Applicable Products
- HDP for Business
- QuTS hero 6.0.2 and later
Purpose
This tutorial takes you from an empty QNAP NAS to a working backup environment: install HDP for Business, build a site, bring virtual machines and computers under protection, create a protection policy, copy backups off site, and restore and verify them. Each section stands on its own, so you can jump to the task you need.
Prerequisites
- A QNAP NAS running QuTS hero 6.0.2 or later. A mid-to-high-end model is recommended for the Management Server.
- An available storage space with enough free space.
- HDP for PC/VM 2.4.1.871 or later installed on the same NAS.
- Virtualization Station 4.2.0.257 or later, if you plan to use Instant Restore or Backup Verification.
- An administrator account on the NAS.
1. Install HDP for Business
- Sign in to the NAS as an administrator and open App Center.
- Search for HDP for Business and click Install.
- Click Open. The welcome page appears.
- Click Set up HDP for Business. The setup steps page opens, where you allocate storage and check dependencies before initializing.

Dependency check
| Status | What it means | What to do |
|---|
| Green check mark | Installed and compatible. | Nothing. The item is selected by default. |
| Yellow warning, grayed out | Installed, but the version is too old. | Upgrade to the version stated on the page. |
| Gray | Not installed. | Install it from App Center. |
Virtualization Station is handled differently: the page only reports whether it is installed and whether the version is sufficient. If it is missing, the options related to Instant Restore are grayed out. You can install it from the guided flow on this page.
Select a storage space
The system creates a shared folder named HDP_Business in the storage space you select. The storage space cannot be changed after initialization, so choose carefully. A storage space is grayed out when it has exceeded its alert threshold or when it is encrypted. If no storage space can be selected, free up space in Storage Manager, and then click Refresh.
HDP for Business never deletes this folder. It remains on the storage space even after you uninstall the app, so your backup data is preserved. To use a different storage space later, delete the HDP_Business folder in Storage Manager first.
Run the initialization
Click Initialize. HDP for Business takes over the existing HDP for PC/VM automatically, without interrupting running backups. Unfinished backups continue after the takeover. When the process completes, the NAS is a Management Server.
2. Build a Site
A site is one Management Server, up to four Backup Servers, and optionally one standby Management Server.
- On the Management Server, go to Site Management and click Join > Generate Invite Key.
- Copy the Server URL and the Invite Key, and send them to the administrator of the Backup Server. The key can be used once and expires after five minutes; click Regenerate if it expires.
- On the Backup Server, go to Site Management and click Join > Join Site.
- Enter the Management Server URL and the Join Key, then click Join. The page shows This server is managed.
On the Management Server, the device moves through Connecting, Syncing, and Online.


Standby Management Server and switch over
In the Add Failover Server area, select a Backup Server to act as the standby. The system checks whether every Backup Server can reach it, because they connect to it after a switchover. You can still add it when some servers report Unreachable, but those servers may be unmanageable after a switchover.
To hand management control to the standby, use Manage > Switch Over on the Management Server, or the Switch Over area on the standby's own page. Scheduled tasks pause during the process and resume automatically.

Transfer workloads to another Backup Server
To retire or release a Backup Server, click the three-dot action menu in its row on the Site Management page and select Transfer. The workload settings move in bulk to the destination Backup Server, which takes over the backup operations.

3. Add What You Want to Protect
Virtual machines
Virtual machine backup connects to the hypervisor to read the inventory. No agent is installed inside the virtual machines.
- Go to the Hypervisor page and click Add, then select the platform.
- Enter the name, host IP address, server port, user name, and password, then click Add.
| Platform | Default port | Notes |
|---|
| VMware | 443 | Standalone ESXi and vCenter are both supported. Connecting the vCenter that manages your hosts is recommended. |
| Hyper-V | 5985 | — |
| Proxmox VE | 22 | Versions 8.x and 9.x. Adding any node brings in the entire cluster. |

Connecting a hypervisor only retrieves the inventory. Add the virtual machines as workloads on the Workloads > Virtual Machine page, in one of two ways.
- Select specific virtual machines: click Add, select the source platform on the left, expand the datacenter or host in the Host and Clusters view on the right, select the virtual machines, and click Select.
- Create an auto protection rule: click Auto Protection Rule > Create, then set the rule name, the source inventory folder, the target Backup Server, and the protection policy. Virtual machines added to that folder later are protected automatically.


