Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Backup » OOTBI Security Best Practices: Enable Honeypot on Object First
  • understanding azure active directory and enterprise mobility security ems 16 638
    Methods for Integrating Azure Active Directory with on-Premise Active Directory AWS/Azure/OpenShift
  • Veeam Zero Trust Data Resilience
    Demystifying Zero Trust with Veeam: Design your Architecture Backup
  • Featured image Clearing cache
    How to clear cache in Windows 11 Windows
  • check and assign privileges to a MySQL User
    How to check and assign privileges to a MySQL User Oracle/MSSQL/MySQL
  • extend proxmox local container instance
    How to extend Proxmox Local Container Storage Virtualization
  • azure active director
    AD Connect Error: The Synchronisation service scheduler is currently synchronization and the configuration change cannot be made at this time AWS/Azure/OpenShift
  • maxresdefault 2 5
    Why am I unable to ping the Public IP Address of an EC2 instance AWS/Azure/OpenShift
  • chamedk8s featured
    Install CNF Certified Kubernetes in AWS AWS/Azure/OpenShift

OOTBI Security Best Practices: Enable Honeypot on Object First

Posted on 28/10/202511/11/2025 Christian By Christian No Comments on OOTBI Security Best Practices: Enable Honeypot on Object First
Object First Honeypot OOTBI

In this guide, we shall discuss “OOTBI Security Best Practices: Enable Honeypot on Object First”. To use Honeypot, a new feature available in OOTBI 1.7. You will have to ensure that you have upgraded to this version. See the release Notes, and you will be redirected to the Request form. Please, see how to Configure Object First OOTBI Appliance, and how to update Object First OOTBI Cluster.

Object First Support is exceptional. Their responsiveness and efficiency in addressing issues are second to none. If you require immediate assistance or approval. Reaching out to their support team is highly recommended. See Understanding User Roles & Access Control in Object First OOTBI.

According to Object First, customers running OOTBI versions earlier than 1.5.55.10660 should complete the update using the intermediate patch (ONLY for offline updates and if the customer hasn’t installed version 1.5.55.10660).

  • Update Ootbi to version 1.5.54.10596
  • Update Ootbi to version 1.7.79.12311

Also, see Object First OOTBI Appliance Unboxing and Quick Setup, how to integrate Object First OOTBI Appliance with VBR, and how to download and update Synology DiskStation NAS to DSM 7.3.

Early detection of Threats Targeting VBR with Object First

Object First has introduced a significant enhancement in version 1.7: the Honeypot feature. This feature enables the deployment of a decoy Veeam Backup & Replication (VBR) environment with just a few clicks. This serves as an early-warning system to detect potential cyber threats targeting your backup infrastructure. Below are some Key Benefits:

  • Seamless Deployment: Activate the Honeypot feature with minimal configuration, integrating effortlessly into your existing setup.
  • Early Threat Detection: The decoy environment attracts malicious actors, allowing for early identification of suspicious activities before they impact your production systems.
  • Real-Time Alerts: Upon detecting any interaction with the Honeypot. Immediate alerts are sent through your preferred communication channels. Thereby, enabling swift response.
  • Enhanced Security Posture: By isolating the Honeypot within a securely segmented part of the Ootbi appliance, the feature acts as a tripwire without increasing the attack surface.

This addition underscores Object First’s commitment to providing secure, simple, and powerful backup solutions optimized specifically for Veeam users.

Note: The Honeypot feature is available at no additional cost to existing Ootbi customers using version 1.7.

Please, see how to resolve “Unknown Error occurred when installing Veeam Software Appliance“, and how to Resize or Expand Proxmox Hard Drive.

Perform Offline Upgrade of Object First (OOTBI)

Therefore, this section discusses how to perform an office upgrade of OOTBI to v1.7 as this is not made to all customers as of yet. To do this, logon to the Object First Web UI.

Login to Objectfirst

These steps are similar to how to perform Offline and Online Update for Object First Out-of-the-Box Cluster. On the release note as attached in the first paragraph, click on Download Offline Bundle.

Offline bundle

In the Request Your Offline Bundle, populate the form with your information. If you want the approval with the speed of light, contact Object First Support.

