Configuration and support of server infrastructure for 1C/BAF
Solution Architecture
Dedicated Server
Hypervisor: #Proxmox VE
Virtual Machines:
#Terminal Server (#Windows Server)
RDP access for users
Centralized work with 1C
1C / BAS Server
#1C Server
#1C Web
#SQL Server
Web server (IIS)
Separate VM for Web publishing
#HTTPS access
isolation from internal services
VPN Server
#OpenVPN / #WireGuard
Two-factor authentication (2FA)
Security:
- Windows Defender enabled
- AppLocker configured to restrict the launch of unwanted software
- HTTPS for web access
- VPN access to internal resources
- Role isolation between virtual machines
Backup and Recovery:
- Snapshots and VM backups on #Hetzner #StorageBox
- Separate backups:
* 1C databases
* document archives
- Backup storage on a separate StorageBox
- Ability to restore to a specific point in time (point-in-time restore)
Dedicated Server
Hypervisor: #Proxmox VE
Virtual Machines:
#Terminal Server (#Windows Server)
RDP access for users
Centralized work with 1C
1C / BAS Server
#1C Server
#1C Web
#SQL Server
Web server (IIS)
Separate VM for Web publishing
#HTTPS access
isolation from internal services
VPN Server
#OpenVPN / #WireGuard
Two-factor authentication (2FA)
Security:
- Windows Defender enabled
- AppLocker configured to restrict the launch of unwanted software
- HTTPS for web access
- VPN access to internal resources
- Role isolation between virtual machines
Backup and Recovery:
- Snapshots and VM backups on #Hetzner #StorageBox
- Separate backups:
* 1C databases
* document archives
- Backup storage on a separate StorageBox
- Ability to restore to a specific point in time (point-in-time restore)