Windows computers
Physical computers are protected by HDP for Business Agent. On the Physical Device page, click Add, download the installer, and create a Join Key that binds a Backup Server and a policy. Install the agent on the computer and connect it with that key. For the full procedure, see the HDP for Business Agent tutorial.
File servers
A file server is added over SMB on the Workloads > File Server page. Click Add and complete the wizard: connection settings including host, port (445 by default), account, password, and timeout; the source paths and the target Backup Server; the protection policy; and the summary.

4. Create a Protection Policy
Two policies are built in and cannot be deleted: Default Policy, which runs daily at 09:00, and Default Manual Policy, which runs only when you start it. Both keep 30 versions. To create your own:
- Go to Protection Policy and click Create > Machine Policy.
- General: enter a unique name and select the policy type. A standard protection policy manages versions by the retention rule; an immutable protection policy prevents backups from being modified or deleted within the retention period and can only be set in days. The type cannot be changed after creation.
- Backup Settings: set the retention rule — a number of versions (30 by default), a number of days (30 by default), or Smart Versioning — and the schedule, which can be manual or automatic with a minimum interval of five minutes.
- Advanced Settings: configure the Virtual Machine, Physical Device, and Database tabs as needed. This is also where you select Enable Backup Verification.
- Backup Copy: optionally copy each backup to remote storage. Set up the remote storage first, as described in section 6.
- Summary: review and click Create.


5. Run and Monitor Backups
- On a schedule: the policy runs at the time you set.
- Manually: on the workload page, click the Backup icon in that row, or select several workloads and click More > Backup.
Check progress and history on the Activities page, and the health of the whole environment on the Dashboard, where every figure can be clicked to drill down.


6. Copy Backups to Remote Storage
A backup copy keeps a second copy of your backups in remote object storage, so the data survives the loss of the Backup Server. Supported types are QuObjects, myQNAPcloud Object, Amazon S3, Wasabi, and S3 Compatible.
- Go to Remote Storage, click Add, and select the storage type.
- Connection: enter the access key and secret key, add the endpoint if the type requires one, and verify the connection.
- Bucket: select a bucket. Only buckets with Object Lock enabled can be selected, so that backups cannot be modified or deleted.
- Password: optionally enable password protection for end-to-end encryption, using 8 to 64 characters with uppercase letters, lowercase letters, numbers, and special characters.
- Summary: review and click Create.
Keep the password safe. If it is lost, the backups in that bucket can never be decrypted or recovered, and the password cannot be changed.
Then open the protection policy, select Enable backup copy on the Backup Copy step, and set the target, the retention, and the schedule.

Recover backups from a bucket
When the versions on a Backup Server are lost, or a new Backup Server takes over an existing bucket, click Import Workloads in that storage's row, select the workloads, and click Import. The result is grouped into Relinked, Updated, and Skipped. A workload imported to a machine other than the original is always Unmanaged: you can restore from it, but you cannot assign a policy to it.
7. Restore
Open Backup Explorer, select a backup version, and click Restore. Then select the restore type.
| Type | When to use it |
|---|
| Instant Restore | Boots the backup directly on the Backup Server within minutes. I/O performance is limited because it runs from read-only backup files. |
| Full Restore | Restores the machine to a hypervisor with full performance, for formal disaster recovery. A backup can only be restored to the same type of hypervisor. Physical computers require bare-metal restore boot media. |

Instant Restore
Virtualization Station must be installed and initialized on the Backup Server, with at least 2 GB of available memory. The wizard has five steps: General, Convert, Storage, Network, and Summary.
On the Convert step, decide what happens to the restored machine:
| Option | What it means |
|---|
| Keep as temporary virtual machine (default) | For review and verification. The machine stops working when HDP for Business stops running, for example when it is disabled, updated, or the NAS restarts. The backup data is not affected. |
| Convert to a permanent virtual machine | Handed over to Virtualization Station with full capabilities. Requires a File Location. After the conversion, the virtual machine and its data can no longer be deleted from HDP for Business. |
Free space required for a conversion: the target storage briefly holds two copies of the disks during the conversion, so make sure the File Location has free space of at least twice the disk size of the virtual machine. The intermediate copy is removed automatically when the conversion finishes.
If you kept the machine as temporary, you can convert it later: on the Activities tab of Backup Explorer, click Convert in that task's row. Tasks already marked Converted no longer offer the action.

8. Verify That Backups Can Boot
With backup verification enabled, HDP for Business starts a temporary virtual machine from each completed backup and records the boot as a video. Virtualization Station must be installed and initialized on the Backup Server, with at least 4 GB of available memory.
- In the protection policy, on the Advanced Settings step, select Enable Backup Verification on the Virtual Machine or Physical Device tab.
- Set the Video Duration in seconds. The default is 120 and the range is 30 to 600. Allow enough time for the machine to boot fully.
- To watch the result, open the workload and go to its Backup Versions tab. The Backup Verification Status column shows the outcome of each version, and you can narrow the list with the Backup Verification Status filter. Open the action menu of a version and select Play Verification Video or Download Verification Video. The same actions are available from Backup Activities.
Backup Activities lists the verification as a task of the type Backup Verification, with the same two actions in its action menu. The dialog shows the workload name and the verified backup time above the player, and the video can be downloaded or opened full screen from the player controls. A video exists only when the verification succeeds.


9. Isolate a Backup Server with AirGap+
AirGap+ creates physical isolation for critical assets by shutting the Backup Server down on a schedule. A device that is powered off cannot be reached over the network, which puts the backups stored on it out of reach of ransomware, insider access, and unauthorized connections.
- Go to Site Management and click the name of the Backup Server to open its detail page.
- Open the Airgap+ tab.
- The weekly grid covers every hour of every day, from 12 AM to 11 PM. Select the hours during which the server is protected. Selected hours are marked Deny all collections, and unselected hours remain No settings applied.
- Click Apply. The button is enabled only after you change the grid.

During the protection period the Backup Server is shut down, no backup collection runs on it, and it appears as Offline in Site Management. Logs of that device cannot be queried while it is offline, because log queries are forwarded to the device in real time. The Logs page on the Management Server records the applied schedule and the next power-off time.
What's Next
适用产品
- HDP for Business
- QuTS hero 6.0.2 and later
目的
本教程将指导您从一个空的 QNAP NAS 到一个可用的备份环境:安装 HDP for Business,建立站点,将虚拟机和计算机纳入保护,创建保护策略,将备份复制到异地,并进行恢复和验证。每个部分都是独立的,因此您可以直接跳到所需的任务。
先决条件
- 运行 QuTS hero 6.0.2 或更高版本的 QNAP NAS。建议使用中高端型号作为管理服务器。
- 一个可用的存储空间,并有足够的可用空间。
- 在同一 NAS 上安装 HDP for PC/VM 2.4.1.871 或更高版本。
- 如果计划使用即时恢复或备份验证,则需要 Virtualization Station 4.2.0.257 或更高版本。
- 在 NAS 上的一个管理员账户。
1. 安装 HDP for Business
- 以管理员身份登录 NAS 并打开App Center。
- 搜索HDP for Business并点击安装。
- 点击打开。欢迎页面将出现。
- 点击设置 HDP for Business。设置步骤页面将打开,您可以在初始化之前分配存储并检查依赖项。

依赖项检查
| 状态 | 含义 | 操作建议 |
|---|
| 绿色对勾 | 已安装且兼容。 | 无需操作。该项目默认已选中。 |
| 黄色警告,灰色显示 | 已安装,但版本过旧。 | 升级到页面上指定的版本。 |
| 灰色 | 未安装。 | 从 App Center 安装。 |
Virtualization Station 的处理方式不同:页面仅报告是否已安装以及版本是否足够。如果缺失,与即时恢复相关的选项将被灰色显示。您可以通过此页面上的引导流程进行安装。
选择一个存储空间
系统会在您选择的存储空间中创建一个名为HDP_Business的共享文件夹。初始化后存储空间无法更改,请谨慎选择。当存储空间超过警戒阈值或被加密时,会显示为灰色。如果无法选择存储空间,请在存储管理器中释放空间,然后点击刷新。
HDP for Business 从不删除此文件夹。即使您卸载应用程序,它仍保留在存储空间中,因此您的备份数据得以保存。若要稍后使用不同的存储空间,请先在存储管理器中删除HDP_Business文件夹。
运行初始化
点击初始化。HDP for Business 会自动接管现有的 HDP for PC/VM,而不会中断正在进行的备份。接管后未完成的备份将继续进行。完成后,NAS 将成为管理服务器。
2. 构建站点
一个站点包括一个管理服务器,较多四个备份服务器,以及可选的一个备用管理服务器。
- 在管理服务器上,进入站点管理,点击加入 > 生成邀请密钥。
- 复制服务器 URL和邀请密钥,并将其发送给备份服务器的管理员。密钥可使用一次,五分钟后过期;如果过期,请点击重新生成。
- 在备份服务器上,进入站点管理,点击加入 > 加入站点。
- 输入管理服务器 URL 和加入密钥,然后点击加入。页面显示此服务器已被管理。
在管理服务器上,设备会经历连接中、同步中和在线。


