Hi Vaulters,
In order to implement a Vault site which will contain one MediaAgent in it, we wanted to restrict the communication of this MediaAgent to only the CS + MAs in Prod site and make connection only be established through the Vault site.
To make things even securised, we wanted to use a dedicated port for the Vault MA unstead of the defaults 8400/8403.
Seems this can be achived through One-Way network topology while setting : Vault MA → Prod CS/MAs.
But not sure about the customized port to be used, as from OS/Network perspective only the custom port will be allowed between the Vault MA and Prod CS/MAs. Should the custom port be set in the below screenshot during topology creation or set as an additional setting in the Vault MA (nCVDPORT) or both ? How to let CV know that the communication will only be established by the Vault MA and use a defined port ?

This is a bit confusing.
Thanks in advance.

