Academy/VVS/Cloud-Based Ransomware Recovery
This solution targets VCF 5.2

Cloud-Based Ransomware Recovery for VMware Cloud Foundation

VCF 5.2architectvcdxautomationstoragePages 794-825

The solution uses VMware Live Cyber Recovery (formerly VMware Cloud DR) to protect business workloads running on a VMware Cloud Foundation instance and recover them into a VMware Cloud on AWS recovery SDDC in the event of a ransomware attack. Two VMware Live Cyber Recovery Connector appliances are deployed in the protected VCF mgmt domain for replication to a Cloud File System. A pilot-light VMware Cloud on AWS SDDC with a minimum of two nodes provides the recovery target.

Key Components: NSX, SDDC Manager, vCenter, ESXi

Protected Site: VCF instance with management and VI workload domain vCenter Servers, protection groups, recovery plans, and Live Cyber Recovery Connector appliances.

Design Decisions
Implementation
Operations
VCDX Defense
Quiz (15)
Flashcards (15)

20 design decisions

DD-IDDecisionQuality
CBR-CDP-CFG-001Deploy two VMware Live Cyber Recovery Connector appliances in default mgmt cluster.RecoverabilitySecurity

Decision: Deploy two VMware Live Cyber Recovery Connector appliances in default mgmt cluster.

Rationale: Secure communication between VCF instance and VMware Live Cyber Recovery.

Implication: Appliances must reach the Internet through a firewall.

Component: CDP

CBR-CDP-CFG-002Protect connectors with vSphere HA.Availability

Decision: Protect connectors with vSphere HA.

Rationale: Availability.

Implication: No significant trade-offs identified for this decision.

Component: CDP

CBR-CDP-CFG-003Place connectors in dedicated VM folder.Manageability

Decision: Place connectors in dedicated VM folder.

Rationale: Organization.

Implication: Create folder during deployment.

Component: CDP

CBR-CDP-CFG-004DRS anti-affinity rule for connectors.Performance

Decision: DRS anti-affinity rule for connectors.

Rationale: Prevent co-location and performance impact.

Implication: Additional config; 4-host cluster maintenance constraint.

Component: CDP

CBR-CDP-CFG-005In multi-AZ, add connectors to AZ1 VM group.Manageability

Decision: In multi-AZ, add connectors to AZ1 VM group.

Rationale: Run in primary AZ host group.

Implication: Update VM group after stretched cluster creation.

Component: CDP

CBR-CDP-NET-001Place connectors on management VLAN.Manageability

Decision: Place connectors on management VLAN.

Rationale: Same network as VCF components; consistent VMware Cloud services deployment.

Implication: No significant trade-offs identified for this decision.

Component: CDP

CBR-CDP-NET-002Static IP from management VLAN.Manageability

Decision: Static IP from management VLAN.

Rationale: Stability.

Implication: IP address management.

Component: CDP

CBR-CDP-NET-003Forward/reverse DNS records.Security

Decision: Forward/reverse DNS records.

Rationale: FQDN access.

Implication: Maintain DNS and firewall.

Component: CDP

CBR-CDP-NET-004Configure DNS servers on connectors.AvailabilitySecurity

Decision: Configure DNS servers on connectors.

Rationale: Accurate name resolution.

Implication: Firewall allow DNS; redundant DNS.

Component: CDP

CBR-CDP-NET-005Use VMware Tools time sync from ESXi (not NTP directly).Manageability

Decision: Use VMware Tools time sync from ESXi (not NTP directly).

Rationale: Prevent time mismatch via host sync.

Implication: ESXi hosts must have NTP pre-configured.

Component: CDP

CBR-AWS-CFG-001Deploy Pilot Light VMware Cloud on AWS recovery SDDC.Recoverability

Decision: Deploy Pilot Light VMware Cloud on AWS recovery SDDC.

Rationale: Lowest RTO; pre-configured networking.

Implication: Minimal SDDC always online (ongoing cost).

Component: AWS

CBR-AWS-CFG-002Deploy recovery SDDC with minimum two nodes.Recoverability

Decision: Deploy recovery SDDC with minimum two nodes.

Rationale: Single-node expires after 60 days.

Implication: Infrastructure cost.

Component: AWS

CBR-AWS-CFG-003Configure management gateway to allow vCenter access over Internet.ManageabilityRecoverability

Decision: Configure management gateway to allow vCenter access over Internet.

Rationale: User access to recovery SDDC.

Implication: Manually manage vCenter access via NSX group.

Component: AWS

CBR-VLCR-CFG-001Deploy Cloud File System in same AZ as recovery SDDC (inside one AWS region).Recoverability

Decision: Deploy Cloud File System in same AZ as recovery SDDC (inside one AWS region).

Rationale: Required by Live Cyber Recovery architecture.

Implication: No significant trade-offs identified for this decision.

Component: VLCR

CBR-VLCR-CFG-002Create protected site using public Internet connection.Manageability

Decision: Create protected site using public Internet connection.

Rationale: Defines VCF instance for protection.

Implication: No significant trade-offs identified for this decision.

Component: VLCR

CBR-VLCR-CFG-003Associate connector appliances with protected site.Manageability

Decision: Associate connector appliances with protected site.

Rationale: Secure comms on-prem-to-cloud.

Implication: Deploy connectors manually to mgmt domain vCenter.

Component: VLCR

CBR-VLCR-CFG-004Register VI workload domain vCenter with protected site.Manageability

Decision: Register VI workload domain vCenter with protected site.

Rationale: Connects vCenter to service for workload protection.

Implication: Requires at least one connector appliance in vCenter.

Component: VLCR

CBR-VLCR-CFG-005Attach pilot-light VMware Cloud on AWS recovery SDDC to VMware Live Cyber Recovery.Recoverability

Decision: Attach pilot-light VMware Cloud on AWS recovery SDDC to VMware Live Cyber Recovery.

Rationale: Provides recovery target.

Implication: No significant trade-offs identified for this decision.

Component: VLCR

CBR-VLCR-CFG-006Configure Live Cyber Recovery to send SLA status alerts.Recoverability

Decision: Configure Live Cyber Recovery to send SLA status alerts.

Rationale: Ensures alerts reach support.

Implication: Uses AWS SES; recipients must verify email.

Component: VLCR

CBR-CDP-LCM-001Use automatic OTA upgrades for connector appliances.Manageability

Decision: Use automatic OTA upgrades for connector appliances.

Rationale: VMware Cloud Services handles upgrades.

Implication: No significant trade-offs identified for this decision.

Component: CDP

Prerequisites

  • VCF healthy per Support Matrix.
  • Parameters captured in Cloud-Based Ransomware Recovery tab of Planning & Preparation Workbook.
  • DNS records created; AD Domain Controllers available.
  • Outbound Internet access on port 443 to VMware Live Cyber Recovery endpoints.

Implementation Procedure

Implementation

VMware Cloud Services account with Live Cyber Recovery entitlement; VMware Cloud on AWS subscription.
Implementation Methods

Powershell

PowerValidatedSolutions — menu entry '12. (CBR) Cloud-Based Ransomware Recovery': Generate JSON, Verify Prereqs, End-to-End Deployment (prepares VCF instance only), Configuration. Service-side config (VMware Live Cyber Recovery service, VMware Cloud on AWS SDDC attach) is manual via UI.
UI

1) Create VM folder for connectors in mgmt vCenter. 2) In VMware Cloud Services → Live Cyber Recovery, deploy Cloud File System in the target AWS region/AZ. 3) Create protected site; download OVA; deploy two connector appliances into mgmt vCenter on the mgmt VLAN; associate with protected site. 4) Create custom vSphere role with minimum privileges; assign to service account used for vCenter registration. 5) Configure DRS anti-affinity rule for connectors; add to AZ1 VM group if multi-AZ. 6) Register VI workload domain vCenter with the protected site (use IP address). 7) Attach pilot-light VMware Cloud on AWS SDDC. 8) Configure email alerts (SLA status).
  • External Services / Integration Points
  • Active Directory (AD)
  • DNS
  • NTP (on ESXi hosts)
  • Configuration Values
  • Connector Firewall PortsOutbound TCP 443 only
  • Recovery SDDC ModelPilot Light
  • Min SDDC Nodes2
  • Cloud File System LocationSame AZ as recovery SDDC
  • Time SyncVMware Tools sync from ESXi

Additional Instance

For additional VCF instance: (1) Create VM folder, (2) Create protected site, (3) Deploy connector appliances, (4) Create custom vSphere role and configure service account, (5) Configure DRS anti-affinity, (6) Add to AZ1 VM group in multi-AZ, (7) Register VI workload domain vCenter with protected site.

Day-2 Operations Tasks

Operations

As needed

Personas

As needed

NameRole

As needed

Cloud AdminOrg Owner; Global Console Admin; Orchestrator Admin; VMware Cloud on AWS Administrator; VMware Cloud on AWS NSX Cloud Admin; Carbon Black C

As needed

VI AdminOrg member; Recovery SDDC Admin; Recovery Admin; Protection Admin; Carbon Black Cloud role

As needed

Site Reliability Engineer (SRE)Org member; Recovery Admin; Carbon Black Cloud role

As needed

Compliance OfficerOrg member; Data Protection Auditor (read-only)

As needed

Operational Verification

As needed

VMware Cloud Services and VMware Live Cyber Recovery status pages: all services operational.

As needed

Connector appliance network test: SSH to connector as admin (password from Live Cyber Recovery UI); run 'drc network test --scope cloud'.

As needed

Monitoring Points

  • Last in mgmt domain startup order: power on connectors via vCenter; verify operational state.
  • MonitoringOptional — Aria Operations monitoring via Ping adapter for connectors.

Likely Panelist Questions

Q: Why did you choose this architecture?

See design decisions for rationale

Failure Scenarios

Deploy two connector appliances for HA; single connector is single point of failure.
Impact:
Mitigation:
Connector Internet connectivity loss stops replication.
Impact:
Mitigation:

Trade-off Analysis

Trade-Offs Analysis

Chosen:

Justification:

Quiz — Cloud-Based Ransomware Recovery

0/15
Q1
Why deploy two VMware Live Cyber Recovery Connector appliances?
  • Performance
  • HA — single connector is SPOF
  • Required by VCF
  • Required by AWS
CBR-CDP-CFG-001: Two appliances provide HA for the secure connection to VMware Live Cyber Recovery.
Q2
Which recovery SDDC deployment model is selected?
  • On-Demand
  • Pilot Light
  • Cold Standby
  • Hot Standby
CBR-AWS-CFG-001: Pilot Light — lowest RTO and pre-configurable networking.
Q3
What is the minimum recovery SDDC node count, and why?
  • 1 node (cheapest)
  • 2 nodes (single-node expires in 60 days)
  • 3 nodes (HA)
  • 4 nodes (DRS)
CBR-AWS-CFG-002: Minimum 2 nodes because a single-node SDDC expires after 60 days.
Q4
Where must Cloud File System and recovery SDDC be located?
  • Different AWS regions for HA
  • Same AWS region, same AZ
  • Same region, different AZ
  • Anywhere
CBR-VLCR-CFG-001: Cloud File System and recovery SDDC must be in the same AZ inside one AWS region.
Q5
Where are connector appliances placed?
  • Cross-instance NSX segment
  • Local-instance NSX segment
  • Management VLAN
  • Public Internet DMZ
CBR-CDP-NET-001: Management VLAN.
Q6
What outbound port is required from the connectors?
  • 22 (SSH)
  • 443 (HTTPS)
  • 9443
  • Multiple ports
Port 443 only outbound to VMware Live Cyber Recovery endpoints.
Q7
How is time synchronized on the connectors?
  • NTP directly
  • VMware Tools sync from ESXi (ESXi must have NTP)
  • AWS time sync
  • Static clock
CBR-CDP-NET-005: VMware Tools sync from ESXi (requires ESXi NTP pre-config).
Q8
Who upgrades the connector appliances?
  • SDDC Manager
  • Aria Suite Lifecycle
  • VMware Cloud Services via OTA auto-upgrade
  • Manual admin
CBR-CDP-LCM-001: Automatic OTA upgrades pushed by VMware Cloud Services.
Q9
What is the recommended snapshot retention for ransomware recovery?
  • 7 days
  • 30 days
  • ≥ 90 days
  • 1 year
Best practices: ≥ 90-day retention for ransomware recovery.
Q10
How do you test recovery plans?
  • Never
  • Once every 5 years
  • At least twice a year
  • Continuously
Best practices: test at least twice a year to catch config drift, architecture changes.
Q11
Which VMware service integrates for malware detection during recovery?
  • Aria Operations
  • Carbon Black Cloud
  • NSX Security
  • AppDefense
Personas mention Carbon Black Cloud role requirements across all personas; Carbon Black integrates for malware scanning.
Q12
Which role is read-only for auditing?
  • Recovery Admin
  • Data Protection Auditor
  • Org Owner
  • Orchestrator Admin
Compliance Officer persona: Data Protection Auditor (read-only).
Q13
What connector command verifies cloud connectivity?
  • ping <cloud>
  • drc network test --scope cloud
  • curl cloud.vmware.com
  • check-cloud
From connector appliance SSH as admin: 'drc network test --scope cloud'.
Q14
How do you refresh service account password after rotation?
  • Redeploy connector
  • VMware Live Cyber Recovery → Protected sites → vCenters → menu → Refresh credentials
  • vCenter → Reconfigure SSO
  • Nothing automatic
Password mgmt: use the Refresh credentials option in the Live Cyber Recovery protected site.
Q15
What PowerShell menu item implements this solution?
  • 07. IOM
  • 08. PCA
  • 11. SPR
  • 12. (CBR) Cloud-Based Ransomware Recovery
PowerValidatedSolutions menu entry 12 (CBR) — only partial automation; SDDC service config is manual.

Flashcards — Cloud-Based Ransomware Recovery

Card 1 of 15
Connector count per VCF instance?
Two — for HA (CBR-CDP-CFG-001).

Labs

Deploy Live Cyber Recovery Connector appliances and register vCenter

Deploy two connectors in mgmt domain, register VI workload domain vCenter with protected site.

Starting State: VCF 5.2 instance healthy; VMware Cloud Services account with Live Cyber Recovery entitlement; outbound 443 open.

Provision recovery SDDC and Cloud File System

Attach a Pilot Light VMware Cloud on AWS SDDC and deploy Cloud File System for recovery.

Starting State: Connectors deployed and registered; AWS region/AZ selected.

Create protection groups, recovery plans, and test recovery

Build protection groups with high-frequency snapshots (≥ 90-day retention), recovery plans with ordered steps, and run a test recovery.

Starting State: Recovery SDDC + Cloud File System attached; vCenter registered.

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.