> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning Veeam B&R

> Capturing Veeam Backup & Replication with its infrastructure, jobs, backups and backup history.

The *Veeam B\&R* scan module captures Veeam Backup & Replication with the jobs
set up in it, their run times, status and backed-up objects. It requires a
connected [gateway](/docs/en/scan/gateway-install) and Veeam Backup & Replication
version 12 or later.

## Captured data

Each Veeam server becomes an asset of the type *Veeam*. The detail page groups
the data as follows:

| Group | Areas |
| - | - |
| Server Configuration | Licenses, Server Settings, Credentials – Datacenter, User & Roles, Network Traffic Rules, Configuration Backup |
| Backup Infrastructure | Backup Proxies, Direct Attached Storage, Network Attached Storage, Scale-Out Repository, WAN Accelerators, Managed Server |
| Tape Infrastructure | Tape Server, Library, All Tapes, Media Pools, Vaults |
| Inventory | Virtual Infrastructure, Protection Group, File Server, SMB Shares |
| Backup & Replication | Jobs, Backups, Replica |
| Recovery | Recovery Objects, Recovery Sessions |

How the detail page of the type is structured is described in
[Storage, Backup, Permissions](/docs/en/assets/storage-backup).

## Setting up the job

The wizard follows the standard path *Basics* › *Targets* › *Schedule* ›
*Summary*—see [Creating a Scan Job](/docs/en/scan/create-inventory). The
*Targets* step is what sets this module apart.

Each row carries the columns *IP/Hostname* and *Credentials*. *IP/Hostname*
takes one Veeam server per row, as an address or hostname; the column does not
accept an address range. The *Credentials* column must be filled, with an
entry of the type *User Account*. An entry in *Credentials for all targets*
applies to every row without an assignment of its own.

The module setting *Collect Backup History (Days)* determines how many days of
backup history the scan captures; it is prefilled with 42 days. Where the
module settings are is described in
[Creating a Scan Job](/docs/en/scan/create-inventory#module-settings).

## Prerequisites

The scan connects to the Veeam server over WMI and queries the Veeam data
through PowerShell.

### Ports and protocols

| Protocol | Port | Transport |
| - | - | - |
| NetBIOS Name Service, NetBIOS Datagram Service | 137, 138 | UDP |
| NetBIOS Session Service, SMB / CIFS over TCP | 139, 445 | TCP |
| RPC, dynamic ports | 49152–65535 | TCP/UDP |

### Permissions

* The account is a local administrator on the Veeam server—for the WMI
  connection.
* The account is a member of the Veeam Backup Administrators group—for the
  Veeam data.
* Multifactor authentication is not active for the account.
* The account has signed in to the Veeam server at least once, opened the
  Veeam Backup & Replication console and confirmed the certificate message.
* If the Veeam server is not a member of the domain, use a local administrator
  account, such as `.\Administrator`.

### Network requirements

* The firewall allows the ports above. In a domain, enable the predefined rules
  through Group Policy:
  * File and Printer Sharing (Echo Request - ICMPv4-In)
  * File and Printer Sharing (Echo Request - ICMPv6-In)
  * Windows Management Instrumentation (WMI-In)
  * Windows Management Instrumentation (DCOM-In)
* PowerShell 7 is installed on the Veeam server.

Backup servers are often heavily isolated. A gateway on the Veeam server is
therefore recommended, or a scan with the `Discovery-VeeamBR.exe` scan script
(Veeam Backup & Replication 13) or `Discovery-VeeamBR-Legacy.exe` (version
12\)—see [Scanning by Script](/docs/en/scan/scan-by-script).

## Common issues

| Symptom | Cause | Resolution |
| - | - | - |
| Access is denied with a local administrator account that is not the built-in Administrator. | User Account Control (UAC) does not connect as a full administrator on remote access. | Set the `LocalAccountTokenFilterPolicy` registry value on the Veeam server (command below the table). |
| The scan fails at sign-in. | Multifactor authentication is active for the account. | Turn off multifactor authentication for the account, or scan by script under the local system account. |
| The scan fails although account and rights are correct. | The account has never signed in to the server or never confirmed the console's certificate message. | Sign in once with the account, open the console and confirm the message. |

The registry value, set on the Veeam server:

```
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f
```

## Related

After it is created, the job appears among the jobs; how you watch and adjust
it is in [Managing Jobs](/docs/en/scan/manage-jobs). How you run the scan scripts as
a scheduled task and read in their results is in
[Scanning by Script](/docs/en/scan/scan-by-script).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.