备用管理服务器和切换
在添加故障转移服务器区域,选择一个备份服务器作为备用。系统会检查每个备份服务器是否可以连接到它,因为在切换后它们会连接到它。即使有些服务器报告无法访问,您仍然可以添加它,但这些服务器在切换后可能无法管理。
要将管理控制权交给备用服务器,请在管理服务器上使用管理 > 切换,或在备用服务器自己的页面上的切换区域。计划任务在此过程中暂停,并会自动恢复。

将工作负载转移到另一个备份服务器
要退役或释放备份服务器,请在站点管理页面的其行中点击三点操作菜单,然后选择转移。工作负载设置将批量移动到目标备份服务器,该服务器将接管备份操作。

3. 添加您想要保护的内容
虚拟机
虚拟机备份连接到虚拟机管理程序以读取清单。虚拟机内部不安装代理。
- 进入虚拟机管理程序页面,点击添加,然后选择平台。
- 输入名称、主机 IP 地址、服务器端口、用户名和密码,然后点击添加。
| 平台 | 默认端口 | 备注 |
|---|
| VMware | 443 | 支持独立的 ESXi 和 vCenter。建议连接管理主机的 vCenter。 |
| Hyper-V | 5985 | — |
| Proxmox VE | 22 | 版本 8.x 和 9.x。添加任何节点都会引入整个群集。 |

连接虚拟机管理程序只会检索清单。在工作负载 > 虚拟机页面上以两种方式之一添加虚拟机作为工作负载。
- 选择特定虚拟机:点击添加,在左侧选择源平台,在右侧的主机和群集视图中展开数据中心或主机,选择虚拟机,然后点击选择。
- 创建自动保护规则:点击自动保护规则 > 创建,然后设置规则名称、源清单文件夹、目标备份服务器和保护策略。稍后添加到该文件夹的虚拟机将自动受到保护。


Windows 计算机
物理计算机由 HDP for Business Agent 保护。在物理设备页面上,点击添加,下载安装程序,并创建一个绑定备份服务器和策略的加入密钥。在计算机上安装代理并使用该密钥连接。完整步骤请参见 HDP for Business Agent 教程。
文件服务器
文件服务器通过 SMB 添加到工作负载 > 文件服务器页面。点击添加并完成向导:连接设置包括主机、端口(默认 445)、账户、密码和超时;源路径和目标备份服务器;保护策略;以及摘要。

4. 创建保护策略
内置了两个策略,无法删除:默认策略,每天 09:00 运行;默认手动策略,仅在您启动时运行。两者均保留 30 个版本。要创建您自己的策略:
- 前往保护策略,点击创建 > 机器策略。
- 常规:输入一个稀有名称并选择策略类型。标准保护策略通过保留规则管理版本;不可变保护策略在保留期内防止备份被修改或删除,并且只能按天设置。创建后类型无法更改。
- 备份设置:设置保留规则——版本数量(默认 30 个)、天数(默认 30 天)或智能版本管理——以及计划,可以是手动或自动,较小间隔为五分钟。
- 优异设置:根据需要配置虚拟机、物理设备和数据库选项卡。在这里您还可以选择启用备份验证。
- 备份副本:可选择将每个备份复制到远程存储。首先按照第 6 节描述设置远程存储。
- 摘要:查看并点击创建。


5. 运行和监控备份
- 按计划:策略将在您设置的时间运行。
- 手动:在工作负载页面,点击该行中的备份图标,或选择多个工作负载并点击更多 > 备份。
在活动页面查看进度和历史记录,并在仪表板上查看整个环境的健康状况,每个数据都可以点击以深入查看。


