BLOG · COMPARISON ·

Veeam replication vs backup: which job protects what, from backup copy to CDP and Cloud Connect

Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software

IN BRIEF
  • A Veeam backup job compresses and deduplicates VM data into restore points in a backup repository; a backup copy job puts the same backup data in a second location and, in immediate copy mode, copies new data as soon as it appears
  • A replication job keeps an exact copy of the VM in native vSphere format on another host, in a ready-to-start state; failover brings it into service at its latest state or at any retained restore point
  • Replica restore points are snapshots in the replica chain, and vSphere allows 32 snapshots in a chain; Veeam’s version 13 guide limits a VM replica to 28 restore points, so a replica updated every 15 minutes reaches back about 7 hours at most, while GFS retention keeps backups for months or years
  • CDP replicates through Veeam’s I/O filter, which uses the vSphere APIs for I/O filtering, without snapshots and with an RPO set in seconds or minutes; it needs the filter on the source and target clusters and CDP proxies on both sides, and version 13 documents Universal CDP for individual server workloads
  • Veeam Cloud Connect replication sends replicas to a provider’s cloud host through a cloud gateway over a TLS connection; the tenant fails over single VMs with network extension appliances, or the whole site with a cloud failover plan

Eurokommerz × Vixen.UNO: Cloud Disaster Recovery  Talk to an expert →

What Veeam backup, backup copy, replication and CDP jobs produce

A Veeam backup job writes compressed and deduplicated restore points to a backup repository for restores, while a replication job keeps a ready-to-start copy of the VM in native vSphere format on another host for failover. Backup copy jobs put the same backup data in a second location, and continuous data protection (CDP) replicates writes as they happen, with an RPO set in seconds or minutes. Backups take you back to a point before deletion, corruption or ransomware; replicas bring systems back quickly after a host, a storage system or a site is lost.

Veeam Cloud Connect sends backups and replicas to a service provider. Job names and behaviour here follow the Veeam Help Center for Veeam Backup & Replication 13.1 with VMware vSphere; 13.1 has been available since 29 July 2026, and the version 12 guides are now marked as archived.

JOB TYPERPO COMES FROMBACK IN SERVICE BYPROTECTS AGAINSTDOES NOT PROTECT
Backup jobthe job schedulea full restore, or Instant Recovery at limited performancedeletion, corruption and ransomware, within retentionsite loss if the repository is on site; an attacker who can reach the repository
Backup copy jobthe source job (immediate copy) or the copy schedule (periodic copy)a restore from the second repositoryloss of the first repository or the sitea long restore
Replication jobthe job schedule, up to continuousfailover to the replicaloss of a host, storage or sitedamage older than the oldest restore point
CDP policythe RPO setting, seconds or minutesfailover to the replicathe same, with seconds of data lostdamage older than the retained points
Cloud Connect replicationthe tenant’s job or CDP policypartial or full site failoversite loss, without a second data centre of your owndamage older than the oldest restore point
Cloud Connect backupthe tenant’s backup or copy joba restore from the cloud repositoryloss of everything on your premisesthe lack of hosts to restore onto

Veeam Help Center for Veeam Backup & Replication 13.1 (Quick Start Guide, User Guide, Cloud Connect Guide, build 13.1.1.18), read on 6 October 2026. The last two columns are our reading.

How a Veeam backup job stores and restores data

A backup job reads VM data from the source storage, compresses and deduplicates it and “writes data to the backup repository in Veeam proprietary format”: a full backup file (.VBK), incremental files (.VIB or .VRB) with the changed blocks, and a metadata file (.VBM). Each session adds a restore point, so the RPO is the interval between sessions and retention sets how far back you can go. Long-term (GFS) retention flags selected backup files to keep them “for weeks, months and even years”.

A full VM restore copies the data back to production storage and takes as long as moving that many bytes; our article on why backup is not disaster recovery works through that arithmetic. Instant Recovery instead starts the workload directly from the backup file, which Veeam offers for recovering “in a matter of minutes but with limited performance”.

What a Veeam backup copy job adds

In Veeam’s words, backup copy “allows you to create several instances of the same backup data in different locations”, and the Quick Start Guide uses it for the off-site backup of the 3-2-1 rule, kept “in the cloud or in a remote site”. In immediate copy mode the job “copies new data as soon as it appears on the source repository”, so the copy trails the source job by the transfer time. The target can be a repository at a second site or a provider’s cloud repository through Veeam Cloud Connect.

A backup copy adds distance and its own retention. After a site loss, the newest restore point you can reach is the newest one copied, and recovery takes as long as a restore from wherever the copy sits. Our article on the 3-2-1-1-0 backup rule covers which copies count towards it.

Veeam replication jobs, the replica on the target host and failover

A replication job “creates the exact copy of the VM in the native VMware vSphere format on a host” and keeps it synchronised with the original. The first run copies the whole VM, later runs copy “only those data blocks that have changed”, and each run adds a restore point. The replica stays on the target in a ready-to-start state, and the Quick Start Guide recommends replication “for VMs running most critical applications”. Runs can be scheduled daily, monthly or periodically, or continuously “in a non-stop manner”.

