Configure private connectivity for Air Gap Protect storage

Private connectivity keeps Air Gap Protect storage traffic on private network infrastructure. Choose the configuration that matches your cloud provider and network architecture.

Support details
  • If you're a Commvault SaaS customer, contact your Commvault account team to enable private connectivity.

Requirements

Before you configure private connectivity:

  • Connect your on-premises environment to the cloud service provider using the applicable private connectivity service, such as AWS Direct Connect, Azure ExpressRoute, or Cloud Interconnect.

  • Configure DNS so that the applicable cloud storage endpoints resolve through the private connectivity solution.

  • Verify that your organization allows the required cross-account or cross-subscription access.

  • Verify that you have permissions to create private endpoints, modify network and DNS settings, and update storage access policies.

Choose a private connectivity option

Cloud provider Option Use when
AWS Configure AWS PrivateLink You want private connectivity to Amazon S3 through an interface VPC endpoint.
Azure Private Link Configure Azure Private Link You want private connectivity to Azure Blob Storage through a private endpoint.
Azure Use Azure ExpressRoute Your environment uses ExpressRoute for private connectivity to Azure.
Google Cloud Configure Private Service Connect You want to access Google Cloud Storage through Private Service Connect.
Google Cloud Configure Private Google Access with VPC Service Controls You use Private Google Access and VPC Service Controls to access Google Cloud Storage.
OCI Configure OCI Private Endpoints You want private connectivity to OCI Object Storage through an OCI Private Endpoint.

Troubleshoot private connectivity

Symptom Resolution
Storage endpoints resolve to public IP addresses Verify DNS configuration and confirm that storage traffic resolves through the configured private connectivity solution.
Connectivity fails Verify endpoint status, routing, network security rules, and firewall configuration.
Storage access is denied Verify storage permissions, endpoint access policies, and cross-account or cross-subscription access configuration.
The endpoint isn't accessible Verify that the endpoint is approved, associated with the correct network resources, and reachable from your environment.
×

Loading...