Backup & DR

Veeam Cloud Connect Step by Step

How to send offsite backups to a cloud provider without VPN or complex networking: architecture, requirements, console configuration and verification, step by step with Veeam Cloud Connect.

business EasyDataHost calendar_today April 25, 2026 schedule 10 min read

The 3-2-1 backup rule states that at least one copy of your data must be stored offsite. However, implementing offsite backup has traditionally meant configuring VPN tunnels, opening firewall ports, managing certificates and maintaining infrastructure in a second data centre. For many organisations, the complexity of this setup has been a barrier preventing them from following sound backup practices.

Veeam Cloud Connect (VCC) solves this problem at the root. It is a built-in feature of Veeam Backup & Replication that lets you send backups to a cloud repository hosted by a certified service provider (VCSP) over the internet, with end-to-end TLS encryption, no VPN required, and a configuration that can be completed in minutes from the Veeam console.

In this guide we explain what VCC is, how its architecture works, what prerequisites you need, and how to configure it step by step so that your first offsite copy is operational today.

What Is Veeam Cloud Connect

Veeam Cloud Connect is a native feature of Veeam Backup & Replication (available since version 7, although current v12+ releases offer vastly superior capabilities) that extends your local backup infrastructure to a cloud repository managed by a Veeam Cloud & Service Provider (VCSP).

From the administrator's perspective, the cloud repository appears as just another destination inside the Veeam console, exactly like a local repository or a NAS share. There is no additional software to install, no agents to deploy on the target servers and no permanent VPN to maintain. All communication travels encrypted over TLS on port 6180/TCP (by default), which greatly simplifies firewall rules.

VCC supports two modes of operation: Backup (sending backup copies of VMs, physical servers and workstations to the cloud) and Replication (replicating entire VMs to the provider for failover in the event of a disaster). This article focuses on Backup mode, which is the most common use case and the starting point for any disaster recovery strategy.

Veeam Cloud Connect Architecture

The VCC architecture is elegant in its simplicity. It involves only two parties: the tenant (your organisation, with its Veeam B&R console) and the provider (the VCSP that hosts the cloud repository). Communication between the two flows as follows:

  • computer Tenant console (Veeam B&R): initiates the outbound connection to the provider's cloud gateway. Backup data is compressed and encrypted before leaving your network.
  • language Internet (TLS 6180/TCP): all communication travels TLS-encrypted. No VPN, IPsec tunnels or complex network configurations are required. You only need outbound access to the provider's gateway on port 6180.
  • dns Cloud gateway (provider): the entry point into the provider's infrastructure. It authenticates the tenant, manages sessions and routes data to the corresponding repository.
  • cloud_sync Cloud repository: the storage where your offsite backups reside. Each tenant has its own isolated space, invisible to other tenants. Data can be encrypted at rest in addition to in-transit encryption.

Key concept:

Veeam Cloud Connect uses an outbound-only connection model from the tenant. The provider never initiates connections to your network. This means you do not need to open any inbound ports on your firewall, which radically simplifies security.

Prerequisites

Before starting the configuration, make sure you have the following items ready:

  • verified Veeam Backup & Replication installed: any edition (Community, Standard, Enterprise or Enterprise Plus). The Cloud Connect feature is available in all editions, although advanced capabilities such as WAN acceleration require Enterprise or higher. We recommend version v12 or later to take advantage of all performance and security improvements.
  • badge VCSP provider credentials: server address (FQDN or IP of the cloud gateway), username and password provided by your provider.
  • wifi Internet connectivity: outbound access from the Veeam server to the cloud gateway on port 6180/TCP. The recommended bandwidth depends on data volume, but VCC includes built-in compression and deduplication that significantly reduce traffic.
  • shield Firewall rule: allow outbound TCP traffic to the provider's gateway on port 6180. No inbound rule is needed.

Step 1: Choose a VCSP Provider

The first step is to choose a Veeam Cloud & Service Provider to host your offsite repository. There are several factors to consider when selecting a provider:

  • location_on Data centre location: to comply with regulations such as GDPR, data must reside within the EU. A provider with a data centre in Spain guarantees data sovereignty and minimal latencies.
  • workspace_premium Veeam partnership level: Gold or Platinum partners have demonstrated technical competence and operational volume to Veeam.
  • lock Immutability: ensure the provider offers repositories with immutable backups, which prevent ransomware from encrypting or deleting your backup copies.
  • storage Storage type: some providers use S3 object lock storage as the backend, adding an extra layer of protection.

EasyDataHost as a VCSP provider offers cloud repositories with S3 storage, built-in immutability, a Tier III+ data centre in Madrid and specialised Veeam technical support. Once you subscribe to the service, you will receive the access credentials (server address, username and password) needed for the next step.

Step 2: Add the Service Provider in Veeam

With your credentials in hand, open the Veeam Backup & Replication console and follow these steps to register the cloud provider:

  • looks_one Navigate to Backup Infrastructure > Service Providers in the left-hand panel of the console.
  • looks_two Click Add Service Provider in the top toolbar.
  • looks_3 Enter the server address (FQDN or IP) provided by your provider and the port (6180 by default). Click Next.
  • looks_4 Veeam will connect to the gateway and display the provider's TLS certificate. Verify it (check the thumbprint if necessary) and accept the certificate.
  • looks_5 Enter the credentials (username and password) provided by the provider. Veeam will authenticate the session and display available resources: cloud repositories and, if applicable, hardware plans for replication.
  • looks_6 Review the summary and click Finish. The cloud repository will now appear as an available destination in your backup infrastructure.

The entire process takes less than two minutes. Once completed, the provider's cloud repository appears under Backup Infrastructure > Cloud and is ready to be used as a target in any backup or backup copy job.

Step 3: Create a Backup Copy Job

The recommended method for sending data to the cloud repository is a Backup Copy Job. This job type takes existing restore points from your local repository and copies them to the offsite target, without needing to re-read data from the production VMs. The steps are as follows:

  • looks_one In the Veeam console, go to Home > Backup Copy and select the workload type (Virtual Machine, Physical, etc.).
  • looks_two Name the job and select the source VMs or backups you want to copy to the cloud.
  • looks_3 In the Target step, select the VCSP provider's cloud repository that you added in the previous step.
  • looks_4 Configure the retention policy: how many restore points to keep in the cloud. For long-term retention, enable GFS (Grandfather-Father-Son) to automatically maintain weekly, monthly and yearly points.
  • looks_5 Configure the schedule: copy frequency (daily is typical) and a transfer window if you need to limit bandwidth usage to certain hours.
  • looks_6 Review the summary, click Finish and, optionally, run the job immediately to start the first transfer.

Tip:

The first transfer (seed) will be the longest because it must send all the data. Subsequent transfers are incremental: they only send the blocks that have changed since the last copy. This drastically reduces both time and bandwidth requirements.

Step 4: Verify the First Copy

Once the first backup copy job completes, it is essential to verify that the data is intact and that restoration works correctly. There are three key checks to perform:

  • task_alt Job status: in the Veeam console, verify that the job shows as completed with a Success or Warning status (a warning usually means a VM took longer than expected, but the data was copied successfully).
  • inventory Data in the cloud: navigate to Backup > Cloud in the console and verify that the corresponding restore points appear. Check that the reported size is consistent with your VM data volumes.
  • restore Restore test: this is the most important check. Perform a test restore (for example, restore individual files from the cloud backup or a complete VM to a test environment) to confirm that the data is recoverable. A backup that cannot be restored is not a backup.

We recommend scheduling periodic restore tests (at least quarterly) to ensure the ongoing integrity of your offsite copies. Veeam includes features such as SureBackup that automate these verifications.