The job registers replicas on a chosen host or cluster and datastore, and the target site needs spare compute and networks to run them. Replica seeding and mapping start the first run from data already at the DR site, so Veeam does not transfer all VM data “across the sites during the first session”.

Failover puts the replica into service at its latest state or at “any of its restore points”, and Veeam calls it “an intermediate step that needs to be finalized” by undoing it, failing back or making it permanent. Our guide to failover and failback steps covers the sequence on the day.

Veeam replica restore points and how far back they reach

Each replica restore point is a snapshot; when Veeam rolls a cloud replica back for failover, “it reverts the VM replica to the necessary snapshot in the replica chain”. The job keeps the number set in Restore points to keep and removes the earliest beyond it. Veeam’s user guide for version 13 states that “Due to VMware restrictions on the number of VM snapshots, the maximum number of restore points for VM replicas is limited to 28”. Broadcom’s KB 318825, which covers ESX 9.x, states that “A maximum of 32 snapshots are supported in a chain”. A replica’s history is therefore its interval multiplied by the points kept: at 28 points, about 7 hours at a 15-minute interval and about 28 hours at an hourly one. These are upper bounds, and the arithmetic is ours.

A failed host, a lost storage array or, with an off-site replica, a fire in the server room leaves the replica untouched, and failover brings the VM back in the time it takes to start and check it. A deleted table, a database damaged by a faulty update or files encrypted by ransomware reach the replica at the next run like any other change. Recovering from them needs a restore point from before the damage, and once the last clean point has left the replica chain, only a backup holds one.

Veeam notes that “Disaster recovery plans often require that you back up and replicate the same VM”; its replica from backup option creates the replica from backup files instead of reading production twice. In our reading, this ties the replica’s RPO to the backup schedule.

Continuous data protection (CDP) in Veeam

Veeam positions CDP for “mission-critical VMware virtual machines when data loss for seconds or minutes is unacceptable”. Instead of snapshots it uses the vSphere APIs for I/O filtering (VAIO). An I/O filter on the source cluster reads I/O operations in transit and passes them to a source CDP proxy, which prepares data for short-term restore points, compresses it and, if network traffic rules enable it, encrypts it for the target proxy. The policy sets the RPO “in seconds or minutes”, which is how often a short-term restore point is created; the minimum is 2 seconds, and Veeam puts the optimal RPO at no less than 15 seconds. Short-term points are kept “for the number of hours or minutes specified in CDP policy settings”, and long-term restore points have a separate retention scheme.

CDP needs more infrastructure than scheduled replication: the I/O filter on the source cluster and on the target cluster that holds the replicas, CDP proxies on each side and, in our reading, a link that carries the writes as they happen. The 13.1 release notes add that the I/O filter “cannot be attached to VMs with snapshots”. Version 13 also documents Universal CDP, which protects individual server workloads through a CDP component on each machine and replicates them to vSphere; per the 13.1 release notes it currently does not support planned failover, failback to the original location or replica seeding to a Cloud Connect provider.

Corrupted data reaches a CDP replica within seconds too, so recovery depends on a retained restore point from before the damage. Our disaster recovery page describes replication from a 15-minute interval through Veeam Cloud Connect, not CDP.

Veeam Cloud Connect replication: tenant, provider and failover

Veeam Cloud Connect lets service providers “offer cloud repository as a service and disaster recovery as a service” to customers that Veeam calls tenants. The provider runs a Veeam backup server and cloud gateways and allocates compute, storage and network resources as a hardware plan, or through VMware Cloud Director. The tenant adds the provider in its own Veeam console and sees a cloud host that serves as “a regular target host for off-site replication”. When a job starts, the provider’s backup server “provides a TLS certificate and establishes a secure connection”, and VM data travels through a cloud gateway to the cloud host.

ASPECTPARTIAL FAILOVERFULL SITE FAILOVER
Used whenone or several VMs fail while the rest of the site and the Veeam infrastructure keep runningthe whole production site is unavailable
Started bythe tenant, in its own consolea cloud failover plan created in advance, started by the tenant or, if its backup server is down, by the provider
Networkingnetwork extension appliances on both sides, a VPN tunnel through the cloud gateway, proxy ARPthe provider’s appliance as gateway, public IP addresses for replicas
Limitsstatic IP addresses only; replication of the original VM on holdat most 10 VMs started at once, in the plan’s order and delays

Veeam Cloud Connect Guide for version 13: Partial Site Failover, Full Site Failover, Cloud Failover Plan and Network Extension Appliance pages (updated November 2023 to November 2025).

Both CDP variants also work with Cloud Connect; there, CDP for vSphere replicates individual VMs, not vApps, and VMware Cloud Director is not supported as the source. With Cloud Connect backup, tenants back up or copy backups to a cloud repository partitioned per tenant, which puts a copy outside the company but provides no hosts to run it on.

