Private connectivity keeps Air Gap Protect storage traffic on private network infrastructure. Choose the configuration that matches your cloud provider and network architecture.
Support details
- If you're a Commvault SaaS customer, contact your Commvault account team to enable private connectivity.
Requirements
Before you configure private connectivity:
-
Connect your on-premises environment to the cloud service provider using the applicable private connectivity service, such as AWS Direct Connect, Azure ExpressRoute, or Cloud Interconnect.
-
Configure DNS so that the applicable cloud storage endpoints resolve through the private connectivity solution.
-
Verify that your organization allows the required cross-account or cross-subscription access.
-
Verify that you have permissions to create private endpoints, modify network and DNS settings, and update storage access policies.
Choose a private connectivity option
| Cloud provider | Option | Use when |
|---|---|---|
| AWS | Configure AWS PrivateLink | You want private connectivity to Amazon S3 through an interface VPC endpoint. |
| Azure Private Link | Configure Azure Private Link | You want private connectivity to Azure Blob Storage through a private endpoint. |
| Azure | Use Azure ExpressRoute | Your environment uses ExpressRoute for private connectivity to Azure. |
| Google Cloud | Configure Private Service Connect | You want to access Google Cloud Storage through Private Service Connect. |
| Google Cloud | Configure Private Google Access with VPC Service Controls | You use Private Google Access and VPC Service Controls to access Google Cloud Storage. |
| OCI | Configure OCI Private Endpoints | You want private connectivity to OCI Object Storage through an OCI Private Endpoint. |
Troubleshoot private connectivity
| Symptom | Resolution |
|---|---|
| Storage endpoints resolve to public IP addresses | Verify DNS configuration and confirm that storage traffic resolves through the configured private connectivity solution. |
| Connectivity fails | Verify endpoint status, routing, network security rules, and firewall configuration. |
| Storage access is denied | Verify storage permissions, endpoint access policies, and cross-account or cross-subscription access configuration. |
| The endpoint isn't accessible | Verify that the endpoint is approved, associated with the correct network resources, and reachable from your environment. |