VCC vs Other Offsite Solutions

The following table compares Veeam Cloud Connect with other common offsite backup alternatives:

Criterion VCC (VCSP) Custom S3 Tape DC-to-DC (VPN)
Ease of setup Very high (minutes) Medium (requires scripting) Low (physical logistics) Low (VPN + remote infra)
In-transit security Native TLS, no VPN HTTPS/TLS Physical (transport) IPsec/WireGuard
Operational cost Low (pay-per-use) Variable (egress fees) High (tapes + transport) High (2 DCs + staff)
RTO (recovery time) Minutes to hours Hours Days Minutes to hours
Ongoing management Minimal (provider manages infra) Medium (bucket/IAM management) High (inventory, rotation) High (2 infrastructures)

Key Advantages of Veeam Cloud Connect

Beyond the simplicity of configuration, VCC offers a set of technical advantages that set it apart from other offsite solutions:

  • vpn_lock No VPN: the outbound-only model over TLS eliminates the need to maintain VPN tunnels, simplifying network architecture and reducing the attack surface.
  • enhanced_encryption End-to-end encryption: data is encrypted in transit (TLS) and can be encrypted at rest in the provider's repository. The tenant can also encrypt data with their own key before sending it, so that even the provider cannot access the contents.
  • speed WAN acceleration: Enterprise and Enterprise Plus editions include built-in WAN acceleration that reduces the volume of transmitted data through global deduplication, compression and caching, speeding up transfers over bandwidth-limited links.
  • lock Built-in immutability: VCSP providers can configure repositories with immutability (hardened repository), preventing backups from being modified or deleted during the retention period, even if an attacker compromises the tenant's credentials.
  • integration_instructions Native integration: there are no additional agents, no separate consoles and no APIs to integrate. Everything is managed from the same Veeam B&R console you already use for your local backups.

VCC for Disaster Recovery as a Service (DRaaS)

Veeam Cloud Connect is not limited to offsite backup. Its Replication mode allows you to replicate entire VMs to the provider's data centre, creating replicas ready to start (failover) in the event of a disaster at the primary site. This turns VCC into a complete Disaster Recovery as a Service (DRaaS) solution.

With DRaaS through VCC, if your primary data centre suffers a catastrophic failure (fire, flood, prolonged power outage), you can activate the replicas at the provider's data centre within minutes, with an RTO that can be under 15 minutes. Once the primary site recovers, you can failback to migrate the VMs back to your own infrastructure.

This model enables organisations to have a complete disaster recovery plan without investing in a second data centre of their own, paying only for the resources they consume at the provider.

EasyDataHost as a VCSP Provider

EasyDataHost is a Veeam Cloud & Service Provider with Gold partnership, which guarantees the technical competencies and operational commitment required to host backup repositories and disaster recovery replicas in production.

  • check_circle S3 storage with Object Lock: repositories backed by S3 storage with native immutability for anti-ransomware protection.
  • check_circle Tier III+ data centre in Madrid: own data centre with power redundancy, N+1 cooling and multi-carrier connectivity. Data sovereignty in Spain.
  • check_circle End-to-end encryption: TLS in transit, AES-256 encryption at rest, option for tenant-side key encryption.
  • check_circle Specialised support: Veeam-certified technical team for assistance with configuration, migration and incident resolution.
  • check_circle Complementary services: Veeam licences, managed offsite backup, DRaaS and Microsoft 365 backup.

Conclusion

Veeam Cloud Connect eliminates the complexity of offsite backup. What previously required VPNs, complex network configurations and a second data centre of your own is now solved in four steps from the Veeam console: choose a VCSP provider, add it as a Service Provider, create a Backup Copy Job and verify the first copy.

  • arrow_right VCC is a native Veeam B&R feature that sends offsite backups to a VCSP provider without VPN.
  • arrow_right Communication travels TLS-encrypted over port 6180, with an outbound-only model (no inbound ports).
  • arrow_right It supports WAN acceleration, end-to-end encryption and immutability for anti-ransomware protection.
  • arrow_right Replication mode extends VCC to DRaaS with failover in minutes.
  • arrow_right EasyDataHost is a Gold VCSP provider with S3 storage, immutability and a data centre in Madrid.

If you want to implement offsite backup with Veeam Cloud Connect or need guidance on your backup and disaster recovery strategy, contact our team to design the solution that best fits your requirements.

Veeam Cloud Connect Offsite Backup DRaaS VCSP
cloud_sync

Offsite backup with Veeam Cloud Connect

EasyDataHost: Gold VCSP provider, S3 storage with immutability, end-to-end encryption, Tier III+ data centre in Madrid. No VPN, no complexity.