Request bundle

As you can see, we have successfully submitted the form.

Donwload link sent

Here is a guide on Troubleshooting WinRM and Kerberos Delegation for WAC, and how to Setup Windows Admin Center Modern Gateway for Single Sign-On.

Upload Offline Bundle

The prerequisite is to ensure that you are running Object First OOTBI (1.5.54.10596). As you can see below, we are already above that and on v1.6. To perform the update, click on “Upload Offline Bundle”.

Offline cluster update

Upload is in progress

uploading

Shortly, you will be prompted to install as shown below.

Install updates

Cluster installation is on progress

installing v1.7

As shown below, the cluster update has completed. Please, reboot the cluster.

reboot cluster

Please, see how to add Synology NFS Storage to Proxmox VE for VMs and Backups, and how to setup Veeam Software Appliance v13.

Enable Honeypot on OOTBI

To enable Honeypot as discussed above, it requires only a few clicks. Navigate to the Settings and then click on the Security tab and select Honeypot.

Enable Honeypot

I am fine using DHCP. You can set the IP statically if you want. Do not forget to save when complete.

Enable DHCP

Changes are applying

Applying changes

As you can see below, the honeypot status is heathy and running. Here, you can also restart the Honeypot.

OOTBI Honeypot
Mimics Veeam Backup & Replication and remote management service and some credits to Marco Escoba who birthed the Honeypot feature (A veeam-decoy project)

Please, see What is taking up by Synology NAS Volume Space, and how to Patch Veeam Backup and replication 12.3.2.3617 to 12.3.2.4165.

OOTBI House Keeping: Enable 2FA for Object first

In this new version of OOTBI 1.7, security and management have been enhanced. Password policies now enforce a minimum length of 15 characters, prevent reuse of the last five passwords, and automatically log users out of management interfaces following a password reset.

Also, if you have not enabled 2FA, enabling Two-Factor Authentication (2FA) for your Object First OOTBI appliance is highly recommended for several critical security reason.

Passwords alone can be compromised through phishing, brute-force attacks, or credential leaks. 2FA adds an additional layer: even if someone steals your password, they cannot log in without the second factor (e.g., a code from an authenticator app etc).

Since OOTBI stores immutable backups and sensitive organizational data. Unauthorized access could lead to deletion, ransomware encryption, or data exfiltration. 2FA helps ensure that only authorized personnel can access the appliance. Please, see how to Set Two-Factor Authentication for SSH in Linux.

Lastly, Many regulations (GDPR, ISO 27001, SOC 2, etc.) recommend or require multi-factor authentication for critical systems. Enabling 2FA demonstrates adherence to cybersecurity best practices and audit readiness. You can also do this by clicking on enable 2FA from the dashboard as shown below.

enable 2fa

Enter the 6 digit code after scanning the QR Code or manually entering the security code. When this is done, click on Enable as shown below.

security code

2FA has now being enabled.

download recovery code

If you wish to disable it, you can from this window below. But why would you?

disable recovery code

Please, see how to update Veeam Backup and Replication [VBR], and how to Configure Active Directory-Based Activation (ADBA) for Windows.

Enable Email Notification

Enabling Email Notification on your Object First OOTBI appliance (or any backup appliance) is important for real-time visibility and proactive management. Instant alerts allow you to resolve problems before they impact production systems or cause data loss.

To do this, under General, ensure your email address is entered. Else, the email notification field will be greyed out.

Set email

Now, click “Enable Email Notification” and select your preferred event severity level. You can also send a test email to verify that notifications are functioning correctly.

Email notifcation
Enabling email notifications ensures you are always informed about backup status, security events, and system health, enabling proactive management and minimizing the risk of data loss or downtime.

lso, see what is the difference between iDRAC, IPMI, and ILO, and how to Generate CSR and Request a Certificate from Herica CA. Here is how to configure WebLAPS to manage Microsoft LAPS.

Disable SSH Access

If for whatsoever reason you enabled SSH, please disable it. SSH provides remote shell access, which can be exploited if credentials are compromised or vulnerabilities exist.

Disabling SSH reduces potential entry points and ensures that only authorized management interfaces are used, lowering the risk of accidental or malicious changes.

