How to perform a Cloud Restore with the Emergency VPN

When the whole site is down and the connector cannot bridge, the restored server is reached over the Emergency VPN.

If the outage took down the whole site, the connector can no longer bridge the restored server to the customer network. In that case you restore with the Emergency VPN, and whoever needs to work gets onto the server from their own laptop with a VPN client.

The rest of the path is the same as the restore with the connector, only the button and the way you reach the machine change.

Set the gateway before the disaster

This step belongs to a quiet day, not to the moment the customer is down.

  1. Open the Connector page.
  2. In the header, in the Emergency VPN box, click the pencil icon.
  3. Enter the IP address and CIDR of the router the protected devices use today, for example 192.168.1.1/24.
  4. Save.

That is the gateway the restored machines will use in the cloud, so they get out to the internet without anyone reconfiguring them by hand.

Restore with the Emergency VPN and VPN users on the connector

Starting the restore

  1. Open the DR page and click Initiate DR.
  2. In the Pre-flight checks the Original device must be powered off. The Connector will be offline here, which is expected, it is the very reason you are taking this route.
  3. Choose Cloud as the destination.
  4. Click Restore with Emergency VPN.

Then pick the restore point with the three-step selector, Day, Snapshot and Disks, and click Start Recovery. You follow progress on the bar inside the Latest Activities card.

From here the plan recovery days start counting, 7 days on trial DRs, 20 on Sefthy PRO. The count starts when the virtual machine is created.

Giving people access

VPN accounts live on the Connector page, in the VPN & Access card. You can also get there from the DR, from the Emergency VPN box, with the Manage button.

  1. Click Add and type the user name.
  2. On the user row open Download VPN Config.
  3. On Windows you get a zip holding the client and the configuration, and the user runs the executable. On Linux and macOS you download the WireGuard client and the configuration file separately, then import it.

Download all users conf gets everything in one go, handy when you have to hand out access to a whole team. If the customer runs an LDAP, the LDAP Sync section creates the VPN users from their directory instead of by hand.

How the server is reached

The public endpoint the VPN client connects to belongs to the Sefthy cloud, it is not a public address assigned to the restored server. Once connected, the server answers on its usual local address, the one it had on site.

To open the machine desktop without a VPN, use Manage the VM on the DR page and then Console remota.

In the press