6. 将备份复制到远程存储
备份副本在远程对象存储中保留备份的第二份副本,因此数据在备份服务器丢失时仍然存在。支持的类型包括 QuObjects、myQNAPcloud Object、Amazon S3、Wasabi 和 S3 兼容。
- 前往远程存储,点击添加,并选择存储类型。
- 连接:输入访问密钥和秘密密钥,如果类型需要,添加端点,并验证连接。
- 存储桶:选择一个存储桶。只有启用了对象锁定的 Bucket 可以被选择,以确保备份不能被修改或删除。
- 密码:可选地启用端到端加密的密码保护,使用 8 到 64 个字符,包括大写字母、小写字母、数字和特殊字符。
- 摘要:查看并点击创建。
请妥善保管密码。如果丢失,该存储桶中的备份将无法解密或恢复,且密码无法更改。
然后打开保护策略,在备份副本步骤中选择启用备份副本,并设置目标、保留时间和计划。

从存储桶中恢复备份
当备份服务器上的版本丢失,或新的备份服务器接管现有存储桶时,点击该存储行中的导入工作负载,选择工作负载,然后点击导入。结果分为重新链接、更新和跳过。导入到非原始机器的工作负载始终为未管理:您可以从中恢复,但无法为其分配策略。
7. 恢复
打开备份资源管理器,选择一个备份版本,然后点击恢复。然后选择恢复类型。
| 类型 | 何时使用 |
|---|
| 即时恢复 | 在几分钟内直接在备份服务器上启动备份。由于从只读备份文件运行,I/ O 性能有限。 |
| 完整恢复 | 将机器恢复到具有完整性能的虚拟机管理程序,用于正式的灾难恢复。备份只能恢复到相同类型的虚拟机管理程序。物理计算机需要裸机恢复启动介质。 |

即时恢复
Virtualization Station 必须安装并在备份服务器上初始化,至少需要 2 GB 的可用内存。向导有五个步骤:常规、转换、存储、网络和摘要。
在转换步骤中,决定恢复后的机器将如何处理:
| 选项 | 含义 |
|---|
| 保留为临时虚拟机(默认) | 用于审查和验证。当 HDP for Business 停止运行时,例如禁用、更新或 NAS 重启时,机器将停止工作。备份数据不受影响。 |
| 转换为长期虚拟机 | 交付给 Virtualization Station,具备完整功能。需要一个文件位置。转换后,虚拟机及其数据将无法从 HDP for Business 中删除。 |
转换所需的空闲空间:目标存储在转换过程中会暂时保留磁盘的两个副本,因此请确保文件位置至少有虚拟机磁盘大小两倍的空闲空间。转换完成后,中间副本会自动删除。
如果您将机器保留为临时的,可以稍后进行转换:在活动选项卡的备份资源管理器中,点击该任务行中的转换。已标记为已转换的任务不再提供此操作。

8. 验证备份是否可以启动
启用备份验证后,HDP for Business 会从每个完成的备份启动一个临时虚拟机,并将启动过程记录为视频。Virtualization Station 必须安装并在备份服务器上初始化,至少需要 4 GB 的可用内存。
- 在保护策略中,在优异设置步骤中,选择虚拟机或物理设备选项卡上的启用备份验证。
- 以秒为单位设置视频时长。默认值为 120,范围为 30 到 600。请确保有足够的时间让机器启动。
- 要查看结果,请打开工作负载并转到其备份版本选项卡。备份验证状态列显示每个版本的结果,您可以使用备份验证状态过滤器缩小列表。在某个版本的操作菜单中选择播放验证视频或下载验证视频。备份活动中也提供相同的操作。
备份活动将验证列为备份验证类型的任务,其操作菜单中有相同的两个操作。对话框在播放器上方显示工作负载名称和已验证的备份时间,视频可以通过播放器控件下载或全屏打开。只有验证成功时才会存在视频。


9. 使用 AirGap+ 隔离备份服务器
AirGap+ 通过按计划关闭备份服务器来为关键资产创建物理隔离。关闭电源的设备无法通过网络访问,这使得存储在其上的备份不受勒索软件、内部访问和未经授权的连接的影响。
- 进入站点管理,点击备份服务器的名称以打开其详细信息页面。
- 打开Airgap+选项卡。
- 每周网格覆盖每天的每个小时,从凌晨 12 点到晚上 11 点。选择服务器受保护的时间段。选中的时间段标记为拒绝所有集合,未选中的时间段保持未应用设置。
- 点击应用。只有更改网格后按钮才会启用。

在保护期间,备份服务器关闭,不会在其上运行备份收集,并且在站点管理中显示为离线。该设备的日志在离线时无法查询,因为日志查询会实时转发到设备。管理服务器上的日志页面记录了应用的计划和下次关机时间。
接下来做什么