This approach aligns with security best practices and regulatory frameworks (e.g., ISO 27001, NIST, SOC 2) that recommend limiting administrative access to critical systems.

Additionally, OOTBI offers web-based management interfaces and APIs for configuration and monitoring, ensuring that all operations occur through controlled, auditable channels

enable ssh

If you have 2FA enabled, you will be prompted to enter it.

Enter 2FA

As you can see, SSH has been disabled

SSH Disabled

Disable IPMI

While OOTBI ensures software-level immutability, IPMI can be a backdoor for attackers to physically disrupt, reconfigure, or compromise storage at the hardware level. Securing IPMI access is critical to maintaining true immutability and preventing attacks that could undermine data integrity. To learn more, see “Best Storage for Veeam: Comparing OOTBI by Object First to VHR“

You can unplug the IPMI network cable from the appliance to disable remote IPMI access. This alone does not change the warning message in this image.

To disable IPMI, please login to the ObjectFirst Management Console, click on Settings and select Network. Under the “Network interfaces”, please select the checkbox “Disable” and click on “Apply Changes”.

Disable IPMI
Disable IPMI

I hope you found this article on OOTBI Security Best Practices: Enable Honeypot on Object First very useful. Please, feel free to leave a comment below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Backup, Storage Tags:Disable IPMI, Disable SSH, Enable Email Notification, Honeypot, Object First Ootbi, Object Firt OOTBI offline and online cluster update, Offline OOTBI Update, Ootbi, OOTBI Update

Post navigation

Previous Post: Unknown Error occurred when installing Veeam Software Appliance
Next Post: Fix Authentication failed: Invalid credential after installing VSA

Related Posts

  • Protecting DS923 NAS
    DSM Security: How to Protect Synology DS923+ NAS Reviews
  • screenshot 2020 04 02 at 23.27.20
    Cloud Protection Manager: N2WS Veeam CPM Guide Backup
  • Snapshot replication fix on synology
    Fix Task failed to perform Scheduled Snapshot Replication Storage
  • veeaamAgent1
    Veeam Agent Vulnerability: Fix Veeam Agent vulnerability for Microsoft Windows  Backup
  • veeam backup for aws Processing postgres rds failed
    Veeam backup for aws Processing postgres rds failed: No valid combination of the network settings was found for the worker configuration AWS/Azure/OpenShift
  • Entire VM restore
    Restore VM to Original location using Veeam Entire VM restore Backup

More Related Articles

Protecting DS923 NAS DSM Security: How to Protect Synology DS923+ NAS Reviews
screenshot 2020 04 02 at 23.27.20 Cloud Protection Manager: N2WS Veeam CPM Guide Backup
Snapshot replication fix on synology Fix Task failed to perform Scheduled Snapshot Replication Storage
veeaamAgent1 Veeam Agent Vulnerability: Fix Veeam Agent vulnerability for Microsoft Windows  Backup
veeam backup for aws Processing postgres rds failed Veeam backup for aws Processing postgres rds failed: No valid combination of the network settings was found for the worker configuration AWS/Azure/OpenShift
Entire VM restore Restore VM to Original location using Veeam Entire VM restore Backup

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a
 
  • understanding azure active directory and enterprise mobility security ems 16 638
    Methods for Integrating Azure Active Directory with on-Premise Active Directory AWS/Azure/OpenShift
  • Veeam Zero Trust Data Resilience
    Demystifying Zero Trust with Veeam: Design your Architecture Backup
  • Featured image Clearing cache
    How to clear cache in Windows 11 Windows
  • check and assign privileges to a MySQL User
    How to check and assign privileges to a MySQL User Oracle/MSSQL/MySQL
  • extend proxmox local container instance
    How to extend Proxmox Local Container Storage Virtualization
  • azure active director
    AD Connect Error: The Synchronisation service scheduler is currently synchronization and the configuration change cannot be made at this time AWS/Azure/OpenShift
  • maxresdefault 2 5
    Why am I unable to ping the Public IP Address of an EC2 instance AWS/Azure/OpenShift
  • chamedk8s featured
    Install CNF Certified Kubernetes in AWS AWS/Azure/OpenShift

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,841 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.