Cloud-Based Ransomware Recovery for VMware Cloud Foundation
The solution uses VMware Live Cyber Recovery (formerly VMware Cloud DR) to protect business workloads running on a VMware Cloud Foundation instance and recover them into a VMware Cloud on AWS recovery SDDC in the event of a ransomware attack. Two VMware Live Cyber Recovery Connector appliances are deployed in the protected VCF mgmt domain for replication to a Cloud File System. A pilot-light VMware Cloud on AWS SDDC with a minimum of two nodes provides the recovery target.
Key Components: NSX, SDDC Manager, vCenter, ESXi
Protected Site: VCF instance with management and VI workload domain vCenter Servers, protection groups, recovery plans, and Live Cyber Recovery Connector appliances.
20 design decisions
| DD-ID | Decision | Quality |
|---|---|---|
| CBR-CDP-CFG-001 | Deploy two VMware Live Cyber Recovery Connector appliances in default mgmt cluster. | RecoverabilitySecurity |
Decision: Deploy two VMware Live Cyber Recovery Connector appliances in default mgmt cluster. Rationale: Secure communication between VCF instance and VMware Live Cyber Recovery. Implication: Appliances must reach the Internet through a firewall. Component: CDP | ||
| CBR-CDP-CFG-002 | Protect connectors with vSphere HA. | Availability |
Decision: Protect connectors with vSphere HA. Rationale: Availability. Implication: No significant trade-offs identified for this decision. Component: CDP | ||
| CBR-CDP-CFG-003 | Place connectors in dedicated VM folder. | Manageability |
Decision: Place connectors in dedicated VM folder. Rationale: Organization. Implication: Create folder during deployment. Component: CDP | ||
| CBR-CDP-CFG-004 | DRS anti-affinity rule for connectors. | Performance |
Decision: DRS anti-affinity rule for connectors. Rationale: Prevent co-location and performance impact. Implication: Additional config; 4-host cluster maintenance constraint. Component: CDP | ||
| CBR-CDP-CFG-005 | In multi-AZ, add connectors to AZ1 VM group. | Manageability |
Decision: In multi-AZ, add connectors to AZ1 VM group. Rationale: Run in primary AZ host group. Implication: Update VM group after stretched cluster creation. Component: CDP | ||
| CBR-CDP-NET-001 | Place connectors on management VLAN. | Manageability |
Decision: Place connectors on management VLAN. Rationale: Same network as VCF components; consistent VMware Cloud services deployment. Implication: No significant trade-offs identified for this decision. Component: CDP | ||
| CBR-CDP-NET-002 | Static IP from management VLAN. | Manageability |
Decision: Static IP from management VLAN. Rationale: Stability. Implication: IP address management. Component: CDP | ||
| CBR-CDP-NET-003 | Forward/reverse DNS records. | Security |
Decision: Forward/reverse DNS records. Rationale: FQDN access. Implication: Maintain DNS and firewall. Component: CDP | ||
| CBR-CDP-NET-004 | Configure DNS servers on connectors. | AvailabilitySecurity |
Decision: Configure DNS servers on connectors. Rationale: Accurate name resolution. Implication: Firewall allow DNS; redundant DNS. Component: CDP | ||
| CBR-CDP-NET-005 | Use VMware Tools time sync from ESXi (not NTP directly). | Manageability |
Decision: Use VMware Tools time sync from ESXi (not NTP directly). Rationale: Prevent time mismatch via host sync. Implication: ESXi hosts must have NTP pre-configured. Component: CDP | ||
| CBR-AWS-CFG-001 | Deploy Pilot Light VMware Cloud on AWS recovery SDDC. | Recoverability |
Decision: Deploy Pilot Light VMware Cloud on AWS recovery SDDC. Rationale: Lowest RTO; pre-configured networking. Implication: Minimal SDDC always online (ongoing cost). Component: AWS | ||
| CBR-AWS-CFG-002 | Deploy recovery SDDC with minimum two nodes. | Recoverability |
Decision: Deploy recovery SDDC with minimum two nodes. Rationale: Single-node expires after 60 days. Implication: Infrastructure cost. Component: AWS | ||
| CBR-AWS-CFG-003 | Configure management gateway to allow vCenter access over Internet. | ManageabilityRecoverability |
Decision: Configure management gateway to allow vCenter access over Internet. Rationale: User access to recovery SDDC. Implication: Manually manage vCenter access via NSX group. Component: AWS | ||
| CBR-VLCR-CFG-001 | Deploy Cloud File System in same AZ as recovery SDDC (inside one AWS region). | Recoverability |
Decision: Deploy Cloud File System in same AZ as recovery SDDC (inside one AWS region). Rationale: Required by Live Cyber Recovery architecture. Implication: No significant trade-offs identified for this decision. Component: VLCR | ||
| CBR-VLCR-CFG-002 | Create protected site using public Internet connection. | Manageability |
Decision: Create protected site using public Internet connection. Rationale: Defines VCF instance for protection. Implication: No significant trade-offs identified for this decision. Component: VLCR | ||
| CBR-VLCR-CFG-003 | Associate connector appliances with protected site. | Manageability |
Decision: Associate connector appliances with protected site. Rationale: Secure comms on-prem-to-cloud. Implication: Deploy connectors manually to mgmt domain vCenter. Component: VLCR | ||
| CBR-VLCR-CFG-004 | Register VI workload domain vCenter with protected site. | Manageability |
Decision: Register VI workload domain vCenter with protected site. Rationale: Connects vCenter to service for workload protection. Implication: Requires at least one connector appliance in vCenter. Component: VLCR | ||
| CBR-VLCR-CFG-005 | Attach pilot-light VMware Cloud on AWS recovery SDDC to VMware Live Cyber Recovery. | Recoverability |
Decision: Attach pilot-light VMware Cloud on AWS recovery SDDC to VMware Live Cyber Recovery. Rationale: Provides recovery target. Implication: No significant trade-offs identified for this decision. Component: VLCR | ||
| CBR-VLCR-CFG-006 | Configure Live Cyber Recovery to send SLA status alerts. | Recoverability |
Decision: Configure Live Cyber Recovery to send SLA status alerts. Rationale: Ensures alerts reach support. Implication: Uses AWS SES; recipients must verify email. Component: VLCR | ||
| CBR-CDP-LCM-001 | Use automatic OTA upgrades for connector appliances. | Manageability |
Decision: Use automatic OTA upgrades for connector appliances. Rationale: VMware Cloud Services handles upgrades. Implication: No significant trade-offs identified for this decision. Component: CDP | ||
Prerequisites
- VCF healthy per Support Matrix.
- Parameters captured in Cloud-Based Ransomware Recovery tab of Planning & Preparation Workbook.
- DNS records created; AD Domain Controllers available.
- Outbound Internet access on port 443 to VMware Live Cyber Recovery endpoints.
Implementation Procedure
Implementation
VMware Cloud Services account with Live Cyber Recovery entitlement; VMware Cloud on AWS subscription.
Implementation Methods
Powershell
PowerValidatedSolutions — menu entry '12. (CBR) Cloud-Based Ransomware Recovery': Generate JSON, Verify Prereqs, End-to-End Deployment (prepares VCF instance only), Configuration. Service-side config (VMware Live Cyber Recovery service, VMware Cloud on AWS SDDC attach) is manual via UI.
UI
1) Create VM folder for connectors in mgmt vCenter. 2) In VMware Cloud Services → Live Cyber Recovery, deploy Cloud File System in the target AWS region/AZ. 3) Create protected site; download OVA; deploy two connector appliances into mgmt vCenter on the mgmt VLAN; associate with protected site. 4) Create custom vSphere role with minimum privileges; assign to service account used for vCenter registration. 5) Configure DRS anti-affinity rule for connectors; add to AZ1 VM group if multi-AZ. 6) Register VI workload domain vCenter with the protected site (use IP address). 7) Attach pilot-light VMware Cloud on AWS SDDC. 8) Configure email alerts (SLA status).
