Skip to main content
Solved

Not able to Discover Amazon EC2 instances via VSA Proxy for snapshot backups

  • February 23, 2022
  • 9 replies
  • 472 views

Mohit Chordia
Byte
Forum|alt.badge.img+11

Hi Team,

I am receiving below error when i am trying to discover amazon EC2 instances in CommVault using  . My media agent ip-*03a is present in Private subnet and has IAM role with EC2 Full access and S3 Full access attached .

 

 




IAM Role which is attached to media agent -
 

Regards,Mohit

Best answer by Mohit Chordia

@Mike Struening 

Thanks for the follow-up.

Yes , this is resolved . Need to configure VPC end points + some additional settings at Commvault side .

Regards,Mohit

View original
If you have a question or comment, please create a topic

9 replies

Mohit Chordia
Byte
Forum|alt.badge.img+11

What are the Ports which would require to be opened in order to discover AWS regions in backup sub client .

When i enable All traffic ( 0.0.0.0/0 ) both inbound and outbound then my discovery works just fine .


Mohit Chordia
Byte
Forum|alt.badge.img+11

As soon as INTERNET(HTTPS-443) is enabled on my access node/media agent Browse is working but i cant enable HTTPS - 443 INTERNET on my access nodes/media agents due to security concerns and they are in PRIVATE SUBNETS.

 

Any suggestions how does access node discover AWS Regions/EC2 instances without internet access on MA/AN ?


Mike Struening
Vaulter
Forum|alt.badge.img+23

@Mohit Chordia , can you open a support case for this?  I see a case we have with this same exact issue that is live NOW and they provided a special update (UpdateBundle_Build1108136_Form2486) though we should have support look and determine if this is right for you first.

Share the case number with me so I can track it as well.


Mohit Chordia
Byte
Forum|alt.badge.img+11

@Mike Struening Thank you for response . This is a POC Lab Environment with temp license , i don't think i will be able to raise support case for this .

I need to understand if Iam missing anything here . 

Do we really need internet access on Private Subnet VSA proxy for Browse & Discovery to work ?

Do we need to create any type of VPC Endpoint for Access node present in Private Subnet to perform Browse and Discovery ?

Regards, Mohit


Mohit Chordia
Byte
Forum|alt.badge.img+11

Some Logs from VSA Proxy  :

 

vsbkp--

660  8c0   02/23 13:46:15 3117 AmazonCompute::GetAccountId() - Exception - Amazon.Runtime.AmazonServiceException: A WebException with status ConnectFailure was thrown. ---> System.Net.WebException: Unable to connect to the remote server ---> System.Net.Sockets.SocketException: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.


Mohit Chordia
Byte
Forum|alt.badge.img+11

This doc says that --

https://documentation.commvault.com/11.23/expert/30944_getting_started_with_virtual_server_agent_for_amazon.html

The access node must have access to the regional and global STS endpoints. For more information about AWS service endpoints, see AWS service endpoints on the AWS documentation site.

  • Global STS endpoints: The service endpoint is https://sts.amazonaws.com.

  • Regional STS endpoints: For example, https://sts.us-east-1.amazonaws.com, to back up instances on us-east-1.

If my access node is in Private Subnet and doesn't have internet configured how can it access these endpoints without internet connectivity . 

Also , what are the CIDR range for these endpoints if i have to allow them in security group ?


Mike Struening
Vaulter
Forum|alt.badge.img+23

@Mohit Chordia , following up on some open threads.

Were you able to get an answer for this?  Based on what you shared, your issue is due to lack of internet access.


Mohit Chordia
Byte
Forum|alt.badge.img+11
  • Author
  • Byte
  • 108 replies
  • Answer
  • March 23, 2022

@Mike Struening 

Thanks for the follow-up.

Yes , this is resolved . Need to configure VPC end points + some additional settings at Commvault side .

Regards,Mohit


Mike Struening
Vaulter
Forum|alt.badge.img+23

Thanks for sharing, as always!!


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings