Syneto Syneto
Solution Brief · 2026

Turning your NAS or SAN into a backup vault.

SynetoOS speaks iSCSI. Point it at the storage you already own, and that spare capacity becomes another independent home for your Recovery Points — no new appliance, no second backup product.

Companies
5,000+
Partners
250+
CSAT
98%
Data lost
0 bytes
SYNETO  |  SOLUTION-BRIEF-ISCSI-VAULTING  |  SOLUTION BRIEF v1.0 EN-IT-ES
Challenge02
Chapter 01 · Challenge

One copy is a single point of failure.

Data rarely disappears in one dramatic event. It disappears because someone with stolen credentials spent a fortnight inside the network before encrypting anything, or because a migration script was pointed at the wrong datastore on a Friday afternoon. The two causes look nothing alike and they have the same defence: more than one copy, far enough apart that whatever reaches the first cannot reach the rest. The industry shorthand is 3-2-1 — three copies of your data, on two kinds of storage, one of them somewhere else — and it has outlived twenty years of technology churn.

For most of those twenty years the answer has been a backup product: an agent on every machine, a nightly window, and a separate server holding the results. It works, and millions of businesses still run on it. But it was designed when the threat was a failed disk and the clock was measured in overnight hours — and both of those assumptions have since expired.

Protection built in, not bolted on

SynetoOS starts from a different premise: protection is not a product bolted alongside the storage and the hypervisor, it is the same system. Snapshots are a property of the file system, replication moves them at block level, and recovery happens in the console your team already works in. Three consequences follow — and they land precisely where traditional backup is weakest.

Recovery speed hours of restore before a VM runs boot straight from a Recovery Point
Immutability the same credentials can delete it immutable Recovery Points, plus RPH
Operational load a second system to run and rehearse one engine, one console, SLA policies

So the copies are being made — on schedule, and beyond the reach of anyone who wants them gone. But look at where those Recovery Points physically sit. Perhaps the same pool as the production data they exist to protect. Perhaps the appliance a few rack units below — the one already running production for the other half of your VMs. Either way: same rack, same room, same power feed. One power event, one burst pipe above the rack, one bad afternoon in that room — and every copy you hold is on the wrong side of it.

Two appliances are still one kind of storage

A pair of appliances replicating both ways is a real improvement: it survives a failed pool, a dead controller, an entire chassis. But the middle number in 3-2-1 asks for two different kinds of storage, and two identical appliances are one kind — same platform, same firmware, same administrative boundary. Whatever a bad update or a stolen credential does to one, it can do to its twin. A third-party NAS or SAN breaks that symmetry, with its own controllers and its own firmware — and it is often already racked a few units away.

syneto.euPage 2 of 5
The Syneto approach03
Chapter 02 · The Syneto approach

A vault on hardware you already own.

What iSCSI changes

SynetoOS can act as an iSCSI initiator, and that single capability rewrites the arithmetic. The appliance logs in to a target on your NAS or SAN, picks up the LUN it exports as a local block device, and builds a native SyFS pool on it — the same file system, the same snapshots and the same unalterable Recovery Points as any pool on internal drives. From there it is simply a destination: point an SLA policy at it, and copies start landing on hardware that fails independently of every appliance you own.

Production pool
VMs on internal drives
SLA policy
block-level, compressed
SyFS vault pool
immutable Recovery Points
Your NAS or SAN
iSCSI LUN, separate hardware
The protection engine you already run, with one more destination: a SyFS pool built on iSCSI capacity, on hardware that fails on its own terms.

The vault pool is a SyFS pool like any other, and that is the whole point. Replication into it is block-level and compressed, driven by the same SLA policies you already maintain — the same high-frequency RPO, the same fast RTO, restores from the same console using the procedure your team already rehearses. It sits alongside the replication you run today rather than replacing it: no second backup product, no second console, nothing new to learn. What changes is only where the Recovery Points come to rest — a different chassis, different controllers, a different power supply, on hardware that fails on its own terms instead of alongside your appliances.

The economics are just as plain. No new appliance, no rack space, no extra vendor to onboard — only the terabytes already sitting in the rack. Retention grows there instead of competing with the pools your VMs run on, which counts for most where two appliances already carry each other's Recovery Points and every gigabyte of history is charged against production capacity. Day to day the pool looks after itself: it re-imports automatically after a reboot, and targets, LUNs, pool health and session problems all surface in the console you already watch. Those pools can carry running VMs as well, where the storage network is solid enough for it.

What you need to start

A NAS or SAN that speaks iSCSI — any array exporting a LUN over your IP network qualifies. No Syneto hardware required on the far end.
Spare capacity on it — sized for the Recovery Points you intend to keep, after compression has done its work.
A solid storage network — ideally a dedicated segment, with enough headroom that replication traffic and production never have to compete.
A few minutes in the console — Storage → iSCSI: one target to add, one pool to create, and an SLA policy pointed at it.
syneto.euPage 3 of 5
The Syneto approach04
Chapter 02 · The Syneto approach

Hardening the vault.

Separate hardware is the foundation, not the finished job. An attacker who already owns your network will go looking for the Recovery Points next, so the value of a vault comes down to how few ways there are to reach it. Almost everything below is configuration rather than purchase — and the parts that happen on the SynetoOS side are console work, not a weekend of CLI.

A dedicated NIC and VLAN — give the storage path its own interface and its own VLAN, so the backup target simply is not reachable from the general network. SynetoOS's visual network management makes the vSwitch, VLAN and port group a few clicks; in the ideal case the array ends up doing nothing but serving SynetoOS.
Target ACLs on the array — allowlist the appliance's IQN and its initiator IP, not one or the other. A rogue initiator that learns the target name still gets turned away at the door.
CHAP — and mutual CHAP — authenticate the initiator to the target, then the target back to the initiator. Neither side ends up talking to an impostor.
Switch off every protocol you are not using — SMB, NFS, AFP, UPnP, SSH and the rest. Each one left running on the array is attack surface nobody is watching; a vault needs exactly one service.
MFA and continuous authentication on SynetoOS — MFA at the login prompt, and continuous authentication re-verifying identity throughout the session rather than only at the door. A session someone else has taken over cannot quietly start destroying Recovery Points.
Recovery Point Hold on what you cannot lose — pin the Recovery Points that matter most and they cannot be deleted, altered or aged out for a fixed period, administrators included.
For partners

Almost every installed base has this gap — one appliance keeping its own Recovery Points, or a pair of appliances protecting each other from the same room — and a good number of those customers already own the array that closes it. That makes iSCSI vaulting an unusually short conversation: no new hardware to quote, no incumbent product to displace, and a resilience improvement the customer can see on the dashboard the same afternoon.

Syneto backs you through it — hands-on help with proof-of-concepts, our customer success team alongside you during the assessment, and post-sales support from native speakers of your language.

syneto.euPage 4 of 5

Give your backups a home of their own.

Join 5,000+ European companies that trust Syneto.

Italy HQ
Via Cefalonia 70
Brescia 25124
Romania
Bastion Office
Timișoara 300054
Spain
Calle Antonio Arias 6
Madrid 28009
Web
syneto.eu
syneto.eu [email protected] +39 051 095 3000

© 2026 Syneto SpA. All rights reserved. "Syneto", the Syneto logo, "SynetoOS", "Syneto CENTRAL", "Hyperion", "HYPER Core", "HYPER Edge", and "HYPER Echo" are trademarks of Syneto SpA. All other trademarks are the property of their respective owners.

SYNETO SPA · VAT IT03460170982 · ISO 9001 · ISO/IEC 27001