compute/1.-working-with-vm/view-vm)
  * [Performing Power Operations on Virtual Machines](/compute/1.-working-with-vm/performing-power-operations-on-virtual-machines)
  * [Editing the properties of a new VM](/compute/1.-working-with-vm/editing-the-properties-of-a-new-vm)
  * [Create VM's Template](/compute/1.-working-with-vm/create-vms-template)
  * [Force change root/administrator's password](/compute/1.-working-with-vm/force-change-root-administrators-password)
  * [Safely remove Disk in Windows OS](/compute/1.-working-with-vm/safely-remove-disk-in-windows-os)
* [Working with vAPP](/compute/2.-working-with-vapp)
  * [Create a vApp](/compute/2.-working-with-vapp/create-a-vapp)
  * [Start and Stop Order of Virtual Machines in a vApp](/compute/2.-working-with-vapp/start-and-stop-order-of-virtual-machines-in-a-vapp)
* [HI GIO Auto Scale](https://docs.higiocloud.vn/)
* [HI GIO API](/compute/4.-hi-gio-api)
  * [API creates VM from Template](/compute/4.-hi-gio-api/api-creates-vm-from-template)
  * [API reconfigures VM's Disk](/compute/4.-hi-gio-api/api-reconfigures-vms-disk)
  * [API reconfigures VM's Networks](/compute/4.-hi-gio-api/api-reconfigures-vms-networks)
  * [API token login](/compute/4.-hi-gio-api/api-token-login)
  * [API reconfigures VM's Memory](/compute/4.-hi-gio-api/api-reconfigures-vms-memory)
  * [API reconfigures VM's CPU](/compute/4.-hi-gio-api/api-reconfigures-vms-cpu)
  * [API power on/off VM](/compute/4.-hi-gio-api/api-power-on-off-vm)
* [HI GIO KMS Service](/compute/5.-hi-gio-kms-service)
* [Encryption Management Service](/compute/6.-encryption-management-service)


# 1. Working with VM

## <mark style="color:green;">Overview</mark>

{% hint style="info" %}
**A Virtual Machine (VM)** is a software computer that, like a physical computer, runs an operating system and applications. The virtual machine consists of a set of specification and configuration files and is backed by the physical resources of a host. Every virtual machine has devices that provide the same functionality as physical hardware but are more portable, secure, and easier to manage.
{% endhint %}

Please refer to the VM usage guide in the list below.

* [Create a New Virtual Machine from ISO](/compute/1.-working-with-vm/create-a-new-virtual-machine-from-iso)
* [Create a Virtual Machine from a Template](/compute/1.-working-with-vm/create-a-virtual-machine-from-a-template)
* [Install VMware Tools in a Virtual Machine](/compute/1.-working-with-vm/install-vmware-tools-in-a-virtual-machine)
* [View VM](/compute/1.-working-with-vm/view-vm)
* P[erforming Power Operations on Virtual Machines](/compute/1.-working-with-vm/performing-power-operations-on-virtual-machines)
* [Editing the properties of a new VM](/compute/1.-working-with-vm/editing-the-properties-of-a-new-vm)
* [Create VM's Template](/compute/1.-working-with-vm/create-vms-template)
* [Force change root/administrator's password](/compute/1.-working-with-vm/force-change-root-administrators-password)
* [Safely remove Disk in Windows OS](/compute/1.-working-with-vm/safely-remove-disk-in-windows-os)

<br>


# Create a New Virtual Machine from ISO

## <mark style="color:green;">Overview</mark>

As well as deploying pre-built VMs from a template, you can build your VMs from scratch, as you would do on a physical machine, using an ISO image instead of a physical CD or DVD.

## <mark style="color:green;">Procedure</mark>

{% stepper %}
{% step %}
**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/W6amEZW9rwJ4ibTP84rv" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Select Card View\Grid View to view the virtual machines
{% endstep %}

{% step %}
**Step 3:** Click **New VM**.

<figure><img src="/files/afvoMFMLwA48jyWUyewr" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** In the *New VM* dialog box, enter a **Name**, **Computer Name,** and **Description** for your VM.

{% hint style="warning" %}
**Attention:**

* **Name** is a name to identify the VM, **Computer Name** is the host name of the VM.
* The **Computer Name** is copied from the **Name** field but can contain only alphanumeric characters and hyphens, so you may need to edit it if your VM **Name** contains spaces or special characters.
  {% endhint %}
  {% endstep %}

{% step %}
**Step 5:** Type: Select **New**
{% endstep %}

{% step %}
**Step 6:** Select the **Power on** check-box. If you want the VM to power on right after its creation
{% endstep %}

{% step %}
**Step 7:** Operating System: Select an **OS family**, **Operating System,** and **Boot image**.
{% endstep %}

{% step %}
**Step 8:** Compute: Enter **Virtual CPUs**, **Core per socket,** and **Memory.**

<figure><img src="/files/odYV0f76TAnRWDLq1QM3" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 9**: Storage: Select **Storage Policy** & **Size** of disk.

* **Add** more disk for VM if needed.
  {% endstep %}

{% step %}
**Step 10:** Networking:

* **Network:** Select **the Organization VDC Networks** that you want to use for VM
* **Network adapter Type:** Select **VMXNET3**
* **IP mode**: Select DHCP\Static – IP Pool or Static – Manual\
  We need active DHCP (via Network\Gateway or relay DHCP server) or create 01 IP Pool in Organization VCD Networks If we use DHCP or Static-IP Pool mode.

<figure><img src="/files/UGBz60CEioHd8urmpGlU" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
**Attention:** We recommend using the VMXNET3 network adapter where possible. The VMXNET virtual network adapter has no physical counterpart and is optimized for VM performance. Because operating system vendors don't provide built-in drivers for this card, you must install **VMware Tools** to have a driver available for the VMXNET network adapter.
{% endhint %}
{% endstep %}

{% step %}
**Step 11:** Click **OK** to save the virtual machine's settings and start the creation process.\
Once the virtual machine is created, it is a VM without OS. We must **Insert Media (ISO)** into the VM and install OS.

{% endstep %}

{% step %}
**Step 12:** Click the **three vertical dots** > **Media** > **Insert Media**

<figure><img src="/files/PzPaOgnXRxpsRxeGlPC9" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 13:** Select the ISO image you want to mount from a catalog in the Insert CD dialog box, then click **Insert**.

<figure><img src="/files/nR0Bn3iSQBsIDPOIRD0Y" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 14:** Click the **three vertical dots** >> **Power** >> **Power On**

<figure><img src="/files/HMO4CeGz1RBJGeE2FuOF" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 15:** Open **VM Console** to install guest OS for VM

<figure><img src="/files/kqU1L6LFI11znD3t5COA" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/QQPnarfiDG8yEIYJ9AWg" alt=""><figcaption></figcaption></figure>

VM has boot from ISO file and start the installation.
{% endstep %}
{% endstepper %}


# Create a Virtual Machine from a Template

## <mark style="color:green;">Overview</mark>

To simplify creating a virtual machine (VM), you can use a pre-built VM template from a catalog.

## <mark style="color:green;">Procedure</mark>

{% stepper %}
{% step %}
**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/2LSiyghRrn2ARoS3MrRm" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Select **Card View\Grid View** to view the virtual machines
{% endstep %}

{% step %}
**Step 3:** Click **New VM**.

<figure><img src="/files/q5oDSKwmEOX50KungP43" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** In the *New VM* dialog box, enter a **Name**, **Computer Name,** and **Description** for your VM.

{% hint style="warning" %}
**Attention:**

* **Name** is a name to identify the VM, **Computer Name** is the host name of the VM.
* The **Computer Name** is copied from the **Name** field but can contain only alphanumeric characters and hyphens, so you may need to edit it if your VM **Name** contains spaces or special characters.
  {% endhint %}
  {% endstep %}

{% step %}
**Step 5:** From the **Type** radio buttons, select **From Template**.
{% endstep %}

{% step %}
**Step 6:** Select the **Power on** check-box. If you want the VM to power on right after its creation,
{% endstep %}

{% step %}
**Step 7:** In the ***Templates*** section, select the template you want to use for your VM, depending on your requirement (OS type and VM size).

<figure><img src="/files/uDpK6tLrql6XTwPgbqlk" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 8:** Select **Storage Policy**
{% endstep %}

{% step %}
**Step 9:** Select **Network**, **Network adapter Type**, **IP mode** for VM

<figure><img src="/files/Q99MirJ1F73iKZH848AJ" alt=""><figcaption></figcaption></figure>

<mark style="color:red;">**Attention**</mark><mark style="color:red;">:</mark> If using the Linux template, you can change the default password or SSH public key (optional)

<figure><img src="/files/cX5wTLRKtox0ndq6plrP" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 10:** Click **OK** to save the virtual machine's settings and start the creation process.

<mark style="color:red;">**Attention:**</mark>

* After the creation is completed using a Windows template, you will see this screen in the first boot.
* Remember: **DO NOT TOUCH** on anything. Let it be completed by itself.

<figure><img src="/files/OxRQCCjkuYPpLN3KONEt" alt=""><figcaption></figcaption></figure>

<mark style="color:red;">**Attention:**</mark>&#x20;

* Just wait for it to restart (about 3 minutes) to apply your specific configuration (IP, hostname,…).
* When you see the Login screen, you can get control from now.

<figure><img src="/files/S1JaKzg0q6WRgBbpL2om" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Install VMware Tools in a Virtual Machine

## <mark style="color:green;">Ov</mark><mark style="color:green;">**erview**</mark> <a href="#overview" id="overview"></a>

**VMware Tools** improves the management and performance of the virtual machine by replacing generic operating system drivers with VMware drivers tuned for virtual hardware such as storage, network, and display. You install VMware Tools into the guest operating system. Although the guest operating system can run without VMware Tools, you lose important features and convenience.

{% hint style="success" %}
**TIP**: All VM templates provided by HI GIO have VMware tools updated to be the best compatible.
{% endhint %}

## <mark style="color:green;">**Procedure**</mark>

{% stepper %}
{% step %}
**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/6IcYnMrGS9P2bz9YeGHK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Click **Card View**
{% endstep %}

{% step %}
**Step 3:** On the card of the virtual machine that you want to start, click **ACTIONS > Install VMware Tools**.

Click **Install** in a Pop-up prompt.

<figure><img src="/files/MT9tFvr4s4rwhnOKdlEV" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Log in to the operating system and follow the wizard to install the tools with OS types: <https://kb.vmware.com/s/article/1014294>.
{% endstep %}
{% endstepper %}


# View VM

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

* You can view virtual machines that are standalone or part of a vApp.
* You can view virtual machines in a **grid view** or a **card view**.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/9GcmqHDUsev8DRV0mUHO" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** You can select **grid view** or **card view** by selecting:

* To view the virtual machines in a **grid view**, click ![](/files/1FaxreV7tbE6Hq416Qpd)
* To view the virtual machines in a **card view**, click ![](/files/64cHxEEWdZuhX13OoM0L)

The list of virtual machines is displayed in a grid view or as a list of card views.

{% hint style="info" %}
**View VM in grid view:**
{% endhint %}
{% endstep %}

{% step %}
**Step 2.1:** From the grid view, click the **three vertical dots** on the left of a virtual machine to display the actions you can take for the selected virtual machine.
{% endstep %}

{% step %}
**Step 2.2:** To access the console for the guest operating system of the virtual machine, click **on VM Console**.
{% endstep %}

{% step %}
**Step 2.3:** To view and edit the details for a virtual machine, click the **VM’s name**.

<figure><img src="/files/yyELilKLSkKObRoQiAKY" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2.4:** From the grid view, click the **three vertical dots** on the left of a virtual machine to display the actions you can take for the selected virtual machine.
{% endstep %}

{% step %}
**Step 2.5:** To access the console for the guest operating system of the virtual machine, click **on VM Console**.
{% endstep %}

{% step %}
**Step 2.6:** To view and edit the details for a virtual machine, click the **VM’s name**.

<figure><img src="/files/ogZJHo7FQpuOLP8VaTy9" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**View VM in Card view:**
{% endhint %}
{% endstep %}

{% step %}
**Step 3.1 :** From the card view, click the **Action** to display your actions for the selected virtual machine.
{% endstep %}

{% step %}
**Step 3.2:** To access the console for the guest operating system of the virtual machine, click **on VM Console**.

{% endstep %}

{% step %}
**Step 3.3:** To view and edit the details for a virtual machine, click **Details**.

<figure><img src="/files/APCNPaEqHREfqcqNWpK6" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Performing Power Operations on Virtual Machines

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

You can perform power operations on virtual machines, such as powering on or off a virtual machine, suspending or resetting a virtual machine, or shutting down the guest operating system of a virtual machine.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% tabs %}
{% tab title="I. Power on a Virtual Machine" %}
**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/SAftSFxeNRXArr4TE8va" alt=""><figcaption></figcaption></figure>

**Step 2:** Click **card view**

**Step 3:** On the card of the virtual machine that you want to start, click **ACTIONS > Power > Power On**.

<figure><img src="/files/ZKiaZAKK4E3zOtfAd1wU" alt=""><figcaption></figcaption></figure>

A powered-on virtual machine displays a Powered-on status in green.

<div align="left"><figure><img src="/files/LFRn27kwqet9mK60ibub" alt=""><figcaption></figcaption></figure></div>
{% endtab %}

{% tab title="II. Shut down Guest OS, Power off, Reset a Virtual Machine" %}

* The Shut Down Guest OS for VM action shuts down the guest operating system and powers off the virtual machine. VMware Tools must be installed and running on the VM.
* Powering off a virtual machine is the equivalent of <mark style="color:red;">**powering off a physical machine**</mark><mark style="color:red;">.</mark>
* Resetting a virtual machine clears the state (memory, cache, and so on), but the virtual machine continues to run. Resetting a virtual machine is the equivalent of pushing the reset button of a physical machine. It initiates a hard reset of the operating system without changing the virtual machine's power state.

**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/1l7pCbY7bcNkp9lYO9nZ" alt=""><figcaption></figcaption></figure>

**Step 2:** Click **card view**

**Step 3:** In the card of the virtual machine that you want to power off, click **ACTIONS** > **Power** > **Power Off**\\**Shut Down Guest OS**\\**Reset**

<figure><img src="/files/y7Ytt6iOMcCbE2b6pNGI" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="III.Suspend a Virtual Machine" %}

* Suspending a virtual machine preserves its current state by writing the memory (RAM) to disk.
* The suspend and resume feature is useful when you want to save your virtual machine's current state (RAM) and continue work later from the same state.

**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/YFlReqpZLhOL9jOWf5Zd" alt=""><figcaption></figcaption></figure>

**Step 2:** Click **card view**

**Step 3:** In the card of the virtual machine that you want to start, click **ACTIONS** > **Power** > **Suspend**.

<figure><img src="/files/w95giaEAakSoXfJOiMCp" alt=""><figcaption></figcaption></figure>

The virtual machine is suspended, but its state is preserved.

<div align="left"><figure><img src="/files/FgingtSiNI1WvnYV2qsx" alt=""><figcaption></figcaption></figure></div>

<mark style="color:red;">**Attention:**</mark> From the **VM Suspended state**, just **power on** if you need the VM to run with the current memory.
{% endtab %}

{% tab title="IV. Discard the suspended state of a Virtual Machine" %}
If a virtual machine is in a **suspended** **state** and you no longer need to resume the use of the machine, you can **discard the suspended state**. Discarding the suspended state removes the saved memory and returns the machine to a **powered-off state**.

**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/UtqMPT3EamJuIQRDOPOa" alt=""><figcaption></figcaption></figure>

**Step 2:** Click **card view**

**Step 3:** In the card of the virtual machine that you want to start, click **ACTIONS > Power >** **Discard the suspended state**.

<figure><img src="/files/ToRZtvfoVSWislaoGzJU" alt=""><figcaption></figcaption></figure>

The state is discarded, and the virtual machine is **powered off**.

<div align="left"><figure><img src="/files/CJvbw6xSOqBfuQHHWlEJ" alt=""><figcaption></figcaption></figure></div>
{% endtab %}
{% endtabs %}


# Editing the properties of a new VM

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

You can edit the properties of a virtual machine, including the **virtual machine name** and **description**, **hardware** and **network settings**, **guest OS settings**, and so on.

## <mark style="color:green;">Procedure</mark> <a href="#procedure" id="procedure"></a>

{% tabs %}
{% tab title="I. Change the general properties of a Virtual Machine" %}
You can review and change a virtual machine's name, description, and other general properties.

**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore and from the left panel, select **Virtual Machines**.

<figure><img src="/files/84M2pkUbQSC3bytzZ9JJ" alt=""><figcaption></figcaption></figure>

**Step 2:** Click card view

**Step 3:** In the virtual machine card you want to edit, click **Details**.

<figure><img src="/files/3FD8Ppli0WvMQd4em9Ht" alt=""><figcaption></figcaption></figure>

**Step 4:** Under ***General*** expands by default > **Edit** to list of properties

<figure><img src="/files/nIalwJjVIcQZZxqtmszL" alt=""><figcaption></figcaption></figure>

**Step 5:** Click **Save** once you complete making your changes.
{% endtab %}

{% tab title="II. Change the hardware properties of a Virtual Machine" %}
**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/Gg2g14afSlzETQRqkc2V" alt=""><figcaption></figcaption></figure>

**Step 2:** Click **card view**

**Step 3:** In the card of the virtual machine that you want to edit, click **Details**.

<figure><img src="/files/V4dUyxlZzo1XcshqlqNx" alt=""><figcaption></figcaption></figure>

**Step 4:** To view the available removable media, such as attached CD/DVD and floppy drives, under **Hardware**, select the **Removable Media** tab.

<figure><img src="/files/zLXp0oytAg5i9Rm7h1lO" alt=""><figcaption></figcaption></figure>

**Step 5:** To edit the hard disk settings or add hard disks, select **Hard Disks** and click **Edit**. Click **Save** once done

<figure><img src="/files/gMKu6ne73T0YeMf8ZiQj" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
**Attention:** You can increase the size of an existing hard disk if the virtual machine is not a linked clone and has **no snapshots.**
{% endhint %}

**Step 6:** To edit the computing settings, select **Compute** > **Edit** the relevant section.

<figure><img src="/files/mcDbwyTV5zR0CfunCwwN" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
**Attention: vSphere restriction**
{% endhint %}

1. VMware has set a maximum value for hot-add memory. By default, this value is 16 times the memory assigned to the virtual machine. (<https://kb.vmware.com/s/article/2020846>)
2. If you are running WM with Linux OS having less than 3GB RAM, you can change the memory to only 3GB RAM in total if you need more. You must power off the VM, increase memory to, for example, 4 GB RAM, and power it on again. (<https://kb.vmware.com/s/article/2008405>).

<figure><img src="/files/YZzf5miv4VsKeUIBSCJc" alt=""><figcaption></figcaption></figure>

&#x20;**Step 7:** To edit the NICs settings or add NICs, click **NICs** > **Edit. Save** once Done.

<figure><img src="/files/ZUh8P1xX6S8Oi0IJKf9m" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/l5PQEl6RM7Za7cPM0bzj" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}


# Create VM's Template

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

* HI GIO provides virtual machine (VM) template sizes and operating systems.
* The HI GIO template is a good place to start when you first deploy VMs into the HI GIO. However, you may want to create a template containing specific applications that you can use to deploy VMs quickly.
* Assume your VM has already installed OS and VMware tools and is preconfigured.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% tabs %}
{% tab title="I. Customize your VM" %}
Prerequisites: VMware Tools must be installed & VM is **powered off**.

**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/GcqOrylYUoxvzX1WcLsq" alt=""><figcaption></figcaption></figure>

**Step 2:** Click **card view**

**Step 3:** On the card of the virtual machine that you want to start, click **DETAILS**.

<figure><img src="/files/87MxvGcg6W9AzWJUAOXf" alt=""><figcaption></figcaption></figure>

**Step 4:** To enable\disable Hot-add for CPU\Memory, Click **Compute** > **Edit** (CPU section or Memory section)

{% hint style="warning" %}
**Attention:** VM’s state must be powered off.
{% endhint %}

<figure><img src="/files/Iesn8tNVSpVUeOeXCzK9" alt=""><figcaption></figcaption></figure>

**Step 5:** Enable **toggle** and click **Save**

<div align="left"><figure><img src="/files/8OADBmQo0REiuwoDTDQo" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="/files/UFQUIoYqHqMkEg1R3H82" alt=""><figcaption></figcaption></figure></div>

{% hint style="warning" %}
**Attention: vSphere restriction attention: vSphere restriction**
{% endhint %}

1. VMware has set a maximum value for hot-add memory. By default, this value is 16 times the memory assigned to the virtual machine. (<https://kb.vmware.com/s/article/2020846>)
2. If you are running WM with Linux OS having less than 3GB RAM, you can change the memory to only 3GB RAM in total if you need more. You must power off the VM, increase memory to, for example, 4 GB RAM, and power it on again. (<https://kb.vmware.com/s/article/2008405>).

<figure><img src="/files/T8Roekoiw9TBlEnAlRTj" alt=""><figcaption></figcaption></figure>

**Step 6:** To customize Guest OS, Click **Guest OS Customization** > **EDIT**

<mark style="color:red;">**TIP**</mark><mark style="color:red;">:</mark> Guest OS Customization will help you prepare the logon, change the password, \ Join the Domain (just for Windows) in the first boot after deploying.

<figure><img src="/files/4ELQ0MxWYjRhMQmlZy1q" alt=""><figcaption></figcaption></figure>

**Step 7:** On Edit Guest Properties

Depends on the guest OS – Linux or Windows. The view of this page has some differences:

* The **Enable guest customization** check box is selected.
* **Change the SID** option (for Windows OS)
* Select **Allow local administrator password**
* Select **Require administrator to change the password on the first login** to require all administrators to change the password upon initial login (Administrators must know the old password)
* Select **Auto Generate password** or **Specify password** (if you want to define it yourself).
* Join Domain (this session is for Windows OS)

<figure><img src="/files/FhRCG8NHmPhKnEi9gsQG" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/ZyIxD9HUDLcOXfQ8WsPF" alt=""><figcaption></figcaption></figure>

**Step 8**: Click **Save**
{% endtab %}

{% tab title="II. Creating VM templates" %}
**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/qC8rLtLTZOLmKmdpkKHQ" alt=""><figcaption></figcaption></figure>

**Step 2:** Click **card view**

**Step 3:** On the card of the virtual machine that you want to start, click **ACTIONS**.

**Step 4:** Click **Create Template**

<figure><img src="/files/RiH4VWLnHodQCqzrwIZx" alt=""><figcaption></figcaption></figure>

On the Add to Catalog page

**Step 5:** Select the **catalog** that will store this template

**Step 6:** Enter the **Name** of the template

**Step 7:** Select **Customize VM** setting and click **OK** to process

<figure><img src="/files/mdlbNfcHbXBqPBUWvBwh" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**The other way to create the template by upload your template to HI GIO**

The maximum import size is **50 GB**. Large image files or templates might take a long time to upload. For assistance with files **larger than** **50 GB**, request the support team.
{% endhint %}
{% endtab %}
{% endtabs %}


# Force change root/administrator's password

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

* You can reset the root/administrator’s account password via Guest OS Customization in the vCD portal.
* This password is used for root (Linux) or Administrator (Windows).

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log in to vCD portal > Data Centers > Virtual Machines > Guest OS Customization > EDIT.

<figure><img src="/files/q6Sswi5dEUrqH2a3k55X" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Verify guest customization is enabled and Specify password > SAVE.

<figure><img src="/files/G2FVlmOTlMebUwFEYKlv" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Power off and Power on, Force Recustomization.

<figure><img src="/files/8LEX86gFBmTC3RByyLDc" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Safely remove Disk in Windows OS

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

* Bring disk to Offline in Windows OS.
* Confirm that the disk’s status = is *offline* in Windows OS and provide disk information to the support team (they will support the infrastructure side).
* Validate again on Windows OS.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log on to Windows and open Disk Management.

Right-click on the **Windows** menu > **Run**.

![](/files/mHK1OU3CwwAeoNHcP6BW)

![](/files/T5S1hAi47Sr6XRthXXnS)<br>
{% endstep %}

{% step %}
**Step 2:** On Disk Management:

Right-click the disk name > **Offline**

<figure><img src="/files/8sx0cR4OcJI7Dbn1zhvM" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Validate disk status:

**Disk status** = *Offline,* and it will disappear on the volume table.

<figure><img src="/files/MBChlGosxrwGNzHdL7ej" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}

#### **Confirm that the disk’s status = offline in Windows OS and provide disk information to the support team (they will support on the infrastructure side).** <a href="#confirm-that-the-disks-status-offline-in-windows-os-and-provide-disk-information-to-the-support-team" id="confirm-that-the-disks-status-offline-in-windows-os-and-provide-disk-information-to-the-support-team"></a>

{% endhint %}

Please provide disk information:

* **Disk size:**
* **Disk ID** (follow as below):

*\*\*\* Check Disk ID via Disk Management:*

Right-click the disk name > **Properties**

<figure><img src="/files/R5iQ2x1sGphG20MTV8yd" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}

#### **Validate again in Windows OS:** <a href="#validate-again-in-windows-os" id="validate-again-in-windows-os"></a>

{% endhint %}

* Once the support team has completed the infrastructure side.
* Please log on to Windows OS and confirm that the disk has been removed. No disk offline status is shown on Disk Management.
  {% endstep %}
  {% endstepper %}


# 2. Working with vAPP

## <mark style="color:green;">Overview</mark>

**vApp** consists of one or more virtual machines communicating over a network and using resources and services in a deployed environment. **vApp** can contain multiple virtual machines.

Please refer to the vAPP usage guide in the list below.

* [Create a vApp](https://docs.higiocloud.vn/)
* [Start and Stop Order of Virtual Machines in a vApp](/compute/2.-working-with-vapp/start-and-stop-order-of-virtual-machines-in-a-vapp)


# Create a vAPP

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

* vApp consists of one or more virtual machines communicating over a network and using resources and services in a deployed environment. vApp can contain multiple virtual machines.
* Instead of creating a vApp based on a vApp template, you can make a vApp using virtual machines from catalogs, new virtual machines, or a combination of both.
* Building a vApp requires you to provide a name and, optionally, a description of the vApp. You can go back and add the virtual machines to the vApp later.

{% hint style="warning" %}
**Attention:** vApp can contain multiple VMs, so **Shut down\Stop** vApp, it will affect all VMs inside vApp.
{% endhint %}

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% tabs %}
{% tab title="I. Create a vApp" %}
**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **vApps**.

<figure><img src="/files/PG2lc0RshjitzCqIANqa" alt=""><figcaption></figcaption></figure>

**Step 2:** In the vApps page, click New, then select New vApp.

<figure><img src="/files/2EtF3LMBUXF0dwYEiugE" alt=""><figcaption></figcaption></figure>

**Step 3:** Enter a **Name** and a Description (optionally) for the vApp.

**Step 4:**

**#Optional:** If you want the vApp to power on upon deployment, select the **Power on** the check box.

{% hint style="warning" %}
**Attention:** The vApp can **power on** only if virtual machines exist.
{% endhint %}

<figure><img src="/files/zxj3CmfIzNxlEFF4brG7" alt=""><figcaption></figcaption></figure>

**Step 5:** Click **Add Virtual Machine.**

{% hint style="warning" %}
Attention: You can click **Create** at this point to create an empty vApp and add VMs to it later.
{% endhint %}

**Step 6:** In the ***New VM*** dialog box, select:

* **New** to create a VM from scratch Create a New Standalone Virtual Machine
* From Template to create a VM from an existing template Create a Virtual Machine from a Template

**Step 7:**

**#Optional:** Repeat [Step 5](https://docs.vmware.com/en/VMware-Cloud-Director/10.3/VMware-Cloud-Director-Tenant-Portal-Guide/GUID-19FD52A4-94B9-4001-8CE0-A50BD1F0D4A1.html#GUID-19FD52A4-94B9-4001-8CE0-A50BD1F0D4A1__step_BE4126BCFB5A476BBF5ACD9EDED86406) for each additional virtual machine you want to create within the vApp.

**Step 8:** To complete the creation of the vApp, click **Create**.
{% endtab %}

{% tab title="II. Add a Network to a vApp" %}
You can add a network to a vApp to make the network available to the virtual machines in the vApp. You can add a virtual data center network to a vApp.

**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **vApps**.

<figure><img src="/files/teCDYfQ4H99wS2G4A3p6" alt=""><figcaption></figcaption></figure>

**Step 2:** On vApps page, select Card View to view vApp in card view.

**Step 3**: Click **Actions** menu of the vApp to which you want to add a network, select **Add > Add Network**.

<figure><img src="/files/1FDiSiZUL4h4jMrjbHPH" alt=""><figcaption></figcaption></figure>

**Step 4:** On the Add Network page:

Check type: **Direct** and select **the network** that you want to add.

<figure><img src="/files/mxOwwCEsEQ22Mm6TOFHE" alt=""><figcaption></figcaption></figure>

**Step 5:** Click **ADD**
{% endtab %}

{% tab title="III. Move a Virtual Machine to vApp" %}
**Step 1:** On the **Virtual Data Center** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **Virtual Machines**.

<figure><img src="/files/UTg5GP8fuHXaejKbd4b5" alt=""><figcaption></figcaption></figure>

**Step 2:** Select **Card View** to view Virtual Machine in Card View on **Virtual Machines Windows**.

**Step 3:** Click **Actions** menu of the Virtual Machine which you want to Move, select **Move**

<figure><img src="/files/HmCv7WyZdzCOIKhyVSgq" alt=""><figcaption></figcaption></figure>

**Step 4:** Select **Destination vApp**, then click **Next**

<figure><img src="/files/4hiadvlyrk7VzbDpcQrT" alt=""><figcaption></figcaption></figure>

**Step 5:** On ***Configure Resource*****:**

Enter & validate the information: **Name**, **Computer Name**, **Target VM storage Policy**, **Network**, **IP Mode** for Virtual Machine, then click **Next**

<figure><img src="/files/9EqB7QKGT2BOQ3F2AWB7" alt=""><figcaption></figcaption></figure>

**Step 6:** Validate and click **Done**

<figure><img src="/files/3ndSmk8mQKveqgw6qFLZ" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}


# Start and Stop Order of Virtual Machines in a vApp

## <mark style="color:green;">**Overview**</mark>

* You can configure virtual machines' start and stop orders within your vApp. Configure the start and stop order if you have applications installed in the virtual machines that must start and stop in a particular order.
* These settings are helpful if you need to start and stop your virtual machines in a particular order.

{% hint style="warning" %}
**Attention:** Verify that the vApp is powered off.
{% endhint %}

## <mark style="color:green;">**Procedure**</mark>

{% stepper %}
{% step %}
**Step 1:** On the **Virtual Data Cnter** dashboard screen, click the card of the virtual data center you want to explore, and from the left panel, select **vApps**.

<figure><img src="/files/I9Vil2t3fl4UZ0t3CSMm" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** In the vApps page, select **card view.**

{% endstep %}

{% step %}
**Step 3: On** the vApp card, click **Details.**

<figure><img src="/files/ShRyaDYrQgvrKC0ruobP" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Click the **Start and Stop Order** tab and click **Edit**.

<figure><img src="/files/6LYwp1nwTmRdvFeBFqNA" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5: Edit** each virtual machine's start and stop order properties and click **OK**.

* ***Start Order**:* Enter the order (0, 1, 2, 3 ...) where you want the virtual machine to start.
* ***Start Action**:* Select **Power On (default)** or **None.**
* ***Start Wait**:* The start wait time is the time (in seconds) you want to wait before VMware Cloud Director starts the next machine in the sequence.
* ***Stop Action**:* Select **Power Off; the** VM powers off without performing shutdow&#x6E;**.** Otherwise, select **Shut Down (**&#x72;equired **VMware tool installed)**, which ensures stability upon shutting down.
* ***Stop Wait**:* The stop wait time is the time (in seconds) you want to wait before VMware Cloud Director shuts down the next virtual machine in the sequence.

<figure><img src="/files/oqVN2Be8IXXxziUs9AuL" alt=""><figcaption></figcaption></figure>

So we can **power off** the vApp. It will automatically start the VMs based on the startup order (The reverse order is used to power them off).
{% endstep %}
{% endstepper %}


# 3. HI GIO Auto Scale

## <mark style="color:green;">**Overview**</mark>

This document guides using the **Auto Scale function** on HI GIO CLOUD.

## <mark style="color:green;">**Procedure**</mark>

* The network has IP addresses on a static IP Pool (used for applications **without** HI GIO Load Balancing).
* Load Balancer Pool and Virtual Service (used for applications with HI GIO Load Balancing).
* The vApp template of the VM needs to be scaled.

{% tabs %}
{% tab title="I. Create Scale Group" %}
**Step 1: Log in to HI GIO Portal > Applications > Scale Groups > NEW SCALE GROUP**

<figure><img src="/files/sqrNX5bCgsmoTPVp0rDQ" alt=""><figcaption></figcaption></figure>

**Step 2: In the General Settings:**

* Pick an owner of the Scale Group.
* Pick an Organisation VDC.
* Enter Group Name.
* Number of Min VMs.
* Number of Max VMs.<br>

  <figure><img src="/files/RpZDyKhI4NsZ2MzA9CD5" alt=""><figcaption></figcaption></figure>

**Step 3: In the Application Settings:**

* Select the vApp template of the previously prepared application.
* Pick a Storage Policy.<br>

  <figure><img src="/files/iE9na0QvK3xMZvPfadC3" alt=""><figcaption></figcaption></figure>

  **Step 4: Se**lect **a network** for the scale group in the **Network Settings** section.

  * If you want to manage the load balancer on your own or if there is **no need for a load balancer**, select *I have a fully set-up network*:
    * Pick a Network.
    * Click CREATE GROUP AND ADD RULES.<br>

      <figure><img src="/files/QpFtmMDa98xOYHDEoKJN" alt=""><figcaption></figcaption></figure>

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Make sure the network has available Static IP Pools.</p></div>

  * If your applications use **HI GIO Load Balancing**, select *I have set-up a Load Balancer* option.
    * Enter Network CIDR.
    * Pick Edge Gateway.
    * Pick Server Pool
    * Click CREATE GROUP AND ADD RULES.<br>

      <figure><img src="/files/cUbUkFgQO6cRiObv9Vs2" alt=""><figcaption></figcaption></figure>

  **Step 5:** Set up Firewall rules depending on the application’s requirements.
  {% endtab %}

{% tab title="II. Create Auto Scaling Rules" %}

<figure><img src="/files/aRedBlEOif1qdFsDVEcE" alt=""><figcaption></figcaption></figure>

**Step 1:** Select Scale Group > Rules > ADD RULE.

**Step 2: In the General tab:**

* **Name:** enter rule name.
* **Number of VMs:** The number of VMs will scale.
* **Behavior:** Select whether the scale group must expand or shrink when the rule takes effect.
  * Grow: scale out.
  * Shink: scale in.
* **Cool down:** Enter a cooldown period in minutes after each auto scale in the group.

{% hint style="warning" %}
**Attention:** The conditions cannot trigger another scaling until the cooldown period expires. The cooldown period resets when any of the rules of the scale group takes effect.
{% endhint %}

**Step 3: In the Conditions tab, Add a condition that triggers the rule.**

* A**vg. Utilization:**
  * CPU usage.
  * memory usage.
* **Condition:**
  * greater or equal to.
  * lower or equal to.
* Amount: in percent.
* **Duration:** The period when the condition must be valid to trigger the rule.

{% hint style="warning" %}
**Attenstion:** An AND operator groups conditions in a rule.

After a condition is met, it might be executed with a delay of **up to 5 minutes.**
{% endhint %}

<figure><img src="/files/tdBRw6C9ve1vKAsdCJHa" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

### **Reference document**

[Auto Scale Groups](https://docs.vmware.com/en/VMware-Cloud-Director/10.4/VMware-Cloud-Director-Tenant-Portal-Guide/GUID-C179B853-709B-455D-94CA-2D5159D70A49.html)


# 4. HI GIO API

## <mark style="color:green;">Overview</mark>

This guide is designed to help developers and technical users integrate and interact with the HI GIO Cloud services through our powerful API.

This manual provides detailed information on authenticating, making API calls, and handling responses effectively. It also covers best practices, code examples, and troubleshooting tips to ensure a smooth integration process.

Please refer to the VM usage guide in the list below.

* [API creates VM from Template](/compute/4.-hi-gio-api/api-creates-vm-from-template)
* [API reconfigures VM's Disk](/compute/4.-hi-gio-api/api-reconfigures-vms-disk)
* [API reconfigures VM's Networks](/compute/4.-hi-gio-api/api-reconfigures-vms-networks)
* [API token login](/compute/4.-hi-gio-api/api-token-login)
* [API reconfigures VM's Memory](/compute/4.-hi-gio-api/api-reconfigures-vms-memory)
* [API reconfigures VM's CPU](/compute/4.-hi-gio-api/api-reconfigures-vms-cpu)
* [API power on/off VM](/compute/4.-hi-gio-api/api-power-on-off-vm)

<br>


# API creates VM from Template

## <mark style="color:green;">Overview</mark>

* In this manual, you will find detailed information on how to prepare & create a VM from the template.
* This API creates a VM with the default name (VM name of template), default network "VM Network," and default compute and storage.

## <mark style="color:green;">Procedure</mark>

{% stepper %}
{% step %}
**Step 1: Preparation**

&#x20;Log in to IAM portal -> vCD portal: collect the information

**{{vcd\_url}}**

<figure><img src="/files/NrunUskW6Ker0Q6vn1Ju" alt=""><figcaption></figcaption></figure>

\
**{{vdc\_uuid}}:** Login vCD portal -> select VDC-> take a look and note **vdc\_uuid** on the URL

<div align="left"><figure><img src="/files/kWf2bjEbjbZT2hiIzzsk" alt="" width="563"><figcaption></figcaption></figure></div>

**{{network\_uuid}}:** On the vCD portal -> Networking -> Networks -> New

{% hint style="warning" %}
**Note that the network name must be “VM Network”**
{% endhint %}

<figure><img src="/files/Nc9TEjdH9JsFpDYIVmKO" alt=""><figcaption></figcaption></figure>

Select the “VM Network” -> take a look and note the network uuid on the url

<figure><img src="/files/0E2HaNcqI3WdFIkYkEGr" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/mR7tPffZZdzPkn8KV8HW" alt=""><figcaption></figcaption></figure>

&#x20; **{{vappTemplate\_uuid}}:** On the vCD portal -> Content Hub -> Catalogs ->HIGIO Shared Catalogs

<figure><img src="/files/GCdlOjyqIdgfdIyp48pH" alt=""><figcaption></figcaption></figure>

-> vApp Templates -> select the template that you want to create VM -> take a look the vappTemplate\_uuid on the url

<figure><img src="/files/y2toCoyLtkZS6c164c7s" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/yeK45rtS3Y6AUHgEiecG" alt=""><figcaption></figcaption></figure>

&#x20;**{{Bearer Token}}**: Please follow **“**[**Api token login**](/compute/4.-hi-gio-api/api-token-login)**”** document
{% endstep %}

{% step %}
**Step 2: Create VM from template**

**Postman:**

POST https\://{{vcd\_url}}/api/vdc

/{{vdc\_uuid}}/action/instantiateVAppTemplate

Authorization: {{Bearer Token }}

Headers:

\- 'Accept: \*/\*;version=37.2

\- ‘Content-type’: application/vnd.vmware.vcloud.instantiateVAppTemplateParams+xml; charset=ISO-8859-1

<figure><img src="/files/JM7pTH2c3uO4Vny7lRbJ" alt=""><figcaption></figcaption></figure>

Body: {{select raw, copy, paste and edit the code below}}

```
<?xml version="1.0" encoding="UTF-8"?>

<vcloud:InstantiateVAppTemplateParams

    xmlns:ovf="http://schemas.dmtf.org/ovf/envelope/1"

    xmlns:vcloud="http://www.vmware.com/vcloud/v1.5"

    deploy="false"

    name="your vapp name"

    powerOn="false">

    <vcloud:Description>VApp Description</vcloud:Description>

    <vcloud:InstantiationParams>

        <vcloud:NetworkConfigSection>

            <ovf:Info>NetInfo</ovf:Info>

            <vcloud:NetworkConfig networkName="VM Network">

                <vcloud:Configuration>

                    <vcloud:ParentNetwork

                        href="https:// {{vcd_url}}/api/network/{{network_uuid}}"

                        name="VM Network"

                        type="application/vnd.vmware.vcloud.network+xml"/>

                    <vcloud:FenceMode>bridged</vcloud:FenceMode>

                </vcloud:Configuration>

            </vcloud:NetworkConfig>

        </vcloud:NetworkConfigSection>

    </vcloud:InstantiationParams>

    <vcloud:Source

        href="https://{{vcd_url}}/api/vAppTemplate/{{vappTemplate_uuid}}"

        name="HIGIO"

        type="application/vnd.vmware.vcloud.vAppTemplate+xml"/>

</vcloud:InstantiateVAppTemplateParams>
```

<figure><img src="/files/S4tcdYHU6Sb0MNtnZ3R9" alt=""><figcaption></figcaption></figure>

**SEND request.**
{% endstep %}

{% step %}

### Step 3: Verify

On the vCD -> Data Center -> select your Virtual Data Center ->vApps -> check your vApp and VM.

{% endstep %}
{% endstepper %}


# API reconfigures VM's Disk

## <mark style="color:green;">Overview</mark>

In this manual, you will find detailed information on how to prepare information, get the VM’s disk information, and reconfigure the VM’s disk.

## <mark style="color:green;">**Procedure**</mark>

{% stepper %}
{% step %}

#### **Step 1: Prepare Information**

Log in to IAM portal -> vCD portal: collect the information

**{{vcd\_url}}**<br>

<figure><img src="/files/IGhGXJinPkqvIejYDfQL" alt=""><figcaption></figcaption></figure>

&#x20;**{{vm-uuid}}:** select VM -> take a look vm uuid on url<br>

<figure><img src="/files/aubHVqjechW77VopgpIh" alt=""><figcaption></figcaption></figure>

**{{Bearer Token}}:** Please follow the **“API token login”** documen
{% endstep %}

{% step %}

#### **Step 2: Getting VM’s Disk information**

* GET **https\://{{vcd\_url}}APIi/vApp/{{vm-uuid}}/virtualHardwareSection/disks**
* Authorization: {{Bearer Token}}
* Headers:

\- ‘Accept’: \*/\*;version=37.2

\- ‘Content-type’: application/vnd.vmware.vcloud.rasdItem+xml
{% endstep %}

{% step %}

#### **Step 3:** **Reconfig VM’s disk**

* PUT https//{{vcd\_url}}APIi/vApp/{{vm-uuid}}/virtualHardwareSection/disks
* Authorization: {{Bearer Token }}
* Headers:

\- 'Accept’: \*/\*;version=37.2

\- ‘Content-type’: application/vnd.vmware.vcloud.rasdItem+xml

* Body: *{{select raw -> copy and paste* *response body from Get VM’s disk information }}*

Ex:

```
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<RasdItemsList xmlns="http://www.vmware.com/vcloud/v1.5" xmlns:vmext="http://www.vmware.com/vcloud/extension/v1.5" xmlns:ovf="http://schemas.dmtf.org/ovf/envelope/1"
…………………………………………….
………………………………………
        <rasd:HostResource xmlns:ns10="http://www.vmware.com/vcloud/v1.5" ns10:storageProfileHref="https://iaas-hcmc02.higiocloud.vn/api/vdcStorageProfile/a7c6c2f7-3c2211e6e7b0" ns10:busType="6" ns10:busSubType="VirtualSCSI" ns10:capacity="15240" ns10:iops="4000" ns10:storageProfileOverrideVmDefault="false"></rasd:HostResource>
        <rasd:InstanceID>2000</rasd:InstanceID>
        <rasd:Limit xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
        <rasd:MappingBehavior xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
        <rasd:OtherResourceType xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
        <rasd:Parent>2</rasd:Parent>
    </Item>
</RasdItemsList>

```

<figure><img src="/files/xIApvuQ8dhgi43xlHPNM" alt=""><figcaption></figcaption></figure>

* Find word <mark style="color:red;">ns10:capacity</mark> and edit the value in ,”, it’s the VM’s disk (MB)
* SEND request.
  {% endstep %}

{% step %}

#### **Step 4: Verify**

* **Get VM’s disk information**

GET https\://{{vcd\_url}}/api/vApp/{{vm-uuid}}/virtualHardwareSection/disks

* **Check on vCD portal**

Login IAM -> vCD portal-> select VM-> Hard disk

{% endstep %}
{% endstepper %}


# API reconfigures VM's Networks

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

In this manual, you will find detailed information on how to prepare information, get VM’s network information, and reconfigure VM’s networks.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}

#### **Step 1: Prepare Information**

Login IAM portal -> vCD portal: collect the information

**{{vcd\_url}}**

<figure><img src="/files/Y7kJzy5K5HCTTlGa9ERf" alt=""><figcaption></figcaption></figure>

**{{vm-uuid}}:** select VM -> take a look vm uuid on url<br>

<figure><img src="/files/2T3sqUULPV3iCdXa1JK6" alt=""><figcaption></figcaption></figure>

**{{network\_name}}**: Select Networking -> Networks -> Copy the Network name<br>

<figure><img src="/files/xfBlpjNpWuVyXjmNyDn0" alt=""><figcaption></figcaption></figure>

**{{Bearer Token}}:** Please follow the **“API token login”** document
{% endstep %}

{% step %}
**Step 2: Get VM’s network information**

* GET https\://{{vcd\_url}}/api/vApp/{{vm-uuid}}/virtualHardwareSection/networkCards
* Authorization: {{Bearer Token}}
* Headers:

\- ‘Accept’: \*/\*;version=37.2

\- ‘Content-type’: application/vnd.vmware.vcloud.rasdItem+xml

<figure><img src="/files/guaxnTqbXVbZkFFDhOfZ" alt=""><figcaption></figcaption></figure>

* SEND request.

Copy **Response Body**
{% endstep %}

{% step %}

#### Step &#x33;**: Reconfig VM’s networks**

* PUT https//{{vcd\_url}}/api/vApp/{{vm-uuid}}/virtualHardwareSection/networkCards
* Authorization: {{Bearer Token }}
* Headers:

\- 'Accept’: \*/\*;version=37.2

\- ‘Content-type’: application/vnd.vmware.vcloud.rasdItemsList+xml; charset=ISO-8859-1

Body: *{{select raw -> copy and paste* *response body from Get VM’s networks information }}*

Ex:

```
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<RasdItemsList xmlns="http://www.vmware.com/vcloud/v1.5" xmlns:vmext="http://www.vmware.com/vcloud/extension/v1.5" xmlns:ovf="http://schemas.dmtf.org/ovf/envelope/1" xmlns:vssd="http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/CIM_VirtualSystemSettingData"
…………………………………..
………………………………….
    <Link rel="edit" href="https://iaas-hcmc02.higiocloud.vn/api/vApp/vm-6cc0d2ef-6823-421a-bed5-8bb0f92a7bca/virtualHardwareSection/networkCards" type="application/vnd.vmware.vcloud.rasdItemsList+json"/>
    <Item>
        <rasd:Address>00:50:56:02:10:2c</rasd:Address>
        <rasd:AddressOnParent>0</rasd:AddressOnParent>
        <rasd:AllocationUnits xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
        <rasd:AutomaticAllocation>true</rasd:AutomaticAllocation>
        <rasd:AutomaticDeallocation xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
        <rasd:ConfigurationName xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
        <rasd:Connection xmlns:ns10="http://www.vmware.com/vcloud/v1.5" ns10:ipAddressingMode="Manual" ns10:ipAddress="10.10.11.20" ns10:primaryNetworkConnection="true">10.10.11.0/24</rasd:Connection>
        <rasd:ConsumerVisibility xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
        …………………………………………………………………….
        <rasd:ResourceSubType>VMXNET3</rasd:ResourceSubType>
        <rasd:ResourceType>10</rasd:ResourceType>
        <rasd:VirtualQuantity xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
        <rasd:Weight xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
    </Item>
</RasdItemsList>
```

\=====================================================================

Find word :

<mark style="color:red;">ns10:ipAddressingMode</mark> and edit the value in “ ” (network mode: “DHCP”, “Pool”, “Manual”)

\+ DHCP: Please setup DHCP pool on your network -> The P Management

\+ Pool: Please setup Static IP pools on yoursetork -> IP Management

<mark style="color:red;">ns10:ipAddress</mark> and edit the value in “” (“VM ipv4 address”) – **no need if using DHCP or Pool**

<mark style="color:red;">ns10:primaryNetworkConnection</mark> and edit the value in “” (paste network name <mark style="color:green;">{{netwok\_name}}</mark> )

* SEND request.
  {% endstep %}

{% step %}

#### **Step 4: Verify**

* **Get VM’s network information.**

GET https\://{{vcd\_url}}/api/vApp/{{vm-uuid}}/virtualHardwareSection/networkCards

* **Check on the vCD portal**

Login IAM -> vCD portal-> select VM-> NICs
{% endstep %}
{% endstepper %}


# API token login

## <mark style="color:green;">**Overview**</mark>

In this manual, you will find detailed information on preparing information, creating a Token on the vCD portal, and creating a Bearer token.

## <mark style="color:green;">**Procedure**</mark>

{% stepper %}
{% step %}

#### **Step 1: Prepare Information**

\* Login IAM portal -> vCD portal: collect the information

* **{{vcd\_url}}**<br>

  <figure><img src="/files/RkuBeWBz8xXM1vckRwNJ" alt=""><figcaption></figcaption></figure>
* **{{tenant\_name}}**

*Ex: <https://iaas-hcmc02.higiocloud.vn/tenant/_**”tenant\\_name**_**”/**&#x76;dcs/dashboard>*<br>

<figure><img src="/files/5SX9fLBP7YUAR0742jB2" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2: Create Token on vCD portal**

* Login IAM portal -> vCD portal -> User preferences<br>

  <div align="left"><figure><img src="/files/1gF6Ct4XvFLPMSQJFJ85" alt=""><figcaption></figcaption></figure></div>
* API tokens -> New

<figure><img src="/files/6LcuZYPJxr4nyadGsWZk" alt=""><figcaption></figcaption></figure>

&#x20;Copy token ({{api-token-generated}})

<figure><img src="/files/kmub2NUUV15MDJ6nP91g" alt=""><figcaption></figcaption></figure>

<br>
{% endstep %}

{% step %}

#### **Step 3: Creating a Bearer token**

* POST https\://{{vcd\_url}}/oauth/tenant/{{tenant\_name}}/token
* Authorization: No Auth
* Headers:

\- 'Accept: application/json'

\- 'Content-Type: application/x-www-form-urlencoded'

* Body:

raw: 'grant\_type=refresh\_token\&refresh\_token={{api-token-generated}}'<br>

<figure><img src="/files/yXQlToZGFOYM9ezuNNTj" alt=""><figcaption></figcaption></figure>

* SEND request.

Response body: "access\_token" (Bearer token)

{% endstep %}
{% endstepper %}


# API reconfigures VM's Memory

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

In this manual, you will find detailed information on how to prepare information, get the VM’s memory information, and reconfigure the VM’s memory.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}

#### **Step 1: Prepare Information**

\* Login IAM portal -> vCD portal: collect the information

* {{vcd\_url}}<br>

  <figure><img src="/files/7ybLg02Dz3RRhsbFsqm8" alt=""><figcaption></figcaption></figure>

\- {{vm-uuid}}: select VM -> take a look vm uuid on url<br>

<figure><img src="/files/zful889AUumQwJlFkp0V" alt=""><figcaption></figcaption></figure>

-{{Bearer Token}}: Please follow **“Api token login”** document
{% endstep %}

{% step %}

#### **Step 2: Get VM’s memory information**

* GET https\://{{vcd\_url}}/api/vApp/{{vm-uuid}}/virtualHardwareSection/memory
* Authorization: {{Bearer Token}}
* Headers:

\- ‘Accept’: \*/\*;version=37.2

\- ‘Content-type’: application/vnd.vmware.vcloud.rasdItem+xml<br>

<figure><img src="/files/QJ1Av96q8i7IOBhZ7xnG" alt=""><figcaption></figcaption></figure>

* SEND request.

Copy **Response Body**
{% endstep %}

{% step %}
**Step 3: Reconfig VM’s memory**

* PUT https\://{{vcd\_url}}/api/vApp/{{vm-uuid}}/virtualHardwareSection/memory
* Authorization: {{Bearer Token }}
* Headers:

-'Accept: */*;version=37.2

-‘Content-type’: application/vnd.vmware.vcloud.rasdItem+xml&#x20;

Body: {{select raw -> copy and paste response body from Get VM’s memory information }}&#x20;

Ex:

```

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<ns4:Item xmlns:ovf="http://schemas.dmtf.org/ovf/envelope/1" xmlns:rasd="http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/CIM_ResourceAllocationSettingData" xmlns:common="http://schemas.dmtf.org/wbem/wscim/1/common" xmlns:ns4="http://www.vmware.com/vcloud/v1.5" xmlns:vssd="http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/CIM_VirtualSystemSettingData" xmlns:vmw="http://www.vmware.com/schema/ovf"
………………………………………………………….
……………………………………………………………
    <rasd:ResourceType>4</rasd:ResourceType>
    <rasdraidtualQuantity>2048</rasd:VirtualQuantity>
    <rasd:VirtualQuantityUnits xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
type="application/vnd.vmware.vcloud.rasdItem+json"/>
</ns4:Item>
```

\==============================================================================

Find line “<mark style="color:blue;">\<rasd:VirtualQuantity>2048\</rasd:VirtualQuantity></mark>” and edit the value, it’s the VM’s memory (MB).Please note that Value must be a multiple of 4 MB<br>

<figure><img src="/files/ZeCjAxrYG9DBQqljuNM9" alt=""><figcaption></figcaption></figure>

* SEND request.
  {% endstep %}

{% step %}

#### **Step 4: Verify**

* **Get VM’s memory information**

GET https\://{{vcd\_url}}/api/vApp/{{vm-uuid}}/virtualHardwareSection/memory

* **Check on vCD portal**

Login IAM -> vCD portal-> select VM-> Compute
{% endstep %}
{% endstepper %}


# API reconfigures VM's CPU

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

In this manual, you will find detailed information on how to prepare information, get the VM’s CPU information, and Reconfigure the VM’s CPU.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}

#### **Step 1: Prepare Information**

Login IAM portal -> vCD portal: collect the information

* **{{vcd\_url}}**<br>

  <figure><img src="/files/VTufGkIpJQDSiKor1oom" alt=""><figcaption></figcaption></figure>
* **{{vm-uuid}}:** select VM -> take a look vm uuid on url<br>

  <figure><img src="/files/0ym1Jgf5AAHBLwNqZLAM" alt=""><figcaption></figcaption></figure>
* **{{Bearer Token}}:** Please follow **“Api token login”** document
  {% endstep %}

{% step %}

#### **Step 2: Get VM’s CPU information**

* GET https\://{{vcd\_url}}/api/vApp/{{vm-uuid}}/virtualHardwareSection/cpu
* Authorization: {{Bearer Token }}
* Headers:

\- ‘Accept’: \*/\*;version=37.2

\- ‘Content-type’: application/vnd.vmware.vcloud.rasdItem+xml<br>

<figure><img src="/files/ZbEZG4ptSpnwKONHzS1P" alt=""><figcaption></figcaption></figure>

* SEND request.

Copy **Response Body**
{% endstep %}

{% step %}
**Step 3: Reconfigure VM’s CPU**

**Postman:**

* PUT https\://{{vcd\_url}}/api/vApp/{{vm-uuid}}/virtualHardwareSection/cpu
* Authorization: {{Bearer Token }}
* Headers:

\- 'Accept: \*/\*;version=37.2

\- ‘Content-type’: application/vnd.vmware.vcloud.rasdItem+xml

Body: *{{select raw -> copy and paste* *response body from Get VM’s CPU information }}*

Ex:

```
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<ns4:Item xmlns:ovf="http://schemas.dmtf.org/ovf/envelope/1" xmlns:rasd="http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/CIM_ResourceAllocationSettingData" xmlns:common="http://schemas.dmtf.org/wbem/wscim/1/common" xmlns:ns4="http://www.vmware.com/vcloud/v1.5"
    <rasd:Reservation>0</rasd:Reservation>
    <rasd:ResourceSubType xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
    <rasd:ResourceType>3</rasd:ResourceType>
…………………………………………………………………………..
………………………………………………………………………….
    <rasd:VirtualQuantity>8</rasd:VirtualQuantity>
    <rasd:VirtualQuantityUnits xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:nil="true"/>
    <rasd:Weight>0</rasd:Weight>
    <vmw:CoresPerSocket ovf:required="false">2</vmw:CoresPerSocket>
type="application/vnd.vmware.vcloud.rasdItem+json"/>
</ns4:Item>
```

\==============================================================================

Find line “<mark style="color:blue;">\<rasd:VirtualQuantity>8\</rasd:VirtualQuantity></mark>” and edit the number, it’s the CPU number.<br>

<figure><img src="/files/L9GozXOPJj0ZUCZIJDtJ" alt=""><figcaption></figcaption></figure>

* SEND request.
  {% endstep %}

{% step %}

#### **Step 4: Verify**

* **Get VM’s CPU information**

GET https\://{{vcd\_url}}/api/vApp/{{vm-uuid}}/virtualHardwareSection/cpu

* **Check on vCD portal**

Login IAM -> vCD portal-> select VM-> Compute
{% endstep %}
{% endstepper %}


# API power on/off VM

## <mark style="color:green;">**Overview**</mark>

In this manual, you will find detailed information on how to prepare information, get VM status, and change status VM.

## <mark style="color:green;">**Procedure**</mark>

{% stepper %}
{% step %}
**Step 1: Prepare information**

Login IAM portal -> vCD portal: collect the information

* **{{vcd\_url}}**<br>

  <figure><img src="/files/9btzlhiwlGrZ0bllOsHx" alt=""><figcaption></figcaption></figure>
* **{{vm-uuid}}:** select VM -> take a look vm uuid on url<br>

  <figure><img src="/files/es3ZV61px7F1r6apO9qR" alt=""><figcaption></figcaption></figure>
* **{{Bearer Token}}:** Please follow **“API token login”** document
  {% endstep %}

{% step %}
**Step 2: Get VM status**

* GET https\://{{vcd\_url}}/api/vApp/{{vm\_uuid}}
* Authorization: {{Bearer Token }}
* Headers:

\- ‘Accept’: \*/\*;version=37.2<br>

<figure><img src="/files/yvstfZNUrFcBSUzKIjhl" alt=""><figcaption></figcaption></figure>

* SEND request.

Check the VM status on line 3 of Response Body. If Link rel="power:powerOff", VM is Power ON else VM is Power Off.<br>

<figure><img src="/files/PcGswXXdrj3JP6MBzAqq" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3: Change the status VM**

* POST https\://{{vcd\_url}}/api/vApp/{{vm\_uuid}}/power/action/{{powerOn/powerOff}}
* Authorization: {{Bearer Token}}
* Headers:

\- ‘Accept’: \*/\*;version=37.2<br>

<figure><img src="/files/yJmAXhNIyPuYHY4sTFED" alt=""><figcaption></figcaption></figure>

* SEND request.
  {% endstep %}

{% step %}

#### **Step 4: Verify**

* **Get VM’s status information**

GET https\://{{vcd\_url}}/api/vApp/{{vm-uuid}}

* **Check on vCD portal**

Login IAM -> vCD portal-> select VM
{% endstep %}
{% endstepper %}


# 5. HI GIO KMS Service

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

**HI GIO KMS** is powered by the HashiCorp Vault solution, which is fully managed by HI GIO teams. Thus, the customer can focus on key management itself.

{% hint style="info" %}
**HashiCorp Vault** is an identity-based secrets and encryption management system. A *secret* is anything you want to control access to tightly, such as API encryption keys, passwords, and certificates. Vault provides encryption services that are gated by authentication and authorization methods. Access to secrets and other sensitive data can be securely stored and managed, tightly controlled (restricted), and auditable using Vault's UI, CLI, or HTTP API.
{% endhint %}

HI GIO KMS has two kinds of deployment models.

* Internet mode
* Private mode (Only can access from customer’s HI GIO VPC system)

<figure><img src="/files/hjgHLqgJwu9II37JpfRI" alt=""><figcaption></figcaption></figure>

&#x20;

Reference:

[![](https://developer.hashicorp.com/favicon.ico)Tutorials | Vault | HashiCorp Developer](https://developer.hashicorp.com/vault/tutorials)


# 6. Encryption Management Service

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

**VMware Cloud Director Encryption Management** is a solution that grants in-transit encryption for disk I/O and vMotion for a customer's Virtual Machine using vTPM and VM Encryption technology.

&#x20;

<figure><img src="/files/AsmB5zuLDLC5X6jvZ7ak" alt=""><figcaption></figcaption></figure>

Please refer to the **Encryption Management service** usage guide below.

## <mark style="color:green;">Procedure</mark>

{% stepper %}
{% step %}
**Step 1:** Customer login to Portal vCD
{% endstep %}

{% step %}

#### Step 2: Verify **Encryption Policy** is available

<figure><img src="/files/QEFe3nIEGGKw1DUlgcZT" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Choose the VM you want to **encrypt. Note: this VM must be powered off before encryption**

<figure><img src="/files/HiitQUl5yCILJ53WIPVo" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Step 4: Change Default Storage Policy

<div align="left"><figure><img src="/files/IVtULFTWFxgpe0W28fxa" alt="" width="363"><figcaption></figcaption></figure></div>

* VM -> General -> EDIT\
  Wait for this VM encryption process to complete (It will take time depending on the size of the VM's hard drive)
* **Optional:** Enable Security Devices – Trusted Platform Module (vTPM)

  <figure><img src="/files/ysMYipXtIK40a0SBoDVi" alt=""><figcaption></figcaption></figure>

  * Choose Security Devices -> Edit -> Enable -> SAVE

  <mark style="color:red;">**NOTED:**</mark> VM must meet the following requirements to add Trusted Platform Module:

  * &#x20;VM is powered off
  * OS is compatible with Trusted Platform Module
  * VM doesn’t have any snapshots
  * Hardware version 14 or late
  * &#x20;Boot firmware is EFI
    {% endstep %}

{% step %}
**Step 5:** Powered on the encrypted VM:

* VM configuration files, including swap files, core dump files, and more, are encrypted.
* All Hard disks are encrypted.

<figure><img src="/files/9YSaoLejRlfr3yHDTm22" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/wrVdgPpFhLYUNadYQ29y" alt=""><figcaption></figcaption></figure>

* vTPM is present (Optional: if it was enabled in step 5)
  {% endstep %}
  {% endstepper %}


# HI GIO S3 STORAGE

## <mark style="color:green;">Information</mark>

This short manual guide is designed to help HI GIO users navigate the features and functionalities of our **cloud storage** service. Whether you need to store large files, collaborate with team members, or ensure data redundancy, **HI GIO Cloud S3 Storage** provides a seamless experience tailored to your needs.

## <mark style="color:green;">**Overview**</mark>

{% hint style="info" %}
**HI GIO S3 Storage - An unlimited Backup Storage solution for businesses**

<img src="/files/NjkQDylSWYEPIGEgSLZZ" alt="" data-size="original">

A comprehensive solution built on the Object Storage platform flexibly connected via the S3 protocol. Meets security standards with fast data access, cost optimization, and high availability from many environments. This solution suits Data Lake, Cloud-native Application Data, Data Archiving, Backup and Recovery.
{% endhint %}

## <mark style="color:green;">**Guidelines**</mark>

* [Login to HI GIO S3 Storage Portal](https://docs.higiocloud.vn/)
* [How to get the S3 Key](https://docs.higiocloud.vn/)
* [Mount HI GIO S3 Storage into Windows](/hi-gio-s3-storage/mount-hi-gio-s3-storage-into-windows)
* [Bucket Management](/hi-gio-s3-storage/bucket-management)
* [Management File, Folder](/hi-gio-s3-storage/management-file-folder)
* [Connect S3 Services with Veeam Backup](https://docs.higiocloud.vn/)
* [Backup DATA from NAS to HI GIO S3 Service](/hi-gio-s3-storage/backup-data-from-nas-to-hi-gio-s3-service)
* [S3 Data Encryption – SSE-C and SSE-S3](/hi-gio-s3-storage/s3-data-encryption-sse-c-and-sse-s3)


# Login to HI GIO S3 Storage Portal

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Refer to this[ **LINK**](/management/1.-iam-portal/activate-hi-gio-iam-account) to learn how to activate your account via Email. After successfully activating your account, you can log in to the HI GIO S3 Portal.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Access the link [https://iam.higiocloud.vn/tenant/ ](https://iam.higiocloud.vn/tenant/)and fill in your tenant (organization) information as we provide

<figure><img src="/files/LgZjsRslPunCiJY0Zag3" alt=""><figcaption></figcaption></figure>

{% endstep %}

{% step %}
**Step 2:** Log in to the account provided by email

<figure><img src="/files/v2eH4nNmBkot6SO1E0U4" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Click on the top-right to access the S3 Portal

<figure><img src="/files/h9bJ2L3vObWBKRu6xbLy" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** After logging in to the S3 Portal, you will be asked to create a new PIN to use the S3 service.\
This PIN Code is used for security authentication when you operate to view the S3 Key (Access key, Secret key) or Delete the Bucket.

<figure><img src="/files/XLUidQ8gOs6VvcWpYoek" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

<br>


# How to get the S3 Key

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log in to HI GIO S3 Portal

{% endstep %}

{% step %}
**Step 2:** Choose the “**Security**” tab and get the S3 Key

<figure><img src="/files/tnByk7aW4GbJftlYVfQX" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Enter the “**Pin code**” you created from the beginning “[**LINK**](https://higio-support.atlassian.net/wiki/pages/createpage.action?spaceKey=v2\&title=Login%20to%20S3%20Portal\&linkCreation=true\&fromPageId=455704666)“ to get the S3 Key.

<figure><img src="/files/wm8vctW8TBtmLk7X0vph" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Save the Key information to add the HI GIO S3

<figure><img src="/files/KU0x0m2xpRxALT12FnEZ" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Mount HI GIO S3 Storage into Windows

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Mounting a bucket to a local drive enables the creation of a virtual drive directly on the computer, allowing users to manage their cloud storage data seamlessly without needing additional tools or portal access.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Download the RClone tool at this [“Link”](https://rclone.org/downloads/) and extract the file after download
{% endstep %}

{% step %}
**Step 2:** Run the RClone tool by **Windows PowerShell**

1. Example: the path of the folder which stores RClone tool **“.\Downloads\rclone\”**
2. Open Window PowerShell and run this command “ **.\Downloads\rclone\rclone.exe help** “ to check RClone tool is working on your Server/PC

<figure><img src="/files/AvnONlUnJABjyZFvVLAy" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Configuration HI GIO S3 storage connect with RClone

* Create the connection configuration file with this command

```
.\Downloads\rclone\rclone.exe config create Higio s3 env_auth false access_key_id xxxxxxxxxxxxxx secret_access_key xxxxxxxxxxxxxxxxxxx region default endpoint https://xxx.xxx.xx
```

\*\* Note: “ `.\Downloads\rclone\rclone.exe`" is the folder path store the RClone tool. Security Key get it in [**“HERE”**](/hi-gio-s3-storage/how-to-get-the-s3-key)

<figure><img src="/files/pUEOiyQSbbViPdqcSA4p" alt=""><figcaption></figcaption></figure>

* Verify the connection to HI GIO S3 Storage by performing operations such as listing buckets and listing objects.
* `"Listing the bucket information"`

```
.\Downloads\rclone\rclone.exe lsf Higio:
```

* `"Listing objects inside the bucket"`

```
.\Downloads\rclone\rclone.exe lsf Higio:examplebucket1
```

<figure><img src="/files/BA0Y9JhS4hnAu0uEB1Mc" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Mount a bucket as a local drive on your computer to enable direct access and management of cloud storage data.

* To mount a bucket as a drive on your computer, ensure that WinFsp is installed. [“Link Download”](https://winfsp.dev/rel/)
* Setup WinFSP → Click Next until Finish

<figure><img src="/files/EDxQ5zuQGTAxkAEW0k4z" alt=""><figcaption></figcaption></figure>

* After installing WinFSP app, run the command below to mount Bucket

```
.\Downloads\rclone\rclone.exe mount Higio:examplebucket1 S:\ --vfs-cache-mode full
```

<figure><img src="/files/Sm5PHCjoDvCgpfYQxhn0" alt=""><figcaption></figcaption></figure>

* Verify if the mount was successful.

<figure><img src="/files/JkpIZkdwSOBQOrgO3FP4" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Set up the configuration to automatically mount the bucket on system reboot.

1. Open “Run,” then type “**shell:startup**”
2. Create the new file withthe name “**mounts3.cmd**” and copy this code below to that file

```
"C:\Users\Administrator".\Downloads\rclone\rclone.exe mount Higio:examblebucket1 S:\ --vfs-cache-mode full
```

<figure><img src="/files/LKGjdaJViIizDW0OU9vM" alt=""><figcaption></figcaption></figure>

3. Save the file, then reboot the Server to test.
   {% endstep %}
   {% endstepper %}


# Bucket Management

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

The Bucket Management page displays information about your Buckets, including name, size, public and private modes, and operations of that Bucket.

* Rules Bucket names must follow domain name constraints.
  * Bucket names must be unique.
  * Bucket names cannot be formatted as IP addresses
  * Bucket names can be 3 to 63 characters long.
  * Bucket names cannot contain uppercase characters or underscores.
  * Bucket names must start with a lowercase letter or number.
  * Bucket names must be a series of one or more labels.
* The following example bucket names are valid and follow the recommended naming guidelines for general-purpose buckets:
  * docexamplebucket1
  * log-delivery-march-2020
  * my-hosted-content
* The following example bucket names are valid but are not recommended for uses other than static website hosting:
  * [docexamplewebsite.com](http://docexamplewebsite.com/)
  * [www.docexamplewebsite.co](http://www.docexamplewebsite.co/)m
  * my.example.s3.bucket
* The following example bucket names are invalid:
  * doc\_example\_bucket (contains an underscore)
  * DocExampleBucket (contains uppercase letters)
  * doc-example-bucket- (ends with a hyphen)


# How to create the new Bucket

## <mark style="color:green;">**Overview**</mark>  <a href="#overview" id="overview"></a>

As well as using pre-configured storage classes, you can set up your own S3 Buckets from scratch, configuring access policies, versioning, and lifecycle rules to suit your specific storage needs.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Click on “Create Bucket”

<figure><img src="/files/Bpslsd7p4m2AVFhgyEco" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Fill in name of “Bucket”. Refer the rule for define the Name for Bucket in this [“**Link**”](/hi-gio-s3-storage/bucket-management)

<figure><img src="/files/sRHNSEE6MqZOGzjbTlFL" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step3:** Enable Object Lock (If needed)

* Object Lock is a feature that allows you to store objects using the write-once, read-many (WORM) model. ObjectLock can help prevent objects from being deleted or overwritten for a fixed period or indefinitely.
* The Object Lock feature is only used when creating a new Bucket. After selecting “Enable object lock” for a Bucket, all files/folders created/uploaded in that Bucket will be automatically set to the mode you selected in the next step.

<figure><img src="/files/l4qAUUp0EKyEjIP6YxYy" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Choose "**Governance mode**" or "**Compliance mode**" or “**NONE**“

* **Governance mode**: Use Governance mode if you want to protect objects from deletion by most users for a pre-set retention period but also want some users with special permissions to have the flexibility to change retention settings or delete objects. Users with the s3:BypassGovernance Retention permission can override or delete retention settings in governance mode.

<figure><img src="/files/kbTyFuAF5RuDYuPhEdX1" alt=""><figcaption></figcaption></figure>

* **Compliance mode**: Use Compliance mode if you have compliance data retention requirements. You should only use Compliance mode if you do not want any users to be able to delete objects within the preset retention period.

<figure><img src="/files/TEvJWZ0Y0nWssulPTHBG" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}

* After choosing 1 of 2 modes to lock the object, you have to choose the desired number of days in the "Retention period" section.\
  *Retention period: 90 days means that the Bucket and the objects in that Bucket are locked in the mode you choose for 90 days from the date the Bucket was created.*
* ***Retention period**:* Specify a fixed period of time during which the object is locked. During this period, your object is protected by WORM and cannot be overwritten or deleted. You can apply a retention period in days with a minimum of 1 day and no maximum.
  {% endhint %}

<figure><img src="/files/L4P8S0rsRkVHIkFTjxqF" alt=""><figcaption></figcaption></figure>

**NONE mode**: Use Veeam Backup mode to protect the backup file “immutable mode of Veeam”.
{% endstep %}
{% endstepper %}


# Setup Public or Private ACL for Bucket

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

**ACL (Access Control List)** is a mechanism that determines who has access to your buckets and objects (files/folders). To set up a Public ACL, right-click on the Bucket and select **"Public"** or select **"Share Link"** to set it up.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Right-click on the Bucket and choose “**Public**“

<figure><img src="/files/EbJLSnkkM8OInEY8hjbF" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2**: Once you have set up Public for a Bucket, the screen will display as “Public” when accessing the link of that Bucket.

<figure><img src="/files/HjulUszaOqViRP3oZnN9" alt=""><figcaption></figcaption></figure>

{% endstep %}
{% endstepper %}


# Versioning

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

**S3 Versioning** allows you to keep multiple versions of an object in the same bucket, protecting against accidental deletions and enabling easy recovery of previous file versions when needed.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Right-click to Bucket, choose “Versions” to enable file versioning for a Bucket, and view all versions of files in that Bucket.

<figure><img src="/files/x0EeRSsHiCEhGHbVWZ2l" alt=""><figcaption></figcaption></figure>

{% endstep %}

{% step %}
**Step 2:** previous versions of files, ensuring data recovery and protection from accidental deletions or overwrites.

<figure><img src="/files/bpHMdNUXsO8bvw5hbZHd" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Lifecycle Rule

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

**Lifecycle rules** for files/folders (Objects) must be clearly defined according to usage needs.

*For example:*

* *You need to upload a large amount of data and want these files to only exist for 90 days.*
* *Enable versioning for the Bucket, but because the number of file versions is large, it takes up much storage space.*
* *Multipart files are not fully uploaded, and parts of the files are still on the system, leading to a waste of storage space.*

Managing Lifecycle rules will help you solve the above problems. In a Bucket, you can create multiple Lifecycle rules to apply only to folders or all files and folders, depending on your needs.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Right-click into Bucket and choose **Lifecycle rules**

<figure><img src="/files/3Ji3fBuKl2bAhpodW5jq" alt=""><figcaption></figcaption></figure>

{% endstep %}

{% step %}
**Step 2:** Click on “**New Rule**” to create the Rules

<figure><img src="/files/dNZNeVBBKnv11bJSPZ08" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Set up the rules you want to apply to your bucket and set the days you need to apply. After choosing the Rules, click “**Add New Rule**”.

* **Permanently delete file**: It will remove all versions of the object from the bucket, including any archived versions, making it unrecoverable once deleted.
* **Permanently deleting previous versions:** It will remove older file versions from the bucket, ensuring they cannot be recovered while the current version remains intact.

{% hint style="danger" %}
After xx days you set, S3 will delete all files created 60 days ago. It does not take into account the frequency of usage for these files.
{% endhint %}

<figure><img src="/files/aFtNpqi38FUVYDBbAOlz" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Click “Save” to apply the Rule to Bucket.

<figure><img src="/files/i8VmmYBhOTrw7cTUaR4E" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Bucket Policy

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

An **HI GIO S3 Bucket Policy** is a JSON-based resource policy that manages access permissions to S3 buckets. It specifies who can access the bucket, the actions allowed, and the conditions for access.

You can prefer the example S3 bucket policy in “[**HERE**](https://docs.aws.amazon.com/AmazonS3/latest/userguide/example-bucket-policies.html)**.**”

## <mark style="color:green;">**Procedure**</mark>  <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Right-click on the Bucket and select 'Bucket Policy.' Customize the Bucket Policy by Amazon S3 standards. For additional examples and further guidance, refer to the official documentation.

<figure><img src="/files/VyHZ7IzyjGyNvlmSTSxA" alt=""><figcaption></figcaption></figure>

{% endstep %}

{% step %}
Step 2: You can modify the Bucket Policy as needed in this popup. Once you have made the necessary changes, click **"Update Policy"** to apply the updates.

<figure><img src="/files/FDRQArqR4ePVC2eLlJNY" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Management File, Folder

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

HI GIO S3 provides flexible file and folder management, allowing you to organize data hierarchically. You can upload, move, rename, or delete files and folders while applying access controls and lifecycle rules.

## <mark style="color:green;">**Guidelines**</mark> <a href="#guidelines" id="guidelines"></a>

* [Create the Folder](/hi-gio-s3-storage/management-file-folder/create-the-folder)
* [Upload Folder/File](/hi-gio-s3-storage/management-file-folder/upload-folder-file)
* [Download Folder/Files](/hi-gio-s3-storage/management-file-folder/download-folder-files)
* [Get the link Download of Files](/hi-gio-s3-storage/management-file-folder/get-the-link-download-of-files)
* [File Versioning](/hi-gio-s3-storage/management-file-folder/file-versioning)


# Create the Folder

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Creating a folder in S3 helps organize your data. Specify a folder name during file upload or manually create a new folder to group and manage related objects efficiently.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Double-click on Bucket. Then select "**New**" -> “**New folder**”

<figure><img src="/files/mSBWW4iJmz8tegJ26NNP" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Enter the Folder name and click “Create the Folder.”

<figure><img src="/files/4GS0LekDofKmXa5HcMio" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

<br>


# Upload Folder/File

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Uploading files or folders to S3 is simple. You can drag and drop or select items to upload, organizing them into folders while maintaining scalable, secure storage in the cloud.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

Click “**New**,” then choose “Upload Folder” or “Upload file(s).” You can also drag the File/Folder here.

<figure><img src="/files/0ZP4sBGqLkISpeV1l7WF" alt=""><figcaption></figcaption></figure>


# Download Folder/Files

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Downloading files or folders from S3 is straightforward. Select the desired objects, and with a click, they will be transferred to your local storage securely and efficiently.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

Right-click on the Files you want to download, then choose “**Download**.”

<figure><img src="/files/cB74KHJgbgs43BN6Iiqw" alt=""><figcaption></figcaption></figure>

&#x20;


# Get the link Download of Files

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

To download files from HI GIO S3, generate a pre-signed URL. This link provides temporary access, allowing users to download files securely without HI GIO S3 credentials.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Right-click on the File you need to get a link and choose “**Public Sharing.**”

<figure><img src="/files/LzfFmvNjcw7EF6FMYxe9" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** In HI GIO S3, you can set the sharing mode of your objects to either **Private** or **Public**.

* **Private Mode**: All HI GIO S3 buckets and objects are private by default. Only the bucket owner has access, ensuring data security.
* **Get link download** option: This URL grants temporary access to the private file, enabling users to download it without needing HI GIO S3 credentials in 60 minutes.

<figure><img src="/files/y1HW2SAYYA5g3N6R4mtF" alt=""><figcaption></figcaption></figure>

* **Public Mode**: If you want to share objects publicly, you can configure the bucket or object permissions to allow public access. This enables anyone with the link to view or download the files. Using this mode cautiously is essential to prevent unauthorized access to sensitive data.

<figure><img src="/files/oQzYnyW5DohQfqqWGxNA" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# File Versioning

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

HI GIO S3 file versioning allows you to keep multiple versions of an object, protecting against accidental deletions and enabling easy recovery of previous file states.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Right-click on the file and choose “**Version**“ to check the file versioning

<figure><img src="/files/SFgjUxypEZchaQl4z3Xg" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Choose the “**Version**” you want to download

<figure><img src="/files/whuvaCdvlXpII5GSvE6X" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
You must enable versioning for the file Bucket to save file versions.
{% endhint %}
{% endstep %}
{% endstepper %}


# Connect S3 Services with Veeam Backup

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Integrating S3 with Veeam Backup allows seamless data backup and recovery in S3 buckets, ensuring data protection, compliance, and efficient cloud storage management.


