
ON-PREMISES VMWARE DR COMPARISON
A Consult Circle comparison of the main disaster recovery options for VMware estates, by architecture and by the recovery outcomes each is built to deliver rather than by feature count.
Subscription licensing has prompted a great many organisations to look at their disaster recovery platform for the first time in years. That is a healthy exercise and it frequently goes wrong in the same way: the comparison is run on replication features, the products all look broadly similar, and the decision gets made on price.
Replication is the easy part. Every serious product in this space can copy blocks between two sites reliably. What differs, and what determines whether you recover successfully, is what happens around the replication: how recovery is orchestrated, how it is tested without disrupting production, what the recovery point actually is under load, and what the product does when the problem is malicious rather than accidental.
This comparison covers VMware Live Site Recovery, HPE Zerto, Veeam, and the wider field, by architecture and by fit. It is deliberately not a scorecard. Each of these products is genuinely good at the problem it was built for, and the useful question is which problem you actually have.
What this comparison covers
- Why architecture predicts fit better than feature lists
- VMware Live Site Recovery: what it is built for
- HPE Zerto: continuous data protection and journalling
- Veeam: backup-first with DR capability
- The wider field, including array-based and cloud options
- Comparison across the dimensions that actually matter
- Which fits which situation
- How to run an evaluation that produces a defensible answer
Architecture Predicts Fit
Three architectural questions separate these products more usefully than any capability list.
- Where does replication happen? In the storage array, in the hypervisor, or in a software layer inserted into the data path. This determines granularity, what hardware you need at both ends, and how low a recovery point you can achieve.
- Is replication continuous or periodic? Continuous data protection writes changes as they happen and can rewind to a point in time. Periodic replication moves changes on a schedule. The difference is recovery point measured in seconds against minutes, and it costs more in both bandwidth and storage.
- Is orchestration native or added? Some products were built around orchestrated recovery. Others replicate well and treat orchestration as a separate component, sometimes separately licensed. This is the difference most often discovered after purchase.
A fourth question increasingly matters: does the product address malicious data loss as well as infrastructure loss? Replication faithfully reproduces encryption. Products differ substantially in what they offer beyond that.
VMware Live Site Recovery
Formerly Site Recovery Manager, rebranded under the VMware Live Recovery family alongside VMware Live Cyber Recovery, the former Cloud Disaster Recovery. The background is covered in our complete guide to the transition.
Architecturally it is an extension to vCenter Server that plans, tests and runs the recovery of virtual machines. It does not perform replication itself. It orchestrates on top of array-based replication through storage replication adapters, host-based replication through vSphere Replication, Virtual Volumes replication, or a combination of all three in the same environment.
- Strongest at. Orchestrated, repeatable, testable recovery of a VMware estate to a second site you own. Recovery plans with dependency ordering, non-disruptive test failover into an isolated network, planned migration, and reprotect and failback.
- Replication flexibility. The ability to mix replication technologies within one environment is genuinely useful on estates where different services have different objectives and the storage is not uniform.
- Scale. Version 9.0 raised the maximum to 1500 virtual machines per protection group, with stretched storage support from 9.0 and Virtual Volumes support from 9.0.3.
- Weakest at. Anything outside vSphere. It is a VMware product for VMware workloads, and it does not attempt to be a backup product. Recovery point depends entirely on the replication technology beneath it.
- Ransomware. Site recovery replicates faithfully, including malicious change. The cyber recovery half of the family exists for that problem, and VCF 9.1 additionally introduced an on-premises clean room with network isolation.
HPE Zerto
Acquired by HPE in 2021, Zerto is a continuous data protection platform built for disaster recovery first, with backup capability added subsequently.
Architecturally it inserts itself into the hypervisor data path. A Zerto Virtual Manager coordinates, and a Virtual Replication Appliance on each host captures writes as they occur and ships them to the recovery site, where they are held in a journal. Protection is organised into Virtual Protection Groups, and the journal allows recovery to a point in time rather than only to the most recent state.
- Strongest at. Very low recovery point objectives, measured in seconds, without depending on array capability. The journal model also allows rewinding to a checkpoint before a problem occurred, which is valuable for both corruption and ransomware.
- Storage independence. Replication happens above the storage layer, which removes the need for matched arrays, storage replication adapters and the LUN-level considerations that come with array-based replication.
- Orchestration. Built in rather than added, with failover, testing and failback part of the core product.
- Weakest at. It is an additional software layer in the write path on every protected host, which needs designing for and consumes resource. Journal storage at the recovery site is a real capacity requirement that scales with retention.
- Backup. Present, and secondary to the DR capability by design and by history.
Veeam
Veeam approaches this from the opposite direction: a backup platform that has established itself in the DR market, rather than a DR product that added backup.
It offers replication alongside backup, plus a continuous data protection capability for lower recovery points, and orchestration through a separate Recovery Orchestrator component that provides runbooks, automated testing and documentation generation.
- Strongest at. Breadth. One platform covering backup, long-term retention, replication and DR, across multiple hypervisors and cloud targets. For organisations wanting fewer vendors and one operational model, this is a genuine advantage.
- Ransomware. The backup heritage shows here, with immutability options, scanning of backup data and recovery from clean points. Organisations whose primary concern is malicious data loss rather than site loss often find this the better fit.
- Recovery point range. Standard replication operates on a schedule, giving recovery points in minutes to hours. The continuous data protection capability targets much lower recovery points for the subset of workloads that need them.
- Weakest at. Orchestration is a separate product rather than intrinsic. Organisations that buy the backup and replication platform without the orchestrator find DR recovery more manual than expected, and that discovery usually happens during a test.
- Licensing. Model your actual estate carefully. Universal licensing changes have produced significant renewal movements for some organisations, and this is worth establishing in writing before committing.
The Wider Field
Several other options are worth knowing about, particularly if you already own one of them.
| Option | Approach | Typically fits |
|---|---|---|
| Dell RecoverPoint for VMs | Journal-based CDP using virtual appliances and a per-host splitter | Dell storage estates wanting low recovery points |
| Array-native replication alone | Storage replication without an orchestration layer | Small estates where recovery can be run manually |
| Commvault, Rubrik, Cohesity | Data protection platforms with recovery orchestration | Organisations consolidating backup and DR with a cyber recovery emphasis |
| Nakivo, Vinchin and similar | Backup and replication at lower cost | Smaller estates where budget dominates |
| Azure Site Recovery | Replication to public cloud | Organisations without a second data centre |
| DRaaS providers | Managed recovery capacity and service | Organisations without a second site or DR operations capability |
| VMware Live Cyber Recovery | Immutable snapshots with isolated cloud recovery environment | Ransomware recovery alongside conventional site recovery |
The last row is worth emphasising because it is complementary rather than competitive. Several organisations reviewing their DR platform actually have a gap in cyber recovery rather than in site recovery, and replacing a working site recovery product will not close it.
Comparison Across What Matters
| Dimension | VMware Live Site Recovery | HPE Zerto | Veeam |
|---|---|---|---|
| Origin | DR orchestration for vSphere | DR-first CDP platform | Backup platform with DR |
| Replication | Consumes array, host or vVols replication | Own hypervisor-level CDP | Own replication plus CDP option |
| Typical RPO | Depends on chosen replication | Seconds | Minutes to hours, seconds with CDP |
| Point-in-time rewind | Depends on replication and snapshots | Journal-based, native | From backups or CDP |
| Orchestration | Core of the product | Built in | Separate Recovery Orchestrator |
| Non-disruptive testing | Test failover to isolated network | Native test failover | Available, stronger with Orchestrator |
| Storage requirements | Matched arrays only if array-based | Storage agnostic | Storage agnostic |
| Hypervisor coverage | vSphere | Multiple | Multiple |
| Backup and retention | Not a backup product | Secondary capability | Core strength |
| Ransomware posture | Via Live Cyber Recovery or clean room | Journal rewind and detection | Immutability and clean recovery points |
Note what this table does not do: it does not declare a winner, because the right answer depends on which row your organisation weights most heavily. An organisation whose recovery point objective is fifteen minutes and whose real anxiety is ransomware should read this table completely differently from one that needs seconds and has a well-drilled second site.
Which Fits Which Situation
- A VMware-only estate with a second site and orchestration as the priority. VMware Live Site Recovery is the natural fit, particularly where storage is mixed and the ability to combine replication technologies is useful. Its testing model is its strongest argument.
- Recovery point objectives measured in seconds. Zerto, or another continuous data protection product. Periodic replication cannot reach those objectives regardless of orchestration quality.
- Backup and DR consolidation onto one platform. Veeam, with the orchestration component included rather than deferred. The saving from a single vendor is real; the orchestration gap if you skip that component is also real.
- Mixed hypervisor estate. Zerto or Veeam. VMware Live Site Recovery is a vSphere product.
- Ransomware as the primary concern. This is a different problem. Look at cyber recovery capability, immutability and isolated recovery environments rather than at site recovery products, and remember that replication reproduces malicious change faithfully.
- No second data centre. Cloud-based recovery or a DRaaS provider, rather than any of the above.
- Small estate, limited DR operations capability. Simplicity should outrank capability. An elegant product nobody exercises is worse than a simple one that gets tested quarterly.
Running an Evaluation That Produces a Defensible Answer
Most evaluations compare feature lists and produce a decision that cannot be defended six months later. This structure produces one that can.
- Recovery objectives established per service with the business before any product is considered
- Current achievable recovery time measured through an actual test, so the comparison has a baseline
- Protected scope defined, since products price and perform differently across full-estate and partial protection
- Ransomware requirement separated from site recovery requirement and assessed independently
- Orchestration requirement stated explicitly, including whether it is licensed separately
- Testing model evaluated specifically, since non-disruptive testing is what turns DR from documented to demonstrated
- Failback exercised in the proof of concept, not only failover
- Resource impact assessed for anything inserting itself into the host write path
- Recovery site storage requirement modelled, including journal capacity where applicable
- Bandwidth requirement measured against actual change rate rather than estimated
- Migration effort from the current platform costed, including rebuilding recovery plans and runbooks
- Operational skills assessed honestly, since the team has to run this at three in the morning
- Total cost modelled over the full term including orchestration components and growth
- Proof of concept run on a representative service rather than a simple one
The item most often missed is the migration cost of leaving your current platform. Recovery plans, runbooks, mappings and testing evidence all have to be rebuilt, and the organisation is running with degraded DR confidence while that happens. That cost is real and it belongs in the comparison.
If VMware Live Site Recovery is on your shortlist, our 68-check Live Site Recovery checklist covers what a good deployment and a defensible test regime look like.
DR platform evaluation
Comparing DR platforms ahead of a renewal?
We run evaluations structured around recovery outcomes rather than feature lists, and we work across these products rather than reselling one.
Frequently Asked Questions
Is Zerto better than VMware Live Site Recovery?
They are built for different emphases. Zerto is a continuous data protection platform achieving recovery points in seconds with journal-based rewind, independent of storage. VMware Live Site Recovery is an orchestration engine that consumes array-based, host-based or Virtual Volumes replication and is strongest at repeatable, testable recovery of a vSphere estate. If your objective is seconds, that points one way. If your priority is orchestration and testing across mixed storage, it points the other.
Can Veeam replace our DR platform?
For many organisations yes, particularly where consolidating backup and DR onto one platform is valuable and recovery points in minutes are acceptable. The caution is orchestration: it comes through a separate Recovery Orchestrator component, and organisations that buy replication without it find DR more manual than expected. Include it in the comparison rather than discovering the gap during a test.
Do we need continuous data protection?
Only if your recovery point objective genuinely requires it, and for most services it does not. Continuous data protection costs more in bandwidth, storage and often licensing. Establish the real objective per service with the business first, because applying the strictest requirement across the estate is how DR budgets get spent badly.
Which is best for ransomware?
None of these on its own, if you mean site recovery. Replication reproduces malicious change faithfully. What matters is immutability, retention of clean recovery points, isolated recovery environments and the ability to rewind to a point before compromise. Journal-based products offer rewind within their retention window, backup-first platforms offer clean points and immutability, and dedicated cyber recovery products offer isolated environments. Treat it as a separate requirement.
Is it worth switching because of licensing costs?
It can be, and the comparison needs to include the cost of switching. Rebuilding recovery plans, runbooks, mappings and testing evidence takes real effort, and your DR confidence is degraded while it happens. Organisations that switch on licence price alone frequently find the total cost closer than the quotes suggested.
What if we run more than just VMware?
VMware Live Site Recovery is a vSphere product. If a meaningful part of your estate is on other hypervisors and you want one DR platform, that points towards Zerto or Veeam. Whether one platform is genuinely better than two well-run ones is a separate question worth asking.
How do we know what our current recovery time actually is?
Test it. Not a tabletop exercise, an actual test failover with application owners validating the result and somebody recording how long it took. Most organisations discover their achievable recovery time differs from their published objective, and that gap is more valuable to know than any product comparison.
Where Consult Circle Fits
We are asked to run this comparison regularly, usually prompted by a renewal. The most useful thing we do is not the product assessment, it is establishing what recovery the organisation can actually achieve today, because that number is frequently different from the published objective and it reframes the whole evaluation.
We work across VMware Live Site Recovery and the alternatives through our Disaster Recovery services, run structured evaluations and proof of concept work, and deliver the implementation and testing afterwards. Where DR forms part of a wider platform refresh, that connects to our VMware Cloud Foundation services. Where your current platform is fine and the design has drifted, we will say so.
Before comparing any products, run a test failover on your current platform and measure how long recovery actually takes with application owners validating the result. That single number reframes most DR evaluations.