Guide

    Taking your backups offsite: the guide, case by case

    What going offsite means, why do it, the criteria for a copy truly separate from production, then how to proceed for what you back up: Proxmox VE, PBS, Windows, Linux, NAS, databases, S3 tools.

    In one sentence: taking your backups offsite means keeping a copy somewhere other than production, so that one disaster or one attack cannot take out both the data and its backups.

    1. What going offsite means

    A backup kept in the same room, on the same network and under the same accounts as the servers it protects shares their risks. Going offsite breaks that link on three levels:

    • Location: another building, another site, another datacenter.
    • Access: an account that backs up must not be able to erase everything. See why separate production and backup.
    • Network: at least one offline copy, disconnected, that no account can reach.

    The backup guide of the French national cybersecurity agency, ANSSI (« Sauvegarde des systèmes d'information — Les fondamentaux », in French), recommends the 3-2-1 rule: 3 copies of the data, on 2 different media, one of which is offline. Among its priority recommendations, it adds that an offline backup is essential, or at least an online offsite one under certain conditions.

    2. Why go offsite

    On 10 March 2021, a fire destroyed OVHcloud's SBG2 datacenter in Strasbourg. Customers whose backups were in the same building, or on the same site, lost both at once. See what the OVH fire taught about two-site backup.

    The most common risk is not fire, though, but ransomware: an attacker who obtains the administrator accounts also looks for the backups they can reach. A copy in another place, under other accounts, and an offline copy answer both risks.

    3. What to take offsite, and the criteria to check

    Everything you would need to restart: virtual machines and servers, NAS data, databases, but also what people forget, such as configurations, restore documentation and the backup encryption key, kept outside the system being backed up (see the PBS encryption key).

    • Distance: far enough that one disaster cannot reach both sites.
    • Separation of rights: the backup account must not be able to delete the history.
    • Encryption: on the client side if a third party hosts the copy, with a key you keep.
    • Verification: stored data is read back regularly to detect corruption. See PBS verify jobs.
    • Tested restore: a backup never restored has proven nothing. The time is measured; the backup window calculator gives an order of magnitude for your bandwidth.

    4. Case by case

    Proxmox VE

    VMs and containers are backed up from Proxmox VE to a Proxmox Backup Server, with deduplication and only new chunks sent. Going offsite means adding a remote PBS as storage, or having a local PBS copied to a second one. See offsite Proxmox backup.

    An existing PBS

    If you already run a PBS on site, the offsite copy is a sync to a second PBS: only missing chunks are transferred. See replication between two PBS.

    Windows servers

    An open-source Windows client backs up a Windows server directly to a PBS. See backing up Windows to Proxmox Backup Server, and our case study on a 1 TB server.

    Linux servers

    proxmox-backup-client, restic or rsync, depending on what you back up and where to. See offsite Linux server backup.

    NAS

    Synology, QNAP, TrueNAS and Unraid each have their own tool (Hyper Backup, HBS 3, rsync tasks or Cloud Sync) and protocols. See offsite NAS backup, then the page for your model.

    Databases

    A database is backed up by dump or by a consistent hot copy before going offsite. See offsite database backup.

    Tools that write to S3

    restic, rclone or a NAS that can write to S3 can target an S3 entry point whose content then goes to PBS: see offsite S3 backup to PBS. Attaching a PBS to a bucket is a different topic: PBS and S3 object storage.

    5. Offline and immutable

    An online offsite copy can still be reached. Two means put it out of reach: rights that forbid deletion (online immutability), and a copy on a disconnected medium. The ANSSI guide considers the second more robust, and accepts as a compromise regular immutable online backups complemented by less frequent offline backups.

    To go further: immutable backup and ransomware, the state of the art of air-gapped Proxmox backup, and our AirGapped Drive plan, whose offline copy runs on disconnected disks.

    6. GDPR and NIS2

    A backup contains personal data: its host becomes a processor under the GDPR, with a contract, a known hosting location and security measures. NIS2 requires the entities in scope to take business continuity measures, including backup management. See GDPR backup obligations and backup and NIS2. At NimbusBackup, hosting is in the European Union, in France on request.

    7. What it costs

    The price of going offsite depends mainly on three things: the reserved volume (after deduplication and compression, often well below the sum of the backups), the number of copies (one site, two sites) and whether there is an offline copy. Our plans and prices are on the offsite backup pricing page.

    Frequently asked questions

    What is an offsite backup?

    It is a copy of your backups kept in a different place from your production systems, out of reach of the same disaster (fire, flood, theft) and, ideally, of the same administrator accounts. It can be online, with a provider or on a second site, or offline, on a disconnected medium.

    What is the difference between an offsite backup and an offline backup?

    Offsite means somewhere else; offline means disconnected. An online offsite copy protects against a disaster on your site, but can still be reached over the network. An offline copy cannot be reached by any account until it is plugged back in. The French national cybersecurity agency (ANSSI) guide asks for both, and considers the offline copy essential (or, failing that, an online offsite copy under certain conditions).

    Should an offsite backup be encrypted?

    It is recommended as soon as a third party hosts the copy, and it is often possible on the client side, with a key that never leaves your infrastructure. The condition: keep that key outside the system being backed up, because without it nothing can be restored.

    Where to start

    Tell us what you back up and how much: we point you to the right method, and to a plan only if it suits you.