Jump to content
NAKIVO Introduces Agent-Based Data Protection for Proxmox VE ×
NAKIVO Community Forum

Network/Firewall thoughts for MSP


NiclasE

Recommended Posts

Hi,

I'm new to this forum so excuse me if this topic already have been discussed (didn't find any though).  My company is hosting and helping multiple customers, both in our hosting and onprem environments. I've been working with Nakivo before but only on onprem installations with one setup per customer (local vcenter and esxi access). But what I now would like to be able to do is to have one central director that we manage multiple customers in.

From what I can see in the docs the setup should then consist of a Director with transport and repos centrally, transport agent at the customer site with Direct connect enabled. Agents on physical machines.

But the main problem is that we need to open ports in the customer FW to the transport agent server. And if we have a customer that doesn't allow access to vCenter and only allow agent based backups we still need to add a transport and open FW to that. Is that correct? 

Is there no alternative to have agents talk to our transport and/or director centrally without opening any firewall inbound on the customer side? 

Hope my question makes sense.

 

  • Like 1
Link to comment
Share on other sites

3 hours ago, NiclasE said:

Hi,

I'm new to this forum so excuse me if this topic already have been discussed (didn't find any though).  My company is hosting and helping multiple customers, both in our hosting and onprem environments. I've been working with Nakivo before but only on onprem installations with one setup per customer (local vcenter and esxi access). But what I now would like to be able to do is to have one central director that we manage multiple customers in.

From what I can see in the docs the setup should then consist of a Director with transport and repos centrally, transport agent at the customer site with Direct connect enabled. Agents on physical machines.

But the main problem is that we need to open ports in the customer FW to the transport agent server. And if we have a customer that doesn't allow access to vCenter and only allow agent based backups we still need to add a transport and open FW to that. Is that correct? 

Is there no alternative to have agents talk to our transport and/or director centrally without opening any firewall inbound on the customer side? 

Hope my question makes sense.

 

Hello @NiclasE, To address your questions and provide you with a tailored solution that meets your specific needs, we highly recommend booking a live demo with a NAKIVO engineer. During this 30-minute session, you can get answers to your questions and assistance if needed to set up the solution in a way that works best for your requirements: https://www.nakivo.com/how-to-buy/request-demo/

Best regards

Link to comment
Share on other sites

1 hour ago, The Official Moderator said:

Hello @NiclasE, To address your questions and provide you with a tailored solution that meets your specific needs, we highly recommend booking a live demo with a NAKIVO engineer. During this 30-minute session, you can get answers to your questions and assistance if needed to set up the solution in a way that works best for your requirements: https://www.nakivo.com/how-to-buy/request-demo/

Best regards

OK thanks. Will do.

  • Like 1
Link to comment
Share on other sites

2 hours ago, NiclasE said:

OK thanks. Will do.

Following up on your query, we recommend that you set up NAKIVO Backup & Replication in multitenant mode and create remote tenants for managing multiple customers through one central Director.

Here's a quick guide:

- To add customers as remote tenants, you should install an independent instance of NAKIVO Backup & Replication with its own license at each remote site.

- Ensure the cloud-based multitenant NAKIVO Backup & Replication is accessible via a public IP and two ports for remote access.

- Manage all tenants from the central multitenant installation. Each remote site remains independent, ensuring jobs continue even with connectivity issues.

- No need to open any ports on the customer's side.

- This setup addresses your concerns about firewall configurations while offering centralized management.

Please don't hesitate to contact our engineers if you need a demo or assistance.

  • Like 1
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...