Our disaster recovery service replicates virtual machines from a 15-minute interval via Veeam Cloud Connect to a recovery site in Baltneta’s Tier-3 data centres in Lithuania. Tell us which VMs you would replicate first and which Veeam jobs protect them today.

Choosing the Veeam job for each tier of systems

Most estates need several of these jobs, assigned by tier. Our guide on choosing RPO and RTO for each system covers the tiering; these steps turn tiers into Veeam jobs.

  1. Give every system a backup job and a backup copy job to a second location; only these reach back further than a replica chain.
  2. Add replication where the RTO is shorter than a full restore would take, at an interval that meets the RPO.
  3. Keep enough replica restore points to cover the time it takes to notice corruption, and plan to restore from backup beyond that.
  4. Reserve CDP for VMs where seconds of lost writes cost more than the filter, the proxies and the bandwidth it needs.
  5. Decide where replicas run, a second site of your own or a provider’s cloud host, and put the start order in a failover plan.
  6. Test failover in an isolated environment and time it against the RTO, as our article on disaster recovery testing describes.

In our DR strategy design we define, together with you, the critical systems, the target RPO and RTO for each tier and the disaster scenarios you protect against. Describe your current Veeam jobs in the form below, with their schedules and restore points.

What we do

Under our disaster recovery service, our engineering partner Vixen.UNO sets up virtual-machine replication from a 15-minute interval via Veeam Cloud Connect, over an encrypted TLS/SSL channel, to a recovery site in Baltneta’s Tier-3 data centres in Lithuania (ISO 27001, PCI DSS). You manage replication from your existing Veeam console, or we manage it entirely on our side; the standard targets are an RPO from 15 minutes and an RTO of 1 to 2 hours for critical systems, and your targets per tier are fixed in the SLA. Scheduled failover tests run in an isolated environment, with a report after each on what came up, how fast and what to fix. For the backup side, our cyber resilience service covers Veeam-based backup with regular test restores to verify backup integrity. Site, replication, tests and support come on one EU contract and invoice from Eurokommerz.

FAQ

What is the difference between Veeam replication and backup?
A backup job writes compressed and deduplicated restore points to a backup repository, and you restore from them; a replication job keeps a copy of the VM in native vSphere format on another host, ready to start, and you fail over to it. Backups can keep restore points for months or years and take you back to before deletion, corruption or ransomware. Replicas keep a short chain of restore points and bring systems back quickly after the loss of a host, storage or a site.
What does a Veeam backup copy job do?
It copies backup data from a backup repository to a second repository, on site, at another site or at a service provider through Veeam Cloud Connect, so that one copy survives the loss of the first repository or the site. In immediate copy mode it copies new data as soon as it appears on the source repository. Restoring from the copy is still a restore, so it does not shorten the recovery time.
How many restore points can a Veeam replica keep?
Veeam’s version 13 user guide gives 28 as the maximum number of restore points for VM replicas, because of VMware restrictions on the number of VM snapshots; the number kept is set per replication job in the Restore points to keep field, and the earliest point is removed when it is exceeded. Each restore point is a snapshot in the replica chain, and Broadcom’s KB 318825 gives a maximum of 32 snapshots in a vSphere chain. At 28 points, a replica updated every 15 minutes reaches back about 7 hours, which is why replicas do not replace backups.
What is Veeam CDP and what RPO does it give?
Continuous data protection replicates vSphere VMs through the vSphere APIs for I/O filtering instead of snapshots, with an RPO set in seconds or minutes in the CDP policy, from a minimum of 2 seconds. It needs the I/O filter on the source and target clusters and CDP proxies on both sides, and keeps short-term restore points for a set number of hours or minutes alongside long-term ones. Version 13 also documents Universal CDP for individual server workloads, which per the 13.1 release notes does not yet support planned failover or failback to the original location.
How does Veeam Cloud Connect replication work?
A service provider allocates compute, storage and network resources as a hardware plan, which the tenant sees as a cloud host and uses as an ordinary off-site replication target from its own Veeam console. Data travels through the provider’s cloud gateway over a connection secured with the provider’s TLS certificate. After a disaster the tenant fails over single VMs with partial site failover, or the whole site with a cloud failover plan that starts at most 10 VMs at a time.
Is a Veeam replica a backup?
No. A replica receives deleted, corrupted or encrypted data at the next run like any other change and keeps only a short chain of snapshot restore points, so once the damage is older than the chain, the replica holds no clean copy. Use replicas for fast recovery after the loss of a host or site, and backups with backup copies for going back to a point before the damage.

Send us your VM list by tier, your current Veeam jobs with their schedules and restore points kept, and the RPO and RTO each tier needs. We reply within one business day with a date for a first call, where we work through your critical systems, current backup and targets, and you leave with two or three possible DR scenarios. The first call is free of charge.

Talk to an expert
Talk to an expert

We reply within one business day

By sending this form you agree that we process your details to answer your enquiry – see our privacy policy.

request@eurokommerz.at
Jordangasse 7, 1010 Vienna