惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏
M
MIT News - Artificial intelligence
腾讯CDC
博客园 - Franky
Engineering at Meta
Engineering at Meta
C
Check Point Blog
T
The Blog of Author Tim Ferriss
有赞技术团队
有赞技术团队
Microsoft Azure Blog
Microsoft Azure Blog
MyScale Blog
MyScale Blog
I
InfoQ
Blog — PlanetScale
Blog — PlanetScale
P
Proofpoint News Feed
The GitHub Blog
The GitHub Blog
N
Netflix TechBlog - Medium
Last Week in AI
Last Week in AI
S
SegmentFault 最新的问题
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
WordPress大学
WordPress大学

VMware Blogs

Diagnostics for VMware Cloud Foundation (VCF) 9.1 with Old Versions of VCF Components Mastering Infrastructure Policies in VMware Cloud Foundation Automation 9.1 Modernizing the Private Cloud: Why VCF 9.1 Lifecycle Management is a Game Changer Announcing the VMware Cloud Foundation 9.1 Upgrade Planning Tool VCF Breakroom Chats Episode 86 – Containers Made Easy: The New “Container-as-a-Service” in VCF 9.1 Securing Your VCF 9.1 Infrastructure with the Symantec Identity Security Platform Virtually Speaking: The AI Reality Check with Dave Linthicum Zero Touch Provisioning: Activating Edge Sites with VMware Cloud Foundation Edge 9.1 VCF Breakroom Chats Episode 85 – Cloning Success at Scale: Inside VCF 9.1’s App Stack Formation VMware Cloud on AWS の使用状況を確認できる API Unlocking the Full Potential of Programmable Infrastructure with VMware Cloud Foundation 9.1 – New Features and Capabilities Smarter Patching at Scale: Vulnerability Assessment and Remediation with VMware Tanzu Platform Encrypted vMotion Offload to Intel QAT in VMware Cloud Foundation 9.1 Deepen Your Expertise: Four Key Benefits of Attending Increase Deployment Flexibility with VCF Edge Automation 1.0.3 Avi Advantage: Automating Certificate Management of VCF Workloads More Memory, Less Effort: Configuring Memory Tiering in VCF 9.1 VCF 9.1 Licensing: Programmatic, Centralized, and Built to Scale Why APJ Networking Professionals Need Private Cloud Expertise VCF 9.1 Networking: Simpler VPC Connectivity Control VCF 9.1 Networking: Exploring Network Services for Virtual Private Clouds VCF Networking 9.1: Seamless DDI Integration with Infoblox The Open Source Advantage: Building from Source for Ultimate Security Expand Shared VMDKs with Clustered Applications in VMware vSAN for VCF 9.1 Monetizing Zero-Trust Security with VCF 9.1 and VMware vDefend Deliver Production SQL Server DBaaS with VMware Data Services Manager 9.1 Maximizing Profitability: VCF 9.1 Cost-Focused Approach for VMware Cloud Service Providers Modernizing Your Infrastructure: Introducing VMware Cloud Foundation 9.1 to VCSPs VCF 9.1 is Available: Explore the New Features in Hands-on Labs What’s New with vSphere in VMware Cloud Foundation 9.1?
VMware vSAN Protection and Recovery Enhancements for VCF 9.1
pete koehler · 2026-05-14 · via VMware Blogs

With the release of VMware Cloud Foundation (VCF) 9.1, we are introducing significant enhancements to vSAN Protection and Recovery (formerly known as vSAN Data Protection). These updates focus on three core areas of the solution: architectural flexibility, sovereign cyber resilience, and operational scale.

Multi-Source Replication

In VCF 9.0, we introduced vSAN-to-vSAN replication. It was the first logical step in providing remote protection for workloads running on vSAN. While powerful, many of our customers operate heterogeneous environments where data resides on a mix of storage platforms. VCF 9.1 breaks these silos by introducing multi-source replication capabilities.

What does this mean? You can now protect VMs from multiple types of storage, including vSAN, VMFS and NFS datastores to a vSAN ESA cluster as the target. Not only does it provide the ability to have multiple sources, but it also allows for a “fan-in” architecture that gives you the ability to protect multiple source clusters to a single, centralized recovery site.

Figure 1. Multi-source replication to a shared recovery site in vSAN Protection and Recovery.

In this type of topology, both the source site and the shared recovery site must have their own respective vCenter Server, as well as a Protection and Recovery appliance. The relationship between the two sites is established by site pairing. Protection Groups can then be configured for local protection at the source site (vSAN only), or remote protection (vSAN, VMFS, or NFS at the source site) to the vSAN ESA cluster in the shared recovery site.

While vSAN Protection and Recovery can protect workloads on a vSAN cluster locally, any of the replication capabilities described here are available through Site Recovery Manager (SRM) which provides site recovery capabilities, or the VMware Advanced Cyber Compliance (ACC) add-on, which provides both site recovery and comprehensive cyber recovery capabilities.

Aside from the conventional use cases of disaster recovery and ransomware recovery, multi-source replication can also assist with data migration efforts, where migrating off of VMFS and/or NFS has been a challenge due to the existing topology.

On-Premises Cyber Recovery: Your Private Clean Room

The ability to perform cyber recovery without a dependency on the public cloud has been a frequent feature request. While cloud-based recovery offers flexibility for environments that do not have another site, many organizations have strict compliance or sovereignty requirements that demand a customer-owned, on-premises Isolated Recovery Environment (IRE).

VCF 9.1, paired with the VMware Advanced Cyber Compliance (ACC) add-on, allows you to build a fully customer-owned and managed clean room. This eliminates the need for cloud-based recovery sites while providing the same push-button isolation and EDR integration.

Figure 2. Cyber recovery using an on-premises clean room.

With a customer-owned recovery site, ransomware protection and recovery processes are built into the SRM workflows. This takes advantage of logic already in place for disaster recovery, but adapts them to accommodate ransomware recovery workflows. Upon detection of a ransomware event, protected VMs are first placed in a validation state within an Isolated Recovery Environment (IRE), where snapshots are scanned and cleaned using EDR sensors. Once verified, they move to a staging state to create a clean replica, followed by a recovered state to resume operations in the secondary site. Finally, the process concludes by reprotecting and failing back the VMs to the primary site, restoring them to their original production environment and steady-state protection.

Combine this new capability with the recent announcement of new ReadyNodes certified for Cyber Recovery, and you can now build out a high value, high-capacity recovery site.

Sometimes it is the smaller features that mean the most to day-to-day operations. We’ve added a trio of enhancements designed to make protection of VMs easier.

Figure 3. Snapshot Retention, protection group tagging, and replica seeding in vSAN Protection and Recovery.

Hierarchical Snapshot Retention

Moving beyond simple First-In-First-Out (FIFO) snapshot retention methods, vSAN Protection and Recovery now supports tiered retention schedules. Sometimes known as a “Grandfather-Father-Son” (GFS) approach, it allows for sophisticated scheduling (Hourly, Daily, Weekly, Monthly) to provide much greater and more efficient recovery depth.

Not sure what retention periods to choose? We’ve even included quick-selection templates to get you started, including:

  • Default. Will automatically select an RPO of 1 hour, keeping the last 12 snapshots, while keeping daily snapshots for 2 weeks. Estimated snapshot count: 26
  • Ransomware recovery. Will automatically select an RPO of 1 hour, keeping the last 1 snapshot, while keeping hourly snapshots for 1 day, daily snapshots for 1 week, weekly snapshots for 1 month, and monthly snapshots for 6 months.
  • Short-term retention. Will automatically select an RPO of 1 hour, keeping the last 1 snapshot, while keeping hourly snapshots for 1 day, keeping daily snapshots for 1 week, and keeping weekly snapshots for 1 month.

Protection Group Memberships using vSphere Tags

Managing protection at scale is now easier, as Protection and Recovery supports the use of vSphere tags for assignments to protection groups. VMs can now be assigned to protection groups using their static names, a dynamic name using wild cards, or now, through tags. You can even use logic like “match all” or “match any” tags to ensure dynamic workloads are protected the moment they are provisioned. Any new VMs that have the associated tag assignment will be protected.

Manual Replica Seeding

For environments with massive datasets or limited bandwidth, the initial “full sync” over the WAN can be a bottleneck. VCF 9.1 introduces Manual Seeding. You can now manually move data (e.g., via a physical shipping device) to the target site to act as a seed. Once the seed is in place, vSAN performs a differential sync to catch up, significantly reducing initial deployment times. Seeding will be a flexible option that can be used for a variety of other scenarios, including the migration to another target site.

Do you have more questions on vSAN as well as vSAN Protection and Recovery? Check out the extensive list of frequently asked questions on the vSAN FAQs document.

Summary

These enhancements in VCF 9.1 represent a major leap forward in making vSAN the most flexible and resilient platform for your mission-critical data. Whether you are protecting legacy VMFS and NFS volumes, or building a sovereign cyber vault, vSAN Protection and Recovery has the tools to keep your business running.

@vmpete


Discover more from VMware Cloud Foundation (VCF) Blog

Subscribe to get the latest posts sent to your email.