- External Services / Integration Points
- Active Directory (AD)
- DNS
- NTP (on ESXi hosts)
- Configuration Values
- Connector Firewall PortsOutbound TCP 443 only
- Recovery SDDC ModelPilot Light
- Min SDDC Nodes2
- Cloud File System LocationSame AZ as recovery SDDC
- Time SyncVMware Tools sync from ESXi
Additional Instance
For additional VCF instance: (1) Create VM folder, (2) Create protected site, (3) Deploy connector appliances, (4) Create custom vSphere role and configure service account, (5) Configure DRS anti-affinity, (6) Add to AZ1 VM group in multi-AZ, (7) Register VI workload domain vCenter with protected site.
Day-2 Operations Tasks
Operations
As neededPersonas
As neededNameRole
As neededCloud AdminOrg Owner; Global Console Admin; Orchestrator Admin; VMware Cloud on AWS Administrator; VMware Cloud on AWS NSX Cloud Admin; Carbon Black C
As neededVI AdminOrg member; Recovery SDDC Admin; Recovery Admin; Protection Admin; Carbon Black Cloud role
As neededSite Reliability Engineer (SRE)Org member; Recovery Admin; Carbon Black Cloud role
As neededCompliance OfficerOrg member; Data Protection Auditor (read-only)
As neededOperational Verification
As neededVMware Cloud Services and VMware Live Cyber Recovery status pages: all services operational.
As neededConnector appliance network test: SSH to connector as admin (password from Live Cyber Recovery UI); run 'drc network test --scope cloud'.
As neededMonitoring Points
- Last in mgmt domain startup order: power on connectors via vCenter; verify operational state.
- MonitoringOptional — Aria Operations monitoring via Ping adapter for connectors.
Likely Panelist Questions
Q: Why did you choose this architecture?
See design decisions for rationale
Failure Scenarios
Trade-off Analysis
Trade-Offs Analysis
Chosen:
Justification:
Quiz — Cloud-Based Ransomware Recovery
- Performance
- HA — single connector is SPOF
- Required by VCF
- Required by AWS
- On-Demand
- Pilot Light
- Cold Standby
- Hot Standby
- 1 node (cheapest)
- 2 nodes (single-node expires in 60 days)
- 3 nodes (HA)
- 4 nodes (DRS)
- Different AWS regions for HA
- Same AWS region, same AZ
- Same region, different AZ
- Anywhere
- Cross-instance NSX segment
- Local-instance NSX segment
- Management VLAN
- Public Internet DMZ
- 22 (SSH)
- 443 (HTTPS)
- 9443
- Multiple ports
- NTP directly
- VMware Tools sync from ESXi (ESXi must have NTP)
- AWS time sync
- Static clock
- SDDC Manager
- Aria Suite Lifecycle
- VMware Cloud Services via OTA auto-upgrade
- Manual admin
- 7 days
- 30 days
- ≥ 90 days
- 1 year
- Never
- Once every 5 years
- At least twice a year
- Continuously
- Aria Operations
- Carbon Black Cloud
- NSX Security
- AppDefense
- Recovery Admin
- Data Protection Auditor
- Org Owner
- Orchestrator Admin
- ping <cloud>
- drc network test --scope cloud
- curl cloud.vmware.com
- check-cloud
- Redeploy connector
- VMware Live Cyber Recovery → Protected sites → vCenters → menu → Refresh credentials
- vCenter → Reconfigure SSO
- Nothing automatic
- 07. IOM
- 08. PCA
- 11. SPR
- 12. (CBR) Cloud-Based Ransomware Recovery
Flashcards — Cloud-Based Ransomware Recovery
Labs
Deploy Live Cyber Recovery Connector appliances and register vCenter
Deploy two connectors in mgmt domain, register VI workload domain vCenter with protected site.
Starting State: VCF 5.2 instance healthy; VMware Cloud Services account with Live Cyber Recovery entitlement; outbound 443 open.
Provision recovery SDDC and Cloud File System
Attach a Pilot Light VMware Cloud on AWS SDDC and deploy Cloud File System for recovery.
Starting State: Connectors deployed and registered; AWS region/AZ selected.
Create protection groups, recovery plans, and test recovery
Build protection groups with high-frequency snapshots (≥ 90-day retention), recovery plans with ordered steps, and run a test recovery.
Starting State: Recovery SDDC + Cloud File System attached; vCenter registered.