# Connect HI GIO S3 with Veeam Backup

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Integrating S3 with Veeam Backup allows seamless data backup and recovery in S3 buckets, ensuring data protection, compliance, and efficient cloud storage management.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log in to HI GIO S3 Portal & Choose the “**Security**” tab and get the S3 Key

<figure><img src="/files/OBtj7MMOGtaWFpnSpcaa" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Enter “**Pin code**” you created from beginning “[**LINK**](https://higio-support.atlassian.net/wiki/pages/createpage.action?spaceKey=v2\&title=Login%20to%20S3%20Portal\&linkCreation=true\&fromPageId=455705158)“ to get the S3 Key

<figure><img src="/files/7OsjxEdrZ2ew4RTNQxsj" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Save the Key information to add the HI GIO S3 to Veeam

<figure><img src="/files/7sQUGXi5ZRmMyJyni9vf" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Open the **Veeam Backup & Replication Console** on your Server

* Then choose **Backup Infrastructure**, then choose **Backup Repositories,** Right Click and choose **Add Backup Repository**

<figure><img src="/files/vxO68UT7N4lRJ59HwR2E" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Choose **Object Storage**

<div align="left"><figure><img src="/files/IKIgeb1mAm9Wav8mAsNr" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
**Step 6:** Choose **S3 Compatible**

<div align="left"><figure><img src="/files/3NG1nbQUsEtsBWjdHLuA" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
**Step 7:** Fill in the “**Name**” for the Repository

<figure><img src="/files/3VpczNWIPkqZAK3kjwyw" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 8:** Fill in the “**Service Point**” information you got on at **Step 3**, then Click “**Add**” to add the Credential.

<figure><img src="/files/dznQ3iLEgLqWGpuXDOfa" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 9:** Click “**Browse**” to choose the Bucket

<figure><img src="/files/C276zrLyHJDacL0IwfNc" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 10:** Click “**Browse**” at “*Folder”* to choose the “**Folder**.” in Bucket

<figure><img src="/files/TEjitwZd6BJoFRQWsvDS" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 11:** Click “**Next**” and “**Apply**” until completed

<figure><img src="/files/hrvgDzt4MMe3oS9nw5Hm" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/u2Dk8yfsPItXELYloMuo" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 12:** **Create a new Job Backup** and choose Backup Repository is HI GIO S3 Storage

* &#x20;*If you want to achieve immutable with S3 Repositories, please enable Object Lock and Versioning on the S3 portal to secure your data.* [*LINK*](https://higio-support.atlassian.net/wiki/x/NwAIFQ)
* *Using S3 repositories still has some limitations. Please refer to this* [*LINK*](https://helpcenter.veeam.com/docs/backup/vsphere/object_storage_repository_cal.html?ver=120)*.*

<figure><img src="/files/9lJUkko0Xx1OWQuYdtcf" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

&#x20;

&#x20;


# Backup DATA from NAS to HI GIO S3 Service

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Backing data from NAS to HI GIO S3 Service using NAS ensures secure, scalable cloud storage. Integrating NAS with HI GIO S3 allows you to automate backups, protect files, and enable quick recovery while managing data efficiently through an easy-to-use interface.\
***We support Synology, Qnap, and other NAS brands that can support S3-compatible.***


# Backup Data from Synology NAS with ClouSync

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Backing data from Synology NAS to HI GIO S3 using CloudSync ensures secure, automated synchronization between your local NAS and S3 cloud storage. It enables continuous data protection, easy file recovery, and efficient storage management.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step1:** Connect to your NAS via Web Browser and install CloudSync

<figure><img src="/files/ZCtncMkN2lMr8AwNSIDQ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Access the **“Package Center”** and then install **“CloudSync”**

<figure><img src="/files/aai12wi1zsvudEj8lovl" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Setup and configure Cloud Sync connect to HI GIO S3 Storage

<figure><img src="/files/jTCN3TaAz28ZyQkVcypw" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Fill in the information from HI GIO S3 Portal

* S3 Server: Choose Custom Server URL
* Server Address, Access Key, Secret Key get it in “[**HERE**](https://higio-support.atlassian.net/wiki/spaces/v2/pages/455704666)”

<figure><img src="/files/ZYYhG9BlUoBSSzcGJDwP" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Setup Backup type

We have 3 ways to take Backup to HI GIO S3 Storage

* 2-way sync (Upload/Download): **Bidirectional**
* 1-way sync (Upload only): Upload local Change only
* 1-way sync (Download only): Download Remote change only

<figure><img src="/files/O1AtuNNi3DQ0EHN7qOej" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Step 6: Scheduling the Backup time

* Depending on the business backup plan, you can choose 2-way synchronization or 1-way synchronization (Upload Only) or 1-way synchronization (Download Only)
* To expand the storage space for the NAS device, we recommend you use the synchronization type (Upload Only). When deleting data on the NAS, the data on the Cloud will remain.
*

```
<figure><img src="/files/29p3P5LHV6bEZDzczmk9" alt=""><figcaption></figcaption></figure>
```

{% endstep %}
{% endstepper %}


# Backup Data from Synology NAS with Hyper Backup

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Backing data from NAS to S3 with Hyper Backup provides secure, scheduled backups, versioning, and data compression. It ensures efficient storage use, easy restoration, and long-term data protection in the cloud.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Install Hyper Backup on NAS via Package Center

<figure><img src="/files/ZDFNo6c4kevUqYPcL4Co" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** After Install and Open, Create the **“DATA Backup Task”** on Hyper Backup

<figure><img src="/files/QElhlDi8nWDhKlSTnotv" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Choose **“S3 Storage”**

<figure><img src="/files/IktDRGZzQPWW7w6s8pz1" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Fill in the information from HI GIO S3 Portal

* S3 Server: Choose Custom Server URL
* Server Address, Access Key, Secret Key get it in [“**HERE**”](/hi-gio-s3-storage/how-to-get-the-s3-key)

<figure><img src="/files/ftLwzdJyJquv9o2GBh52" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Choose [**Folder** ](#user-content-fn-1)[^1]that needs to be backup then click **Next**

<figure><img src="/files/Cf7cW2Sznw3Du1BHVmKu" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 6:** Choose the application on NAS needs to Backup

<figure><img src="/files/UoJGPoDWJdW2MRvGXBCK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 7:** Pick the time for Run Backup Task

<figure><img src="/files/NNMhSYzJLxhhNynJr1Dc" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Step 8: Complete setup Backup Task

<figure><img src="/files/vm3vH4HvZCmU9hALXDD4" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

[^1]:


# S3 Data Encryption – SSE-C and SSE-S3

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

* With the increasing security threats and stricter legal requirements, it is essential to consistently implement strong measures to secure data transit. This includes data not only in transit but also **at rest.**
* Protecting data stored on physical devices or in the cloud is crucial to any organization's IT security strategy. In this context, there are two main approaches to encrypting this data: **client-side encryption (CSE)** and **server-side encryption (SSE).**

|                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| :-------------------------------------------------------------: | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------: |
| <ul><li><strong>Client-side encryption (CSE)</strong></li></ul> |                                                                                                                                                                                                                                                                                                                  Allows customers to encrypt their data on their devices before sending it to the Fstorage server for storage. This ensures that the data remains encrypted throughout its entire lifecycle, providing a high level of security because the customer manages the encryption keys, which are never shared with Fstorage or any third parties. This approach requires customers to manage their keys carefully, but it is an ideal solution for those needing complete data security control.                                                                                                                                                                                                                                                                                                                  |
| <ul><li><strong>Server-side encryption (SSE)</strong></li></ul> | <p>Provides an alternative solution where data is encrypted when it reaches the Fstorage server. This is Fstorage’s responsibility, significantly reducing the security management burden on customers. There are two methods of server-side encryption:</p><ul><li><strong>SSE-C - Server-Side Encryption with Customer Keys</strong>: Customers can provide and manage their own encryption keys, giving them full control over data security. This option is particularly suitable for organizations with specific compliance and data security needs, as it allows exclusive management of encryption keys.</li><li><strong>SSE-S3 - Server-Side Encryption with HI GIO S3 Cloud-Managed Keys</strong> (in development): This simplifies the encryption process by using keys managed by Fstorage. This method is ideal for customers who want a robust encryption solution without the complexities of key management. It integrates the use of KMS (Key Management Service).</li></ul><p>HI GIO S3 Storage does not store your keys. If the key is lost, all data will be lost, and there is no way to recover it.</p> |

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

Using **server-side encryption (SSE)** with customer-provided encryption keys (**SSE-C - Server-Side Encryption with Customer Keys**) allows you to specify your encryption keys.

* When you download an object, HI GIO S3 Storage uses the encryption key provided by the customer to apply AES-256 encryption to the data.
* While checking an Object, the client must provide the same encryption key as part of its request. Firstly, HI GIO S3 will check that the client’s encryption key matches, then decrypt the Object before returning the data to you.

When using SSE-C, you must provide encryption key information using the following request headers:

<table><thead><tr><th valign="middle">Name</th><th>Description</th></tr></thead><tbody><tr><td valign="middle">--sse​-customer-algorithm</td><td>Use this header to specify the encryption algorithm. The header value must be AES256.</td></tr><tr><td valign="middle">--sse-customer-key</td><td>Use this header to provide a 256-bit, base64-encoded encryption key for HI GIO S3 to encrypt and decrypt data</td></tr><tr><td valign="middle"><p>--sse​-customer-key-md5</p><p><em><mark style="color:blue;">(Optional)</mark></em></p></td><td>Use this header to provide a base64-encoded 128-bit MD5 digest of the encryption key per RFC 1321. S3 uses this header to check the integrity of the message to ensure that the encryption key was transmitted without error.</td></tr></tbody></table>


# BACK-UP AS A SERVICE

## <mark style="color:green;">**Introduction**</mark>

This short manual guide is designed to help HI GIO users understand the features and benefits of our **Backup as a Service** and provide step-by-step instructions for setting up and managing your backups. Whether a small business or a large enterprise, our BaaS solution is tailored to meet your unique needs, ensuring your data is protected against loss, corruption, or unforeseen disasters.<br>

## <mark style="color:green;">**Overview**</mark>

{% hint style="info" %}
We provide **BaaS** for all enterprises who need to protect their data in cloud environments, on-premises virtualization environments, and physical servers with a comprehensive backup solution. This solution can back up multiple platforms such as Centos, RedHat, Ubuntu, Windows, etc.
{% endhint %}

## <mark style="color:green;">**Guidelines**</mark>

|                                                                                                                                                                                                                                                                                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <img src="/files/J0WmhaVelSFJR2fqXx2n" alt="" data-size="original">                                                                                                                                                                                                                                                                                             | <img src="/files/a1pUi3myYymnVUHKnj7j" alt="" data-size="original">                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | <img src="/files/ygQEmnK0Ow6y1T441cxK" alt="" data-size="original">                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p>We offer a user-friendly & cost-effective online Data Backup & Recovery solution ensuring safeguarding <strong>files, folders</strong>, etc.</p><ul><li>Utilizing Veeam Portal</li><li>Applying on Gen.1, Gen.2 and on-premises environment</li><li>Tailoring a secure & efficient storage, disaster recovery, and backup service to business need</li></ul> | <p>We offer a high-speed Backup & Recovery solution with <strong>VM servers</strong> in a single portal, exclusively available for <strong>HI GIO Gen.2.</strong></p><ul><li>Allowing tenants to backup & restore single VMs and vApps.</li><li>Facilitating handy self-service restoration within a single portal using vCloud Director (vCD).</li><li>Swiftly restore diverse workloads as VMs by instant recovery; aid in migration or quickly recovering with minimal impact; improve RTO and minimize disruption to mere minutes.</li></ul> | <p>Our current Backup as a Service (BaaS) for Microsoft 365 solution harnesses Veeam’s proficiency and capabilities in backup, recovery, and data management to deliver a simple and complete way to eliminate the risk of losing access and control over your Office 365 data.</p><p><strong>Microsoft 365</strong> (formerly Office 365) provides robust services, but a comprehensive backup of your data is not included in a standard Microsoft 365 license.</p> |


# 1. HI GIO BaaS

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

{% hint style="info" %}
![](/files/76eNJOSpElFJfLVkGEyM)

Online backup service, also known as cloud backup or backup as a service (BaaS), is a method of offsite data storage in which a service vendor regularly backs up files, folders, or the entire contents of a hard drive to a remote secure cloud-based data repository over a network connection.

* **Portal:**

**HCM site:** <https://portal-hcmc-backup.higio.net/>

**HN site:** <https://portal-hni-backup.higio.net/>

* **Cloud Gateway:**

**HCM site:** [backup-hcmc.higio.net](http://backup-hcmc.higio.net/) (IP address 118.68.171.248 and 118.68.171.233)

**HN site:** [backup-hni.higio.net](http://backup-hni.higio.net/) (IP address 1.55.215.248 and 1.55.215.250)
{% endhint %}

## <mark style="color:green;">Procedure</mark> <a href="#guidelines" id="guidelines"></a>

{% stepper %}
{% step %}
**Step 1:** Check and prepare your machine to match the requirements from [BaaS Support Matrix](/back-up-as-a-service/1.-hi-gio-baas/baas-support-matrix):
{% endstep %}

{% step %}
**Step 2:** Open firewall outbound to ***Cloud Gateway IP*** with ports 6180 and 53:

<figure><img src="/files/xmtWzHKUY11G5Eg6Qusw" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Access the BaaS portal, download and install the Agent following OS types:

For [Linux ](/back-up-as-a-service/1.-hi-gio-baas/install-veeam-agent-for-linux)Server.

For [Windows](/back-up-as-a-service/1.-hi-gio-baas/install-veeam-agent-for-windows) Server.

* **Manage backup** (After installation is completed, you can manage the backup job and machine via the BaaS portal or via the Veeam agent console).
  * Create a backup job:
    * Via agent console:

      * [Linux](/back-up-as-a-service/1.-hi-gio-baas/create-backup-job-on-linux-os-via-veeam-agent-console)
      * [Windows](/back-up-as-a-service/1.-hi-gio-baas/create-backup-job-on-windows-os-via-veeam-agent-console)

      Via portal:

      * [Linux](/back-up-as-a-service/1.-hi-gio-baas/create-backup-job-for-linux-via-portal)
      * [Windows](/back-up-as-a-service/1.-hi-gio-baas/create-backup-job-for-windows-via-portal)

      [Active alarm](/back-up-as-a-service/1.-hi-gio-baas/how-to-configure-receive-alarm-from-baas) for a backup job
* **Restore process:** Restore the machine after disaster, system error, or with Veeam media:
  * [Linux](/back-up-as-a-service/1.-hi-gio-baas/restore-linux-vm-on-higio-cloud-via-media-file-iso-file)
  * [Windows](/back-up-as-a-service/1.-hi-gio-baas/restore-windows-on-physical-server-by-veeam-recovery-media)

Please refer to the HI GIO BaaS guide in the list below.

* [BaaS Support Matrix](/back-up-as-a-service/1.-hi-gio-baas/baas-support-matrix)
* [Install Veeam Agent for Linux](/back-up-as-a-service/1.-hi-gio-baas/install-veeam-agent-for-linux)
* [Install Veeam Agent for Windows](/back-up-as-a-service/1.-hi-gio-baas/install-veeam-agent-for-windows)
* [Update Veeam Service Provider Console Management Agent v.7 & Backup Agent v.6](/back-up-as-a-service/1.-hi-gio-baas/update-veeam-service-provider-console-management-agent-v.9-and-backup-agent-v.6.3)
* [Create backup job on Linux OS via Veeam agent console](/back-up-as-a-service/1.-hi-gio-baas/create-backup-job-on-linux-os-via-veeam-agent-console)
* [Create backup job on Windows OS via Veeam agent console](/back-up-as-a-service/1.-hi-gio-baas/create-backup-job-on-windows-os-via-veeam-agent-console)
* [Create backup job for Linux via Portal](/back-up-as-a-service/1.-hi-gio-baas/create-backup-job-for-linux-via-portal)
* [Create backup job for Windows via Portal](/back-up-as-a-service/1.-hi-gio-baas/create-backup-job-for-windows-via-portal)
* [How to configure receive Alarm from BaaS](/back-up-as-a-service/1.-hi-gio-baas/how-to-configure-receive-alarm-from-baas)
* [Workaround](/back-up-as-a-service/1.-hi-gio-baas/workaround)<br>
  {% endstep %}
  {% endstepper %}


# BaaS Support Matrix

## <mark style="color:green;">Overview</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

This is a document for which the agent supported:

* Management (MGMT) Agent Compatibility
* Management Agent OS and Infrastructure support
* Backup Agent Compatibility
* Backup Agent OS and Infrastructure support
* Documentation References

***

## <mark style="color:green;">Management (MGMT) Agent Compatibility</mark> <a href="#id-2.-management-mgmt-agent-compatibility" id="id-2.-management-mgmt-agent-compatibility"></a>

| Version                   | Supported                  |
| ------------------------- | -------------------------- |
| MGMT Agent v8.1 and below |                            |
| MGMT Agent v9             | **x** *(will auto-update)* |
| MGMT Agent v9.1           | **x**                      |

## <mark style="color:green;">Management Agent OS and Infrastructure support</mark> <a href="#id-3.-management-agent-os-and-infrastructure-support" id="id-3.-management-agent-os-and-infrastructure-support"></a>

### <mark style="color:green;">1.</mark> <mark style="color:green;">Management Agent v9</mark>

| Windows                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Linux                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p></p><p>64-bit versions of the following operating systems are supported except Server Core installations for server OS:</p><ul><li>Microsoft Windows Server 2025</li><li>Microsoft Windows Server 2022</li><li>Microsoft Windows Server 2019</li><li>Microsoft Windows Server 2016</li><li>Microsoft Windows Server 2012 R2</li><li>Microsoft Windows Server 2012</li><li>Microsoft Windows 11</li><li>Microsoft Windows 10 (starting from version 1909)</li><li>Microsoft Windows 10 LTSC versions (1607, 1809)</li></ul> | <p></p><p>Linux kernel versions 2.6.32 – 6.10 are supported if you use kernels supplied by your distribution.</p><p>Only 64-bit versions of the following operating systems are supported:</p><ul><li>Rocky Linux 8.10, 9.3 – 9.6 and 10.0</li><li>AlmaLinux 8.10, 9.3 – 9.6 and 10.0</li><li>Debian 10.13 – 12.11</li><li>Ubuntu 16.04, 18.04, 20.04, 22.04, 22.10, 23.04, 23.10, 24.04, 24.10 and 25.04</li><li>RHEL 6.4 – 9.6 and 10.0</li><li>CentOS 7</li><li>Oracle Linux 6 – 9.6 and 10.0 (RHCK)</li><li>Oracle Linux 6 (starting from UEK R2) – Oracle Linux 8 (up to UEK R6)</li><li>Oracle Linux 8 (UEK R7) – for information on installing Veeam Agent, <a href="https://www.veeam.com/kb4394">see this Veeam KB article</a></li><li>Oracle Linux 9 (UEK R8) – for information on installing Veeam Agent on Oracle Linux 9 with UEK R8, <a href="https://www.veeam.com/kb4732">see this Veeam KB article</a></li><li>SLES 12 SP4, 12 SP5, 15 SP1 – SP6</li><li>SLES for SAP 12 SP4, 12 SP5, 15 SP1 – 15 SP6</li><li>Fedora 36, 37, 38, 39</li><li>openSUSE Leap 15.3 – 15.6</li><li>openSUSE Tumbleweed (experimental support)</li></ul><p>Consider the following limitations:</p><ul><li>Linux kernel version 2.6.32 or later is supported as long as you use kernels supplied by your distribution.</li><li>Fedora and openSUSE Tumbleweed are supported up to kernel 6.14.</li><li>Linux kernel 2.6.32 - 754.6.3 in CentOS / RHEL and Oracle Linux (RHCK) is not supported.</li><li><p>Automatic deployment from the Veeam Service Provider Console is not supported for the following distributions:</p><ul><li>Fedora 36, 37, 38, 39</li><li>openSUSE Tumbleweed.</li></ul></li></ul> |

### <mark style="color:green;">2.</mark> <mark style="color:green;">Management Agent v9.1</mark>

| Windows                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Linux                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p></p><p>64-bit versions of the following operating systems are supported except Server Core installations for server OS:</p><ul><li>Microsoft Windows Server 2025</li><li>Microsoft Windows Server 2022</li><li>Microsoft Windows Server 2019</li><li>Microsoft Windows Server 2016</li><li>Microsoft Windows Server 2012 R2</li><li>Microsoft Windows Server 2012</li><li>Microsoft Windows 11</li><li>Microsoft Windows 10 (starting from version 1909)</li><li>Microsoft Windows 10 LTSC versions (1607, 1809)</li></ul> | <p></p><p>Linux kernel versions 2.6.32 – 6.17 are supported if you use kernels supplied by your distribution.</p><p>Only 64-bit versions of the following operating systems are supported:</p><ul><li>Rocky Linux 8.10, 9.4 – 9.6 and 10.0</li><li>AlmaLinux 8.10, 9.4 – 9.6 and 10.0</li><li>Debian 11 – 13.1</li><li>Ubuntu 16.04, 18.04, 20.04, 22.04, 22.10, 24.04</li><li>RHEL 8.4 – 9.6 and 10.0</li><li>Oracle Linux 7 – 10.0 (RHCK)</li><li>Oracle Linux 7 (starting from UEK R4) - Oracle Linux 8 (up to UEK R6)</li><li>Oracle Linux 8 (UEK R7) – for information on installing Veeam Agent, see <a href="https://www.veeam.com/kb4394">this Veeam KB article</a></li><li>Oracle Linux 9 (UEK R7 up to 5.15.0-311.185.9.el9uek.x86\_64)</li><li>Oracle Linux 9 (UEK R8) – for information on installing Veeam Agent on Oracle Linux 9 with UEK R8, see <a href="https://www.veeam.com/kb4732">this Veeam KB article</a></li><li>Oracle Linux 10 (UEK R8)</li><li>SLES 12 SP5, 15 SP3 – 15 SP7</li><li>SLES for SAP 12 SP5, 15 SP3 – 15 SP7</li></ul><p>Consider the following limitations:</p><ul><li>Linux kernel version 2.6.32 or later is supported as long as you use kernels supplied by your distribution.</li><li>Linux kernel 2.6.32 - 754.6.3 in RHEL and Oracle Linux (RHCK) is not supported.</li><li>For the full list of limitations, see Veeam Agent for Linux documentation: Veeam Agent for Linux 13 User Guide.</li></ul> |

***

## <mark style="color:green;">Backup Agent Compatibility</mark> <a href="#id-4.-backup-agent-compatibility" id="id-4.-backup-agent-compatibility"></a>

| **Agent Version**                | **Supported** |
| -------------------------------- | ------------- |
| Veeam Agent Windows v6.2 & below |               |
| Veeam Agent Linux v6.2 & below   |               |
| Veeam Agent Windows v6.3.2       | x             |
| Veeam Agent Linux v6.3.2         | x             |
| Veeam Agent Windows v13          | x             |
| Veeam Agent Linux v13            | x             |

***

## <mark style="color:green;">Backup Agent OS and Infrastructure support</mark> <a href="#id-5.-backup-agent-os-and-infrastructure-support" id="id-5.-backup-agent-os-and-infrastructure-support"></a>

### <mark style="color:green;">1. Veeam Agent for Microsoft Windows</mark>

<table><thead><tr><th width="150">Version</th><th>Windows OS</th></tr></thead><tbody><tr><td><strong>6.3.2.1205</strong></td><td><p></p><p>Both 64-bit and 32-bit (where applicable) versions of the following operating systems are supported:</p><ul><li>Microsoft Windows Server 2025</li><li>Microsoft Windows Server 2022</li><li>Microsoft Windows Server 2019</li><li>Microsoft Windows Server 2016</li><li>Microsoft Windows Server General Availability Channel (from version 1803 to version 20H2)</li><li>Microsoft Windows Server 2012 R2</li><li>Microsoft Windows Server 2012</li><li>Microsoft Windows Server 2008 R2 SP1</li><li>Microsoft Windows 11 (from versions 21H2 to version 24H2)</li><li>Microsoft Windows 10 (from version 1909 to version 22H2)</li><li>Microsoft Windows 10 Long-Term Servicing Channel (versions 2015, 2016, 2019)</li><li>Microsoft Windows 8.1</li><li>Microsoft Windows 7 SP1</li></ul></td></tr><tr><td><strong>13.0.1.120</strong></td><td><p></p><p>64-bit versions of the following operating systems are supported:</p><ul><li>Microsoft Windows Server 2025</li><li>Microsoft Windows Server 2022</li><li>Microsoft Windows Server 2019</li><li>Microsoft Windows Server 2016</li><li>Microsoft Windows 11 (from version 22H2 to version 25H2)</li><li>Microsoft Windows 10 General Availability Channel 22H2</li><li>Microsoft Windows 10 LTSC (versions 2015, 2016, 2019, 2021)</li><li>Server Core installations of Microsoft Windows Server OSes can be backed up only by Veeam Agent backup jobs managed by the Veeam backup server.</li><li>Windows Embedded / Windows IoT OSes are supported (except for custom builds that do not have components required for Veeam Agent operation).</li><li>Each Veeam Agent computer must have a unique BIOS UUID.</li></ul></td></tr></tbody></table>

### <mark style="color:green;">2. Veeam Agent for Linux</mark>

<table><thead><tr><th width="150">Version</th><th>Linux OS</th></tr></thead><tbody><tr><td><strong>6.3.2.1207</strong></td><td><p></p><p>Linux kernels from version 2.6.32 to version 6.14 are supported.</p><p>Veeam Agent for Linux supports 64-bit versions of the following distributions:</p><ul><li>Debian 10.13 – 12.11</li><li>Ubuntu 16.04, 18.04, 20.04, 22.04, 22.10, 23.04, 23.10, 24.04, 24.10 and 25.04</li><li>RHEL 6.4 – 9.6 and 10.0</li><li>Rocky Linux 8.10, 9.3 – 9.6 and 10.0</li><li>AlmaLinux 8.10, 9.3 – 9.6 and 10.0</li><li>CentOS 7</li><li>Oracle Linux 6 – 9.6 (RHCK)</li><li>Oracle Linux 6 (starting from UEK R2) – Oracle Linux 8 (up to UEK R6)</li><li>Oracle Linux 8 (UEK R7) — for information on installation, see <a href="https://www.veeam.com/kb4394">this Veeam KB article</a>.</li><li>Oracle Linux 9 (UEK R7 up to 5.15.0-308.179.6.3.el9uek)</li><li>Oracle Linux 9 (UEK R8) – for information on installing Veeam Agent on Oracle Linux 9 with UEK R8, see <a href="https://www.veeam.com/kb4732">this Veeam KB article</a>.</li><li>SLES 12 SP4, 12 SP5, 15 SP1 – 15 SP6</li><li>SLES for SAP 12 SP4, 12 SP5, 15 SP1 – 15 SP6</li><li>Fedora 36, 37, 38 and 39</li><li>openSUSE Leap 15.3 – 15.6</li><li>openSUSE Tumbleweed has an experimental support status. For details about experimental support, see <a href="https://www.veeam.com/kb2976">this Veeam KB article</a>.</li></ul><p>Veeam Agent for Linux supports 32-bit versions of:</p><ul><li>RHEL 6.</li><li>Oracle Linux 6 distributions only.</li></ul><p>Limitation: <a href="https://helpcenter.veeam.com/rn/veeam_agent_linux_6_3_2_release_notes.html#considerations-and-limitations">https://helpcenter.veeam.com/rn/veeam_agent_linux_6_3_2_release_notes.html#considerations-and-limitations</a></p></td></tr><tr><td><strong>13.0.1.94</strong></td><td><p></p><p>Linux kernel version 3.10 to version 6.17 is supported. For the most up-to-date information on the Veeam Agent compatibility with Linux kernel versions of the supported distributions, see <a href="https://www.veeam.com/kb2804">this Veeam KB article</a>.</p><p>Veeam Agent supports the 64-bit versions of the following Linux distributions:</p><ul><li>Debian 11.0 – 13.21</li><li>Ubuntu 16.04, 18.04, 20.04, 22.04 and 24.04</li><li>RHEL 8.4 – 9.6 and 10.0</li><li>Oracle Linux 7 – 10.0 (RHCK)</li><li>Oracle Linux 7 (starting from UEK R4) – Oracle Linux 8 (up to UEK R6)</li><li>Oracle Linux 8 (UEK R7) — for information on installation, see <a href="https://www.veeam.com/kb4394">this Veeam KB article</a>.</li><li>Oracle Linux 9 (UEK R7 up to 5.15.0-313.189.5.2.el9uek.x86_64)</li><li>Oracle Linux 9 (UEK R8) – for information on installing Veeam Agent on Oracle Linux 9 with UEK R8, see <a href="https://www.veeam.com/kb4732">this Veeam KB article</a>.</li><li>Oracle Linux 10 (UEK R8)</li><li>SLES 12 SP5, 15 SP3 – 15 SP7</li><li>SLES for SAP 12 SP5, 15 SP3 – 15 SP7</li><li>Rocky Linux 8.10, 9.4 – 9.6 and 10.0</li><li>AlmaLinux 8.10, 9.4 – 9.6 and 10.0</li></ul><p>Limitation: <a href="https://helpcenter.veeam.com/docs/agentforlinux/userguide/system_requirements.html?ver=13#hardware_lim">https://helpcenter.veeam.com/docs/agentforlinux/userguide/system_requirements.html?ver=13#hardware_lim</a></p></td></tr></tbody></table>

### <mark style="color:green;">3. Veeam Backup & Replication (VBR)</mark>

Veeam Backup & Replication 12.3.2 (starting from 12.3.2.3617) and 13.0.1 or later

{% hint style="info" %}
**NOTE:**

Veeam Backup & Replication 13.0.0 is not supported.
{% endhint %}

***

## <mark style="color:green;">Documentation References</mark> <a href="#id-6.-documentation-references" id="id-6.-documentation-references"></a>

* Management Agent (Management Agent line): [System Requirements - Veeam Service Provider Console Deployment Guide](https://helpcenter.veeam.com/docs/vac/deployment/system_requirements.html?ver=81)
* Backup Agent Windows: [KB2683: Build Numbers and Versions of Veeam Agent for Microsoft Windows](https://www.veeam.com/kb2683)
* Backup Agent Linux: [KB2681: Build Numbers and Versions of Veeam Agent for Linux](https://www.veeam.com/kb2681)
* Linux Backup Agent module: [KB2804: Veeam Agent for Linux - veeamsnap and blksnap Extended Linux Distribution Support](https://www.veeam.com/kb2804)

<br>


# Install Veeam Agent for Linux

## <mark style="color:green;">**Overview**</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

<img src="/files/X3Q7fk9qluGlwkN1U9hi" alt="" data-size="line"> This is a document on how to Install Veeam Agent for Linux

## <mark style="color:green;">**Procedure - Install Veeam Agent for Linux**</mark> <a href="#id-2.-install-veeam-agent-for-linux" id="id-2.-install-veeam-agent-for-linux"></a>

{% stepper %}
{% step %}
**Step 1:** Download Veeam Service Provider Console Management Agent

* Login to the **Web UI** with the customer user
* Select **Managed Computers** > **Discovered Computers**
* Choose **Download Agent** > **Linux**

<figure><img src="/files/UwywjvSybZzOCcTpOR9I" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Install **Linux Management Agent**

* Log on to the machine where you want to install the master agent.
* Copy the agent installation package (the .sh file) to the machine where you want to install the agent.
* Make sure that you have permission to execute the installation package file.

`sudo chmod +x LinuxAgentPackages...`
{% endstep %}

{% step %}
**Step 3:** Install the package with the following command:

`sudo ./LinuxAgentPackages....`

<figure><img src="/files/Pn6KYhaysOyUVdIJq8lE" alt=""><figcaption></figcaption></figure>

Check connection by command:

`veeamconsoleconfig -s`

<div align="left"><figure><img src="/files/In8qiCSi57Ipm2d3NhOm" alt=""><figcaption></figcaption></figure></div>

<mark style="color:red;">**Note**</mark><mark style="color:red;">:</mark> if you cannot connect to Cloud Gateway, please check:

Cloud Gateway address:

HCM: **backup-hcmc.higio.net**

HN: **backup-hni.higio.net**

* *Check connections to the internet.*
* *Check connections to Cloud Gateway port 6180. #telnet {*&#x43;loud Gateway addres&#x73;*} 6180*
* *If the connection to Cloud Gateway port 6180 cannot be opened, do the following command:*

```
#iptables -I OUTPUT -p udp --dport 53 -j ACCEPT 
#iptables -I OUTPUT -d {Cloud Gateway address} -p tcp --dport 6180 -j ACCEPT 
#iptables-save
```

Delete iptables rule:

```
#iptables -D OUTPUT -d {Cloud Gateway address} -p tcp --dport 6180 -j ACCEPT 
#iptables-save
```

{% endstep %}

{% step %}
Step 4: Return to the Veeam Server Provider Console that the Linux Machine will be displayed in “Discovery Computer” with the status “active.”

<figure><img src="/files/RgRqfxSqusioIg2jsk0x" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Install **Veeam Backup Agent Linux**

* Login to the **Web UI** > **Managed Computers** > **Discovered Computers**
* Choose the **Linux Server** > **Install Backup Agent**

<figure><img src="/files/sVNoG2H6a9PiYjtmqq3m" alt=""><figcaption></figcaption></figure>

* In the **Use guest OS credentials form** section, select an account that will be used to upload setup files to client computers and start installation.
* The Account must have local root permissions on computers where you want to install Veeam backup agents.

  * Select the **Account specified in the discovery rule or the management agent settings** if you want to install the same Account that you specified for the discovery of client computers, either in the master agent configuration or in the discovery rule settings.
  * Select **The following user account** if you want to specify an account different from the one you used for discovery. You can select an account from the list or click Create New to specify credentials for a new account.

  <figure><img src="/files/1BWvw5DRfRQtPSr2Yed6" alt=""><figcaption></figcaption></figure>

  <figure><img src="/files/diDbMYOyhdv3H3eHi6Ks" alt=""><figcaption></figcaption></figure>
* In the **Backup policy to apply** list, choose a backup policy that must be used as part of the installation process.
  * If you allocate all cloud resources specified in the policy to the company, the chosen backup policy will configure backup job settings after installing Veeam backup agents. You can select No policy if you do not want to configure backup job settings as part of installation.
* By default, read-only access is enabled for all Veeam backup agents. To disable the read-only access mode for Veeam backup agents, set the **Enable read-only UI access for the backup** agent toggle to **Off**.

<figure><img src="/files/MYkjXiZtfwfPKgggYpqU" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 6:** Check **the result** via portal and VM:

<figure><img src="/files/woilH3KW6Ov3S1QOj7E0" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/eT3yFmti8Xd7s3o8CxZ0" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Install Veeam Agent for Windows

## <mark style="color:green;">**Overview**</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

<img src="/files/5V3Es8qPVJzazN3TQeYn" alt="" data-size="line">  This is a document on how to install Veeam Agent for Windows.<br>

## <mark style="color:green;">Procedure - Install Veeam Agent for Windows</mark> <a href="#id-2.-install-veeam-agent-for-windows" id="id-2.-install-veeam-agent-for-windows"></a>

{% stepper %}
{% step %}
**Step 1:** Download Veeam Service Provider Console **Management Agent**

* Login to the **Web UI** with the customer user
* Select **Managed Computers** > **Discovered Computers**
* Choose **Download Agent** > **Windows**

<figure><img src="/files/JfW6heotVzIQ35gDNH48" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Install **Windows Management Agent**

* Copy the agent installation file to the machine where you want to install the agent.
* Make sure that you have permission to execute the installation file.
* Install the **Management Agent**:

<figure><img src="/files/usENI2EzVuF5iZocaB9T" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/JmKVZTAx4NgvdsjAJmTo" alt=""><figcaption></figcaption></figure>

Wait for the connection to be connected:

<figure><img src="/files/9VBVvDIqXdR3CN29FPxb" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
**Attention:** if you cannot connect to Cloud Gateway, please check:

Cloud Gateway address:

* HCM: **backup-hcmc.higio.net**
* HN: **backup-hni.higio.net**

*Check connections to the internet.*

*Check connections to Cloud Gateway port 6180. #telnet {Cloud Gateway address*} *6180*

Return to the Veeam Server Provider Console that the Linux Machine will be displayed in “**Discovery Computer**” with the status “**active**.”
{% endhint %}
{% endstep %}

{% step %}

<figure><img src="/files/r78nTEJhJ9MzXSBszXhi" alt=""><figcaption></figcaption></figure>

**Step 3:** Install **Veeam Backup Agent Windows**

* Login to the **Web UI** > **Managed Computers** > **Discovered Computers**
* Choose the **Windows Server** > **Install Backup Agent**

<figure><img src="/files/oTCXg4DBgeXhYoZMo1uE" alt=""><figcaption></figcaption></figure>

* In the **Use guest OS credentials form** section, select an account that will be used to upload setup files to client computers and start installation.
* The account must have local privilege permissions on computers where you want to install Veeam backup agents.
  * Select the **Account specified in the discovery rule or the management agent settings** if you want to install the same account that you specified for the discovery of client computers, either in the master agent configuration or in the discovery rule settings.

Select **The following user account** if you want to specify an account different from the one you used for discovery. You can select an account from the list or click Create New to specify credentials for a new account.

<figure><img src="/files/lUWdR6vutAVfAQqDbPuK" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/NLCsuACO54c3f1Tzqn22" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Check the result via portal and OS:

<figure><img src="/files/7H4onrlaL3bMbWW6Wb8I" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/UGSplMekczINwwtTiB3O" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Update Veeam Service Provider Console Management Agent v.9 & Backup Agent v.6.3

## <mark style="color:green;">**Overview**</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

This is a document on how to:

* *Update Veeam Service Provider Console Management Agent for **Linux from v.8.1 to v9 and Veeam Backup Agent for Linux from v.6 to v.6.3***
* *Update Veeam Service Provider Console Management Agent for **Windows from v.8.1 to v9 and Veeam Backup Agent for Windows from v.6 to v.6.3***

## <mark style="color:green;">**Procedure**</mark> <a href="#id-2.-guideline" id="id-2.-guideline"></a>

{% hint style="success" %} <img src="/files/uwQnF2MCXn2tLfYKTuPI" alt="" data-size="line"> **Update Veeam Service Provider Console Management Agent for Windows from v.8.1 to v.9 & Veeam Backup Agent for Windows from v.6 to v.6.3**
{% endhint %}

{% stepper %}
{% step %}
**Step 1:** Update **Veeam MGMT Agent for Window**

* **Management Agent for Windows** will auto-update to the v9 – If not, we can do it in UI
* Login to the **Web UI** > **Managed Computers** > **Discovered Computers**
* Choose Server **Windows** > **Management Agent** > **Upgrade**

<figure><img src="/files/jWbXY3hZAd0HU6M9x4tU" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Update **Backup Agent for Windows**

* Select **Managed Computers** > **Backup Agents**
* Choose **Server Windows** > **Backup Agent** > **Upgrade**

<figure><img src="/files/XPnqMGUbyffoHMhGMC6W" alt=""><figcaption></figcaption></figure>

* Wait for Deployment Progress

<figure><img src="/files/rP9eoNCEYrMNoD0GdEJ0" alt=""><figcaption></figcaption></figure>

Backup Agent updated successfully:

<figure><img src="/files/MBmoxbz9kcLJRly183Lk" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/JqkxDZoo2BBzZqjLBtpQ" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

{% hint style="success" %} <img src="/files/gdM458WlcEO5nR4Q4Q07" alt="" data-size="line">**Update Veeam Service Provider Console Management Agent for Linux from v.8.1 to v.9 and Veeam Backup Agent for Linux from v.6 to v.6.3**
{% endhint %}

{% stepper %}
{% step %}
**Step 1:** Update **Veeam MGMT Agent for Linux**

* **Management Agent for Windows** will auto-update to the v9 – If not, we can do it in UI
* Login to the **Web UI** > **Managed Computers** > **Discovered Computers**
* Choose Server **Windows** > **Management Agent** > **Upgrade**

<figure><img src="/files/u4zoCeG3IryuAdAnBKep" alt=""><figcaption></figcaption></figure>

Wait for Deployment Progress

<figure><img src="/files/uUWV14cBNUaWtzwukIMO" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Update **Backup Agent for Linux**

* Select **Managed Computers** > **Backup Agents**
* Choose **Server Linux** > **Backup Agent** > **Upgrade.**

<figure><img src="/files/DdukcNClUVvPmktdzeuX" alt=""><figcaption></figcaption></figure>

* Wait for Deployment Progress

<figure><img src="/files/Ymis4E7AlHy3DqzsS5DB" alt=""><figcaption></figcaption></figure>

* Backup Agent updated successfully:

<figure><img src="/files/kxuidHMXyHYYWrmbgMmo" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/xBjbX5fZuvixv4v7lNDh" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Create backup job on Linux OS via Veeam agent console

## <mark style="color:green;">**Overview**</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

<img src="/files/8WBxOqnKXBiiq0VlMltE" alt="" data-size="line"> This is a document on how to Create a backup job on Linux.

## <mark style="color:green;">**Procedure**</mark> <a href="#id-2.-guideline" id="id-2.-guideline"></a>

{% stepper %}
{% step %}
**Step 1:** Start Veeam Backup Agent

Using this command “***veeam”** to start service Veeam*

<figure><img src="/files/7PYUkwVQG93OwSuYIptB" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Create a **Back Job**

Press “**c**” and input **Job name**

<div align="left"><figure><img src="/files/5Sr5rlmZax9ILCIokAjD" alt=""><figcaption></figcaption></figure></div>

Choose **Veeam Cloud Connect Repository**

<div align="left"><figure><img src="/files/KXO3GzUlKfjBcPjUq4fb" alt=""><figcaption></figcaption></figure></div>

Enter the address of BaaS Cloud Gateway Address:

* HCM: **backup-hcmc.higio.net**
* HN: **backup-hni.higio.net**

<div align="left"><figure><img src="/files/7GVOZ1mEpE8K381BpZgu" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="/files/YWyKmDXPBdjhJDtVQvvP" alt=""><figcaption></figcaption></figure></div>

* **Accept** the certificate details.
* Enter **Username** and **Password**

<div align="left"><figure><img src="/files/7Tui0vUKYxhJf4m0yHoa" alt=""><figcaption></figcaption></figure></div>

Check the capacity of **BaaS Storage.**

<div align="left"><figure><img src="/files/lxSZmvMoe3kMEGTclTc4" alt=""><figcaption></figcaption></figure></div>

**Advanced** configuration.

<div align="left"><figure><img src="/files/bWrZmB4fVeYvLcahan5J" alt=""><figcaption></figcaption></figure></div>

**Schedule** Backup.

<div align="left"><figure><img src="/files/ROMHz91tGaVjHvTRr8CN" alt=""><figcaption></figcaption></figure></div>

**Check the settings.**

<div align="left"><figure><img src="/files/yJe4KEN7lvPMXAzaNx4L" alt=""><figcaption></figcaption></figure></div>

Run the **Backup Job.**

<figure><img src="/files/sn3zFLD4CmpZ4LRcoWnJ" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Create backup job on Windows OS via Veeam agent console

## <mark style="color:green;">**Overview**</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

<img src="/files/xWU7VeDXebwcFhumn346" alt="" data-size="line">  This is a document on how to create a backup job on Windows.

## <mark style="color:green;">Procedure</mark> <a href="#id-2.-guidance" id="id-2.-guidance"></a>

{% stepper %}
{% step %}
**Step 1:** Configure job on **Veeam Backup Agent**

Start **Veeam Backup Agent Application**
{% endstep %}

{% step %}
**Step 2:** Create a Back Job

Choose **Add New Job…**

<div align="left"><figure><img src="/files/qv6IQnsMk7W79hwZRDK2" alt=""><figcaption></figcaption></figure></div>

Input **Name** and **Description** for the job

<figure><img src="/files/ONaQiJr6HLkPov9uQIC7" alt=""><figcaption></figcaption></figure>

Choose **Backup Mode**

<figure><img src="/files/AafVV6UoBGtNKJ0Nc0Y8" alt=""><figcaption></figcaption></figure>

Choose **Veeam Cloud Connect Repository**

<figure><img src="/files/U6ecWKlbI6Vr5zcgPvVf" alt=""><figcaption></figcaption></figure>

Enter the address of BaaS Cloud Gateway Address:

* HCM: **backup-hcmc.higio.net**
* HN: **backup-hni.higio.net**

<figure><img src="/files/Ovr8JNr6E08lADcJRWho" alt=""><figcaption></figcaption></figure>

* **Accept** the certificate details.
* Enter **Username** and **Password.**

<figure><img src="/files/kVrasLxoGxZBfejWje6k" alt=""><figcaption></figcaption></figure>

Check the capacity of **BaaS Storage**

<figure><img src="/files/mJOC4o3isb4bZ3SmP69T" alt=""><figcaption></figcaption></figure>

**Advantage** configuration

<div align="left"><figure><img src="/files/WNXR0lbkhOkI2gwFWGwj" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="/files/EoqSL3AFDPCZsx0taDP7" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="/files/G8hbyb6usjOlstORGo0o" alt=""><figcaption></figcaption></figure></div>

Enable or Disable **Backup Cache**

<figure><img src="/files/BB0CpgYzSs51WkIe4Y90" alt=""><figcaption></figcaption></figure>

Enable or Disable **Guest Processing** (Backup SQL, File index)

<figure><img src="/files/kKblaG8ZLrEomFyB5aEM" alt=""><figcaption></figcaption></figure>

**Schedule Backup**

<figure><img src="/files/y6RQxyanMlbiiqB7YvwG" alt=""><figcaption></figcaption></figure>

Check the settings

<figure><img src="/files/C8kP9mtcFdZJtwJRVKOo" alt=""><figcaption></figcaption></figure>

Run the **Backup Job**

<figure><img src="/files/NbgF3JWxo315BKshDmJy" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Create backup job for Linux via Portal

## <mark style="color:green;">Overview</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

This is a document on creating a backup job for Linux on Portal.

## <mark style="color:green;">Procedure</mark> <a href="#id-2.-guidance" id="id-2.-guidance"></a>

{% stepper %}
{% step %}
**Step 1:** Access and login to BaaS portal:

* **HCM:** [https://portal-hcmc-backup.higio.net](https://portal-hcmc-backup.higio.net/)
* **HN:** [https://portal-hni-backup.higio.net](https://portal-hni-backup.higio.net/)

<figure><img src="/files/9al4DxTlCEtsRWuSaImK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Create a Backup Job

Choose **Managed Computers** → **Choose Backup Agents** tab → Tick **Computer** want to create job → Choose **Assign…**

<figure><img src="/files/SHfvfqG3Hl7GV6jdO2As" alt=""><figcaption></figcaption></figure>

You can choose the job that was already created from the Service Prover template, or you can create a new one by choosing **Create New**.

<figure><img src="/files/pQytnESvHXKsmhS9ix8z" alt=""><figcaption></figcaption></figure>

Input the **Name** and **description** (Optional), then click **Next**

<figure><img src="/files/VNftDviNfe0zhSTAT8rX" alt=""><figcaption></figcaption></figure>

Choose **Server,** then **Next**

<figure><img src="/files/LdBqSA0kfFEEulTZZPmq" alt=""><figcaption></figcaption></figure>

Choose the **Backup Mode** that you want, then **Next**

<figure><img src="/files/Zm59uXgH84Y8YZotxJ9v" alt=""><figcaption></figcaption></figure>

Choose the **Veeam Cloud Connect repository,** then **Next**

<figure><img src="/files/7D7MPH9F9VsKXjAs6sis" alt=""><figcaption></figcaption></figure>

Set the **Restore points** you want to keep and choose **Advanced Settings…** for more options.

<figure><img src="/files/5LgqMbPIkLI7vaMS9cQa" alt=""><figcaption></figcaption></figure>

Advanced Option:

<figure><img src="/files/QoVoYfJ0imXFXpCWPx2z" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/bS2OZ9D3NAYAC18yIiRE" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/x65Jka0moWx56pr53SV7" alt=""><figcaption></figcaption></figure>

After finishing **Apply** then, choose **Next** to continue.

<figure><img src="/files/wYHcCK8j1FOUZzj3BajD" alt=""><figcaption></figcaption></figure>

Choose **Use sub-tenant accounts for each managed backup agent with the following quota** and set the **quota** for this backup job, or you can set it **Unlimited**.

<figure><img src="/files/1eQ5mLBwcMI4uHQCjPZO" alt=""><figcaption></figcaption></figure>

Enable **application-aware** **processing** or **script execution** or **file system indexing** if you want to back up. **Next**.

<figure><img src="/files/65PFxub5LU8YxOCXfK5p" alt=""><figcaption></figcaption></figure>

**Schedule** the backup job, then **Next**.

<figure><img src="/files/apfdR4BJGvsgX73IukcV" alt=""><figcaption></figcaption></figure>

**Review** the backup job configuration and then choose **Finish**.

<figure><img src="/files/gtseiBQa2x7Cgl9DvOBD" alt=""><figcaption></figcaption></figure>

Tick the **job** that wants to run, then choose **Assign**.

<figure><img src="/files/pAw5llkdpOqxAbg85ghN" alt=""><figcaption></figcaption></figure>

Choose the **policy** from the **Backup Policy** column to check the create backup job process.

<figure><img src="/files/cvwP1y22GevJkEeBvwGc" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/T1L0cVA5GayEgdPoOigd" alt=""><figcaption></figcaption></figure>

The backup job has been created and completed.

<figure><img src="/files/HNfXFhWYjGODnC83kFRo" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Create backup job for Windows via Portal

## <mark style="color:green;">Overview</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

This is a document on creating a backup job for Windows on Portal.

## <mark style="color:green;">Procedure</mark> <a href="#id-2.-guidance" id="id-2.-guidance"></a>

{% stepper %}
{% step %}
**Step 1:** Access and login to BaaS portal:

* **HCM:** [https://portal-hcmc-backup.higio.net](https://portal-hcmc-backup.higio.net/)
* **HN:** [https://portal-hni-backup.higio.net](https://portal-hni-backup.higio.net/)

<figure><img src="/files/XGPgnGzxdfeMzoxWWghx" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Ste**p 2:** Create a Backup Job

Choose **Managed Computers** → **Choose Backup Agents** tab → Tick **Computer** want to create job → Choose **Assign…**

<figure><img src="/files/y74GOWRO4uFb29LSXedB" alt=""><figcaption></figcaption></figure>

You can choose the job already created from the Service Prover **template,** or you can create a new one by choosing **Create New**.

<figure><img src="/files/0Zl2FA4nFIQ9TdS7BhN4" alt=""><figcaption></figcaption></figure>

Input the **Name**, **Description** (Optional) then click **Next.**

<figure><img src="/files/Orrz7qIcXvPzMUrAJYQq" alt=""><figcaption></figcaption></figure>

Choose **Server,** then **Next.**

<figure><img src="/files/gFM8wCNuPL9OQAWlzacs" alt=""><figcaption></figcaption></figure>

Choose the **Backup Mode** that you want, then **Next.**

<figure><img src="/files/9fzY5FwlPHoACzAEg4Nm" alt=""><figcaption></figcaption></figure>

Choose **Veeam Cloud Connect repository,** then **Next.**

<figure><img src="/files/ZFWbcMqUKf5Nldb2SPCD" alt=""><figcaption></figcaption></figure>

Set the **Restore points** you want to keep and choose **Advanced Settings…** for more options.

<figure><img src="/files/r0euRkvGEswKxHqOq9HD" alt=""><figcaption></figcaption></figure>

Advanced Option:

<figure><img src="/files/6SsXcWppnoEAy4Bmt80c" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/hY9tBFhAonIPNmJzuI1M" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/4U9G0J3dGHnAxnkGgtbZ" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/URfOzdTXpNZys3qwRyUm" alt=""><figcaption></figcaption></figure>

After finishing **Apply** then, choose **Next** to continue.

<figure><img src="/files/jmUvvWA3bWSukY8UkX6I" alt=""><figcaption></figcaption></figure>

Choose **Use sub-tenant accounts for each managed backup agent with the following quota** and set the **quota** for this backup job, or you can set it **Unlimited**.

<figure><img src="/files/FbygtHjoOP8jt6wS7J0T" alt=""><figcaption></figcaption></figure>

Enable the **backup cache** feature if needed, then **go next**.

<figure><img src="/files/IpgAkRmmMfpMeJNBGemy" alt=""><figcaption></figcaption></figure>

Enable **application-aware** **processing** or **file system indexing** you want to backup, then **Next**.

<figure><img src="/files/KXUqxV0WFxyy06ZL56sx" alt=""><figcaption></figcaption></figure>

**Schedule** the backup job, then **Next**.

<figure><img src="/files/RKlExiyzYcrhuup1M50A" alt=""><figcaption></figcaption></figure>

**Review** the backup job configuration and then choose **Finish**.

<figure><img src="/files/EYAv33kFMTwa8QqrhaE0" alt=""><figcaption></figcaption></figure>

Tick the **job** that wants to run, then choose **Assign**.

<figure><img src="/files/rSYflGXlqnu1Hm0r9Wtm" alt=""><figcaption></figcaption></figure>

Choose the **policy** from the **Backup Policy** column to check the create backup job process.

<figure><img src="/files/ofoIaCF3puTwHFxcY7lU" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/pJ4sdv4UqKMqvMhEf4kD" alt=""><figcaption></figcaption></figure>

The backup job has been created and completed.

<figure><img src="/files/HpgEcD8IGnVrhHVGTDzU" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Restore Linux VM on HIGIO Cloud via Media file (ISO file)

## <mark style="color:green;">Overview</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

This is a document on how to Restore a Linux VM.

## <mark style="color:green;">Procedure</mark> <a href="#id-2.-how-to-restore-linux-vm" id="id-2.-how-to-restore-linux-vm"></a>

{% stepper %}
{% step %}
**Step 1:** Insert Veeam Recovery Media for Windows to VM

From VM choose **ALL ACTION** > **Media** > **Insert Media**

<figure><img src="/files/ZENheUXqXno0gCtsS2gB" alt=""><figcaption></figcaption></figure>

Choose **Veeam Recovery Media(According to your OS)** > **Insert**

<figure><img src="/files/pNeW1rWReD873tGmnFDu" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/cdjeOVFjDx9S9kOjIy5a" alt=""><figcaption></figcaption></figure>

Then **POWER ON** VM and wait for Veeam Recovery Media to boot

<figure><img src="/files/aIFHznc2KDAhIsivYvCk" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Restore from a restore point

When boot is completed, choose **Proceed without SSH**

<figure><img src="/files/t1fFnJEW3vqzlnqdGWgf" alt=""><figcaption></figcaption></figure>

**Accept** license agreement

<figure><img src="/files/cAMNFY4eygxoWLBtSutA" alt=""><figcaption></figcaption></figure>

Remember to configure IP for the connection to Cloud Gateway via **Configure network**

<figure><img src="/files/htluh0UCqdU7pJpKKMUa" alt=""><figcaption></figcaption></figure>

Choose **Edit a connection**

<figure><img src="/files/3vYyQ0HOLzB5O8nUEiru" alt=""><figcaption></figcaption></figure>

Choose available **Ethernet** > **Edit**

<figure><img src="/files/bTjtn6GfW8zGOcllLA8g" alt=""><figcaption></figcaption></figure>

Input the **IP address** then choose **OK**

<figure><img src="/files/12Lq0qePWFM3cY2wE1Wu" alt=""><figcaption></figcaption></figure>

Choose **Restore volumes**

<figure><img src="/files/UK6rKpaSsAzn2N16xVG0" alt=""><figcaption></figcaption></figure>

Choose **Add** **Cloud Connect provider**

<figure><img src="/files/ukqO5l5o5g63cSDtovAA" alt=""><figcaption></figcaption></figure>

Enter address of BaaS Cloud Gateway Address:

* HCM: **backup-hcmc.higio.net**
* HN: **backup-hni.higio.net**

<figure><img src="/files/2AasO1wX7msTgq9U2OfU" alt=""><figcaption></figcaption></figure>

* **Accept** the certificate details.

<figure><img src="/files/huPHRdYcJ7zi9cTjotP4" alt=""><figcaption></figcaption></figure>

* Enter **Username** and **Password**

<figure><img src="/files/8Ah2TdP9fahKXKo3ZQpW" alt=""><figcaption></figcaption></figure>

* Select **Job** and **restore point** that want to restore

<figure><img src="/files/eTdxNYcMk8NM4KajOOEX" alt=""><figcaption></figcaption></figure>

* Choose **Hard disk** that want to restore

<figure><img src="/files/ZMfFZoAGXxoYZm3Ph11s" alt=""><figcaption></figcaption></figure>

* **Enter** and select **Restore from…**

<figure><img src="/files/RuhInfW0fDEJLUIMK9fK" alt=""><figcaption></figcaption></figure>

* Choose the exact disk want to restore

<figure><img src="/files/Dbkv7TupYk1g8rzOPCQK" alt=""><figcaption></figcaption></figure>

* Check that the mapping is correct, and then press ”s” to continue

<figure><img src="/files/90IHXwUoOvRzLeWlf6ei" alt=""><figcaption></figcaption></figure>

* Review the **Summary** of the restore job, then press Enter to begin

<figure><img src="/files/IJmNRQ9soeN3JNedwqjE" alt=""><figcaption></figcaption></figure>

* Begin the process and complete the restore

<figure><img src="/files/DWTMR5UOZvHmv0GTmrBc" alt=""><figcaption></figcaption></figure>

* Shutdown the VM and then Eject Media

<figure><img src="/files/Jz3buecgl0AzJZRQjqZK" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/yFweIvjaoOmWeUBV3LoO" alt=""><figcaption></figcaption></figure>

**POWER ON** the VM

<figure><img src="/files/JERAS90VzJWlKTFVqq4y" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/4v3oAmYmSUJ50mEbMKx4" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

&#x20;


# Restore Windows VM on HIGIO Cloud via Media file (ISO file)

## <mark style="color:green;">Overview</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

This is a document on how to Restore a Windows VM.

## <mark style="color:green;">Procedure</mark> <a href="#id-2.-how-to-restore-windows-vm" id="id-2.-how-to-restore-windows-vm"></a>

{% stepper %}
{% step %}
**Step 1:** Insert Veeam Recovery Media for Windows to VM

From VM choose **ALL ACTION** > **Media** > **Insert Media**

<figure><img src="/files/EEdf27YLTHei77Nf1Jcn" alt=""><figcaption></figcaption></figure>

Choose **Veeam Recovery Media(According to your OS)** > **Insert**

<figure><img src="/files/xD5nn45QqNs1ii4CsZLv" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/VwAuM8wkH4pivdo9POy1" alt=""><figcaption></figcaption></figure>

Then **POWER ON** VM and wait for Veeam Recovery Media to boot

<figure><img src="/files/QpHRD1u2ju99SzdcDzu2" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Restore from restore point

When the boot is completed, choose **Bare Metal Recovery**

<figure><img src="/files/iOoQErijd096XEXsakVd" alt=""><figcaption></figcaption></figure>

Choose **Network storage**

<figure><img src="/files/5ZbccDeKxJt6jsWbxa9L" alt=""><figcaption></figcaption></figure>

Remember to configure IP for the connection to Cloud Gateway via **Configure network settings**

<figure><img src="/files/PdtRiijJ7TPH5Lu9XAQ6" alt=""><figcaption></figcaption></figure>

Choose available **Ethernet** > **Properties.**

<figure><img src="/files/t8UPqX6IbIyHaP0vFDEO" alt=""><figcaption></figcaption></figure>

Input the **IP address,** then choose **OK**

<figure><img src="/files/gqyU996e1aXTVMWD3nYG" alt=""><figcaption></figcaption></figure>

Choose the **Veeam Cloud Connect repository**

<figure><img src="/files/eWyk1fNxCP5JRo8Cj0Vf" alt=""><figcaption></figcaption></figure>

Enter the address of BaaS Cloud Gateway Address:

* HCM: **backup-hcmc.higio.net**&#x20;
* HN: [**backup-hni.higio.net**](http://backup-hni.higio.net/)

<figure><img src="/files/kKxHWypjNMIYfRQ6eFjg" alt=""><figcaption></figcaption></figure>

* **Continue** on the certificate details.

<figure><img src="/files/PaTqHqOZr7bBbHWD2rqG" alt=""><figcaption></figcaption></figure>

* Enter **Username** and **Password**

<figure><img src="/files/DFF6VvFClHb9kfjosFQ4" alt=""><figcaption></figcaption></figure>

* Select **Job** that want to restore

<figure><img src="/files/hWLkGUiQJoZdXE22VSgy" alt=""><figcaption></figcaption></figure>

* Select restore point that want to restore

<figure><img src="/files/NUEwuci6TQyp4qnMtmXB" alt=""><figcaption></figcaption></figure>

* Choose **Restore Mode**

<figure><img src="/files/Y4p1b85jSSEAW2edrV0b" alt=""><figcaption></figcaption></figure>

* Review **Summary** of restore job

<figure><img src="/files/bXu0jcE7fpON6MV7tZW8" alt=""><figcaption></figcaption></figure>

* Begin the process and complete the restore

<figure><img src="/files/cr68Y0zAaiGLlVgz2Um3" alt=""><figcaption></figcaption></figure>

* Shutdown the VM and then Eject Media

<figure><img src="/files/ll129VevQy7zPHaCaxiA" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/qJsIRw73FVHv91EmiZls" alt=""><figcaption></figcaption></figure>

* **POWER ON** the VM

<figure><img src="/files/ah6lsPfLUptVRw0u4fve" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/RXyLK7jcfLOrW2lobA33" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

<br>


# How to prepare and setup Veeam Recovery Media for Linux

## <mark style="color:green;">**Overview**</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

<img src="/files/X3Q7fk9qluGlwkN1U9hi" alt="" data-size="line"> This is a document on how to prepare and setup Veeam Recovery Media for Linux

## <mark style="color:green;">**Procedure - Prepare & setup Veeam Recovery Media for Linux**</mark> <a href="#id-2.-install-veeam-agent-for-linux" id="id-2.-install-veeam-agent-for-linux"></a>

For this Veeam Recovery Media we don’t need to make the ISO by ourselves because Veeam already public this ISO from theirs’s repository. Just download and use it.

{% stepper %}
{% step %}
**Step 1:** Access to this link: <https://repository.veeam.com/backup/linux/agent/veeam-recovery-media/>

* Choose the correct **architectures** you want (Example: **x64**).

<figure><img src="/files/LZh3lUaOswlHKwSDnLBW" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Choose the version you want download, the requirement of our portal will be v13.x and above.

<figure><img src="/files/9jU2AtWFa8iTAb8J1RpZ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Validate the ISO file after completed the download progress.

<figure><img src="/files/N0NXwlPoLzOibCZNuTku" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

The Veeam Recovery Media for Linux preparation is completed.


# How to prepare and setup Veeam Recovery Media for Windows

## <mark style="color:green;">**Overview**</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

<img src="/files/5V3Es8qPVJzazN3TQeYn" alt="" data-size="line">  This is a document on how to prepare and setup Veeam Recovery Media for Windows.

## <mark style="color:green;">**Procedure - Prepare & setup Veeam Recovery Media for Windows**</mark> <a href="#id-2.-install-veeam-agent-for-linux" id="id-2.-install-veeam-agent-for-linux"></a>

We will need Windows machine or VM to setup.

{% stepper %}
{% step %}
**Step 1:** Install Veeam Backup Agent for Windows (v13 and above).

* Deploying by BaaS portal following this guide [Install Veeam Agent for Windows | HI GIO User Guide](https://docs.higiocloud.vn/back-up-as-a-service/1.-hi-gio-baas/install-veeam-agent-for-windows)

<figure><img src="/files/PzGYwx11iqp1FMMxiwSL" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** After completed installed the Backup Agent go to **Start** > **Veeam** folder > Choose **Create Recovery Media.**

<figure><img src="/files/O3xcurIUwSmTFtP8RKTG" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** From Create Recovery Media windows you can choose what you want to include to media from current OS, after done click **Next**.

* For detail: <https://helpcenter.veeam.com/docs/agentforwindows/userguide/image_create_options.html?ver=13>

{% hint style="info" %}
**NOTE:** In VMware environments or on physical servers, if Windows uses VMXNET3 NIC drivers or other specific storage/network drivers that are not detected when booting Veeam Recovery Media, follow [this KB](https://www.veeam.com/kb4506) article to add the required drivers to the recovery media.
{% endhint %}

<figure><img src="/files/J4jsmRmZkN5Ow9J2gOIy" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
**NOTE:** To make sure Veeam Recovery Media can manually install VMXNET3/PVSCSI drivers during recovery, if the VM is deployed using the HI GIO template, you must follow [this KB](https://www.veeam.com/kb4506) article to add the required drivers into the recovery media.
{% endhint %}
{% endstep %}

{% step %}
**Step 4:** Specify Path to for the ISO file choose **Browse** to choose the correct path you want, you also can set credential for ISO too by enabling **This share requires access credentials**. After done click **Next.**

<figure><img src="/files/wy5kurlQYCCCJwpMfPMw" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Review again the config of Recovery Media you have configured. If all correct click **Create.**

<figure><img src="/files/ENMHsSjvbHon0R91hZ5e" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 6:** Wait for the creation completed, after that click **Finish**.

<figure><img src="/files/yil3TFNh0Xl0mJfsumzc" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 7:** Validate the ISO file that already choose the path from **Step 4.**

<figure><img src="/files/l6oWrTfbNaJ7pBEz30Dq" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

The Veeam Recovery Media for Windows preparation is completed.


# Restore Linux on Physical Server by Veeam Recovery Media

## <mark style="color:green;">Overview</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

This is a document on how to Restore Linux on Physical Server by Veeam Recovery Media.

## <mark style="color:green;">Procedure</mark> <a href="#id-2.-how-to-restore-linux-vm" id="id-2.-how-to-restore-linux-vm"></a>

We will need a USB to make a booting device for Veeam Recovery Media.

{% stepper %}
{% step %}
**Step 1:** Access to Microsoft Store or go to [this link](https://rufus.ie/en/) to download **Rufus.**

<figure><img src="/files/xIEsk82awTdTy5tpGTkd" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Open **Rufus**, from the **Device** option, verify and choose the correct USB drive.

<figure><img src="/files/wXW4poLJoST7WKHnVOUF" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** From **Boot selection** option click **SELECT** to choose the Veeam Recovery Media ISO file that already prepared on [this guide](https://docs.higiocloud.vn/back-up-as-a-service/1.-hi-gio-baas/how-to-prepare-and-setup-veeam-recovery-media-for-linux).

<figure><img src="/files/AuWDzero2bNeo8fZ2McK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** After seeing the **Status** option showing **READY** choose **START** to begin creating the USB bootable device (Please note that this action will erase all data exist on the USB).
{% endstep %}

{% step %}
**Step 5:** After completed creating the USB bootable device insert to the machine need to restore. Then power on the machine and choose boot from USB drive.
{% endstep %}

{% step %}
**Step 6:** Restore from a restore point

When boot is completed, choose **Proceed without SSH**

<figure><img src="/files/t1fFnJEW3vqzlnqdGWgf" alt=""><figcaption></figcaption></figure>

**Accept** license agreement

<figure><img src="/files/cAMNFY4eygxoWLBtSutA" alt=""><figcaption></figcaption></figure>

Remember to configure IP for the connection to Cloud Gateway via **Configure network**

<figure><img src="/files/htluh0UCqdU7pJpKKMUa" alt=""><figcaption></figcaption></figure>

Choose **Edit a connection**

<figure><img src="/files/3vYyQ0HOLzB5O8nUEiru" alt=""><figcaption></figcaption></figure>

Choose available **Ethernet** > **Edit**

<figure><img src="/files/bTjtn6GfW8zGOcllLA8g" alt=""><figcaption></figcaption></figure>

Input the **IP address** then choose **OK**

<figure><img src="/files/12Lq0qePWFM3cY2wE1Wu" alt=""><figcaption></figcaption></figure>

Choose **Restore volumes**

<figure><img src="/files/UK6rKpaSsAzn2N16xVG0" alt=""><figcaption></figcaption></figure>

Choose **Add** **Cloud Connect provider**

<figure><img src="/files/ukqO5l5o5g63cSDtovAA" alt=""><figcaption></figcaption></figure>

Enter address of BaaS Cloud Gateway Address:

* HCM: **backup-hcmc.higio.net**
* HN: **backup-hni.higio.net**

<figure><img src="/files/2AasO1wX7msTgq9U2OfU" alt=""><figcaption></figcaption></figure>

* **Accept** the certificate details.

<figure><img src="/files/huPHRdYcJ7zi9cTjotP4" alt=""><figcaption></figcaption></figure>

* Enter **Username** and **Password**

<figure><img src="/files/8Ah2TdP9fahKXKo3ZQpW" alt=""><figcaption></figcaption></figure>

* Select **Job** and **restore point** that want to restore

<figure><img src="/files/eTdxNYcMk8NM4KajOOEX" alt=""><figcaption></figcaption></figure>

* Choose **Hard disk** that want to restore

<figure><img src="/files/ZMfFZoAGXxoYZm3Ph11s" alt=""><figcaption></figcaption></figure>

* **Enter** and select **Restore from…**

<figure><img src="/files/RuhInfW0fDEJLUIMK9fK" alt=""><figcaption></figcaption></figure>

* Choose the exact disk want to restore

<figure><img src="/files/Dbkv7TupYk1g8rzOPCQK" alt=""><figcaption></figcaption></figure>

* Check that the mapping is correct, and then press ”s” to continue

<figure><img src="/files/90IHXwUoOvRzLeWlf6ei" alt=""><figcaption></figcaption></figure>

* Review the **Summary** of the restore job, then press Enter to begin

<figure><img src="/files/IJmNRQ9soeN3JNedwqjE" alt=""><figcaption></figcaption></figure>

* Begin the process and complete the restore

<figure><img src="/files/DWTMR5UOZvHmv0GTmrBc" alt=""><figcaption></figcaption></figure>

* Shutdown the VM and then Eject the USB drive

<figure><img src="/files/Jz3buecgl0AzJZRQjqZK" alt=""><figcaption></figcaption></figure>

Power on the machine again to boot to the Linux OS that already restored.

<figure><img src="/files/lSNxp8eGoJtVya2WpzZX" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

&#x20;


# Restore Windows on Physical Server by Veeam Recovery Media

## <mark style="color:green;">Overview</mark> <a href="#id-1.-introduction" id="id-1.-introduction"></a>

This is a document for how to restore Windows on Physical Server by Veeam Recovery Media.

## <mark style="color:green;">Procedure</mark> <a href="#id-2.-how-to-restore-windows-vm" id="id-2.-how-to-restore-windows-vm"></a>

{% stepper %}
{% step %}
**Step 1:** Access to Microsoft Store or go to [this link](https://rufus.ie/en/) to download **Rufus.**

<figure><img src="/files/Br1i1kOo1jP0CItSocvL" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Open **Rufus**, from the **Device** option, verify and choose the correct USB drive.

<figure><img src="/files/kExJztLXQtHYpJNiVTYZ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** From **Boot selection** option click **SELECT** to choose the Veeam Recovery Media ISO file that already prepared on [this guide](https://docs.higiocloud.vn/back-up-as-a-service/1.-hi-gio-baas/how-to-prepare-and-setup-veeam-recovery-media-for-windows).

<figure><img src="/files/yjbRnzC1k79FiTjT783G" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** After seeing the **Status** option showing **READY** choose **START** to begin creating the USB bootable device (Please note that this action will erase all data exist on the USB).
{% endstep %}

{% step %}
**Step 5:** After completed creating the USB bootable device insert to the machine need to restore. Then power on the machine and choose boot from USB drive.
{% endstep %}

{% step %}
**Step 6:** Restore from a restore point

When the boot is completed, choose **Bare Metal Recovery**

<figure><img src="/files/iOoQErijd096XEXsakVd" alt=""><figcaption></figcaption></figure>

Choose **Network storage**

<figure><img src="/files/5ZbccDeKxJt6jsWbxa9L" alt=""><figcaption></figcaption></figure>

Remember to configure IP for the connection to Cloud Gateway via **Configure network settings**

<figure><img src="/files/PdtRiijJ7TPH5Lu9XAQ6" alt=""><figcaption></figcaption></figure>

Choose available **Ethernet** > **Properties.**

<figure><img src="/files/t8UPqX6IbIyHaP0vFDEO" alt=""><figcaption></figcaption></figure>

Input the **IP address,** then choose **OK**

<figure><img src="/files/gqyU996e1aXTVMWD3nYG" alt=""><figcaption></figcaption></figure>

Choose the **Veeam Cloud Connect repository**

<figure><img src="/files/eWyk1fNxCP5JRo8Cj0Vf" alt=""><figcaption></figcaption></figure>

Enter the address of BaaS Cloud Gateway Address:

* HCM: **backup-hcmc.higio.net**&#x20;
* HN: **backup-hni.higio.net**

<figure><img src="/files/kKxHWypjNMIYfRQ6eFjg" alt=""><figcaption></figcaption></figure>

* **Continue** on the certificate details.

<figure><img src="/files/PaTqHqOZr7bBbHWD2rqG" alt=""><figcaption></figcaption></figure>

* Enter **Username** and **Password**

<figure><img src="/files/DFF6VvFClHb9kfjosFQ4" alt=""><figcaption></figcaption></figure>

* Select **Job** that want to restore

<figure><img src="/files/hWLkGUiQJoZdXE22VSgy" alt=""><figcaption></figcaption></figure>

* Select restore point that want to restore

<figure><img src="/files/NUEwuci6TQyp4qnMtmXB" alt=""><figcaption></figcaption></figure>

* Choose **Restore Mode**

<figure><img src="/files/Y4p1b85jSSEAW2edrV0b" alt=""><figcaption></figcaption></figure>

* Review **Summary** of restore job

<figure><img src="/files/bXu0jcE7fpON6MV7tZW8" alt=""><figcaption></figcaption></figure>

* Begin the process and complete the restore

<figure><img src="/files/cr68Y0zAaiGLlVgz2Um3" alt=""><figcaption></figcaption></figure>

* Shutdown the VM and then Eject the USB drive

<figure><img src="/files/ll129VevQy7zPHaCaxiA" alt=""><figcaption></figcaption></figure>

* Power on the machine again to boot to the Windows OS that already restored.

<figure><img src="/files/qa98PXRnRvRBRXB2lsYX" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

<br>


# How to configure receive Alarm from BaaS

## <mark style="color:green;">**Overview**</mark> <a href="#introduction" id="introduction"></a>

This is a document for how to configure receive Alarm from BaaS

## <mark style="color:green;">**Procedure**</mark> <a href="#guidance" id="guidance"></a>

{% stepper %}
{% step %}
**Step 1:** Access by URL:

* HN site: <https://portal-hni-backup.higio.net/>
* HCM site: [https://portal-hcmc-backup.higio.net/](https://portal-hni-backup.higio.net/)

Log in, then click **Configuration**:

<figure><img src="/files/L9tok0mpCdDDxcu3SR7z" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Choose **Templates > Predefined Alarms** and then choose the alarm that wants to notification to set up the parameter:

<figure><img src="/files/OPjx8ecQnQar9Z5MF88U" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
**Attention:** The details of all the alarms in the Veeam document are as follows.

Alarms - Use the Veeam Service Provider Console Guide, or you can read the Knowledge Base option in Edit Alarm.
{% endhint %}
{% endstep %}

{% step %}
**Step 3:** Choose specific rule by **Tick a rule > Edit** to define **Rules** to get the notification or **Add** more parameters:

<figure><img src="/files/0isPF0lgdx1tL5vKiA3M" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/i2bCDajApufHgPijE2rV" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Define **Actions** to Receive the notification. We have 2 methods and can **Add** more parameters, too:

* **Send email notification:** Input the email for the received notification (separate by commas).
* **Execute script:** execute a custom script that you want.

Then, choose the **condition** to trigger the **actions**.

<figure><img src="/files/nutJ2lsA2dAZcpjRZCQr" alt=""><figcaption></figcaption></figure>

<mark style="color:red;">**Attention:**</mark> If you have defined the email on your user profile, you can specify it by role instead of email.
{% endstep %}

{% step %}
**Step 5:** Click **Finish** to save Alarm Settings:

<figure><img src="/files/2cFuhZAfqK8d3HOvMyQd" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 6:** **Enable** it to use the Alarm:

<figure><img src="/files/L2BeT7nm79v8221ue9KN" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Workaround

## <mark style="color:green;">Procedure</mark>

Please refer to the other guides in the list below.

* [Veeam Agent Installation for CentOS 9 Stream](/back-up-as-a-service/1.-hi-gio-baas/workaround/veeam-agent-installation-for-centos-9-stream)
* [Veeam Agent Installation for CentOS 8 Stream](/back-up-as-a-service/1.-hi-gio-baas/workaround/veeam-agent-installation-for-centos-8-stream)
* [Veeam Agent Installation for RHEL 9.2](/back-up-as-a-service/1.-hi-gio-baas/workaround/veeam-agent-installation-for-rhel-9.2)


# Veeam Agent Installation for CentOS 9 Stream

## <mark style="color:green;">Overview</mark> <a href="#introduction" id="introduction"></a>

This document is for installing the Veeam Backup Agent Linux on CentOS 9 Stream.

## <mark style="color:green;">Procedure</mark> <a href="#guidance" id="guidance"></a>

* OS: CentOS 9 Stream, running kernel 5.14.0-344.el9.x86\_64
* Veeam repository:  veeam-release-el9-1.0.8-1.x86\_64.rpm
* Veeam Agent: veeam-6.0.3.1221-1.el9.x86\_64

{% tabs %}
{% tab title="1. Install with non-UEFI Secure" %}
**Step 1: Download Veeam repository:**

The Veeam repository for Linux can be found at [![](https://repository.veeam.com/favicon.ico)Index of /backup/linux/agent/rpm/el/9/x86\_64/](https://repository.veeam.com/backup/linux/agent/rpm/el/9/x86_64/) . On this page, select "**veeam-release-el9-1.0.8-1.x86\_64.rpm**".

<figure><img src="/files/f4adSLx1eaFo5UqvfCkW" alt=""><figcaption></figcaption></figure>

**Step 2: Install Veeam and dependencies:**

* This will download an RPM file.  You will likely be unable to download this directly from this page to your Linux machine, as your server will likely not have a GUI or web browser.  To get around this, it is best to download the RPM to your workstation and then use WinSCP or MobaXterm to copy the RPM file to your server via SSH.
* Once the RPM is on your server, install it and its dependencies:

```
# dnf clean all 
# rpm -hi veeam-release-el9-1.0.8-1.x86_64.rpm 
# dnf install epel-release -y 
# dnf install dkms python3 make gcc perl kernel-modules-extra -y 
# dnf update 
# dnf install blksnap veeam -y
```

* The modules bdevfilter and blksnap will be created in /lib/modules/$(uname -r)/extra

```xml
[root@centos9 ~# ls /lib/modules/$(uname -r)/extra bdevfilter.ko.xz blksnap.ko.xz
```

* We can confirm that this module has not loaded by running lsmod, and grepping for blksnap.  We will see that grep returns 0 lines of output.

```
[root@centos9 ~]# lsmod | grep blksnap 0
```

**Step 3:** Insert modules bdevfilter and blksnap:

{% hint style="warning" %}
Important: If the server boots with Secure Boot, we can’t insert the module → Must run step 3 on Secure Boot below first.
{% endhint %}

We need to load the module into the currently running kernel using insmod:

```
[root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/bdevfilter.ko.xz 
[root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/blksnap.ko.xz 
[root@centos9 ~]# lsmod | grep blksnap 
blksnap 217088 0 
bdevfilter 20480 1 blksnap

```

At this point, our agent-based backups will run fine; however, the loaded module will not persist if we reboot.  We must create a file called /etc/modules-load.d/bdevfilter.conf and/etc/modules-load.d/blksnap.conf , and make sure that it has the name of the kernel module.  We must also run depmod to add the loaded kernel module to the kernel module dependencies list.

```
[root@centos9 ~]# depmod
[root@centos9 ~]# echo bdevfilter > /etc/modules-load.d/bdevfilter.conf
[root@centos9 ~]# echo blksnap > /etc/modules-load.d/blksnap.conf
[root@centos9 ~]# cat /etc/modules-load.d/bdevfilter.conf
bdevfilter
[root@centos9 ~]# cat /etc/modules-load.d/blksnap.conf
blksnap
```

Once we reboot the CentOS server, the veeamsnap module will automatically be loaded as a kernel module.

```
[root@centos9 ~]# uptime && lsmod | grep blksnap
 17:43:06 up 18 min,  1 user,  load average: 0.00, 0.00, 0.00
blksnap               217088  0
bdevfilter             20480  1 blksnap
```

<figure><img src="/files/cwAwy90jHK0X4ORk4fQ3" alt=""><figcaption></figcaption></figure>

And our agent-based backups will now work correctly.

Grand permission for 3 scripts:

`# chmod u+x one-time-setup sign-modules dkms-sign-module`

Create 2 files for signing modules to the UEFI database.

```
# echo POST_BUILD=../../../../../../root/module-signing/dkms-sign-module > /etc/dkms/bdevfilter.conf
# echo POST_BUILD=../../../../../../root/module-signing/dkms-sign-module > /etc/dkms/blksnap.conf
```

Run the file one-time-setup first and then reboot:

```
# /root/module-signing/one-time-setup
# reboot
```

During the reboot, when prompted, press any key to perform MOK management.

<div align="left"><figure><img src="/files/m3MFCNdIPxmWWWicMKuM" alt=""><figcaption></figcaption></figure></div>

At the wizard's first step, select **Enroll MOK** and press \[Enter].

<div align="left"><figure><img src="/files/6wjvSUCH3oxIopfGehPI" alt=""><figcaption></figcaption></figure></div>

At the **Enroll the key(s)** step, select **Yes** and press \[Enter].

<div align="left"><figure><img src="/files/lWrfqZpbmCqY0C99LhFX" alt=""><figcaption></figcaption></figure></div>

Provide the password for the root account and press \[Enter].

<div align="left"><figure><img src="/files/qESWIoqHXdKCsSv8mRjF" alt=""><figcaption></figcaption></figure></div>

At the final step, select **Reboot** and press \[Enter].

<div align="left"><figure><img src="/files/wUuql2cCtEvY8UGSLqRJ" alt=""><figcaption></figcaption></figure></div>

After that, sign 2 modules by running file sign-modules:

```
# /root/module-signing/sign-modules /lib/modules/$(uname -r)/extra/bdevfilter.ko.xz
# /root/module-signing/sign-modules /lib/modules/$(uname -r)/extra/blksnap.ko.xz
```

**Step 4: Insert modules bdevfilter and blksnap:**

We need to load the module into the currently running kernel using insmod:

```
[root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/bdevfilter.ko.xz
[root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/blksnap.ko.xz
[root@centos9 ~]# lsmod | grep blksnap
blksnap               217088  0
bdevfilter             20480  1 blksnap
```

At this point, our agent-based backups will run fine; however, the loaded module will not persist if we reboot.  We must create a file called /etc/modules-load.d/bdevfilter.conf and/etc/modules-load.d/blksnap.conf , and make sure that it has the name of the kernel module.  We must also run depmod to add the loaded kernel module to the kernel module dependencies list.

```
[root@centos9 ~]# depmod
[root@centos9 ~]# echo bdevfilter > /etc/modules-load.d/bdevfilter.conf
[root@centos9 ~]# echo blksnap > /etc/modules-load.d/blksnap.conf
[root@centos9 ~]# cat /etc/modules-load.d/bdevfilter.conf
bdevfilter
[root@centos9 ~]# cat /etc/modules-load.d/blksnap.conf
blksnap
```

Once we reboot the CentOS server, the veeamsnap module will automatically be loaded as a kernel module.

```
[root@centos9 ~]# uptime && lsmod | grep blksnap
 17:43:06 up 18 min,  1 user,  load average: 0.00, 0.00, 0.00
blksnap               217088  0
bdevfilter             20480  1 blksnap
```

And our agent-based backups will now work correctly.
{% endtab %}

{% tab title="2. Install with Secure Boot" %}
**Step 1: Download Veeam repository:**

The Veeam repository for Linux can be found at [![](https://repository.veeam.com/favicon.ico)Index of /backup/linux/agent/rpm/el/9/x86\_64/](https://repository.veeam.com/backup/linux/agent/rpm/el/9/x86_64/) . On this page, select "veeam-release-el9-1.0.8-1.x86\_64.rpm".

<div align="left"><figure><img src="/files/vebUDOmO3ayUC4CvSZy2" alt=""><figcaption></figcaption></figure></div>

**Step 2: Install Veeam and dependencies:**

* This will download an RPM file.  You will likely be unable to download this directly from this page to your Linux machine, as your server will likely not have a GUI or web browser.  To get around this, it is best to download the RPM to your workstation and then use WinSCP or MobaXterm to copy the RPM file to your server via SSH.
* Once the RPM is on your server, install it and its dependencies:

```
# dnf clean all
# rpm -hi veeam-release-el9-1.0.8-1.x86_64.rpm
# dnf install epel-release -y
# dnf install dkms python3 make gcc perl kernel-modules-extra -y
# dnf update
# dnf install blksnap veeam -y
```

* The modules bdevfilter and blksnap will be created in /lib/modules/$(uname -r)/extra

```
[root@centos9 ~]# ls /lib/modules/$(uname -r)/extra
bdevfilter.ko.xz  blksnap.ko.xz
```

* We can confirm that this module has not loaded by running lsmod, and grepping for blksnap.  We will see that grep returns 0 lines of output.

```
[root@centos9 ~]# lsmod | grep blksnap 
0
```

**Step 3:** Enrolling Veeam Kernel Module Key:

Create a directory /root/module-signing:

```
# mkdir module-signing/
```

Download 3 scripts from the link: [![](https://gist.github.com/favicon.ico)Make DKMS sign kernel modules on installation, with full script support and somewhat distro independent](https://gist.github.com/sbueringer/bd8cec239c44d66967cf307d808f10c4) and put it in the directory just created:

Grand permission for 3 scripts:

`# chmod u+x one-time-setup sign-modules dkms-sign-module`

Create 2 files for signing modules to the UEFI database.

```
# echo POST_BUILD=../../../../../../root/module-signing/dkms-sign-module > /etc/dkms/bdevfilter.conf
# echo POST_BUILD=../../../../../../root/module-signing/dkms-sign-module > /etc/dkms/blksnap.conf
```

Run the file one-time-setup first and then reboot:

```
# /root/module-signing/one-time-setup
# reboot
```

During the reboot, when prompted, press any key to perform MOK management.

<div align="left"><figure><img src="/files/m3MFCNdIPxmWWWicMKuM" alt=""><figcaption></figcaption></figure></div>

At the wizard's first step, select **Enroll MOK** and press \[Enter].

<div align="left"><figure><img src="/files/6wjvSUCH3oxIopfGehPI" alt=""><figcaption></figcaption></figure></div>

At the **Enroll the key(s)** step, select **Yes** and press \[Enter].

<div align="left"><figure><img src="/files/lWrfqZpbmCqY0C99LhFX" alt=""><figcaption></figcaption></figure></div>

Provide the password for the root account and press \[Enter].

<div align="left"><figure><img src="/files/qESWIoqHXdKCsSv8mRjF" alt=""><figcaption></figcaption></figure></div>

At the final step, select **Reboot** and press \[Enter].

<div align="left"><figure><img src="/files/wUuql2cCtEvY8UGSLqRJ" alt=""><figcaption></figcaption></figure></div>

After that, sign 2 modules by running file sign-modules:

```
# /root/module-signing/sign-modules /lib/modules/$(uname -r)/extra/bdevfilter.ko.xz
# /root/module-signing/sign-modules /lib/modules/$(uname -r)/extra/blksnap.ko.xz
```

**Step 4: Insert modules bdevfilter and blksnap:**

We need to load the module into the currently running kernel using insmod:

```
[root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/bdevfilter.ko.xz
[root@centos9 ~]# insmod /lib/modules/$(uname -r)/extra/blksnap.ko.xz
[root@centos9 ~]# lsmod | grep blksnap
blksnap               217088  0
bdevfilter             20480  1 blksnap
```

At this point, our agent-based backups will run fine; however, the loaded module will not persist if we reboot.  We must create a file called /etc/modules-load.d/bdevfilter.conf and/etc/modules-load.d/blksnap.conf , and make sure that it has the name of the kernel module.  We must also run depmod to add the loaded kernel module to the kernel module dependencies list.

```
[root@centos9 ~]# depmod
[root@centos9 ~]# echo bdevfilter > /etc/modules-load.d/bdevfilter.conf
[root@centos9 ~]# echo blksnap > /etc/modules-load.d/blksnap.conf
[root@centos9 ~]# cat /etc/modules-load.d/bdevfilter.conf
bdevfilter
[root@centos9 ~]# cat /etc/modules-load.d/blksnap.conf
blksnap
```

Once we reboot the CentOS server, the veeamsnap module will automatically be loaded as a kernel module.

```
[root@centos9 ~]# uptime && lsmod | grep blksnap
 17:43:06 up 18 min,  1 user,  load average: 0.00, 0.00, 0.00
blksnap               217088  0
bdevfilter             20480  1 blksnap
```

And our agent-based backups will now work correctly.
{% endtab %}
{% endtabs %}


# Veeam Agent Installation for CentOS 8 Stream

## <mark style="color:green;">**Overview**</mark> <a href="#introduction" id="introduction"></a>

This document is for installing the Veeam Backup Agent Linux on CentOS 8 Stream

## <mark style="color:green;">**Procedure**</mark> <a href="#guidance" id="guidance"></a>

* OS: CentOS is 8 Stream, running kernel 4.18.0-500.el8.x86\_64
* Veeam repository:  veeam-release-el8-1.0.8-1.x86\_64.rpm
* Veeam Agent: veeam-6.0.3.1221-1.el8.x86\_64

{% tabs %}
{% tab title="1. Install with non-UEFI Secure" %}
**Step 1: Download Veeam repository:**

The Veeam repository for Linux can be found at [![](https://repository.veeam.com/favicon.ico)Index of /backup/linux/agent/rpm/el/8/x86\_64/](https://repository.veeam.com/backup/linux/agent/rpm/el/8/x86_64/). On this page select "veeam-release-el8-1.0.8-1.x86\_64.rpm".

<div align="left"><figure><img src="/files/UmVlwIaQPNyN4n79wbWh" alt=""><figcaption></figcaption></figure></div>

**Step 2: Install Veeam:**

* This will download an RPM file.  It is likely that you will be unable to download this directly from this page to your Linux machine, as your server will most likely not have a GUI and a web browser.  To get around this it is best to download the RPM to your workstation, then use WinSCP or MobaXterm to copy the RPM file to your server via SSH.
* Once the RPM is on your server, install it.

```
# dnf clean all
# rpm -hi veeam-release-el8-1.0.8-1.x86_64.rpm
# dnf install -y veeam
```

* This will install the required packages for the Veeam agent, including a kmod-veeamsnap package; however, you will notice that there are still issues with the Linux kernel module for veeamsnap.  If we inspect the files installed with kmod-veeamsnap, and compare it with our current kernel version, we can see that the kernel module is not installed for our version.  The difference is very minute.

```
[root@centos8 ~]# uname -r
4.18.0-500.el8.x86_64

[root@centos8 ~]# dnf download kmod-veeamsnap
Last metadata expiration check: 0:32:53 ago on Mon 07 Aug 2023 04:10:27 PM +07.
kmod-veeamsnap-6.0.3.1221-1.el8.x86_64.rpm

[root@centos8 ~]# rpm -qlp kmod-veeamsnap-6.0.3.1221-1.el8.x86_64.rpm | grep ko$
/lib/modules/4.18.0-147.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-193.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-240.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-305.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-348.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-372.9.1.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-425.10.1.el8_7.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-425.3.1.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-477.10.1.el8_8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-80.el8.x86_64/extra/veeamsnap.ko
```

* From this, we can see that the kernel module was installed for 4.18.0-**477**.10.1.el8\_7.x86\_64, but our current kernel is 4.18.0-**500**.el8.x86\_64. &#x20;
* Without this kernel module, our agent based Veeam backups will fail.
* We can confirm that this module has not loaded by running lsmod, and grepping for Veeam.  We will see that grep returns 0 lines of output.

```
[root@centos8 ~]# lsmod | grep veeam -c 
0
```

* Fortunately, the difference in these kernel versions is small enough that the veeamsnap.ko file will still work for us. &#x20;
* First, we must create the /extra/ directory for our kernel version, then copy the kernel module to this directory.

```
[root@centos8 ~]# mkdir -p /lib/modules/$(uname -r)/extra
[root@centos8 ~]# cp /lib/modules/4.18.0-477.10.1.el8_7.x86_64/extra/veeamsnap.ko /lib/modules/$(uname -r)/extra/.
[root@centos8 ~]# ls /lib/modules/$(uname -r)/extra
veeamsnap.ko
```

**Step 3: Insert module veeamsnap:**

{% hint style="warning" %}
**Important:** If the server boots with Secure Boot, we can’t insert the module → Must run step 3 on Secure Boot below first.
{% endhint %}

We need to load the module into the currently running kernel using insmod:

```
[root@centos8 ~]# insmod /lib/modules/$(uname -r)/extra/veeamsnap.ko
[root@centos8 ~]# lsmod | grep veeam
veeamsnap             225280  0
```

At this point, our agent based backups will run fine; however, the loaded module will not persist if we reboot.  We will need to create a file called /etc/modules-load.d/veeam.conf, and make sure that it has the name of the kernel module in it.  We will also need to run depmod to add the loaded kernel module into the kernel module dependencies list.

```
[root@centos8 ~]# depmod
[root@centos8 ~]# echo veeamsnap > /etc/modules-load.d/veeam.conf
[root@centos8 ~]# cat /etc/modules-load.d/veeam.conf
veeamsnap
```

Now, once we reboot the CentOS server, the veeamsnap module will automatically be loaded as a kernel module.

```
[root@centos8 ~]# uptime && lsmod | grep veeam
 14:55:59 up 0 min,  1 user,  load average: 0.00, 0.00, 0.00
veeamsnap             225280  0
```

And our agent-based backups will now work correctly.
{% endtab %}

{% tab title="2. Install with Secure Boot" %}
**Step 1: Download Veeam repository:**

The Veeam repository for Linux can be found at [![](https://repository.veeam.com/favicon.ico)Index of /backup/linux/agent/rpm/el/8/x86\_64/](https://repository.veeam.com/backup/linux/agent/rpm/el/8/x86_64/) . On this page select "veeam-release-el8-1.0.8-1.x86\_64.rpm".

<div align="left"><figure><img src="/files/SA21xRfcXYeIEQVg3blO" alt=""><figcaption></figcaption></figure></div>

**Step 2: Install Veeam:**

* This will download an RPM file.  It is likely that you will be unable to download this directly from this page to your Linux machine, as your server will most likely not have a GUI and a web browser.  To get around this it is best to download the RPM to your workstation, then use WinSCP or MobaXterm to copy the RPM file to your server via SSH.
* Once the RPM is on your server, install it.

```
# dnf clean all
# rpm -hi veeam-release-el8-1.0.8-1.x86_64.rpm
# dnf install -y veeam
```

* This will install the required packages for the Veeam agent, including a kmod-veeamsnap package; however, you will notice that there are still issues with the Linux kernel module for veeamsnap.  If we inspect the files installed with kmod-veeamsnap, and compare it with our current kernel version, we can see that the kernel module is not installed for our version.  The difference is very minute.

```
[root@centos8 ~]# uname -r
4.18.0-500.el8.x86_64

[root@centos8 ~]# dnf download kmod-veeamsnap
Last metadata expiration check: 0:32:53 ago on Mon 07 Aug 2023 04:10:27 PM +07.
kmod-veeamsnap-6.0.3.1221-1.el8.x86_64.rpm

[root@centos8 ~]# rpm -qlp kmod-veeamsnap-6.0.3.1221-1.el8.x86_64.rpm | grep ko$
/lib/modules/4.18.0-147.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-193.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-240.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-305.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-348.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-372.9.1.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-425.10.1.el8_7.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-425.3.1.el8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-477.10.1.el8_8.x86_64/extra/veeamsnap.ko
/lib/modules/4.18.0-80.el8.x86_64/extra/veeamsnap.ko
```

* From this we can see that the kernel module was installed for 4.18.0-**477**.10.1.el8\_7.x86\_64, but our current kernel is 4.18.0-**500**.el8.x86\_64. &#x20;
* Without this kernel module, our agent based Veeam backups will fail.
* We can confirm that this module has not loaded by running lsmod, and grepping for Veeam.  We will see that grep returns 0 lines of output.

```
[root@centos8 ~]# lsmod | grep veeam -c
0
```

* Fortunately, the difference in these kernel versions is small enough that the veeamsnap.ko file will still work for us. &#x20;
* First, we need to create the /extra/ directory for our kernel version, then copy the kernel module over to this directory.

```
[root@centos8 ~]# mkdir -p /lib/modules/$(uname -r)/extra
[root@centos8 ~]# cp /lib/modules/4.18.0-477.10.1.el8_7.x86_64/extra/veeamsnap.ko /lib/modules/$(uname -r)/extra/.
[root@centos8 ~]# ls /lib/modules/$(uname -r)/extra
veeamsnap.ko
```

**Step 3: Enrolling Veeam Kernel Module Key:**

Install the package that contains the public key for pre-built Veeam kernel module by using the following command:

```
# dnf install veeamsnap-ueficert -y
```

We will have the notification like this:

```
Certificate /etc/uefi/certs/veeamsnap-ueficert.crt has been imported successfully, please reboot this computer to enroll it into the UEFI database.
```

Reboot the computer to enroll the Veeam public key into the UEFI database.

During reboot, when prompted, press any key to perform MOK management.

<figure><img src="/files/ZozipjlrsQsOWFDrIrSv" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
**Important:** The prompt will time out in 10 seconds. If you don't press any key, the system will continue booting without enrolling the key. If you don't enroll the key at reboot, you will have to reconfigure the key by reinstalling the ueficert package and reboot again
{% endhint %}

At the first step of the wizard, select **Enroll MOK** and press \[Enter].

<figure><img src="/files/ow5WkUzxpX5Ll5bWtlxS" alt=""><figcaption></figcaption></figure>

At the **Enroll the key(s)** step, select **Yes** and press \[Enter].

<figure><img src="/files/Ree8MF2iGsZMFDffWuaW" alt=""><figcaption></figcaption></figure>

Provide the password for the root account and press \[Enter].

<figure><img src="/files/vpfMluj3A2eKjbDodJjZ" alt=""><figcaption></figcaption></figure>

At the final step, select **Reboot** and press \[Enter].

<figure><img src="/files/vVJNTdcGucDuleRIuCW3" alt=""><figcaption></figcaption></figure>

**Step 4: Insert module veeamsnap:**

We need to load the module into the currently running kernel using insmod:

```
[root@centos8 ~]# insmod /lib/modules/$(uname -r)/extra/veeamsnap.ko
[root@centos8 ~]# lsmod | grep veeam
veeamsnap             225280  0
```

At this point, our agent based backups will run fine; however, the loaded module will not persist if we reboot.  We will need to create a file called /etc/modules-load.d/veeam.conf, and make sure that it has the name of the kernel module in it.  We will also need to run depmod to add the loaded kernel module into the kernel module dependencies list.

```
[root@centos8 ~]# depmod
[root@centos8 ~]# echo veeamsnap > /etc/modules-load.d/veeam.conf
[root@centos8 ~]# cat /etc/modules-load.d/veeam.conf
veeamsnap
```

Now, once we reboot the CentOS server, the veeamsnap module will automatically be loaded as a kernel module.

```
[root@centos8 ~]# uptime && lsmod | grep veeam
 14:55:59 up 0 min,  1 user,  load average: 0.00, 0.00, 0.00
veeamsnap             225280  0
```

And our agent-based backups will now work correctly.
{% endtab %}
{% endtabs %}


# Veeam Agent Installation for RHEL 9.2

## <mark style="color:green;">Overview</mark> <a href="#introduction" id="introduction"></a>

This document is for installing the Veeam Backup Agent Linux on RHEL 9.2

## <mark style="color:green;">Procedure</mark> <a href="#guidance" id="guidance"></a>

* OS: RHEL 9.2, running kernel 5.14.0-362.13.1.el9\_3.x86\_64
* Veeam repository:  veeam-release-el9-1.0.8-1.x86\_64.rpm
* Veeam Agent: veeam-6.0.3.1221-1.el9.x86\_64
* Veeam blksnap module: blksnap-6.0.3.1221-1

{% tabs %}
{% tab title="1. Install with non-UEFI Secure" %}
**Step 1: Download Veeam repository:**

The Veeam repository for Linux can be found at [![](https://repository.veeam.com/favicon.ico)Index of /backup/linux/agent/rpm/el/9/x86\_64/](https://repository.veeam.com/backup/linux/agent/rpm/el/9/x86_64/) . On this page select "veeam-release-el9-1.0.8-1.x86\_64.rpm", “blksnap-6.0.3.1221-1.noarch.rpm”, “veeam-6.0.3.1221-1.el9.x86\_64.rpm“.

<div align="left"><figure><img src="/files/fgzc2ZyAplVCmyQoURqT" alt=""><figcaption></figcaption></figure></div>

**Step 2: Install Veeam and dependencies:**

* This will download an RPM file.  You will likely be unable to download this directly from this page to your Linux machine, as your server will likely not have a GUI or web browser.  To get around this, it is best to download the RPM to your workstation and then use WinSCP or MobaXterm to copy the RPM file to your server via SSH.
* Once the RPM is on your server, install it and its dependencies:

```
# sudo rpm -ivh veeam-release-el9-1.0.8-1.x86_64.rpm
# sudo subscription-manager repos --enable codeready-builder-for-rhel-9-$(arch)-rpms
# sudo dnf install \
https://dl.fedoraproject.org/pub/epel/epel-release-latest-9.noarch.rpm
# sudo yum install dkms perl kernel-modules-extra -y
# sudo rpm -ivh blksnap-6.0.3.1221-1.noarch.rpm
# sudo rpm -ivh veeam-6.0.3.1221-1.el9.x86_64.rpm
```

The modules bdevfilter and blksnap will be created in /lib/modules/$(uname -r)/extra

```
[root@rhel9 ~# ls /lib/modules/$(uname -r)/extra
bdevfilter.ko.xz  blksnap.ko.xz
```

We can confirm that this module has not loaded by running lsmod, and grepping for blksnap.  We will see that grep returns no output.

```
[root@rhel9 ~]# lsmod | grep blksnap
```

**Step 3: Insert modules bdevfilter and blksnap:**

We need to load the module into the currently running kernel using insmod:

```
[root@rhel9 ~]# sudo insmod /lib/modules/$(uname -r)/extra/bdevfilter.ko.xz
[root@rhel9 ~]# sudo insmod /lib/modules/$(uname -r)/extra/blksnap.ko.xz
[root@rhel9 ~]# lsmod | grep blksnap
blksnap               217088  0
bdevfilter             20480  1 blksnap
```

At this point, our agent-based backups will run fine; however, the loaded module will not persist if we reboot.  We must create a file called /etc/modules-load.d/bdevfilter.conf and/etc/modules-load.d/blksnap.conf , and make sure that it has the name of the kernel module.  We will also need to run depmod to add the loaded kernel module to the kernel module dependencies list.

```
[root@rhel9 ~]# sudo depmod
[root@rhel9 ~]# sudo echo bdevfilter > /etc/modules-load.d/bdevfilter.conf
[root@rhel9 ~]# sudo echo blksnap > /etc/modules-load.d/blksnap.conf
[root@rhel9 ~]# cat /etc/modules-load.d/bdevfilter.conf
bdevfilter
[root@rhel9 ~]# cat /etc/modules-load.d/blksnap.conf
blksnap
```

Once we reboot the RHEL server, the bdevfilter and blksnap module will automatically be loaded as a kernel module.

```
[root@rhel9 ~]# uptime && lsmod | grep blksnap
 17:43:06 up 18 min,  1 user,  load average: 0.00, 0.00, 0.00
blksnap               217088  0
bdevfilter             20480  1 blksnap
```

And our agent-based backups will now work correctly.
{% endtab %}

{% tab title="Second Tab" %}

{% endtab %}
{% endtabs %}


# 2. HI GIO Backup

## <mark style="color:green;">Overview</mark>

{% hint style="info" %}
![](/files/qecUBpy1n8jbgTFF7ab3)

We offer a high-speed Backup & Recovery solution with **VM servers** in a single portal, exclusively available for **HI GIO Gen.2.** This is a document for how to:

* How to access to Veeam Backup
* How to create Backup Jobs
* How to perform Backup
* How to perform Restore
  {% endhint %}

## <mark style="color:green;">Procedure</mark>

{% tabs %}
{% tab title="1. How to access to Veeam Backup" %}
**Step 1:** From the main menu vCD Portal, select **More Data Protection with Veeam**

<figure><img src="/files/dneWmr9BS7WREKkz2PTh" alt=""><figcaption></figcaption></figure>

**Step 2:** The **Dashboard** will display statistics:

* Number of VMs backed up
* Number of backup jobs configured
* Total storage quota
* Used storage size
* Status of backup jobs
* Average data transfer speed

{% endtab %}

{% tab title="2. How to Create Backup Jobs" %}
**Step 1:** Select the tab **Jobs**

**Step 2:** Select **Create**

<figure><img src="/files/uaGiyAwi5JYCMKdEocPQ" alt=""><figcaption></figcaption></figure>

**Step 3:** Open the **Backup Job** window

<figure><img src="/files/eucwvY0CXrqkG03DEVsa" alt=""><figcaption></figcaption></figure>

**Step 4:** Input the backup job name in the box **Job name**

**Step 5:** Input a description of the backup job in the box **Description** (or keep default)

**Step 6:** Select the number of **Restore points** to keep

After each successful backup, the system creates a version of the data during that backup, called a restore point.

If a customer needs to backup 1 VM daily, once a day, and store all those backups in the last 15 days, the number of restore points customers need to set is 15.

{% hint style="info" %}
*(Note: The more restore points, the storage usage of customers increase)*
{% endhint %}

Select **Next** to continue.

**Step 7:** At the tab **Virtual Machines**, select **Add**

<figure><img src="/files/y1NZdyPkBiJcsKm1opiI" alt=""><figcaption></figcaption></figure>

**Step 8:** Select VM need backup, select **OK**

*Select symbol + to open the components until the list of VMs appears (VM will be at the last symbol +)*

Select **Next** to continue.

<figure><img src="/files/g7rDQ0lQC2z90x5MfeW1" alt=""><figcaption></figcaption></figure>

**Step 9:** (Optional) Set some advanced features (can keep default)

Select **Next** to continue.

<figure><img src="/files/RZvRWLonLhWZBJnv99mQ" alt=""><figcaption></figcaption></figure>

**Step 10:** Schedule a backup job

Check the box **Run the job automatically,** and let the system automatically backup according to the set schedule.

Specify the time to backup (every day, every month, specific days of the week, …)

* **Automatic retry:** Option to run the backup job again if the job fails for some reason.
* **Wait before each attempt for:** interval between retry.

<figure><img src="/files/nfGwtTpId5yGgUuGtNHo" alt=""><figcaption></figcaption></figure>

**Step 11:** (Optional) Setting Email Notifications

Check the box **Enable e-mail notifications** to turn on notifications

Input e-mail address in the box **Recipients**

Select cases to receive notifications:

* **Notify on success:** Receive email notification if the job is completed successfully
* **Notify on warning:** Receive an email notification if the job is completed with a warning
* **Notify on error:** Receive email notification if the job fails
* **Suppress notifications until the last retry:** Receive email notification about the final job status

<figure><img src="/files/3xxcgy51ZcTQMs2Pvuot" alt=""><figcaption></figcaption></figure>

{% endtab %}

{% tab title="3. How to perform Backup" %}
**Step 1:** After creating the Backup Jobs, the created backup jobs will display in the tab **Jobs**.

<figure><img src="/files/QjS9K2uADmm5I24j7G22" alt=""><figcaption></figcaption></figure>

**Step 2:** To execute the backup job, select the backup job and select **Start**

Here, the customer can also select **Stop** to stop the backup job

<figure><img src="/files/niH1x6gnNGydKDWrp0N5" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="4. How to perform Restore" %}
**Step 1:** Select tab **VMs**

The list of VMs that have been successfully backed up and the number of restore points corresponding to each VM will be displayed here.

**Step 2:** Select VM needs to be restored, select **Restore VM Overwrite**

* **Overwrite:** Backup data will be restored overwriting the current VM
* **Keep:** Backup data will be restored as a new VM

<figure><img src="/files/g4cy9l7Tn4DqFBjWB30x" alt=""><figcaption></figcaption></figure>

**Step 3:** Select the restore point needed to restore

Check the box **Power on a machine after restoring** to power on the VM after the restore is complete.

<figure><img src="/files/ROq0zctX8wIyqi0HeH8G" alt=""><figcaption></figcaption></figure>

**Step 4:** Select **History** to view restore history and restore process

<figure><img src="/files/lwqq3qNlgJ05LG5UITm4" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/ykjZY2BAFpjUnxwRIIa9" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}


# Restore Entire VM via vCD's portal

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

With the option of Entire recovery, you can restore an entire VM from a backup file to the latest state or to a previous point in time if the original VM fails. Entire VM restore enables full disk I/O performance.

## <mark style="color:green;">**Requirement**</mark>

* Check your available resources.
* Create a new vApp to restore the VM if you want to restore it to a new location.
* Add the original VM network to the new vApp.

## <mark style="color:green;">**Procedure**</mark>

* Choose the VM and point that needs to be restored with Entire Recovery.
* Select Restore mode.
* Verify status restore.

{% stepper %}
{% step %}

#### Step 1. From the main menu vCD Portal, select More -> Data Protection with Veeam <a href="#step-1.-from-the-main-menu-vcd-portal-select-more-greater-than-data-protection-with-veeam" id="step-1.-from-the-main-menu-vcd-portal-select-more-greater-than-data-protection-with-veeam"></a>

<figure><img src="/files/YdFSpLmslDjpKGgSpmdF" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/1rfDe4hOcj53OINEzrew" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
Step 2. Select tab VMs

<figure><img src="/files/bjMxGazOQuNdrnkR1rqB" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Step 3. Select VM need to restore --> Entire Recovery <a href="#step-3.-select-vm-need-to-restore-greater-than-entire-recovery" id="step-3.-select-vm-need-to-restore-greater-than-entire-recovery"></a>

<figure><img src="/files/iZ5kU30YJwoL64HO8cFa" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Step 4. On Restore Point <a href="#step-4.-on-restore-point" id="step-4.-on-restore-point"></a>

Select backup date want to restore --> **Next**

<figure><img src="/files/qQufh5vTZro1GOZ8YlKj" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Step 5. On Restore mode

There are 2 modes:

**Mode 01- Restore to the original location:** Quickly restore the selected VM to its original location with the original name and settings. This option minimizes the chance of user input error.

* The restore **VM will override the original VM.**
* **The original VM will be shut down and deleted when the storage is successful.**

***>> Please follow\*\*\*\*&#x20;**<mark style="color:red;">**step 5.1**</mark>*

**Mode 02 - Restore to a new location or with different settings: Customize the restored VM location and change its settings.** The wizard will automatically populate all controls with the original VM settings as the defaults.

* This mode will increase your resources, so please check your available resource and contact HI GIO-Sales if you want to add more resources to restore the VM.
* You need to create a new vApp to restore the VM.

***>> Please follow\*\*\*\*&#x20;**<mark style="color:red;">**step 5.2**</mark>*

#### Step 5.1. Restore to the original location <a href="#step-5.1.-restore-to-the-original-location" id="step-5.1.-restore-to-the-original-location"></a>

**5.1.1 Select Next**

<figure><img src="/files/akuX0zbQJZ02yojipXmp" alt=""><figcaption></figcaption></figure>

**5.1.2 On Summary**

Verify VM restore information → select Power on VM automatically → Finish

<figure><img src="/files/899yRKTNi3Q8o7lAR16L" alt=""><figcaption></figcaption></figure>

#### Step 5.2 Restore to a new location, or with different settings <a href="#step-5.2-restore-to-a-new-location-or-with-different-settings" id="step-5.2-restore-to-a-new-location-or-with-different-settings"></a>

**5.2.1 Select Next**

<figure><img src="/files/CiUwB6NBdVb3NrVv7yDu" alt=""><figcaption></figcaption></figure>

**5.2.2 On Destination**

\*\*\* Specify vApp to restore the virtual machine to, and type in the restored VM's name.

Click Choose

<figure><img src="/files/3ELtcuVBFfwlUex8ASoN" alt=""><figcaption></figcaption></figure>

Select vApp has been created before

<figure><img src="/files/MA6RNmfGK4cDoryQzASM" alt=""><figcaption></figcaption></figure>

Change VM name → **Next**

<figure><img src="/files/2rWHaK40dyaYT8VL3cxI" alt=""><figcaption></figcaption></figure>

**5.2.3 On Network**

Keep default or choose network already added on vApp → Select **Next**

<figure><img src="/files/OGSZu3kFrtPshvaDq7G6" alt=""><figcaption></figcaption></figure>

**5.2.4 On Datastore**

Keep default or choose Policy already on your resource → Select **Next**

<figure><img src="/files/5Mv0rxvqqorJKS2q82Rz" alt=""><figcaption></figcaption></figure>

**5.2.5 On Summary**

Verify VM restore information → select Power on VM automatically → **Finish**

<figure><img src="/files/glaStkA7vZEU44oCYeD7" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Step 6. Verify Status VM restore <a href="#step-6.-verify-status-vm-restore" id="step-6.-verify-status-vm-restore"></a>

Select tab VMs → History to check the status of VM restore

<figure><img src="/files/a8jDUbh1KNGOp4N9yZHv" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/0G1T5b9ft9hSvBxRejGh" alt=""><figcaption></figcaption></figure>

Restore VM successfully

<figure><img src="/files/GOhjk98JvNWihnLdTUZM" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}

### In a some case after restore the linux VM (RHEL, CentOS, Ubuntu..) the machine will boot up without the local network interface. <a href="#in-a-some-case-after-restore-the-linux-vm-rhel-centos-ubuntu..-the-machine-will-boot-up-without-the" id="in-a-some-case-after-restore-the-linux-vm-rhel-centos-ubuntu..-the-machine-will-boot-up-without-the"></a>

**You'll get the message like this:** `"Bringing up interface eth0: Device eth0 has different MAC address than expected, ignoring."`

The reason for this is VM has been assigned an ethernet adapter with a different MAC address than what the source VM was using.

**Resolve:** Get MAC address that VM has assigned and update it to interface
{% endhint %}

<figure><img src="/files/cROp8qx7gnucGYZHBneL" alt=""><figcaption><p>Get MAC address from portal</p></figcaption></figure>

<div align="left"><figure><img src="/files/LHBaPUPLKao93xkxmink" alt=""><figcaption><p>Follow on your distribute to update MAC address</p></figcaption></figure></div>
{% endstep %}
{% endstepper %}


# Instant Recovery

## <mark style="color:green;">Over</mark><mark style="color:green;">**view**</mark> <a href="#overview" id="overview"></a>

With the option of Instant recovery, you can recover VM quickly. VM will mount workload images to a host directly from the backup stored on backup repositories. However, it will be limited I/O performance; you must migrate the VM to production when successfully restored.

## <mark style="color:green;">**Requirement**</mark>

* Check your available resources.
* Create a new vApp to restore the VM

**\*\*\* During recovery**

You can only restore and migrate each VM in turn.

**\*\*\* If you want to restore and migrate many VMs at the same time**

* Please contact HI GIO support.

## <mark style="color:green;">**Procedure**</mark> <a href="#main-step" id="main-step"></a>

* Choose the VM and point that needs to be restored with Instant Recovery.
* Select Restore mode.
* Verify status restore.
* Migrate and Verify VM.

{% stepper %}
{% step %}
**Step 1:** From the main menu vCD Portal, select **More -> Data Protection with Veeam**

<figure><img src="/files/aXDFpBdQrgqrWlzr5jDv" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/p8Nu9DQeAeUqLgJ9w0Yd" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Select tab VMs

<figure><img src="/files/U817giOnEr6a8Fw5ZVVE" alt=""><figcaption></figcaption></figure>

&#x20;

<figure><img src="/files/yhJ2RcMPyCLRt0l2Sf8b" alt=""><figcaption></figcaption></figure>

{% endstep %}

{% step %}
**Step 3:** Select VM need to restore --> **Instant Recovery**

<figure><img src="/files/CTnAImKNKtroGlEexVy3" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** On **Restore Point**

* Select backup date want to restore --> **Next**

<figure><img src="/files/aXalQxOQ4RYmngZ3lxiN" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5. On Restore mode**

There are 2 modes:

**\*\*\* Restore to the original location**: Quickly restore the selected VM to its original location with the original name and settings. This option minimizes the chance of user input error.

* VM restore will override the original VM.
* VM original will be shut down and deleted when you successfully restore.

***>> Please follow\*\*\*\*&#x20;**<mark style="color:red;">**step 5.1**</mark>*

&#x20;**\*\*\* Restore to a new location or with different settings: Customize the restored VM location and change its settings.** The wizard will automatically populate all controls with the original VM settings as the defaults.

* This mode will increase your resources, so please check your available resources and contact HI GIO-Sales if you want to add more resources to restore the VM.
* You need to create a new vApp to restore the VM.

***>> Please follow\*\*\*\*&#x20;**<mark style="color:red;">**step 5.2**</mark>*

#### **Step 5.1. Restore to the original location** <a href="#step-5.1.-restore-to-the-original-location" id="step-5.1.-restore-to-the-original-location"></a>

**5.1.1 Select Next**

<figure><img src="/files/ILImtcqHu6xrLoCXMLUp" alt=""><figcaption></figcaption></figure>

&#x20;**5.1.2 On Summary**

* Verify VM restore information → select Power on VM automatically → Finish

<figure><img src="/files/Kjk61UskYKI1yjvLYfkh" alt=""><figcaption></figcaption></figure>

#### **Step 5.2 Restore to a new location, or with different settings**  <a href="#step-5.2-restore-to-a-new-location-or-with-different-settings" id="step-5.2-restore-to-a-new-location-or-with-different-settings"></a>

**5.2.1 Select Next**

<figure><img src="/files/xViC4fS6jbjo6PlI31vS" alt=""><figcaption></figcaption></figure>

&#x20;**5.2.2 On Destination**

Specify vApp to restore the virtual machine to, and type in the restored VM's nam&#x65;**.**

* Click Choose

<figure><img src="/files/K3LIkcEK4kuzKK6qK1h1" alt=""><figcaption></figcaption></figure>

* Select vApp has been created before

<figure><img src="/files/FcHC8QocQL0ogNpTNdi3" alt=""><figcaption></figcaption></figure>

* Change VM name → Next

<figure><img src="/files/aP1Zi5iDAmsm1C9hZu8z" alt=""><figcaption></figcaption></figure>

&#x20;

**5.2.3 On Network**

* Keep default → Select Next

<figure><img src="/files/bHIOzRJWLvqhqzU48YyH" alt=""><figcaption></figcaption></figure>

&#x20;

**5.2.4 On Summary**

* Verify VM restore information → select **Power on VM automatically** → **Finish**

<figure><img src="/files/iJpe2r7BFGkOuS5mbBfv" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 6:** Verify Status VM restore

* Select tab **VMs → History** to check the status of VM restore

<figure><img src="/files/cr4BF42rjxBYamtAvcYj" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/AhVj3JQhlGBzIKTbJfe0" alt=""><figcaption></figcaption></figure>

&#x20;

<figure><img src="/files/kVJ4we5yFJczMAar0dna" alt=""><figcaption><p>VM restore has been recovered successfully, we can back to vCD portal to check the data</p></figcaption></figure>

* Back to vCD portal, VM restore had power-on

<figure><img src="/files/tJXadQgixPv8C6y80H8W" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
**When Instant Recovery is performed**:\
Veeam Backup & Replication uses the Veeam vPower technology to mount a workload image to an ESXi host directly from a compressed and deduplicated backup file.\ <mark style="color:red;">**DO NOT shutdown\Power Of VM to avoid data loss.**</mark>

<mark style="color:red;">**Please process step 7 & 8 to complete the recovery.**</mark>
{% endhint %}
{% endstep %}

{% step %}
**Step 7:** Migrate to Production

**\*\*\* After checking the data on VM restore, if it contains the data you want, you need to migrate to production to ensure I/O performance for the VM.**

* Back to Data Protection with Veeam → Instant Recovery

<figure><img src="/files/5j5jdWPA02rxV0XeYaks" alt=""><figcaption></figcaption></figure>

* Select VM restore → Migrate to Production

<figure><img src="/files/TytFAopGiFwZVLZWkXgG" alt=""><figcaption></figcaption></figure>

* On Destination → Select **Choose...**

<figure><img src="/files/pkG7SXR2Tep85lnH26RT" alt=""><figcaption></figcaption></figure>

* Select Storage Policy → **OK**

<figure><img src="/files/LJkPEjbM8AklJhuv6ILL" alt=""><figcaption></figcaption></figure>

* Select **Next**

<figure><img src="/files/1wyxfjRWam5N9B4ABrRG" alt=""><figcaption></figcaption></figure>

* On Ready → **Finish**

<figure><img src="/files/edwMiuUmCYSB4pG49Q2H" alt=""><figcaption></figcaption></figure>

* To check the status of the migrated VM restore, select VMs → **History**

<figure><img src="/files/D83e7r8kR4Mla4VhvAcP" alt=""><figcaption></figcaption></figure>

* Select VM restore

<figure><img src="/files/0n1am8uIFKrC0CmioKwt" alt=""><figcaption></figcaption></figure>

* VM restore has migrated to production

<figure><img src="/files/kkG5rofsx7JdobNi8LuK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 8:** Verify VM restore information

**\*\*\* To make sure VM restore has run with the correct configuration, go back to vCD portal and check:**

* Hard disk (Size, IOPS, Storage Policy)

<figure><img src="/files/6mWjFii47rk9lhEOS3HD" alt=""><figcaption></figcaption></figure>

* Compute (CPU, Memory)

<figure><img src="/files/hQwLnatVgF6kNUtNtuGh" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# 3. HI GIO M365 BaaS

## <mark style="color:green;">Overview</mark>  <a href="#introduction" id="introduction"></a>

This is a document on how to:

* *Add New Organizations*
* *Create a Backup Job*
* *Restore on Self-service Restore Portal*

## <mark style="color:green;">**Procedure**</mark> <a href="#guidance" id="guidance"></a>

{% tabs %}
{% tab title="1. How To Add New Organizations on the HI GIO Portal" %}
**Step 1:** Log in to HI GIO Portal <https://portal-hcmc02-backup.higiocloud.vn/> with your company account.

* In the Enter Company\User and Enter password fields, specify the credentials of an authorized user.
* The user name must be provided in the Company Name\User format.
* Click **Log in.**

<figure><img src="/files/S7AO1RhNDLJCvdMvoQdy" alt=""><figcaption></figcaption></figure>

**Step 2:** At the top right corner of the HIGIO Portal., click **Configuration**

<figure><img src="/files/cv7Q7D6tNNKM3jhiwRxx" alt=""><figcaption></figcaption></figure>

**Step 3:** In the configuration menu on the left, click Plugin Library, then Click the **Veeam Backup for Microsoft 365** plugin tile.

<figure><img src="/files/PztQmdA7nAERKmNiBtyR" alt=""><figcaption></figcaption></figure>

**Step 4:** In the menu on the left, click **Organizations**, then at the top of the list, click New.

<figure><img src="/files/MCddz6atY4SfBcFQGyJs" alt=""><figcaption></figcaption></figure>

**Step 5:** At the **Protected Services** step of the wizard, select Microsoft services that you want to protect (Exchange Online, SharePoint Online and OneDrive for Business, Microsoft Teams, Teams chats).

You can select Microsoft Teams and Teams chats check boxes only if both Exchange Online, SharePoint Online, and OneDrive for Business check boxes are selected.

{% hint style="warning" %}
**Attention:** Backing up Teams chats requires using protected APIs and additional billing charges from Microsoft. For details, see Microsoft Docs. For details on configuring your backup infrastructure to back up Teams chats, see this [Veeam KB article.](https://www.veeam.com/kb4340)
{% endhint %}

<figure><img src="/files/z3KB0pMXIo1o2gc1IjBp" alt=""><figcaption></figcaption></figure>

**Step 6:** At the Connections Settings step of the wizard, select Microsoft Azure region is **Default**

<figure><img src="/files/AXjraUwfSupzkmBnYyZY" alt=""><figcaption></figcaption></figure>

&#x20;

**Step 7:** At the Application Settings step of the wizard, select the **Register a new Azure AD application automatically** option and specify the name of the new Azure AD application.

\[If you have selected to protect SharePoint Online and OneDrive for Business] Select a**llow this application to enable export mode for SharePoint Web Parts** check box to allow Veeam Backup for Microsoft 365 to back up web parts of your Microsoft SharePoint sites. For details on web parts, see [Microsoft Docs](https://docs.microsoft.com/en-us/visualstudio/sharepoint/creating-web-parts-for-sharepoint?view=vs-2019).

<figure><img src="/files/R84UGYpf32CDlY1M3Pg9" alt=""><figcaption></figcaption></figure>

**Step 8:** At the **Microsoft 365 Logon** step of the wizard, log in to your Microsoft 365 organization:

Click **Copy code** to copy an authentication code.

* Consider that the code is valid for 15 minutes. You can click **Refresh code** to request a new code from Microsoft.

<figure><img src="/files/zHJocebtHl8CeovjLV3k" alt=""><figcaption></figcaption></figure>

* Click the Microsoft verification portal link.
* A web browser window will open.

<figure><img src="/files/thNmbqtHE1NtcgA6XcTI" alt=""><figcaption></figcaption></figure>

* On the **Sign in to your account** webpage, paste the code you have copied and sign in to Microsoft Azure.

<div align="left"><figure><img src="/files/tEYx70CYIrIsOPIX9s0Z" alt=""><figcaption></figcaption></figure></div>

* Make sure to sign in with the user account that has the *Global Administrator* role. For details on this role, see [Microsoft Docs](https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/directory-assign-admin-roles).

<figure><img src="/files/31EJhyLlAE5feAmJ4P1L" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/AahY5gchS89CYVkPNndD" alt=""><figcaption></figcaption></figure>

Return to the wizard and click **Next** when the Verification status: **Verified**

<figure><img src="/files/KZ211GPSOjXSpGxgpUov" alt=""><figcaption></figcaption></figure>

**Step 9:** Review organization settings and click **Finish at the Summary step of the wizard**.

<figure><img src="/files/grvcBT80pEsj0PY2CQUo" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/1AtwrWgtGTk59eOd5rAQ" alt=""><figcaption></figcaption></figure>

***From now on, these steps below just need to be done one time***

**Step 10: Register AzureADServicePrincipal for Tenant**

Azure AD application that end users and restore operators from tenant organizations will use to access Restore Portal must be created for a Microsoft 365 organization on a service provider side.

* Open the Powershell

<figure><img src="/files/F5MxDXsoEYLAyj0ZO1oC" alt=""><figcaption></figcaption></figure>

* Update PowerShell with Winget by below command

```
winget install --id Microsoft.Powershell --source winget
```

<figure><img src="/files/LzJGbYjmzpuXcwszSvz9" alt=""><figcaption></figcaption></figure>

* Run the [Install-Module](https://docs.microsoft.com/en-us/powershell/module/powershellget/install-module?view=powershell-7.3) cmdlet to install the Azure Active Directory PowerShell for Graph module. For more information, see [this Microsoft article](https://docs.microsoft.com/en-us/microsoft-365/enterprise/connect-to-microsoft-365-powershell?view=o365-worldwide#step-1-install-the-required-software).
* Open a Windows PowerShell Command Prompt window. Depending on the permissions of your logged-in account, you may need to open the PowerShell window in Administrator mode.
* To install the v1 module of the SDK in PowerShell Core or Windows PowerShell, run the following command:

```
Install-Module Microsoft.Graph -Scope CurrentUser
```

This process may take some time to complete.

<figure><img src="/files/7sJ9g2fI9Qr2KMGvA1hE" alt=""><figcaption></figcaption></figure>

* Run this command to install the beta module:

```
Install-Module Microsoft.Graph.Beta
```

<figure><img src="/files/1JPed5C2O3TdNrvuCYgy" alt=""><figcaption></figcaption></figure>

* Run this command to install AzureAD module:

```
Install-Module AzureAD
```

<figure><img src="/files/eGzdfY1DTZZBKkfixtr2" alt=""><figcaption></figcaption></figure>

* Register AzureADServicePrincipal with Power Shell
  * Connect to Organization and register AzureADServicePrincipal using the command below.

**Connect-AzureAD**

This command to log in to Azure Organization, the please user account that has Global Administrator permission

**New-AzureADServicePrincipal -AppId "XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX"**

The AppId support team will provide for customers.

***Example: New-AzureADServicePrincipal -AppId "514abb4a-63c9-44b9-9f88-2b188b32a3cf"***

&#x20;

<figure><img src="/files/5HYRiQ818s249cVYcWMn" alt=""><figcaption></figcaption></figure>

**Step 11:** Grant admin consent to this application on behalf of all users in the tenant organization

1. Access Azure Portal <https://portal.azure.com/> with a user account that has Global Administrator permission
2. Find AzureADServicePrincipal by application ID.

<figure><img src="/files/d5A9kX9Upo3utirjsfnh" alt=""><figcaption></figcaption></figure>

3. Choose tab permission to Grant admin consent.

<figure><img src="/files/oYxaxbsYGe7Zoyskxew3" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="2. How To Create a Backup Job" %}
**Step 1:** To launch the **New Backup Job** wizard:

1. In the menu on the left, click **Backup Jobs**.
2. Open the **Microsoft 365 Objects** tab.
3. At the top of the jobs list, click **Create Job** and select Backup Job.
4. Veeam Service Provider Console will open the **New Backup Job** wizard.

<figure><img src="/files/R8R2HfKpvIc4jB6hTRoH" alt=""><figcaption></figcaption></figure>

**Step 2:** At the **Job Name** step of the wizard, specify the job name and description.

<figure><img src="/files/G3iR7VAAb4GyUeoHKHz7" alt=""><figcaption></figcaption></figure>

**Step 3:** At the **Organization** step of the wizard, choose an organization to back up:

1. Click **Select**.
2. In the **Available Organizations** window, select an organization to back up.
3. Click **Apply**.

<figure><img src="/files/YPYwu1DpZwcmVb5oXWuS" alt=""><figcaption></figcaption></figure>

**Step 4:** At the **Backup Mode** step of the wizard, select the mode in which you want to create a backup:

1. In the **Backup scope** section, specify objects to back up:
2. Select the **Entire organization** option to back up the whole organization.

{% hint style="warning" %}
***This option is not recommended due to the time it takes to back up the whole organization. We should choose what to back up.***
{% endhint %}

<figure><img src="/files/YYxwS84Y4GGg0ncy6Tui" alt=""><figcaption></figcaption></figure>

* Select the **Back up the specified objects** option to back up individual objects:
  * Click **Configure**.

<figure><img src="/files/gvAPIQcMTBcTJCYPuT3O" alt=""><figcaption></figcaption></figure>

* In the **Objects to Back up** window, select the type of object to back up: *User*, *Group*, *Site*, *Teams, Personal Sites,* or *Current organization*.

The list of available objects depends on which Microsoft Online services are selected in the organization settings.

* Click **Add**. In this guide, I choose User for **Objects to back up**&#x20;

<figure><img src="/files/ceHToqCib0Z9hIXCIRFD" alt=""><figcaption></figcaption></figure>

* Select an object in the list to customize processing options, click **Edit Processing Options,** or click a link in the **Processing Options** column.
* \[For *User*, *Teams*, *Group,* and *Current organization* object types] In the **Edit processing options** window, select the necessary processing options and click **Save**.

Note that processing options for *Current organization* objects will be applied to all users, groups, sites, and teams in the organization.

\[For *Teams* and *Current organization* object types] You can modify the *Chats* and *Teams chats* check boxes only if the *Teams* *chats* protected service is selected in the organization settings.

For details about available object types and their processing options, see the section [Organization Object Types](https://helpcenter.veeam.com/docs/vbo365/guide/vbo_object_types.html) of the Veeam Backup for Microsoft 365 User Guide.

<figure><img src="/files/wp1XlZ8ba2iSJqdd6VNR" alt=""><figcaption></figcaption></figure>

<mark style="color:red;">**#Optional:**</mark> To exclude specific objects, in the **Exclusions** section, set the toggle to *On* and specify objects to exclude:

<figure><img src="/files/CwjhX7J1DJyb7y6Gkp8d" alt=""><figcaption></figcaption></figure>

**Step 5:** Review backup job settings at the wizard's Summary step.

<figure><img src="/files/aIBEEQs39sYuXjTxKvGm" alt=""><figcaption></figcaption></figure>

After creating a Backup Job, please contact the support team to apply the daily schedule.
{% endtab %}

{% tab title="3.How To Restore On Self-service Restore Portal" %}
**Step 1:** Open a web browser on any computer and navigate to the Restore Portal web address <https://portal-hcmc02-restore.higiocloud.vn/>

* Internet Explorer is not supported. To access Restore Portal, use Microsoft Edge (version 79 or later), Mozilla Firefox (version 21 or later), or Google Chrome (version 24 or later).
* Log in with the Microsoft Office account that you need to restore items. You must provide a user account in one of the following formats: *<user@domain.com>* or [*user@domain.onmicrosoft.com*](mailto:user@domain.onmicrosoft.com).
* Click **Log In.**
* Restore Portal will redirect you to the Microsoft authentication portal where you will be prompted to enter your Microsoft 365 user account password.

<figure><img src="/files/Zv6LjPIDAw4kUDIWsnGG" alt=""><figcaption></figcaption></figure>

**Step 2:** Select a restore point from which you want to explore and restore data from backups created by Veeam Backup for Microsoft 365. For more information on how to view and select available restore points in Restore Portal, see [Selecting Restore Point](https://helpcenter.veeam.com/docs/vbo365/guide/ssp_selecting_restore_point.html).

To view available restore points and select a restore point that you want to use, do the following:

* In the upper-left corner of the Restore Portal window, click **Select Restore Point** or the restore point timestamp.
  * In the displayed dialog box, do one of the following:
  * In the calendar, click the date for which Veeam Backup for Microsoft 365 has available restore points. Such dates are marked in bold. The available restore points for the selected date will be displayed on the right.
* Click **Select Latest Point** to select the latest restore point available in a backup repository.
* Click **Apply**.

<figure><img src="/files/FAAWb5xRR1f1aLpM2PQS" alt=""><figcaption></figcaption></figure>

**Step 3:** Example with Exchange Restore

To restore Exchange items, do the following:

1. Open the **Explore** tab.
2. Select a restore point from which you want to explore and restore data. For more information, see [Selecting Restore Point](https://helpcenter.veeam.com/docs/vbo365/guide/ssp_selecting_restore_point.html).
3. In the navigation pane, browse through the hierarchy of folders with backed-up data.
4. Select a folder that contains the data you want to restore.
5. Select check boxes next to the necessary Exchange items in the preview pane.
6. Click **Restore**.

<figure><img src="/files/oHQhY0XwXdugouSowUxU" alt=""><figcaption></figcaption></figure>

The **Exchange Restore** wizard runs to configure the restore operation options.

**Step 4:** At the **Items** step, specify the items you want to restore. If you no longer wish to restore an item, select it and click **Remove**.

<figure><img src="/files/mvr9GazM8a34dHqMhza8" alt=""><figcaption></figcaption></figure>

**Step 5:** At the **Restore mode** step, select where you want to restore the selected items:

* **Restore to the original location**. Select this option if you want to restore the selected items to their original location.
* **Restore to a new location**. Select this option if you want to restore the selected items to another location and specify the folder name in the **Restore to the following folder** field. If the specified folder does not exist, it will be created automatically.

<figure><img src="/files/sopXzWhDN2ooRTGFt1gE" alt=""><figcaption></figcaption></figure>

**Step 6:** Click **Advanced options** to open the **Restore options** dialog.

In the **Restore Options** dialog, select check boxes next to the additional options that you want to apply during the restore operation and then click **Apply**:

* **Restore changed items**. Select this check box if you want to restore items that have been changed.
* **Restore missing items**. Select this check box if you want to restore missing items in the target folder.
* **Mark restored items as unread**. Select this check box if you want to mark each restored item as unread.

Default is all options are selected.

<figure><img src="/files/YasjEYGiUFjC1uyU2Cm1" alt=""><figcaption></figcaption></figure>

<mark style="color:red;">**#Optional:**</mark> At the **Reason** step, specify a restore reason. This information will be available in the **Reason** column on the **Restore Sessions** tab, which you can reference later.

<figure><img src="/files/4ndJh3PUcBn7XgASGB45" alt=""><figcaption></figcaption></figure>

**Step 7:** At the **Summary** step, review the details of the restore operation and click **Finish**.

<figure><img src="/files/jJP3YK3Ff2waMMeaVqdf" alt=""><figcaption></figcaption></figure>

The Restore Portal runs the restore operation immediately and opens the Restore Sessions tab, where you can view details about the restore session's progress and results.

<figure><img src="/files/Dhl9k4lpjYrx8a9DU3F4" alt=""><figcaption></figcaption></figure>

As we can see, restore items were restored to the Restore folder that we chose and marked as unread.

<figure><img src="/files/JDgvjmQCp5akJPPU6gVc" alt=""><figcaption></figcaption></figure>

Restore other items. We can do the same step with Restore Exchange items.&#x20;
{% endtab %}
{% endtabs %}


# HI GIO DRaaS

## <mark style="color:green;">**Information**</mark>

This short manual guide is intended to assist HI GIO users in understanding the features and benefits of our **DRaaS** offering. In this guide, you will find step-by-step instructions for setting up your disaster recovery environment, best practices for maintaining your recovery plans, and tips for testing and optimizing your DRaaS strategy.

## <mark style="color:green;">**Overview**</mark>

{% hint style="info" %}
![](/files/AZcjSYhkUKdyp81USlpO)

We provide **HI GIO DRaaS** for all enterprises who need to initiate secure data replication to another region, such as on-premises to HI GIO Cloud, HI GIO Cloud Ho Chi Minh to HI GIO Cloud Hanoi, or vice versa by setting up HI GIO DRaaS on their resource servers. Furthermore, the RPO has a minimum value of 5 minutes, which suits their critical system.
{% endhint %}

## &#x20;<mark style="color:green;">**Guideline**</mark>

* [How To Install vCDA On-Premises appliance](/hi-gio-draas/how-to-install-vcda-on-premises-appliance)
* [How To Use vCDA On-Premises](/hi-gio-draas/how-to-use-vcda-on-premises)
* [Stretching layer 2 networks for HI GIO's DRaaS.](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas)
* [FAILOVER SCENARIO](/hi-gio-draas/failover-scenario)


# How To Install vCDA On-Premises appliance

## <mark style="color:green;">**Overview**</mark>  <a href="#overview" id="overview"></a>

This short manual guide is designed to help HI GIO users navigate

* *How to install vCDA On-Premises*
* *How to complete the vCDA Configuration Wizard*

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% tabs %}
{% tab title="1. System Requirements" %}

* Before installing the VMware Cloud Director Availability On-Premises Appliance, verify that the on-premises site meets the deployment requirements. Also, allow the network communication within the on-premises site and to the cloud site
* **vCenter Requirements.** 6.5U3, 6.7U3, 7.0 (GA-U3), 8.0 (GA, U1). (We also support vCenter 6.0U3, 5.5U3 only for migration purpose)
* **Network Requirements.** To get a list of the required firewall ports to be opened, see VMware Cloud Director Availability Network Ports.

**Link:** <https://ports.esp.vmware.com/home/VMware-Cloud-Director-Availability>

&#x20;

<figure><img src="/files/Fm6iEiS66sPBniU3YI4n" alt=""><figcaption></figcaption></figure>

&#x20;

&#x20;&#x20;

<figure><img src="/files/KmVuYb0khgrpF2zBDWF9" alt=""><figcaption></figcaption></figure>

&#x20;

* **Hardware Requirements.** From a hosting perspective, the VMware Cloud Director Availability On-Premises Appliance is a virtual machine with the following hardware requirements
  * 4 vCPUs
  * 4 GB RAM
  * 10 GB Storage
* **Deployment Requirements.** In ESXi hosts, a VMkernel interface can be dedicated for the replication traffic. By default, ESXi handles the replication traffic through its management VMkernel interface. As a best practice, you can separate the management traffic from the replication traffic by creating a dedicated VMkernel interface. Use following tags when creating a VMkernel interface for the replication traffic

Use the **vSphere Replication** tag to configure the ESXi host for the **Outgoing Replication Traffic**

Use the **vSphere Replication NFC** tag to configure the ESXi host for the **Incoming Replication Traffic**

* Configure the replication VMkernel interface in its own IP subnet and connect the VMware Cloud Director Availability On-Premises Appliance to the same virtual port group. Using this configuration, the replication traffic between the ESXi hosts and the VMware Cloud Director Availability On-Premises Appliance stays in the same broadcast domain. As a result, uncompressed replication traffic avoids crossing a router and saves the network bandwidth

<figure><img src="/files/5er8Uyx8BLtdm34qIsOS" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="2. How to install vCDA on-premises" %}

* The tenant deployment process is similar to all typical VMware OVF deployments. The tenant must install the vCloud Availability On-Premises Appliance OVA into the vCenter.
* Please download OVA file from this link

[![](https://idc.fdrive.vn/apps/theming/favicon?v=14)VMware-Cloud-Director-Availability-On-Premises-4.5.0.5226630-ab9eb01ccb\_OVF10.ova](https://idc.fdrive.vn/s/QgF5ZJNJr9sPCM4)

* Once downloaded, log into your vSphere Client and **Deploy OVF Template**

<figure><img src="/files/7Qme0tIK4xUrB7Vyw44t" alt=""><figcaption></figcaption></figure>

&#x20;

* **Select an OVF template**. Install from a local file. Browse to the location of the previously downloaded OVA. Select the vCDA OVA file and click **Next**

<figure><img src="/files/atyH4rjte4emJ5aCndPq" alt=""><figcaption></figcaption></figure>

* **Select a name and folder**. Type in your desired virtual machine (appliance) name. Next, select a location for your virtual machine

<figure><img src="/files/yPbvn7ixKOr5V6SmV5zr" alt=""><figcaption></figcaption></figure>

* **Select a compute resource**. Choose a host or a cluster for the appliance. Click **Next**

<figure><img src="/files/k9JTNBWMRfpMNYkKZPxC" alt=""><figcaption></figcaption></figure>

* **Review details**. This is a chance for you to evaluate and verify the template

<figure><img src="/files/iUrzASRofeg1ut2lu6zu" alt=""><figcaption></figcaption></figure>

&#x20;

* **License agreement**. Check the I accept all license agreements checkbox and click **Next**

&#x20;

<figure><img src="/files/Rgv4a18uh13oByYi4qAk" alt=""><figcaption></figcaption></figure>

* **Select storage**. Configure optional storage options for the deployment and click **Next**

<figure><img src="/files/t6nM7S9aufysXkH6Nowz" alt=""><figcaption></figcaption></figure>

* **Select networks.** Choose a destination network for every individual source network

<figure><img src="/files/25LQUpSXD6kN4kmsxEp1" alt=""><figcaption></figcaption></figure>

* **Customize template**. During this step of the wizard, customize the deployment

<figure><img src="/files/VtNXra78mJnQUN4qHU1T" alt=""><figcaption></figcaption></figure>

&#x20;

* **Root Password**. Defining a root password is mandatory. However, you will need to change it when you log in to vCDA for the first time. So, you don’t need to define a very strong password at this point
* **Enable SSH**. Select the Enable SSH checkbox
* **NTP Server**. Enter the NTP server address the vCDA appliance will use. vCenter Server, ESXi, vCloud Director, Platform Services Controller, and the vCloud Availability appliance MUST all use the same NTP server
* **Hostname**. The hostname of VM
* **IP.** IP address ( e.g. **192.168.1.186/24** )
* **Gateway.** Gateway address
* **MTU.** MTU ( e.g. 1500 )
* **DNS Server.** IP DNS Server. It needs to resolvable the domain name of vCenter Server and Service Endpoint
* **Search Domains.** List of search Domains ( e.g. abc.local )
* **Ready to complete**. Review the settings. You can also select Power on after deployment. Click **Finish** to deploy the Appliance

<figure><img src="/files/4tqTZRQQiASz5g6zwAi3" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="3. How to complete the vCDA configuration Wizard" %}

* **Log in to your vCDA** appliance at **<https://your-appliance-IP/ui/admin>**. Use the root/password defined during OVA deployment
* **Change the root password**. Set and confirm a new password. Create a strong password with at least eight (8) characters. Make sure to use lowercase, uppercase, numeric, and special characters.
* To get started, you will need to configure a **Lookup Service Endpoint**. To do so, select **Run Initial Setup Wizard**

<figure><img src="/files/dFFIS6b4XdTTuCqQdIqh" alt=""><figcaption></figcaption></figure>

* **Lookup Service**. Enter your connection details to set up the lookup service along with SSO admin credentials
  * Lookup service address. Type in the following URL, adding the IP address of **your vCenter**: https\://*Ip-of-your-vcenter*:443/lookupservice/sdk
  * Enter SSO admin account credentials in the Username and Password field

&#x20;

<figure><img src="/files/KrQYWsUAKHzDKLGxwhDm" alt=""><figcaption></figcaption></figure>

* **Site Details**. In it, type your **Site Name** and optionally, a short **Description** about the site. Click **Next**

<figure><img src="/files/eS1IbOcFnZ6oP5vHhNzA" alt=""><figcaption></figcaption></figure>

* Proceed to the configure **Cloud Details** by pairing up your **vCloud and vCDA sites**

<figure><img src="/files/yJi8naUtHLssLDMvfHat" alt=""><figcaption></figcaption></figure>

&#x20;

* **Service Endpoint Address**, **Organization Admin and Organization Password** is provided by HI GIO Support
* Configure your organization’s credentials for logging in to the cloud site. Type in **Organization Admin** (user\@org) and **Organization Password**
  * Optional: Select Allow Access from Cloud. If you select this feature, the cloud provider and organization administrators can access and perform certain operations through the vCloud Availability Port
  * If you leave this feature deselected, configuring new replications will only be accessible to users authenticated to the on-premises vCloud Availability Portal. Additionally, no existing replications will be reversed from the Portal
  * **Service Endpoint Address**, **Organization Admin and Organization Password** is provided by HI GIO Support

&#x20;

* Click **Next** and accept the **SSL certificate** of the vCenter Server Lookup to continue

&#x20;

<figure><img src="/files/SksMVcMbNNMnoTdwibdJ" alt=""><figcaption></figcaption></figure>

&#x20;

* **Move on to Ready to Complete**. It shows the details you have provided in the previous steps. Verify that everything is accurate
  * **Check Configure local placement** **now** to enable cloud to datacenter replications. Leaving the box unchecked requires additional set up to configure the replications

<figure><img src="/files/rJHOUnriv1c3JTuHhYaj" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}


# How To Use vCDA On-Premises

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

This short manual guide is designed to help HI GIO users navigate

* *How to create a Migration Job*
* *How to create a Protection Job*
* *How to Test Failover, Failover, Reverse, or Migrate*

## &#x20;<mark style="color:green;">**Procedure**</mark>

{% tabs %}
{% tab title="1. How to create a migration job" %}

* Configuring a migration allows later migrating a vApp or a virtual machine to a remote organization and running the workload in the destination site
* The target recovery point objective **(RPO)** for a migration is **24 hours**
* If you log in to VMware Cloud Director Availability **On-Premises** Appliance, then :
  * **Outgoing Replications** are replication and failover VM from the on-premises vCenter Server to a cloud site
  * **Incoming Replications** are replication and failover VM from the cloud site to the on-premises vCenter Server
* If you login to VMware Cloud Director Availability **Tenant Portal** (provided by Services Provider) then :
  * **Incoming Replications** is replication and failover VM from the on-premises vCenter Server to a cloud site
  * **Outgoing Replications** are replication and failover VM from cloud site to on-premises vCenter Server or Cloud to Cloud
* In the left pane, choose a Replication Direction – Choose **Outgoing Replication** – Create **New Migration**

<figure><img src="/files/9Llb6di3kJXM6wSDwDiP" alt=""><figcaption></figcaption></figure>

* Select the VMs you want to migration by checking the corresponding box(es). Click **Next**

<figure><img src="/files/VPHeIK8YL2K5IYUdIHLg" alt=""><figcaption></figcaption></figure>

* On **the Destination VDC and Storage** policy page, select the virtual data center for the replication destination and the storage policy for placing the recovered virtual machines, and click **Next**.

<figure><img src="/files/SR1uN7wzkrrF9FwShFHv" alt=""><figcaption></figcaption></figure>

* On the Settings page, configure the following replication settings and click **Next**
  * To apply compression on the replication data traffic for reducing the network data traffic at the expense of CPU, leave **Compress replication traffic** selected
  * To start the replication when the wizard finishes, leave **Delay start synchronization** deselected. Alternatively, to schedule the start of the replication, select it and enter the local date and time for starting the replication
  * From the **VDC VM placement policy** drop-down menu, select an organization VDC placement compute policy for the recovered virtual machines
  * *(Optional)* To select specific hard disks of the virtual machines for replicating to the destination site for reducing the replication data network traffic, select **Exclude disks**
  * *(Optional)* To select a previous copy of the virtual machines in the destination site for reducing the replication data network traffic, select **Configure Seed VMs**

<figure><img src="/files/mxT75Cx2UozwBjEaX5RA" alt=""><figcaption></figcaption></figure>

* If you selected **Exclude disks**, on the **Replicated Disks** page select the virtual machine disks for replicating and click **Next**

<figure><img src="/files/ZezsNWAQshwVl89BLASt" alt=""><figcaption></figcaption></figure>

* On the **Ready to complete** page, verify that the replication settings of the migration are correct and click **Finish**

<figure><img src="/files/hLbV8S9IsBOFu1ZjRJYP" alt=""><figcaption></figcaption></figure>

* After the replication finishes, for the vApp and its virtual machines in the **Replication type column**, you see a **Migration** state

<figure><img src="/files/H7O7esHxPoHtgBLst7wH" alt=""><figcaption></figcaption></figure>

&#x20;
{% endtab %}

{% tab title="2. How to create a protection job" %}

* Configuring a protection allows protecting a vApp or a virtual machine from one organization to another, while keeping the workload running in the source site. If the source site is unavailable, after a successful replication you can fail over and power on the source virtual machine in the destination site
* If you login to VMware Cloud Director Availability **On-Premises** Appliance then :
  * **Outgoing Replications** is replication and fail over VM from the on-premises vCenter Server to a cloud site
  * **Incoming Replications** is replication and fail over VM from cloud site to on-premises vCenter Server
* If you login to VMware Cloud Director Availability **Tenant Portal** (provided by Services Provider) then :
  * **Incoming Replications** is replication and fail over VM from the on-premises vCenter Server to a cloud site
  * **Outgoing Replications** is replication and fail over VM from cloud site to on-premises vCenter Server or Cloud to Cloud
* In the left pane, choose a Replication Direction – Choose **Outgoing Replication** – Create **New Protection**

<figure><img src="/files/GJN40csYX6KHJktiV21h" alt=""><figcaption></figcaption></figure>

* Select the VMs you want to protect by checking the corresponding box(es). Click **Next**

<figure><img src="/files/QcsS4Y4MHjjCCiTcnnYV" alt=""><figcaption></figcaption></figure>

* On **the Destination VDC and Storage** policy page, select the virtual data center for the replication destination and the storage policy for placing the recovered virtual machines, and click **Next**.

<figure><img src="/files/7bYsH4g4bVzgPyOJ60pR" alt=""><figcaption></figcaption></figure>

* To set the SLA settings of the replication, select any of the preconfigured SLA profiles. Click **Next**
  * From the **VDC VM placement policy** drop-down menu, select an organization VDC placement compute policy for the recovered virtual machines
  * *(Optional)* To select specific hard disks of the virtual machines for replicating to the destination site for reducing the replication data network traffic, select **Exclude disks**
  * *(Optional)* To select a previous copy of the virtual machines in the destination site for reducing the replication data network traffic, select **Configure Seed VMs**

<figure><img src="/files/dXU9W2YBGV6gtvnLFdAi" alt=""><figcaption></figcaption></figure>

* To manually configure the SLA settings, select **Configure settings manually**
  * **Target recovery point objective (RPO):** If you selected Configure settings manually, set the acceptable period for which data can be lost if there is a site failure by using the slider or by clicking the time intervals. The available RPO range for a protection is from one minute to 24 hours
  * **Retention policy for point in time instances:** If you selected Configure settings manually, to preserve multiple rotated distinct instances to which the virtual machines can be recovered, select this option, select the number of replication instances to keep, and select the retention time distance and unit. The retention distance unit must be greater than RPO
  * **Compress replication traffic:** If you selected Configure settings manually, to apply compression on the replication data traffic for reducing the network data traffic at the expense of CPU, select this option
  * **Delay start synchronization:** If you selected Configure settings manually, choose the following option
    * To schedule the start of the replication, select this option and enter the local date and time to start the replication.
    * To start the replication when the wizard finishes, leave this option deselected.
  * **VDC VM placement policy:** Select an organization VDC placement compute policy for the recovered virtual machines
  * **Exclude disks:** To select specific hard disks of the virtual machines for replicating to the destination site for reducing the replication data network traffic, select this option
  * **Configure Seed VMs :** To select a previous copy of the virtual machines in the destination site for reducing the replication data network traffic, select this option
* **Create a Replication Seed**: Use one of the following methods for creating a seed VM in the destination site
  * **Offline data transfer**: Export the VM as an OVF package into removable media and send it to Cloud service administrator imports the package to your cloud organization
  * **Copy over the network:** Copy a source VM to the cloud organization and transfer the source data to the destination site by using other means than VMware Cloud Director Availability (FTP, OneDrive, Google Drive, …)

<figure><img src="/files/e9h9P3Y5mcwHV6bCFQEw" alt=""><figcaption></figcaption></figure>

&#x20;

* **Instances**: Select how many rotated instances participate in the current retention rule. The total number of instances in this example matches **the maximum of 24 rotated instances**
* **Distance:** Select the time distance that the rotated instances spread apart in the current retention rule
* **Unit:** Select the time unit for spreading the rotated instances in the current retention rule. Select one from: Minutes – Hours – Days – Weeks – Months – Years
* On the **Disks page** you must select the hard disks to replicate and click **Next**

<figure><img src="/files/Wy9G4eoKCzj34OgkwPvz" alt=""><figcaption></figcaption></figure>

* On the Ready to complete page, verify that the replication settings of the protection are correct and click **Finish**

<figure><img src="/files/dBBkVuuZgQp8o21Bsx7B" alt=""><figcaption></figcaption></figure>

&#x20;
{% endtab %}

{% tab title="3. How to Failover, Reverse, or Migrate" %}

* **Diagram for Replication State**

<figure><img src="/files/X5N8C7BeogdGXZ0ouc0t" alt=""><figcaption></figcaption></figure>

* **Test Failover**: By performing a test failover you can validate that the data from the source site replicates correctly in the destination site
* In the left pane, choose a replication direction
* Select the protected vApp or virtual machine to test the failover and click **All actions > Test Failover**

<figure><img src="/files/RrFN24H0hcSArZjnYxDi" alt=""><figcaption></figcaption></figure>

* On the **Recovery Settings page**, configure the recovered workload and click **Next**
  * **Power on recovered vApps**: Select to power on the virtual machines in the destination site after the task completes
  * **Network settings:**
    * Select *Apply preconfigured network settings on failover*, to assign the network configured during the virtual machine replication
    * Select *Connect all VMs to network* and from the drop-down menu select a network to connect the replicated virtual machines to

<figure><img src="/files/86HA1DXHMhW1z5tdm3bz" alt=""><figcaption></figcaption></figure>

&#x20;

* On the **Recovery Instance** page, configure the recovery point in time and click **Next**
  * *Synchronize all VMs to their current state*: Creates an instance of the power on workload with its latest changes and uses that instance for the test failover
  * *Manually select existing instance:* Select an instance without synchronizing the data for the recovered workload

<figure><img src="/files/h3BXJm2WBH3BsqnKWrBq" alt=""><figcaption></figcaption></figure>

* On the **Ready To Complete** page, review the test details and click **Finish**

<figure><img src="/files/Pj8Cdrph72HAnUdAbEyZ" alt=""><figcaption></figcaption></figure>

* In the **Last changed column**, you can monitor the progress of the test. After the test finishes, for the vApp and its virtual machines in the **Recovery state** column you see a **Test image ready state**

<figure><img src="/files/haOrsLkTf1Pg6QmdyQgr" alt=""><figcaption></figcaption></figure>

* To Delete the Test Failover results, select the replication to clean. **Click All actions** > **Test Cleanup.**

<figure><img src="/files/W03XPJubIKKYlbXGW0at" alt=""><figcaption></figcaption></figure>

* The Cleanup Deletes All recovered vApps and virtual machines

<figure><img src="/files/epdlfsIhXGO06raSgvdj" alt=""><figcaption></figcaption></figure>

* **Perform a Failover Task**: If the protected source site is unavailable, in the destination site perform a workload disaster recovery operation
* Select the protected vApp or virtual machine to fail over and click **All actions > Failover**

<figure><img src="/files/RpJQs0SH7mH9s4khdhHw" alt=""><figcaption></figcaption></figure>

* In the **Failover wizard**, configure your selected workload for the failover
  * **Consolidate VM disks**: Select this option for a better performance of the recovered virtual machines at the expense of the failover task taking longer to complete
  * **Power on recovered vApps**: Select this option to power on the virtual machines on the destination site after the task completes.
  * **Network settings:**
    * Select *Apply preconfigured network settings on failover*, to assign the network configured during the virtual machine replication
    * Select *Connect all VMs to network* and from the drop-down menu select a network to connect the replicated virtual machines to

<figure><img src="/files/8ZtksFCLeGIofFPmHuPP" alt=""><figcaption></figcaption></figure>

* On the **Recovery Instance** page, configure the recovery point in time and click **Next**

<figure><img src="/files/FHhZM8R7ecgI5Q2k6W7U" alt=""><figcaption></figcaption></figure>

* On the **Ready To Complete page**, review the task details and click **Finish**

<figure><img src="/files/rgjS0XZh3Wd1zG6mMshd" alt=""><figcaption></figcaption></figure>

* After the failover task finishes, the failed over workload is running in the destination site and the workload is no longer protected upon the task completion. For the vApp and its virtual machines, in the **Recovery state** column you see a **Failed-Over state**

<figure><img src="/files/MsXAKHE3KkFWmwhCu2Un" alt=""><figcaption></figcaption></figure>

* **Perform a Reverse Task**:
  * After performing failover or migration, return the workload data from the destination site back to the original source site by reversing the replication.
  * After failing over or migrating from the source site to the destination site, the workload runs on the destination site. A subsequent reverse task replicates the failed-over or migrated workload data back to the original source protected vApp or virtual machine
  * When reversing a replication from a cloud site back to an on-premises site, VMware Cloud Director Availability uses the original datastore for the placement of the workload, regardless of the current on-premises local placement setting
* Select the vApp or the virtual machine that are failed-over and **All actions > Reverse**
* In the **Reverse window**, to confirm the reversal click **Reverse.** Reversing the replication enables the replication traffic and allows the replication to be recovered back to the source

<figure><img src="/files/xs4W2kbUylrq9c1xPDMa" alt=""><figcaption></figcaption></figure>

* After the reverse task finishes, the reversed replication overwrites the source vApp or virtual machine. The reversed workload runs in the destination site with a workload protection in the original source site. For the vApp and its virtual machines, in the **Recovery state** column you see a **Reversed state**

<figure><img src="/files/qwOV3XE7ZLswiHopn0MG" alt=""><figcaption></figcaption></figure>

&#x20;

&#x20;

* **Perform a Migrate Task**: By migrating an existing replication to a remote organization, the workload runs in the destination site and the source workload is powered off
* Select the protected vApp or virtual machine to migrate over and **All actions > Migrate**

&#x20;

<figure><img src="/files/anHZfTJxyB3eSi3Uzn1b" alt=""><figcaption></figcaption></figure>

* On the **Migrate Settings** page, configure the recovered workload and click **Next**
* *All source vApps will be powered-off after successful recovery*
  * **Consolidate VM disks**: Select this option for a better performance of the recovered virtual machines at the expense of the failover task taking longer to complete
  * **Power on recovered vApps**: Select this option to power on the virtual machines on the destination site after the task completes.
  * **Network settings:**
    * Select *Apply preconfigured network settings on failover*, to assign the network configured during the virtual machine replication
    * Select *Connect all VMs to network* and from the drop-down menu select a network to connect the replicated virtual machines to

<figure><img src="/files/s5CNZWcoMGiK2qOhjDHR" alt=""><figcaption></figcaption></figure>

&#x20;

* On the **Ready To Complete** page, review the task details and click **Finish**

<figure><img src="/files/BmMQWz3mxCm74DitvsfM" alt=""><figcaption></figcaption></figure>

&#x20;

&#x20;

* After a successful recovery, all source **virtual machines** are synchronized and then **powered off**. The migration completes when in the **Recovery state** column of the replication you see **Failed-Over**
* A manual (offline) sync runs. If the source workload is powered on, then it is powered off and a manual sync runs. Then the vApp or virtual machines are recovered on the destination site

  &#x20;

<figure><img src="/files/pkd8cmRe7erLiLnAQg93" alt=""><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}


# Stretching layer 2 networks for HI GIO's DRaaS

## <mark style="color:green;">Overview</mark> <a href="#overview" id="overview"></a>

During on-premises to the cloud migrations, stretch the on-premises networks across the HI GIO cloud site to allow network connectivity between already migrated and not yet migrated virtual machines in the same network segment.

