Agentless, cloud-native backup for Microsoft Azure
Post Reply
dddang
Lurker
Posts: 1
Liked: never
Joined: Jul 16, 2024 6:01 pm
Full Name: Don Dang
Contact:

Key Vault Public Access

Post by dddang »

Currently I have my backup repositories encrypted with a key vault that is publicly exposed. Is there a way to disable the public exposure? I have disabled the public access & white listed the public IP of the Azure Veaam appliance & that did not work. I also created a private endpoint, that did not work either. Backups fail whenever I disable the public access on the key vault.
nielsengelen
Product Manager
Posts: 5899
Liked: 1235 times
Joined: Jul 15, 2013 11:09 am
Full Name: Niels Engelen
Contact:

Re: Key Vault Public Access

Post by nielsengelen »

Hi,

Let me verify what can be done here and get back once I have an answer.
GitHub: https://github.com/nielsengelen
nielsengelen
Product Manager
Posts: 5899
Liked: 1235 times
Joined: Jul 15, 2013 11:09 am
Full Name: Niels Engelen
Contact:

Re: Key Vault Public Access

Post by nielsengelen »

Hi,

Hereby feedback which should work. Can you try this and let me know if it works for you?
You can configure to deny public access in the key networking settings and then use a private endpoint using the vnet of Veeam Backup for Microsoft Azure and add it to a private DNS zone.

The Veeam Backup for Microsoft Azure vnet then must be associated with the DNS zone. This way the key vault will accept communication only via the private IP address and only from vnets associated with the zone.
GitHub: https://github.com/nielsengelen
Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests