Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC PowerProtect DDVE on Amazon Web Services 7.9 Installation and Administration Guide

PDF

Network setup in AWS

Network configuration requirements and recommendations are provided.

VPC Architecture

It is recommended that you use a public or private subnet architecture to deploy the DDVE in a private subnet. This architecture secures the DDVEs (VMs) with the appropriate use of various VPC components such as route tables, access control lists, security groups, and so on.

Public IP address

To protect the DDVE from potential attacks over the open Internet, do not expose the DDVE by using a public IP address directly over the Internet. It is recommended that you use VPN connections between different geographical regions (VPCs). For example, the replication between different VPCs, different cloud regions, cloud to on-premises, and on-premises to cloud can occur over the secure VPN connection.

Network interfaces

You can add multiple network interfaces to the DDVE instance. The maximum number of network interfaces varies by instance type. See Elastic network interfaces for more information.

Custom primary private IP address

If you want to assign the network interface with a custom private IP address, follow the steps in Create a network interface, choose Custom when adding a private IP address, then attach it to the DDVE instance.

Within DDVE, there is no requirement to configure the interface to a static IP address. Configuring the network interface using DHCP, which is enabled by default, is recommended.

Object store connectivity

The DDVE object store feature must connect to its object storage, for example, to the S3 bucket. The object store communication is over HTTPS, so the outbound security group setting must allow communication over port 443. Different ways to enable DDVE connectivity to the object store are available. Out of the following three options, only the third option (using VPC endpoint) is recommended.

  • Public IP address from the public subnet - Do no use.
  • Network Address Translation (NAT) - If the private subnet is configured to use NAT, the DDVE can communicate to object store over NAT.
  • VPC endpoint for accessing the Amazon S3 - VPC does not require the DDVE to have a public IP address to communicate to S3. It uses the private IP address instead. (In this case, an Internet gateway, NAT, or virtual private gateway are not required to access S3.) Using VPC endpoint allows the traffic to the S3 endpoint to stay within the Amazon network and is routed internally to S3.
AWS object store connectivity
NOTE

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\