Layer 2 VPN (L2 VPN) stretches the L2 networks across the sites.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

1. **Prerequisites:** [**deployed VMware Cloud Director Availability On-premises Appliance**](https://higio-support.atlassian.net/wiki/spaces/v2/pages/69992561/Stretching+layer+2+networks+for+HI+GIO+s+DRaaS.)

{% hint style="info" %}
On-premises VMs must connect to VLAN-backed networks **configured** **on** **Distributed Switches**

(Standard Switch is **NOT** supported).
{% endhint %}

2. **Procedure:** To complete the L2 stretch, we follow the steps:

* [Preparing the configure:](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas/preparing-the-configure)

&#x20;      **On-premises Site:** fulfill VLAN, IP address, port groups, and Public IP.

&#x20;      **HI GIO site:** Public IP, networks.

* [Deploy NSX Autonomous Edge (on-premises site)](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas/deploy-nsx-autonomous-edge-on-premises-site)
* [Register & configure the Networks of the NSX Autonomous Edge On-Premises](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas/register-and-configure-the-networks-of-the-nsx-autonomous-edge-on-premises)
* [Create a L2 VPN - Server session (HI GIO cloud site).](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas/create-a-l2-vpn-server-session-hi-gio-site-.)
* [Create a L2 VPN - Client session (on-premises site).](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas/create-a-l2-vpn-client-session-on-premises-site)

## **Guidelines** <a href="#guidelines" id="guidelines"></a>

* [Preparing the configure](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas/preparing-the-configure)
* [Deploy NSX Autonomous Edge (on-premises site)](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas/deploy-nsx-autonomous-edge-on-premises-site)
* [Register & configure the Networks of the NSX Autonomous Edge On-Premises](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas/register-and-configure-the-networks-of-the-nsx-autonomous-edge-on-premises)
* [Create a L2 VPN server session (HI GIO site).](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas/create-a-l2-vpn-server-session-hi-gio-site-.)
* [Create a L2 VPN - Client session (on-premises site).](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas/create-a-l2-vpn-client-session-on-premises-site)
* [(Optional) Deploy the secondary NSX Autonomous Edge in HA mode (on-premises site)](/hi-gio-draas/stretching-layer-2-networks-for-hi-gios-draas/optional-deploy-the-secondary-nsx-autonomous-edge-in-ha-mode-on-premises-site)


# Preparing the configure

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}

#### **Step 1:** Please fill in the formation in yellow cells. <a href="#step-1-please-fill-in-the-formation-in-yellow-cells" id="step-1-please-fill-in-the-formation-in-yellow-cells"></a>

* VLAN & Port groups will be created on vDistributed Switch.

| **#** | **Port Group** | **VLAN**                                                    | **Remark**                         |
| ----- | -------------- | ----------------------------------------------------------- | ---------------------------------- |
| 1     | Management     | 1<mark style="background-color:yellow;">37</mark>           | For NSX Autonomous Edge management |
| 2     | Uplink         | <mark style="background-color:yellow;">138</mark>           | For NSX Autonomous Edge uplink     |
| 3     | Trunk          | <mark style="background-color:yellow;">140, 141, 142</mark> | Stretch L2 network traffic         |

* Network settings for NSX Autonomous Edge.

<table data-header-hidden data-full-width="false"><thead><tr><th></th><th></th><th width="286"></th><th></th><th></th><th></th></tr></thead><tbody><tr><td>#</td><td>OVF Template Name</td><td>Port Group</td><td>Primary Node</td><td>Second Node (optional)</td><td>Remark</td></tr><tr><td>1</td><td>Network 0</td><td>Management</td><td><mark style="background-color:yellow;">192.168.137.79</mark></td><td><mark style="background-color:yellow;">192.168.137.80</mark></td><td> </td></tr><tr><td>2</td><td>Network 1</td><td>Uplink</td><td><mark style="background-color:yellow;">192.168.138.77</mark></td><td>–</td><td>must to have access to internet</td></tr><tr><td>3</td><td>Network 2</td><td>Trunk</td><td>–</td><td>–</td><td> </td></tr><tr><td>4</td><td>Network 3</td><td>– (HA, optional)</td><td><mark style="background-color:yellow;">192.</mark>1<mark style="background-color:yellow;">68.137.81</mark></td><td><mark style="background-color:yellow;">192.168.137.82</mark></td><td> </td></tr></tbody></table>

&#x20;

<figure><img src="/files/CBxGP7F0cjT7AHoWMxnL" alt=""><figcaption><p>NSX Autonomous Interfaces</p></figcaption></figure>

* Public IP address:

| On-premises Public IP                                       | HI GIO's Public IP                                          |
| ----------------------------------------------------------- | ----------------------------------------------------------- |
| <mark style="background-color:yellow;">\<IP Address></mark> | <mark style="background-color:yellow;">\<IP Address></mark> |
| {% endstep %}                                               |                                                             |

{% step %}

#### **Step 2:** Creating port groups (VLANs)on vCenter (if we don't have) <a href="#step-2-creating-port-groups-vlans-on-vcenter-if-we-dont-have" id="step-2-creating-port-groups-vlans-on-vcenter-if-we-dont-have"></a>

<figure><img src="/files/t0qJMxScCbArTudyjT1e" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### **Step 3:** Configure VLAN & Security for TRUNK port <a href="#step-3-configure-vlan-and-security-for-trunk-port" id="step-3-configure-vlan-and-security-for-trunk-port"></a>

* Tag VLAN:<br>

  <figure><img src="/files/avw3zD5tsuTqI1hMpec9" alt=""><figcaption></figcaption></figure>

* Set security: enable Promiscuous mode and Forged transmits

  <figure><img src="/files/IFd2RTMqIDiYhnAEzczI" alt=""><figcaption></figcaption></figure>

{% endstep %}

{% step %}

#### **Step 4:** Creating Network on HI GIO (detail steps can check [here](https://higio-support.atlassian.net/wiki/spaces/v2/pages/33095854/Working+with+Organization+VDC+Networks#II.-Creating-a-Routed-VCD-network)) <a href="#step-4-creating-network-on-hi-gio-detail-steps-can-check-here" id="step-4-creating-network-on-hi-gio-detail-steps-can-check-here"></a>

* These networks are stretch layer 2 (same subnet as on-prem).
* Select IP for gateway CIDR **(It's must not duplicate IP address)**

<figure><img src="/files/i8zRVL8ujymIMXXIejAS" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

{% endstep %}
{% endstepper %}


# Deploy NSX Autonomous Edge (on-premises site)

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

On-premises sites or the client’s L2 VPN require a specially configured VMware® NSX Edge™ appliance called autonomous edge. Deploy the NSX Autonomous Edge appliance using an OVF file on the ESXi host.

The autonomous NSX Edge is straightforward to deploy and provides a high-performance VPN. The autonomous NSX Edge is deployed using an OVF file. You can also enable high availability (HA) for VPN redundancy by deploying primary and secondary autonomous Edge L2 VPN clients.

*Please request the HI GIO team to get the OVF file.*

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log in to the vCenter Server.
{% endstep %}

{% step %}
**Step 2:** Select Hosts and Clusters. To show the available hosts, expand the clusters.
{% endstep %}

{% step %}
**Step 3:** To deploy the NSX Edge, right-click the host where you want it and select Deploy OVF Template.

<figure><img src="/files/n3sHJfWW6J8gMADKEOI1" alt=""><figcaption></figcaption></figure>

&#x20;

* On the Select an **OVF template** page, to download and deploy the OVF file, paste the URL, or select a locally downloaded OVF file and click NEXT.

<figure><img src="/files/dhdhxsjjHD3W5krh1G1Q" alt=""><figcaption></figcaption></figure>

* On the **Select a name and folder** page, Enter **Virtual machine name** & select a location for its > click **Next**.

<figure><img src="/files/4l9ecTD8IxeEocTf1Vk6" alt=""><figcaption></figcaption></figure>

&#x20;

* Select the destination compute resource > click Next on the Select a compute resource page.

<figure><img src="/files/FA0vGGnQYdLxD8O8pBKv" alt=""><figcaption></figcaption></figure>

* On the **Review details** page, verify the OVF package template details > click **Next**.

<figure><img src="/files/LaRCkPkdMMGaX3IyDf9s" alt=""><figcaption></figcaption></figure>

* On the **Configuration** page, select a deployment configuration size (**detail as below**) > click **Next**.

{% hint style="warning" %}
Medium size is suitable for normal use-case. If you don’t have special requirement, please use it.
{% endhint %}

<figure><img src="/files/FaAvPnRagn3mS4kANvsy" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/EWAAA4TC43UlTHUdyioq" alt=""><figcaption></figcaption></figure>

**Sizing for NSX Autonomous Edge VM**

* On the **Select storage** page: select a storage & select virtual disk format = Thin provision > click **Next**.

<figure><img src="/files/M4dbp5Zvk1Ij8T7mSR9k" alt=""><figcaption></figcaption></figure>

* On the **Select networks** page, for all destination networks select the management network > click **Next**.

<figure><img src="/files/uzHYduauHQ0IDKT9mJBj" alt=""><figcaption></figcaption></figure>

* On the **Customize template** page, enter the following properties > click **NEXT**.

*+ In the **Application** section, do the following:*

> Set the **System Root User Password**.
>
> Set the **CLI "admin" User Password**.
>
> Select the **Is Autonomous Edge** checkbox.

Leave the remaining fields empty.

{% hint style="warning" %}
NSX Edge core services do not start unless you enter passwords meeting these requirements:

At least 12 characters

At least one uppercase letter

At least one lowercase letter

At least one digit

At least one special character

At least five different characters
{% endhint %}

*+ In the **Network Properties** section, do the following:*

> Set the **Hostname**.
>
> Set the **Management Network IPv4 Address**. This is the management IP for the autonomous edge.
>
> Set the **Management Network Netmask**. This is the management network prefix length.
>
> Set the **Default IPv4 Gateway**. This is the default gateway of the management network.

<figure><img src="/files/gY09GkZkINWJ6I4i3PWp" alt=""><figcaption></figcaption></figure>

***+** In the **DNS** section, do the following:*

> In the **DNS Server list** field, enter the DNS server IP addresses separated by spaces.
>
> In the **Domain Search List** field, enter the domain name.

***+** In the **Services Configuration** section, do the following:*

> Enter the **NTP Server List**.
>
> Enter the **NTP Servers**, separated by spaces.
>
> Select the **Enable SSH** checkbox.
>
> Select the **Allow Root SSH logins** checkbox.

***+** In the **External** section, do the following:*

&#x20;Enter the **External Port** details in the following format: VLAN\_ID,Exit Interface,IP,Prefix Length.

*For example: 138,eth2,192.168.138.77,24*. Replace the following values:

VLAN ID: VLAN ID of the uplink VLAN

Exit Interface: interface ID reserved for uplink traffic

IP: IP address reserved for the uplink interface

Prefix Length: prefix length for the uplink network

In the **External Gateway** field, enter the default gateway of the uplink network.

***+ (Optional)** In the **HA** section, do the following:*

Enter the **HA Port** details in the following format: VLAN\_ID,Exit Interface,IP,Prefix Length.

*For example:* *137,eth2,192.168.137.81,24*. Replace the following values:

VLAN ID: VLAN ID of the uplink VLAN

Exit Interface: interface ID reserved for uplink traffic

IP: IP address reserved for the uplink interface

Prefix Length: prefix length for the uplink network

In the **HA Port Default Gateway** field, enter the default gateway of the management network

<figure><img src="/files/krbO0l7kDn1hpl3FF6Mj" alt=""><figcaption></figcaption></figure>

* Review the NSX Autonomous Edge settings > on the Ready to complete page> and click **FINISH**.

<figure><img src="/files/HODdp3zieyQaOX8RLR8A" alt=""><figcaption></figcaption></figure>

&#x20;After the deployment completes, power on the NSX Autonomous Edge virtual machine.

Log in NSX autonomous via web browser:

<figure><img src="/files/WsI8bANey6IBszSm2RbY" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Register & configure the Networks of the NSX Autonomous Edge On-Premises

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Once the NSX Autonomous Edge appliance is deployed in the on-premises site, the On-Premises to Cloud Director Replication Appliance starts managing the NSX Autonomous Edge after you register it on-premises.

To complete the L2 stretch configuration entirely by using the management interface of the On-Premises to [Cloud Director Replication Appliance](https://higio-support.atlassian.net/wiki/spaces/OPs/pages/56918017), after deploying the NSX Autonomous Edge in the on-premises site, you register it by using the On-Premises to Cloud Director Replication Appliance.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log in to the management interface of the VMware Cloud Director Availability On-premises Appliance.

In a Web browser, go to [https://On-Premises-Appliance-IP-address/ui/admin](https://on-premises-appliance-ip-address/ui/admin).

Log in as the **root** user.

<figure><img src="/files/apzUbDh2F3jfGiF3qv6y" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** In the left pane, under the **System** section click **L2 Stretch**.
{% endstep %}

{% step %}
**Step 3:** On the **NSX Autonomous edges** page, click **New**.

<figure><img src="/files/9MmPKvSj3thyq2HRtGoZ" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4: Register a New NSX Autonomous Edge** window, register the new NSX Autonomous Edge with the On-Premises to Cloud Director Replication Appliance.

* Enter a friendly name for the new NSX Autonomous Edge in the Name text box.
* From the **vCenter Server** drop-down menu, select the vCenter Server instance hosting the NSX Autonomous Edge virtual machine.
* Under **NSX Autonomous Edge VMs**, select the virtual machine of the newly deployed NSX Autonomous Edge.
* In the **Management Address** text box, enter the URL for the NSX Autonomous Edge management.
* In the **User name** and **Password** text boxes, enter the **admin** user credentials for the NSX Autonomous Edge management.

**(Optional)** In the **Description** text box, enter a description for this NSX Autonomous Edge.

-To register the NSX Autonomous Edge for management, click **REGISTER**.

<figure><img src="/files/RXfYxblPqL2J8o7NdenH" alt=""><figcaption></figcaption></figure>

&#x20;

NSX Autonomous Edge will show up once completed.

<figure><img src="/files/gVPfWWicQWiEVwKPh3cz" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** On the **NSX Autonomous edges** page, select deployed NSX Autonomous Edge instance & Click **EDIT NETWORK**

Select the network adapters of the NSX Autonomous Edge > click **Apply**.

<figure><img src="/files/cKPA8Uf19Iny8kq1hBeS" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 6:** On the **NSX Autonomous edges** page, select deployed NSX Autonomous Edge instance > Click **Configure the uplink port**.

Enter the settings for the external network port > click **Apply**.

<figure><img src="/files/TExorZhWyk12hgEwFCkt" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Create a L2 VPN server session (HI GIO site).

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

By using the management interface in the HI GIO cloud site, organization administrators create the server side of the L2 VPN session, enabling the L2 stretch of one or more networks across the on-premises site.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1**: Log in to HI GIO Portal

Select **Network** > **Edge Gateways** > VPC name

<figure><img src="/files/QQ8PbQzGDTI6VM58RT7C" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** Under Services, click **L2 VPN** > **NEW** to *open L2 VPN Tunnel window.*

<figure><img src="/files/FPovHtCE3iOSQkoaS1zU" alt=""><figcaption></figcaption></figure>

* On Choose Session Mode, select **Server** > click **Next**.

<figure><img src="/files/dkVq4Ur9t7W4Lije4Z2D" alt=""><figcaption></figcaption></figure>

* Enter a name and pre-shared key > **NEXT**

<figure><img src="/files/kdzNkEU2AWsyQOJsWh0k" alt=""><figcaption></figcaption></figure>

* Enter the IP address for the Local IP, remote IP, Initiation Mode > **NEXT**

<figure><img src="/files/XV9nyMJCiNNtK1Kc3sI4" alt=""><figcaption></figcaption></figure>

&#x20;\- Select Networks > **NEXT**&#x20;

These networks were created in the preparation phase.

<figure><img src="/files/nEOPXtIlKQLUvoiNdz1q" alt=""><figcaption></figcaption></figure>

* Review and click **FINISH.**

<figure><img src="/files/SS4QXhyu0J3ayq4qjHVj" alt=""><figcaption></figcaption></figure>

Waiting some minutes.

Once complete, we can see tunnel **IDs (use it for manual configure on NSX autonomous edge)**

<figure><img src="/files/06NfzQ9G7Yf9FVO4AXOm" alt=""><figcaption></figcaption></figure>

&#x20;And copy Peer code **(use it for manual configure on NSX autonomous edge)**

<figure><img src="/files/OErLBu4I6Qt2TXvJtRnn" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Create a L2 VPN - Client session (on-premises site)

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

After configuring the networks of the NSX Autonomous Edge, by using On-Premises to Cloud Director Replication Appliance create the client side of the L2 VPN session, stretching one or more networks across the cloud site.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log in to the management interface of the VMware Cloud Director Availability On-premises Appliance.

In a Web browser, go to [https://On-Premises-Appliance-IP-address/ui/admin](https://on-premises-appliance-ip-address/ui/admin).

Log in as the **root** user.

<figure><img src="/files/uYPEwC2a2X9DJcbExTKW" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2:** In the left pane, under the **System** section, click **L2 Stretch**.
{% endstep %}

{% step %}
**Step 3:** On the **NSX Autonomous edges** page, click **L2 VPN Sessions** > **NEW**

<figure><img src="/files/XwjKozZ3QpXQSy1N6obf" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4**: If your user session is not currently extended to the cloud site, enter credentials to authenticate to the cloud site.
{% endstep %}

{% step %}
**Step 5:** Select the cloud site virtual data center and the edge gateway on the **VDC and edge Gateway page.**

<figure><img src="/files/xRCeViFVZ6Ezi0hMgIxU" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 6:** On the **Settings and networks** page, configure the L2 VPN and click **Next**.

* In the **Name** text box, enter a name for this client L2 VPN session.
* From the **Server session** drop-down menu, select the cloud side L2 VPN server session.
* In the **Local Address** text box, enter the on-premises IP address at the client side of the L2 VPN session.\
  The local IP address must be the same as the uplink port IP address of the NSX Autonomous Edge hosting the client L2 VPN session.
* In the **Remote Address** text box, enter the HI GIO public IP address at the server side of the L2 VPN session.
* Under the Client Network column, to create an L2 stretch across the networks select an on-premises VLAN network.

&#x20;

<figure><img src="/files/zaKKu1kel53bzXHoMTkM" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 7:** On the **Ready To Complete** page, review and click **FINISH**.

<figure><img src="/files/hqHfc9bppSEuEFNKxWQ2" alt=""><figcaption></figcaption></figure>

**>>>** The client L2 VPN session on-premises is created and the L2 stretch across the cloud site is complete.

<figure><img src="/files/tJBGVxjZVhNxTW7ygV3b" alt=""><figcaption></figcaption></figure>

&#x20; **\*\*\* Test Connectivity**

Ping to Gateway (on-prem) from HI GIO.

<figure><img src="/files/b4xklpYwl3OcT25Rm5Cd" alt=""><figcaption></figcaption></figure>

Ping to HI GIO’s VM (same VLAN\difference VLAN) from on-prem.

<figure><img src="/files/XpxG757GeaitWaSy5CQT" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# (Optional) Deploy the secondary NSX Autonomous Edge in HA mode (on-premises site)

## <mark style="color:green;">O</mark><mark style="color:green;">**verview**</mark> <a href="#overview" id="overview"></a>

Optionally, use the following steps to deploy a secondary NSX-T Autonomous Edge (Layer 2 VPN client) in HA mode in your on-premises environment:

| **#** | **OVF Template Name** | **Port Group**   | **Primary Node**                                             | **Second Node (optional)**                                                                                 | **Remark**                      |
| ----- | --------------------- | ---------------- | ------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------- | ------------------------------- |
| 1     | Network 0             | Management       | <mark style="background-color:yellow;">192.168.137.79</mark> | <mark style="background-color:yellow;">192.168.137.</mark>8<mark style="background-color:yellow;">0</mark> |                                 |
| 2     | Network 1             | Uplink           | <mark style="background-color:yellow;">192.168.138.77</mark> | –                                                                                                          | must to have access to internet |
| 3     | Network 2             | Trunk            | –                                                            | –                                                                                                          |                                 |
| 4     | Network 3             | – (HA, optional) | <mark style="background-color:yellow;">192.168.137.81</mark> | 1<mark style="background-color:yellow;">92.168.137.82</mark>                                               |                                 |

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Follow the steps in [Deploy NSX Autonomous Edge (on-premises site)](https://higio-support.atlassian.net/wiki/spaces/v2/pages/69992630) until you reach the **Customize template** step.
{% endstep %}

{% step %}
**Step 2:** On the **Customize template** step, do the following instead:

* In the **Application** section, do the following:
  * Set the **System Root User Password**.
  * Set the **CLI "admin" User Password**.
  * Select the **Is Autonomous Edge** checkbox.
  * Leave the remaining fields empty.

{% hint style="warning" %}
NSX Edge core services do not start unless you enter passwords meeting these requirements:

At least 12 characters

At least one uppercase letter

At least one lowercase letter

At least one digit

At least one special character

At least five different characters
{% endhint %}

* In the **Network Properties** section, do the following:

  * Set the **Hostname**.
  * Set the **Management Network IPv4 Address**. This is the management IP for the autonomous edge.
  * Set the **Management Network Netmask**. This is the management network prefix length.
  * Set the **Default IPv4 Gateway**. This is the default gateway of the management network.

  <figure><img src="/files/ih0AVBMENaPU5KtfjLXL" alt=""><figcaption></figcaption></figure>
* In the **DNS** section, do the following:
  * In the **DNS Server list** field, enter the DNS server IP addresses separated by spaces.
  * In the **Domain Search List** field, enter the domain name.
* In the **Services Configuration** section, do the following:
  * Enter the **NTP Server List**.
  * Enter the **NTP Servers**, separated by spaces.
  * Select the **Enable SSH** checkbox.
  * Select the **Allow Root SSH logins** checkbox.
* Leave **External** section empty.
* In the **HA** section, do the following:

-Enter the **HA Port** details in the following format: VLAN\_ID, Exit Interface, IP, Prefix Length.

*For example:* *137,eth2,192.168.137.81,24*. Replace the following values:

VLAN ID: VLAN ID of the uplink VLAN

Exit Interface: interface ID reserved for uplink traffic

IP: IP address reserved for the uplink interface

Prefix Length: prefix length for the uplink network

-In the **HA Port Default Gateway** field, enter the default gateway of the management network

-Select the **Secondary API Node** checkbox.

-In the **Primary Node Management IP** field, enter the management IP address of the primary autonomous edge.

-In the **Primary Node Username** field, enter the username of the primary autonomous edge (for example, "admin").

-In the **Primary Node Password** field, enter the password of the primary autonomous edge.

-In the **Primary Node Management Thumbprint** field, enter the API thumbprint of the primary autonomous edge.

> You can get this by connecting using SSH to the primary autonomous edge using admin credentials and running the command: “**get certificate api thumbprint**”

<figure><img src="/files/fvoFitwrCyW2qBvDS1KK" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/s4SB9A3VXp7mnCKhrAmL" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Complete the remaining OVF template deployment steps to deploy the secondary autonomous edge (on-premises Layer 2 VPN client).

<figure><img src="/files/rIOFLhgED1rQ5R6D0KE7" alt=""><figcaption></figcaption></figure>

PowerOn the second NSX autonomous edge
{% endstep %}

{% step %}
**Step 4:** Validate:

It will take some minutes to sync.

Log in to both NSX autonomous nodes, check High Availability, L2VPN\\

-Primary node:

<figure><img src="/files/Ay8bFTLJw6GNiU6XnJKg" alt=""><figcaption></figcaption></figure>

-Secondary node:

<figure><img src="/files/qfzB4ZsAfBfqwOfQEEeV" alt=""><figcaption></figcaption></figure>

-Port ID, Tunnel ID, exit interfaces are same on both nodes.

<figure><img src="/files/2qxEa2cUbliwFM0j01GU" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Failover test:

To test the NSX autonomous failover:

-Ping from on-premises to HI GIO cloud.

-Shutdown NSX autonomous primary node

-Result:

NSX autonomous secondary status will change to ACTIVE, L2 VPN = UP

<figure><img src="/files/BMUP016W23e9h4FwfAdV" alt=""><figcaption></figcaption></figure>

The connection drop \~ 5-10 seconds

<figure><img src="/files/mUds1wGpkqJlh68GT9Bu" alt=""><figcaption></figcaption></figure>

After powering on the NSX autonomous primary node, the HA status between the nodes was re-established. The secondary edge remains active, and the primary will become active only in case of additional failure.

<figure><img src="/files/m9zRWcs2V3z9iQShBJUp" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# FAILOVER SCENARIO

## <mark style="color:green;">Partial Failover</mark> <a href="#partial-failover" id="partial-failover"></a>

* Partial failover is necessary when your DC (on-premises site) is **still up and running** but only one (or a subset) of your servers, applications, or virtual machines (VMs) is experiencing problems.
* In this scenario, a complete site failover is unnecessary. Partial failover allows you to run the corrupted systems at the DR site (HI GIO cloud) while the rest of your functional systems keep running on your DC site (on-premises site).

## <mark style="color:green;">Full Failover</mark> <a href="#full-failover" id="full-failover"></a>

* Disaster scenarios almost always strike unexpectedly. In a disaster event, it is critical to restore the infrastructure of your business as soon as possible before any significant damage is done.
* Failover and failback can help ensure that your business continues functioning properly, even if the DC site is affected by a disaster.&#x20;


# ENVIRONMENT

## <mark style="color:green;">**Architecture Diagram**</mark> <a href="#id-1.-architecture-diagram" id="id-1.-architecture-diagram"></a>

<figure><img src="/files/N15Pu6KpFB8n0hglwCvT" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/CihFmcYwg7VrZvajgkNN" alt=""><figcaption></figcaption></figure>

DC site has an issue - full failover

## &#x20;<mark style="color:green;">**Environment Information**</mark> <a href="#id-2.-environment-information" id="id-2.-environment-information"></a>

1. **On-premises Site**&#x20;

| **No.** | **Item**         | **Description**                                | **IP Address**  | **Note** |
| ------- | ---------------- | ---------------------------------------------- | --------------- | -------- |
| **1**   | vcsa7.lab.local  | vCenter                                        | 192.168.137.77  |          |
| **2**   | vcda7.lab.local  | VMware Cloud Director Availability On-premises | 192.168.137.78  |          |
| **3**   | host16.lab.local | ESXi host                                      | 192.168.137.50  |          |
| **4**   | DC.lab.local     | Primary Domain controller                      | 192.168.137.200 |          |

2. **HI GIO Site**

|         |                      |                             |                 |          |
| ------- | -------------------- | --------------------------- | --------------- | -------- |
| **No**. | **Item**             | **Description**             | **IP Address**  | **Note** |
| 1       | ASG000001-Customer01 | Organizations               |                 |          |
| 2       | ADC.lab.local        | Secondary Domain controller | 192.168.137.201 |          |

&#x20;**3. Environment System Configuration**

| # | **App Name**                                       | **Hostname**                                                 | **On-prem IP address**                                       | **HI GIO's Network**                                     | **HI GIO IP address**                                        | **Remark**                       |
| - | -------------------------------------------------- | ------------------------------------------------------------ | ------------------------------------------------------------ | -------------------------------------------------------- | ------------------------------------------------------------ | -------------------------------- |
| 1 | <mark style="background-color:yellow;">APP1</mark> | <mark style="background-color:yellow;">APP1.lab.local</mark> | <mark style="background-color:yellow;">192.168.140.14</mark> | <mark style="background-color:yellow;">\[L2]VM140</mark> | <mark style="background-color:yellow;">192.168.140.14</mark> | <http://app1.lab.local/Students> |
| 2 | <mark style="background-color:yellow;">APP1</mark> | <mark style="background-color:yellow;">DB1.lab.local</mark>  | <mark style="background-color:yellow;">192.168.141.14</mark> | <mark style="background-color:yellow;">\[L2]VM141</mark> | <mark style="background-color:yellow;">192.168.141.14</mark> |                                  |


# FAILOVER

## <mark style="color:green;">**Guideline**</mark> <a href="#guidelines" id="guidelines"></a>

* [Step 1: Create a protection job (from on-premises site)](/hi-gio-draas/failover-scenario/failover/step-1-create-a-protection-job-from-on-premises-site)
* [Step 2: Configure the Network Settings for On-Premises to Cloud Replications](/hi-gio-draas/failover-scenario/failover/step-2-configure-the-network-settings-for-on-premises-to-cloud-replications)
* [Step 3P - Partial failover VMs (VM - APP1) from on-premise site to HI GIO site.](/hi-gio-draas/failover-scenario/failover/step-3p-partial-failover-vms-vm-app1-from-on-premise-site-to-hi-gio-site)
* [Step 3F - Full failover vAPP1 (VM - APP1 & VM - DB1) from on-premise site to HI GIO](/hi-gio-draas/failover-scenario/failover/step-3f-full-failover-vapp1-vm-app1-and-vm-db1-from-on-premise-site-to-hi-gio)
* [Step 4: Reverse replication of the VM from HI GIO Cloud to On-Premises](/hi-gio-draas/failover-scenario/failover/step-4-reverse-replication-of-the-vm-from-hi-gio-cloud-to-on-premises)
* [Step 5: Migrate the VMs back from HI GIO Cloud to On-Premises](/hi-gio-draas/failover-scenario/failover/step-5-migrate-the-vms-back-from-hi-gio-cloud-to-on-premises)
* [Step 6: Reprotect the VMs from On-Premises to HI GIO Cloud](/hi-gio-draas/failover-scenario/failover/step-6-reprotect-the-vms-from-on-premises-to-hi-gio-cloud)
* [NOTEs](/hi-gio-draas/failover-scenario/failover/faqs)

<figure><img src="/files/ojflmFUyRBJoF05UaOpP" alt=""><figcaption><p>Failover workflow</p></figcaption></figure>


# Step 1: Create a protection job (from on-premises site)

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log in to vCenter, Expand **Menu** > Click on **Cloud Provider DR and Migration**

<figure><img src="/files/I3wFL0Gc3IgJzG7kL40n" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 2**: Click on **Outgoing Replications** > **New Protection**

<figure><img src="/files/54d2x4bRJ2l89GGUrL4q" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Enter *credential of Organization* > **LOGIN**

<figure><img src="/files/P7BGd78JIC6Gu8ktKEGG" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** On Source VMs windows:

**- Enable Group VMs to a single vApp.**

**- Select APP1 & DB1.**

**- Click NEXT**

<figure><img src="/files/cefw35FIJdF7G9M5VfNw" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** On vApp Settings

**- Enter vApp name: vAPP1**

**- Set: start wait time**&#x20;

**- Click NEXT**

<figure><img src="/files/pNLq6HJfEhlsQyHncDXd" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 6:** Select *destination VDC & storage policy* > **NEXT**

<figure><img src="/files/ZGuWAQmHaZNUAF6g5fBI" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 7:** Select *SLA profile* > **NEXT**

<figure><img src="/files/ZcYyFQmPdsBHFMVL1Wdn" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 8:** Review > **FINISH**

<figure><img src="/files/TiDJWweipNKzhPM5xrbx" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 9:** Expectation result

* Confirm the **Replication is started**. You can monitor the **% progress** here

<figure><img src="/files/d0laBHY4c1G4r6LY4QIU" alt=""><figcaption></figcaption></figure>

* Replication state completed. Confirm that:

**- Replication state = healthy,**

**- Overall health = Green.**

<figure><img src="/files/kpHK9sSlFWKM8OGYYySe" alt=""><figcaption></figcaption></figure>

* Confirm the Replication Status from HI GIO Cloud:

**Log in to** HI GIO Availability > **Incoming Replications**, select **INSTANCES.**

Confirm the vAPP&#x31;**:**

\- **Replication state** = **Healthy**

\- **Overall Health** = **Green**

<figure><img src="/files/usuoUr9i3QKqzRDzIeRO" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

&#x20;

&#x20;


# Step 2: Configure the Network Settings for On-Premises to Cloud Replications

## <mark style="color:green;">Overview</mark>

Before running the replicated VM's Recovery, we must configure a Failover Network on APP1.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log in to HI GIO Availability.
{% endstep %}

{% step %}
**Step 2:** Select *Incoming Replications* > select **vAPP1** > **ALL ACTIONS** > **Recovery settings**.

<figure><img src="/files/KOMKw0uX7ekOjiTZ2U0M" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** In the Recovery settings window > click the **Nics** tab > **vAPP1**
{% endstep %}

{% step %}
**Step 4:** Assign a network that fits with HI GIO's network > **APPLY**

<figure><img src="/files/19b34Ey2WzJnORHpVZtG" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Step 3P - Partial failover VMs (VM - APP1) from on-premise site to HI GIO site

## <mark style="color:green;">**Overview**</mark>

Use this step when your primary infrastructure (on-premise) is running well. After this step:

**- Workload is on the HI GIO cloud site.**

**- Source workload is powered off.**

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log on to the HI GIO portal.
{% endstep %}

{% step %}
**Step 2:** Expand **More** > Click on **Availability ()**

<figure><img src="/files/3b8WWE3Qcbz9EeK3wIQs" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Click on **Incoming Replications >** Check the checkbox for VM **APP1** > Expand **ALL ACTIONS** > Click on **Migrate**

<figure><img src="/files/Jl6gUAyORBzC8VYa4dMs" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Configure Recovery Settings for Migrate

**- Instances handing after recovery: Default.**

**- Power Settings: Power on recovered vApps.**

**- Network Settings: Apply preconfigured network settings on migrate (configured in step2)**

<figure><img src="/files/pQqnIVayJAd4cwRhzLwt" alt=""><figcaption></figcaption></figure>

**- Click NEXT**

<figure><img src="/files/ZkMcY7IgrceVzqwbnXRL" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Review and click **FINISH**

<figure><img src="/files/5kfuJOwptVqoNSRWd3nL" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 6:** Expectation result:

1. Failover in Progress: You will notice Migrate **in Progress with %** progress in the Detailed Status.

<figure><img src="/files/0JGeAEnY2HFnuYdl1pyE" alt=""><figcaption></figcaption></figure>

2. Once the migration task is completed, confirm on

**STATUS**, **VM**:

**APP1:**&#x20;

\- Recovery state = Failed-Over,&#x20;

\- Replication Type = On-Premise Protection,&#x20;

\- Overall health = Green.

**DB1:**&#x20;

\- Recovery state = Not stated,&#x20;

\- Replication Type = On-Premise Protection,&#x20;

\- Overall health = Green.

<figure><img src="/files/BE7lXWMvqOZt33akZbwY" alt=""><figcaption></figcaption></figure>

Migrate completed successfully. The workload is running in the HI GIO cloud, and the workload is no longer protected.
{% endstep %}
{% endstepper %}

***

## <mark style="color:orange;">Validate - APP1</mark> <a href="#validate-app1" id="validate-app1"></a>

## <mark style="color:green;">**Procedure**</mark>

{% stepper %}
{% step %}
**Step 1:** Log on to the HI GIO portal: *select vAPP1* > **Virtual machines**.
{% endstep %}

{% step %}
**Step 2:** Confirm that VM APP1 was migrated to HI GIO and powered on.

<figure><img src="/files/C6eAb8GSNjTIfBNvOoyM" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Ping, tracert, HTTP to APP1 from on-premises site must be success.

<figure><img src="/files/bSTNZvPpQ00jfPFSPeUV" alt=""><figcaption></figcaption></figure>

{% endstep %}

{% step %}
**Step 4:** Expectation result:

1. The VM APP1 is running on the HI GIO site now. The VM is no longer protected.
2. The VM APP1 is power off on-premises - automatic by vCDA.

<figure><img src="/files/hXDtjsbBxijkDOsj2i09" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

<br>


# Step 3F - Full failover vAPP1 (VM - APP1 & VM - DB1) from on-premise site to HI GIO

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

If the protected site (on-premises) is **unavailable**. In the HI GIO cloud, you can perform a workload disaster recovery operation (full failover)

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log on to the HI GIO portal.
{% endstep %}

{% step %}
**Step 2:** Expand **More** > Click on **Availability ()**

<figure><img src="/files/OmqP1e8qbfBSVlcfE4fN" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Click on **Incoming Replications >** Check the checkbox for VM **APP1** > Expand **ALL ACTIONS** > Click on **Failover**

<figure><img src="/files/quREPTLD4kkC3cnTisBY" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Configure Recovery Settings for Failover

**- Instances handing after recovery: Default.**

**- Power Settings: Power on recovered vApps.**

**- Network Settings: Apply preconfigured network settings on migrating.**

Click **NEXT**

<figure><img src="/files/tK2drBuXkHRYr6A7ca7M" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Configure Recovery Instance for Failover

Click **SELECT LATEST FOR EVERY VM** > **NEXT**

&#x20;

<figure><img src="/files/2FGSXGDd9GCNIDtkRIpj" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 6:** Review and **FINISH**

<figure><img src="/files/9DOZm5u23Y6EItbffW9j" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 7:** Expectation result:

1. Failover in Progress: In the Detailed Status, you will notice Failover **in Progress with %** progress.

<figure><img src="/files/wfqkZOJk2tgtAnOS6e5r" alt=""><figcaption></figcaption></figure>

2. Failover successfully: This process will take a couple of minutes. Please be patient.

After the failover task finishes, the failed over workload runs in the HI GIO cloud.

**Confirm that all VMs in vAPP1:**

**- Recovery State = Failed-Over.**

**- Replication Type = On-Premise Protection**

**- Overall health = Green**

<figure><img src="/files/8qzt696FQ6cdThjjAQSp" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## <mark style="color:orange;">Validate - vAPP1 (VM APP1 & DB1)</mark> <a href="#validate-vapp1-vm-app1-and-db1-on-hi-gio-cloud" id="validate-vapp1-vm-app1-and-db1-on-hi-gio-cloud"></a>

In this scenario, on-premise has issues: network, hardware host, and storage… that make it not available.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure.1" id="procedure.1"></a>

{% stepper %}
{% step %}
**Step 1:** Log on to the HI GIO portal: *select vAPP1* > **Virtual machines**.
{% endstep %}

{% step %}
**Step 2:** Confirm that 02 VMs, APP1 & DB1, were migrated to HI GIO and are running.

<figure><img src="/files/lAvlKl5PPm1jLsPFyB3f" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Change default gateway for APP1 & DB1 (on-prem network is problem)

Logon **APP1 & DB1** by admin local > change default gateway and validate that **APP1 & DB1** can be reachable.

<figure><img src="/files/2dVIZ4HARFfGUZY2MVcH" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/biNKK1IjLH2DvOMtqMOg" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Point domain name to APP1 (public DNS record if needed).
{% endstep %}

{% step %}
**Step 5:** Access to APP1 via the internet (in my case, I used a public IP).

<figure><img src="/files/c9BcCNr73hFGFgTUvUQM" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

<br>


# Step 4: Reverse replication of the VM from HI GIO Cloud to On-Premises

## <mark style="color:green;">**Overview**</mark>  <a href="#overview" id="overview"></a>

After the on-premises site has **recovered from the issue** and is **available**, we can migrate the workload (APP1, DB1) from the HI GIO cloud back to on-premises by reversing the replication.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log on to the HI GIO portal.
{% endstep %}

{% step %}
**Step 2:** Expand **More** > Click on **Availability ()**

<figure><img src="/files/TEFV84UPXMkw8TzWFkXH" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Click **Incoming Replications >** Check the checkbox for vAPP1 > Expand ALL ACTIONS > Click on **Reverse.**

You can also select individual VMs in this step.

<figure><img src="/files/D6COU4HXq2VaEhrm6PJK" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Confirm Reverse Replication from HI GIO Cloud to on-prem. Click **REVERSE**.

<figure><img src="/files/buXIEJ0kkmdmkC902BNG" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Expectation result:

1. Reverse Replication is in progress. You can monitor the progress of the Reverse task in the Last changed section and replicate the state.

<figure><img src="/files/35sESYmoLHVajD4fwpXo" alt=""><figcaption></figcaption></figure>

2. Reverse Replication is Completed. Here, APP1 & DB1 are replicated back to On-Prem, and the Recovery State is Reversed.

<figure><img src="/files/VxxvsS1DHAS1A0Xkyhlh" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Step 5: Migrate the VMs back from HI GIO Cloud to On-Premises

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Since the VM is successfully replicated from Cloud to On-Prem, we will migrate the VM APP1, DB1 from HI GIO Cloud back to On-Prem.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log on to the HI GIO portal.
{% endstep %}

{% step %}
**Step 2:** Expand **More** > Click on **Availability ()**

<figure><img src="/files/a3UmEZ86DANMJh5VuJTe" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Click on **Outgoing Replications >** Check the checkbox for vAPP1 > Expand **ALL ACTIONS** > Click on **Migrate**

<figure><img src="/files/GRKqC6f5oMfNnVUu4qib" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 4:** Configure Migrate Settings. Leave the Defaults and Click on **NEXT**

<figure><img src="/files/dj7dl1kquZmLkQSqdSE2" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Review the Migration Settings and click on **FINISH**

<figure><img src="/files/wuAiQTtRf0JgCSsg53Na" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### **Step 6:** Expectation result <a href="#step-6-expectation-result" id="step-6-expectation-result"></a>

1. Migration in Progress

<figure><img src="/files/xk5GN9WQQjLj0xlruLyZ" alt=""><figcaption></figcaption></figure>

2. Migration to on-premises is Completed Successfully. **Confirm that:**

**- Recovery state = Failed-Back**

**- Replication type = On-Premise Protection**

**- Overall health = Green**

<figure><img src="/files/zWOGJK0AF9nIE9UooJMr" alt=""><figcaption></figcaption></figure>

3. **Confirm VMs migrated back to On-premises.**

VM APP1-xxxx, DB-xxxx now show up in the vCenter's inventory

<figure><img src="/files/Aezp2jsngPmTc0V5a3EZ" alt=""><figcaption></figcaption></figure>

4. **Login to APP1 & DB1 by local account > change the IP address to fit with the on-premise site** (in my case, I just changed the default gateway to .1) and validate the application.

<figure><img src="/files/6OATzdVOCavYU3BhXapz" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Step 6: Reprotect the VMs from On-Premises to HI GIO Cloud

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

After migrating over the workload to On-Premises, we can reverse the replication and reprotect it back to the HI GIO Cloud site.

Once reprotect is successful, this will show as outgoing replication from On-Premises to the Cloud.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Log on to the HI GIO portal.
{% endstep %}

{% step %}
**Step 2:** Expand More > Click on **Availability** ()

<figure><img src="/files/gggODfwA5Ds7PcuH9sbB" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 3:** Click on Outgoing Replications >Check the checkbox for vAPP1 > Expand ALL ACTIONS

{% endstep %}

{% step %}
**Step 4:** Click on **Reverse**

<figure><img src="/files/TnxgsxXN3sID0tjIQsyE" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Step 5:** Click on REVERSE

<figure><img src="/files/Ukurk3b195zCsHfzOnjY" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### **Step 6:** Expectation result: <a href="#step-6-expectation-result" id="step-6-expectation-result"></a>

1. The reverse from On-Premises to HI GIO Cloud Is **In Progress**

<figure><img src="/files/Lgg6S0OZBXrVN0iM44fS" alt=""><figcaption></figcaption></figure>

2. Reverse from On-Premises to Cloud **Completed Successfully**. Outgoing Replications is empty now.&#x20;

<figure><img src="/files/K4VkhODYrmj5aYhgvRod" alt=""><figcaption></figcaption></figure>

3. Since the replication is **configured** from On-Premises to Cloud, we will view Incoming Replications.

Select **Incoming Replications**. Here, you will notice VM APP1-xxxx is replicated back from On-Premises to Cloud, and the Replication type is On-Premise Protection.

<figure><img src="/files/gfXDaiJzFT3xHkWiEx8I" alt=""><figcaption></figcaption></figure>

4. Verify replication status from the On-Premises site

Expand **Menu** > Click on **Cloud Provider DR and Migration.**

<figure><img src="/files/5Zyy7xNVfPM2KMnl7sOz" alt=""><figcaption></figcaption></figure>

Click on **Outgoing Replications.**

Confirm VM APP1-xxxx & DB1-xxxx is replicated back from On-Premises to Cloud and Replication type is Protection.

<figure><img src="/files/QNCcjRx4pvQ7FB3JVjZ9" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# FAQs

1. <mark style="color:green;">**You can find the protected jobs on the jobs on-premises site.**</mark>

After creating the protection job\reverse job on HI GIO cloud (by provider account), you cannot see these jobs on-premises site.

**Solution**: Change the owner of these jobs to a tenant organization

<figure><img src="/files/KMo6sHGn7H6swymGiwGl" alt=""><figcaption></figcaption></figure>

&#x20;

<figure><img src="/files/P25wG8m6tT9VTh0QJjlw" alt=""><figcaption></figcaption></figure>

&#x20;

2. <mark style="color:green;">**Virtual Machine disk consolidation is needed.**</mark>

Migrating back VMs from HI GIO cloud to on-premises made VMs warn - virtual machine disk consolidation is needed.

<figure><img src="/files/jzw6AmkQIvNbr4Pu7TKL" alt=""><figcaption></figcaption></figure>

**Solution**: consolidate for VMs

<figure><img src="/files/XzEF0feqcYqxJ3C7n6BZ" alt=""><figcaption></figcaption></figure>

3. <mark style="color:green;">**The issue with the Windows server - lost trust relationship after migrating VM to HI GIO cloud or migrating back to on-premises.**</mark>

<figure><img src="/files/OgQAPf3bdHhUgLVhOqov" alt=""><figcaption></figcaption></figure>

* **Solution**: Follow this guide to resolve it <https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/windows/troubleshoot-broken-secure-channel>
* **Tip.** You can configure the maximum computer password age using the **Domain member: Maximum machine account password age** policy under Computer Configuration-> Windows Settings-> Security Settings-> Local Policies-> Security Options. A computer password lifetime may last from 0 to 999 days (30 days by default);


# NETWORK

## <mark style="color:green;">**Information**</mark>

This short manual guide is crafted to help HI GIO users navigate our network offerings, providing you with the knowledge and tools necessary to optimize your network infrastructure. In this guide, you will find step-by-step instructions for configuring and managing your network services, best practices for maintaining optimal performance, and tips for troubleshooting common issues.

## <mark style="color:green;">**Overview**</mark>

{% hint style="info" %} <img src="/files/Z2G1Mc44Tl1uk5SsYLdE" alt="" data-size="original">

We provide **HI GIO Network & Security** for all enterprises’ networks that need to address their particular protection and compliance requirements by fine-grained protections at host, network, and application levels such as Distributed Firewall, Edge Firewall, Web Application Firewall (WAF), Third Party Firewall (Checkpoint, Fortigate), Zero Trust Network Access (ZTNA).
{% endhint %}

## <mark style="color:green;">**Guideline**</mark>

* [1. Working with Network](/network/1.-working-with-network)
  * [Working with Organization VDC Networks](/network/1.-working-with-network/working-with-organization-vdc-networks)
  * [How to create NAT rules on Edge Gateway](/network/1.-working-with-network/how-to-create-nat-rules-on-edge-gateway)
  * [Using Edge Gateway Firewall](/network/1.-working-with-network/using-edge-gateway-firewall)
  * U[sing Distributed Firewall in a Data Center Group](/network/1.-working-with-network/using-distributed-firewall-in-a-data-center-group)
* [2. VPN](/network/2.-vpn)
  * [IPSec parameters](/network/2.-vpn/ipsec-parameters)
  * [IPSec VPN](/network/2.-vpn/ipsec-vpn)
  * [IPSec Remote Access VPN Clients on Windows](/network/2.-vpn/ipsec-remote-access-vpn-clients-on-windows)
* [3. Load Balancer](/network/3.-load-balancer)
  * [IMPORT SSL CERTIFICATE](/network/3.-load-balancer/import-ssl-certificate)
  * [CREATE POOLS ON LOAD BALANCING](/network/3.-load-balancer/create-pools-on-load-balancing)
  * [CREATE VIRTUAL SERVICE (VS) ON LOAD BALANCING](/network/3.-load-balancer/create-virtual-service-vs-on-load-balancing)
  * [OPEN FIREWALL RULE TO PUBIC SERVICE TO INTERNET](/network/3.-load-balancer/open-firewall-rule-to-public-service-to-internet)
  * [MONITOR TRAFFIC ANALYTICS IN FPT HI GIO CLOUD UI](/network/3.-load-balancer/monitor-traffic-analytics)


# 1. Working with Network

## <mark style="color:green;">Overview</mark>

HI GIO uses a layered networking architecture with four categories of networks to provide a highly flexible and secure network infrastructure in a multipurpose cloud environment. The categories are external networks, organization virtual data center (VDC) networks, data center group networks, and vApp networks. Most types of networks require additional infrastructure objects, such as edge gateways and network pools.


# Working with Organization VDC Networks

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Organization virtual data center (VDC) networks enable vApps\VMs to communicate with each other or with external networks outside the organization.

Depending on the connection of the organization VDC network, there are several different types of organization VDC networks:

* **An isolated (internally connected) network** is one that only VMs within the VDC network can connect to.
* **A routed network (externally connected)** provides access to machines and networks outside the VDC via the edge gateway.

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% stepper %}
{% step %}
**Step 1:** Creating an Isolated VCD Network

* In the top navigation bar, click **Networking**.
* On the *Networks* tab, click **New** to Open New Organization VDC Network window.
* On the *Scope* page, select **Organization Virtual Data Center** or **Data Center Group** which to create the network, and click **Next**

<figure><img src="/files/dzqrLcmCNOn3R5R7AlmZ" alt=""><figcaption></figcaption></figure>

* On the *Select Network Type* page, select **Isolated** >> **Next**.

<figure><img src="/files/0UXxM7W5ApEGJM3rKyaa" alt=""><figcaption></figcaption></figure>

* Enter a **Name and** **description** (optional) for the network.
* To enable dual-stack networking (enable the network to have both IPv4 & IPv6 subnet), turn on the **Dual-Stack Mode** toggle.
* Enter the Classless Inter-Domain Routing (CIDR) settings for the network >>**Next**

Format: network\_gateway\_IP\_address/ subnet\_prefix\_length like *192.168.100.254/24*

<figure><img src="/files/wEn3lkpG9dbjE24WeZnH" alt=""><figcaption></figcaption></figure>

* In *Static IP Pools*, enter the ranges of IP addresses that you want to use, click **Add** >> **Next**

<figure><img src="/files/1NPtafkNxYWZVqmW2YNk" alt=""><figcaption></figcaption></figure>

* Configure the DNS settings (Optional).

You can put Primary DNS\Secondary DNS\DNS suffix >> **Next**

<figure><img src="/files/uHJDwD3nIfzHhfl0gt3p" alt=""><figcaption></figcaption></figure>

* Review your settings and click **Finish**.
  {% endstep %}

{% step %}
**Step 2**:  Creating a Routed VCD Network

* In the top navigation bar, click **Networking**.
* On the *Networks* tab, click **New** to Open New Organization VDC Network window.
* On the *Scope* page, select **Organization Virtual Data Center** or **Data Center Group** which to create the network, and click **Next**

<figure><img src="/files/nhv2onxIw3xDEg6EvduU" alt=""><figcaption></figcaption></figure>

* On the *Select Network Type* page, select **Routed** >> **Next**.

{% hint style="info" %}
Edge Gateway created by the HI GIO team
{% endhint %}

<figure><img src="/files/vpZgJc8cHndwE1vRb9IM" alt=""><figcaption></figcaption></figure>

* Enter a **Name** and D**escription** (optional) for the network.
* To enable dual-stack networking (enable the network to have both IPv4 & IPv6 subnet), turn on the **Dual-Stack Mode** toggle.
* Enter the Classless Inter-Domain Routing (CIDR) settings for the network >>**Next**

Format: network\_gateway\_IP\_address/ subnet\_prefix\_length like *192.168.100.254/24*

<figure><img src="/files/VU9LKc4xQwxhneBNhPGa" alt=""><figcaption></figcaption></figure>

* In *Static IP Pools*, enter the ranges of IP addresses that you want to use, click **Add** >> **Next**

<figure><img src="/files/Uc1o9y5c0nINhF1Ab565" alt=""><figcaption></figcaption></figure>

* Configure the DNS settings (Optional).

You can put Primary DNS\Secondary DNS\DNS suffix >> **Next**

<figure><img src="/files/esWMPhf5FfTmOu7QzhT5" alt=""><figcaption></figcaption></figure>

* Review your settings and click **Finish**.
  {% endstep %}

{% step %}
**Step 3:** View the Available Organization VDC Networks

* In the top navigation bar, click **Networking**.
* In the **Networks** tab, you will see a list of the available networks that you can also edit, increase the scope, or delete the Organization VDC network

<figure><img src="/files/EiB9SXBi5BdniSELVVNB" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# How to create NAT rules on Edge Gateway

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

Network address translation (NAT) allows the source or destination IP address to be changed to enable traffic to transition through a gateway or router.

HI GIO supports some NAT types:

> A **SNAT** rule translates the source IP address of packets sent from an organization's VDC network out to an external network or another organization's VDC network.
>
> A **NO SNAT** rule prevents the translation of the internal IP address of packets sent from an organization VDC out to an external network or another organization VDC network.
>
> A **DNAT** rule translates the IP address and, optionally, the port of packets received by an organization VDC network that are coming from an external network or another organization VDC network.
>
> A **NO DNAT** rule prevents the translation of the external IP address of packets received by an organization VDC from an external network or another organization VDC network.

{% hint style="warning" %}
The public IP addresses must have been added to the edge gateway interface where you want to add the NAT rule.
{% endhint %}

{% hint style="warning" %}
Firewall rule will be applied to the local IP address by default configuration. If you want to specify a firewall rule for the Public IP address, please change the "Firewall Match" configuration to "Match External Address" on the Advanced option
{% endhint %}

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% tabs %}
{% tab title="I. Creating a DNAT\No DNAT rule" %}
**Step 1:** In the top navigation bar, click **Networking** and **Edge Gateways**.

**Step 2:** Select the edge gateway that you want to edit

<figure><img src="/files/XTDYQtezB1CpMvrmK4jn" alt=""><figcaption></figcaption></figure>

**Step 3:** Under *Security*, click **NAT**

**Step 4:** Click **New**.

**Step 5:** Configure an **DNAT**

*<mark style="color:blue;">**Name**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">\[Name of rule]</mark>

*<mark style="color:blue;">**Description**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">\[optional]</mark>

*<mark style="color:blue;">**Interface type**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">Select DNAT\No DNAT</mark>

*<mark style="color:blue;">**External IP**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">Enter the</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**public IP address**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">of the edge gateway</mark>

*<mark style="color:blue;">**External Port**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">\[optional - Enter a port into which the DNAT rule is translating]</mark>

*<mark style="color:blue;">**Internal IP**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">Enter IP or range IP to receive traffic from the external network</mark>

*<mark style="color:blue;">**Application**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">\[optional – select application profile with port]</mark>

*<mark style="color:blue;">**Advanced Settings**</mark><mark style="color:blue;">: (Optional)</mark>*

<mark style="color:blue;">-</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**State**</mark><mark style="color:blue;">: Enable or disable the NAT rule.</mark>*

<mark style="color:blue;">-</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**Logging**</mark><mark style="color:blue;">: Toggle the Logging button to enable logging</mark>*

<mark style="color:blue;">-</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**Priority**</mark><mark style="color:blue;">: A lower value means a higher priority. The default is 0. A No SNAT or No DNAT rule should have a higher priority than other rules.</mark>*

<mark style="color:blue;">-</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**Firewall Match**</mark><mark style="color:blue;">: The available settings are</mark>*

* *<mark style="color:blue;">**Match External Address**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">- The firewall will be applied to external address of a NAT rule.</mark>*

<mark style="color:blue;">For SNAT, the external address is the translated source address after NAT is done.</mark>

<mark style="color:blue;">For DNAT, the external address is the original destination address before NAT is done.</mark>

* <mark style="color:blue;">**Match Internal Address**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">- Indicates the firewall will be applied to internal address of a NAT rule.</mark>

&#x20;       *<mark style="color:blue;">For SNAT, the internal address is the original source address before NAT is done.</mark>*

&#x20;       *<mark style="color:blue;">For DNAT, the internal address is the translated destination address after NAT is done.</mark>*

* <mark style="color:blue;">**Bypass**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">- The packet bypasses firewall rules</mark>

<figure><img src="/files/DZgLWyKYiVNQMH3S8cyi" alt=""><figcaption></figcaption></figure>

**Step 6:** Click **Save**
{% endtab %}

{% tab title="II. Creating a SNAT\No SNAT rule" %}
**Step 1:** In the top navigation bar, click **Networking** and **Edge Gateways**.

**Step 2:** Select the edge gateway that you want to edit

<figure><img src="/files/PKmlzk9ez1ETFfGdY5qD" alt=""><figcaption></figcaption></figure>

**Step 3:** Under *Security*, click **NAT**

**Step 4:** Click **New**.

**Step 5:** Configure an SNAT

*<mark style="color:blue;">**Name**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">\[Name of rule]</mark>

*<mark style="color:blue;">**Description**</mark>*<mark style="color:blue;">: \[optional]</mark>

*<mark style="color:blue;">**Interface type:**</mark>* <mark style="color:blue;">Select SNAT\No SNAT</mark>

*<mark style="color:blue;">**External IP**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">Enter the</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**public IP address**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">of the edge gateway</mark>

*<mark style="color:blue;">**Internal IP**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">Enter IP or range IP to receive traffic from the external network</mark>

*<mark style="color:blue;">**Destination IP**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">\[Optional]</mark>

*<mark style="color:blue;">**Advanced Settings**</mark><mark style="color:blue;">: (Optional)</mark>*

<mark style="color:blue;">-</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**State**</mark><mark style="color:blue;">: Enable or disable the NAT rule.</mark>*

<mark style="color:blue;">-</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**Logging**</mark><mark style="color:blue;">: Toggle the Logging button to enable logging</mark>*

<mark style="color:blue;">-</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**Priority**</mark><mark style="color:blue;">: A lower value means a higher priority. The default is 0. A No SNAT or No DNAT rule should have a higher priority than other rules.</mark>*

<mark style="color:blue;">-</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**Firewall Match**</mark><mark style="color:blue;">: The available settings are</mark>*

* *<mark style="color:blue;">**Match External Address**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">- The firewall will be applied to external address of a NAT rule.</mark>*

<mark style="color:blue;">For SNAT, the external address is the translated source address after NAT is done.</mark>

<mark style="color:blue;">For DNAT, the external address is the original destination address before NAT is done.</mark>

* <mark style="color:blue;">**Match Internal Address**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">- Indicates the firewall will be applied to internal address of a NAT rule.</mark>

&#x20;       *<mark style="color:blue;">For SNAT, the internal address is the original source address before NAT is done.</mark>*

&#x20;       *<mark style="color:blue;">For DNAT, the internal address is the translated destination address after NAT is done.</mark>*

* <mark style="color:blue;">**Bypass**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">- The packet bypasses firewall rules</mark>

<figure><img src="/files/cHPfVnHv4EaTTi35F8iB" alt=""><figcaption></figcaption></figure>

**Step 6:** Click **Save**

<mark style="color:red;">Note: Please do not remove SNAT/DNAT rules name starting with</mark> <mark style="color:red;"></mark><mark style="color:red;">**HIGIO-**</mark> <mark style="color:red;"></mark><mark style="color:red;">(if any)</mark>

**Step 7:** Add Edge Firewall rules for SNAT/DNAT after completing NAT rules.
{% endtab %}
{% endtabs %}


# Using Edge Gateway Firewall

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

An edge gateway firewall monitors North-South traffic to provide perimeter security functionality, including firewall, Network Address Translation (NAT), and site-to-site IPSec and SSL VPN functionality.

Firewall rules to apply to an edge gateway firewall to protect the virtual machines in an organization's virtual data center from outside network traffic

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% tabs %}
{% tab title="I. Predefine Object" %}
To create firewall rules and add them to an edge gateway, you need to define some things:

*<mark style="color:blue;">Name</mark>*<mark style="color:blue;">: Name for the rule.</mark>

*<mark style="color:blue;">Source</mark>*<mark style="color:blue;">:</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**IP Sets\Dynamic Groups\Static Group (1.1, 1.2, 1.3, 1.4)**</mark>

*<mark style="color:blue;">Destination</mark>*<mark style="color:blue;">:</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**IP Sets\Dynamic Groups\Static Group (1.1, 1.2, 1.3, 1.4)**</mark>

*<mark style="color:blue;">Application:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">Select applications with port to apply rule</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**(1.5)**</mark>

*<mark style="color:blue;">Action</mark>*<mark style="color:blue;">:</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**Allow**</mark><mark style="color:blue;">\\</mark><mark style="color:blue;">**Reject**</mark><mark style="color:blue;">\\</mark><mark style="color:blue;">**Drop**</mark>

*<mark style="color:blue;">IP Protocol:</mark>* <mark style="color:blue;">**IPv4/IPv6**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">or</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**both**</mark>

* **Add an IP Set:**

**Step 1:** IP sets are groups of IP addresses and networks to which the firewall rules apply (as **Source** and **Destination**).

**Step 2:** In the top navigation bar, click **Networking** and click **Edge Gateways**.

**Step 3:** Select the edge gateway that you want to edit

<figure><img src="/files/sSW5C7zcHqAoVEjtvbBw" alt=""><figcaption></figcaption></figure>

**Step 4:** Under *Security*, click **IP Sets**

**Step 5:** Click **New**.

**Step 6:** Enter a meaningful **Name,** and a **Description** for IP Sets

**Step 7:** Enter an IPv4 address, IPv6 address, or an address range in a CIDR format, and click **Add**.

**Step 8:** To modify an existing IP address or range, click **Modify** and edit the value.

**Step 9:** To confirm, click **Save**.

<figure><img src="/files/amq1T9fhn1yZrYy6K2Jx" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Please do not remove IP Sets name starting with HIGIO- (if any)
{% endhint %}

* **Create a Static Security Group:**

Static security groups are data center group networks to which distributed firewall rules apply (as **Source** and **Destination**). Grouping networks helps you reduce the number of distributed firewall rules that need to be created.

**Step 1:** In the top navigation bar, click **Networking** and click **Edge Gateways**.

**Step 2:** Select the edge gateway that you want to edit

<figure><img src="/files/E1Mg1OYWMFeC6eqm0sOr" alt=""><figcaption></figcaption></figure>

**Step 3:** Under *Security*, click **Static Groups**.

**Step 4:** click **New**.

**Step 5:** Enter a **Name and** a **Description** for the static group, and click **Save**.

<figure><img src="/files/ZEdKPGFB9ONm5xp3pTP8" alt=""><figcaption></figcaption></figure>

The static security group will appear in the list.

**Step 6:** Select the newly created static security group and click **Manage Members**.

<figure><img src="/files/eGd6iUYfKCc00gc5stWP" alt=""><figcaption></figcaption></figure>

**Step 7:** Select the data center group networks that you want to add to the static security group >> **Save**

<div align="left"><figure><img src="/files/tsZITWIqO7RkCsPonX2N" alt=""><figcaption></figcaption></figure></div>

* **Assign Security Tags to VM:**

Security tags you create and assign to virtual machines help you define edge gateway and distributed firewall rules.

**Step 1:** In the top navigation bar, click **Networking.**

**Step 2:** Click **Security Tags**.

**Step 3:** Click **Add Tag**.

**Step 4:** Enter a **tag name**.

**Step 5:** From the list of virtual machines in the organization, select the ones to assign the newly created tag.

**Step 6:** Click **Save**.

<figure><img src="/files/vkkZhjjZGaj0cjZAG46w" alt=""><figcaption></figcaption></figure>

* **Create a Dynamic Security Group:**

You can define dynamic security groups of virtual machines based on specific criteria (**VM Name** or **Tag Name**) to which firewall rules should be applied.

**Step 1:** In the top navigation bar, click **Networking** and **Edge Gateways**.

**Step 2:** Select the edge gateway that you want to edit

<figure><img src="/files/cWms6gAY29HCEeBbCrYd" alt=""><figcaption></figcaption></figure>

**Step 3**: Under *Security*, click **Dynamic Groups**.

**Step 4:** Click **New**.

**Step 5:** Enter a **Name and** a **Description** for the dynamic security group.

**Step 6:** To create a **Criterion** for inclusion in the group, add up to **four rules** that apply to a VM Name **or** a VM security tag.

* *VM Name:* a rule that applies to VM names containing or starting with a term you specify.
* *VM tag:* a rule that applies to VM tags that **equal**, **contain**, **start with**, or **end with** a term you specify.

<figure><img src="/files/AT7chfyhVk9XlU1OJNAb" alt=""><figcaption></figcaption></figure>

As figured out, I created 02 rules

* *VM Name*: **Start With** “demo”
* *VM Tag*: **Equals** “non-prd” (*That you created in **1.3**)*

**Step 7**: Click **Save**.

**Add a Custom Application Port Profile:**

You can use preconfigured and custom application port profiles to create firewall rules.

Application port profiles include a combination of a protocol and a port or a group of ports used for firewall services.&#x20;

**Step 1:** In the top navigation bar, click **Networking** and click **Edge Gateways**.

**Step 2:** Select the edge gateway that you want to edit

<figure><img src="/files/MiQKUg2FGJGpk9TAiPbP" alt=""><figcaption></figcaption></figure>

**Step 3:** Under *Security*, click **Application Port Profiles**

**Step 4:** In the **Custom Applications** pane, click **New**.

**Step 5:** Enter a **Name** and a **Description** for the application port profile.

**Step 6:** From the *Protocol* drop-down menu, select the protocol: **TCP**, **UDP**, **ICMPv4**, **ICMPv6**

**Step 7:** Enter a port or a range of ports, separated by a comma, and click **Save**.

<figure><img src="/files/ipu7jYDlOgRFSmDNuQmR" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="II. Add an Edge Gateway Firewall Rule" %}
We have predefined Objects in the previous. We will create the edge gateway firewall rule as below:

**Step 1:** In the top navigation bar, click **Networking** and click **Edge Gateways**

**Step 2:** Select the edge gateway.

<figure><img src="/files/ZFiAhlCiT5z1PtewNyJM" alt=""><figcaption></figcaption></figure>

**Step 3:** Select **Firewall** under Services on the left.

**Step 4:** Click **Edit Rules**.

**Step 5:** To add a firewall rule, click **New on Top**.

{% hint style="warning" %}
Each traffic session is checked against the top rule in the firewall table before moving down the subsequent rules in the table. The first rule in the table that matches the traffic parameters is enforced.
{% endhint %}

**Step 6:** Configure the rule

*<mark style="color:blue;">**Name**</mark>*<mark style="color:blue;">: \[Name of rule]</mark>

*<mark style="color:blue;">**State**</mark>*<mark style="color:blue;">: \[Enable or disable rule by toggle]</mark>

*<mark style="color:blue;">**Applications**</mark>*<mark style="color:blue;">: Select default profiles or custom profiles that created in</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**1.5**</mark>

*<mark style="color:blue;">**Source**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">Select Any or Object created in</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**1.1, 1.2, 1.3, 1.4**</mark>*

*<mark style="color:blue;">**Destination**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">Select Any or Object created in</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**1.1, 1.2, 1.3, 1.4**</mark>*

*<mark style="color:blue;">**Action**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">**Allow**</mark><mark style="color:blue;">\\</mark><mark style="color:blue;">**Reject**</mark><mark style="color:blue;">\\</mark><mark style="color:blue;">**Drop**</mark>

*<mark style="color:blue;">**IP**</mark>* *<mark style="color:blue;">**Protocol**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">**IPv4/IPv6**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">or</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**both**</mark>

*<mark style="color:blue;">**Logging**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">\[Enable or disable by toggle] enable to have the address translation performed by this rule logged</mark>

<figure><img src="/files/mrW6C0019y8GuOBaxX2z" alt=""><figcaption></figcaption></figure>

**Step 7:** Click **Save**.

After creating the firewall rules, they appear in the Edge Gateway Firewall Rules list. You can move up, down, edit, or delete the rules as needed.

{% hint style="warning" %}
Please do not remove the rules name starting with HIGIO- (if any)
{% endhint %}
{% endtab %}
{% endtabs %}


# Using Distributed Firewall in a Data Center Group

## <mark style="color:green;">**Overview**</mark> <a href="#overview" id="overview"></a>

HI GIO supports a distributed firewall service for data center groups. You create a single default security policy applied to the data center group.

It can inspect every packet and frame coming to and leaving the VM regardless of the network topology. Packet inspection is done at the VM virtual NIC (vNIC) level, which enables access-control lists (ACLs) to be applied closest to the source.

<figure><img src="/files/kZeIhDYnw4lTUJYZrOkd" alt=""><figcaption></figcaption></figure>

## <mark style="color:green;">**Procedure**</mark> <a href="#procedure" id="procedure"></a>

{% tabs %}
{% tab title="I. Predefine Object" %}
To create distributed firewall rules and add them to a data center group, you need to define some things:

*<mark style="color:blue;">Name</mark>*<mark style="color:blue;">: Name for the rule.</mark>

*<mark style="color:blue;">Source</mark>*<mark style="color:blue;">:</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**IP Sets\Dynamic Groups\Static Group (1.1, 1.2, 1.3, 1.4)**</mark>

*<mark style="color:blue;">Destination</mark>*<mark style="color:blue;">:</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**IP Sets\Dynamic Groups\Static Group (1.1, 1.2, 1.3, 1.4)**</mark>

*<mark style="color:blue;">Application:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">Select applications with port to apply rule</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**(1.5)**</mark>

*<mark style="color:blue;">Action</mark>*<mark style="color:blue;">:</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**Allow**</mark><mark style="color:blue;">\\</mark><mark style="color:blue;">**Reject**</mark><mark style="color:blue;">\\</mark><mark style="color:blue;">**Drop**</mark>

*<mark style="color:blue;">IP Protocol:</mark>* <mark style="color:blue;">**IPv4/IPv6**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">or</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**both**</mark>

* **Add an IP Set to the Data Center Group:**

IP sets are groups of IP addresses and networks to which the distributed firewall rules apply (as **Source** and **Destination**). Combining multiple objects into IP sets helps you reduce the total number of distributed firewall rules to be created

**Step 1:** In the top navigation bar, click **Networking** and then click the **Data Center Groups** tab

**Step 2:** Click the data center group name

<figure><img src="/files/5kdRlviuXOJkPICocsXM" alt=""><figcaption></figcaption></figure>

**Step 3:** Under *Security*, click **IP Sets**

**Step 4:** Click **New**.

**Step 5:** Enter a meaningful **Name,** a **Description** for IP Sets

**Step 6:** Enter an IPv4 address, IPv6 address, or an address range in a CIDR format, and click **Add**.

**Step 7:** To modify an existing IP address or range, click **Modify** and edit the value.

**Step 8:** To confirm, click **Save**.

<figure><img src="/files/dR0D0w9LEhj8wQypglCZ" alt=""><figcaption></figcaption></figure>

* **Create a Static Security Group:**

Static security groups are data center group networks to which distributed firewall rules apply (as **Source** and **Destination**). Grouping networks helps you reduce the total number of distributed firewall rules that need to be created.

**Step 1:** In the top navigation bar, click **Networking** and then click the **Data Center Groups** tab

**Step 2:** Click the data center group name

<figure><img src="/files/XqOdoQ240KceHt5h00bB" alt=""><figcaption></figcaption></figure>

**Step 3:** Under *Security*, click **Static Groups**.

**Step 4:** Click **New**.

**Step 5:** Enter a **Name**, a **Description** for the static group, and click **Save**.

<figure><img src="/files/CrvJ5duFey29o8trA21I" alt=""><figcaption></figcaption></figure>

The static security group will appear in the list.

**Step 6:** Select the newly created static security group and click **Manage Members**.

<figure><img src="/files/e0iiX6AoeL2nWWH01LSK" alt=""><figcaption></figcaption></figure>

**Step 7:** Select the data center group networks that you want to add to the static security group >> **Save**

<figure><img src="/files/EYsMTVFZbejRSxPzxjrb" alt=""><figcaption></figcaption></figure>

* **Assign Security Tags to VM:**

Security tags you create and assign to virtual machines help you define edge gateway and distributed firewall rules.

**Step 1:** In the top navigation bar, click **Networking.**

**Step 2:** Click **Security Tags**.

**Step 3:** Click **Add Tag**.

**Step 4:** Enter a **tag name**.

**Step 5:** From the list of virtual machines in the organization, select the ones to assign the newly created tag.

**Step 6:** Click **Save**.

<figure><img src="/files/SMPDVvHagUvIPy2hldMR" alt=""><figcaption></figcaption></figure>

* **Create a Dynamic Security Group:**

You can define dynamic security groups of virtual machines based on specific criteria (**VM Name** or **Tag Name**) to which to apply distributed firewall rules.

**Step 1:** In the top navigation bar, click **Networking** and then click the **Data Center Groups** tab

**Step 2:** Click the data center group name

<figure><img src="/files/ak50dasycEFGHh7CezAu" alt=""><figcaption></figcaption></figure>

**Step 3:** Under *Security*, click **Dynamic Groups**.

**Step 4:** Click **New**.

**Step 5:** Enter a Name and a Description for the dynamic security group.

**Step 6:** To create a **Criterion** for inclusion in the group, add up to **four rules** that apply to a VM Name or a VM security tag.

* *VM Name:* a rule that applies to VM names containing or starting with a term you specify.
* *VM tag:* a rule that applies to VM tags that **equal**, **contain**, **start with**, or **end with** a term you specify.

<figure><img src="/files/Xfl4J4rErQAAgffbFrPp" alt=""><figcaption></figcaption></figure>

As figured out, I created 02 rules

* *VM Name*: **Start With** “demo”
* *VM Tag*: **Equals** “non-prd” (*That you created in **1.3**)*

**Step 7:** Click **Save**.

* **Add a Custom Application Port Profile:**

You can use preconfigured and custom application port profiles to create distributed firewall rules.

Application port profiles include a combination of a protocol and a port or a group of ports, used for firewall services.&#x20;

**Step 1:** In the top navigation bar, click **Networking** and then click the **Data Center Groups** tab

**Step 2:** Click the **data center group name**

<figure><img src="/files/YjiCsszU0cmcmh25oQF6" alt=""><figcaption></figcaption></figure>

**Step 3:** Under *Security*, click **Application Port Profiles**

**Step 4:** In the **Custom Applications** pane, click **New**.

**Step 5:** Enter a **Name** and, a **Description** for the application port profile.

**Step 6:** From the *Protocol* drop-down menu, select the protocol: **TCP**, **UDP**, **ICMPv4**, **ICMPv6**

**Step 7:** Enter a port, or a range of ports, separated by a comma, and click **Save**.

<figure><img src="/files/EJMmqcbtIsy3T3lWT2Id" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="II. Add a Distributed Firewall Rule" %}
We have predefined Objects in the previous. We will create the distributed firewall rules as below:

1. In the top navigation bar, click **Networking** and then click the **Data Center Groups** tab
2. Click the data center group name

<figure><img src="/files/Wc4qr2iQmMTyCNmMV5kc" alt=""><figcaption></figcaption></figure>

3\. Click the **Distributed Firewall** tab on the left.

4\. Click **Edit Rules**.

5\. To add a firewall rule, click **New on Top**.

**NOTE**: Each traffic session is checked against the top rule in the firewall table before moving down the\
subsequent rules in the table. The first rule in the table that matches the traffic parameters is\
enforced

6\. Configure the rule

*<mark style="color:blue;">**Name**</mark>*<mark style="color:blue;">: \[Name of rule]</mark>

*<mark style="color:blue;">**State**</mark>*<mark style="color:blue;">: \[Enable or disable rule by toggle]</mark>

*<mark style="color:blue;">**Applications**</mark>*<mark style="color:blue;">: Select default profiles or custom profiles that created in</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**1.5**</mark>

*<mark style="color:blue;">**Context**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">(Optional) Select context profile for the rule.</mark>

*<mark style="color:blue;">**Source**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">Select Any or Object created in</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**1.1, 1.2, 1.3, 1.4**</mark>*

*<mark style="color:blue;">**Destination**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">Select Any or Object created in</mark> <mark style="color:blue;"></mark>*<mark style="color:blue;">**1.1, 1.2, 1.3, 1.4**</mark>*

*<mark style="color:blue;">**Action**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">**Allow**</mark><mark style="color:blue;">\\</mark><mark style="color:blue;">**Reject**</mark><mark style="color:blue;">\\</mark><mark style="color:blue;">**Drop**</mark>

*<mark style="color:blue;">**IP Protocol**</mark><mark style="color:blue;">:</mark>* <mark style="color:blue;"></mark><mark style="color:blue;">**IPv4/IPv6**</mark> <mark style="color:blue;"></mark><mark style="color:blue;">or</mark> <mark style="color:blue;"></mark><mark style="color:blue;">**both**</mark>

***Logging**:* \[Enable or disable by toggle] enable to have the address translation performed by this rule logged

<figure><img src="/files/ocIOT7xsTjXmBSGfKkbw" alt=""><figcaption></figcaption></figure>

7\. Click **Save**.

{% hint style="warning" %}
Please do not remove the rules name starting with HIGIO (if any)
{% endhint %}
{% endtab %}
{% endtabs %}




---

[Next Page](/llms-full.txt/1)

