Discussions related to Microsoft Azure workloads protection.
Post Reply
nhkm
Novice
Posts: 3
Liked: never
Joined: Mar 24, 2025 9:31 pm
Full Name: Keith Mitchell
Contact:

Feature request - separate VDC traffic the internet traffic

Post by nhkm »

VDC requires the Microsoft.Storage.Global service configured on the azure vnet subnet, but this causes issues in our environment.
Being able to nominate a dedicated vnet, or subnet, for VDC to use for backups would be a solution to this issue.

From case #07953313:
Per case notes would like to clarify "A virtual network service endpoint (routing) for the Microsoft.Storage.Global service must be configured for virtual networks to which worker instances will be connected — you can either configure the endpoint manually in Microsoft Azure beforehand or let Veeam Backup for Microsoft Azure do it for you automatically while deploying the worker instances."
For vdc Azure the worker instances config is handled in the backend maintaining the components required for the VM backups to be taken and traffic needs to be routed through this service endpoint. At this stage there is no way to separate the VDC traffic from the internet traffic and would be a feature request for the VDC Azure team if you would like to raise.
nielsengelen
Product Manager
Posts: 6257
Liked: 1310 times
Joined: Jul 15, 2013 11:09 am
Full Name: Niels Engelen
Contact:

Re: Feature request - separate VDC traffic the internet traffic

Post by nielsengelen »

Hi Keith,

We currently do not have any short-term plans for this. Could you clarify which issues it causes in your environment?
GitHub: https://github.com/nielsengelen
nhkm
Novice
Posts: 3
Liked: never
Joined: Mar 24, 2025 9:31 pm
Full Name: Keith Mitchell
Contact:

Re: Feature request - separate VDC traffic the internet traffic

Post by nhkm »

Hi Niels

We have scripts that run each night that connect to other Azure hosted file shares. These file shares have IP whitelisting requirements.
When the Microsoft.Storage.Global service is enabled on the subnet, it causes the traffic to route via the MS routed service instead of via the internet. This results in the connection coming from a random Microsoft IP that is not whitelisted and the connection fails.

There are some ways to get around this, but it involves reworking scripts and network routes. Was hoping to avoid that :)
nielsengelen
Product Manager
Posts: 6257
Liked: 1310 times
Joined: Jul 15, 2013 11:09 am
Full Name: Niels Engelen
Contact:

Re: Feature request - separate VDC traffic the internet traffic

Post by nielsengelen »

Hi Keith,

The use case is clear but unfortenately, we will not have this option available anytime soon. We'll note it down as future enhancement.
GitHub: https://github.com/nielsengelen
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest