Adding Configurations for Backup Account
By default, Veeam Backup for AWS launches worker instances used for retention, backup and restore operations in the backup account. You can choose an IAM role and specify network settings that will be used to deploy these worker instances.
To specify an IAM role for worker instances, do the following:
For an IAM role to be displayed in the list of available IAM roles, it must be added to Veeam Backup for AWS as described in section Adding IAM Roles.
Important |
After you choose an IAM role, it is not recommended to change it. Otherwise, all the created worker configurations will be removed automatically as soon as you choose another IAM role. |
After you specify the IAM role, it is recommended that you check whether permissions of the specified IAM role are sufficient to launch worker instances. For information on how to check IAM role permissions, see Checking IAM Role Permissions. To learn what permissions must have the IAM role used to launch worker instances, see Service IAM Role in Backup Account.
To add a worker configuration:
- At the Network step of the wizard, select an Amazon VPC and a subnet to which you want to connect worker instances, and specify a security group that must be associated with the instances. For an Amazon VPC, a subnet and a security group to be displayed in the lists of available network specifications, they must be created in AWS as described in AWS Documentation.
Veeam Backup for AWS will apply the specified network settings to all worker instances that will be launched in the AWS Region and Availability Zone selected at the General step of the wizard.
Important |
When selecting a subnet and security group, consider the following:
Proxy redirect and setting a proxy in the Veeam Backup for AWS configuration are not supported.
|
By default, Veeam Backup for AWS uses public IPv4 addresses to communicate with worker instances. If the public IPv4 addressing attribute is disabled for the selected subnet, Veeam Backup for AWS will display a warning at the Summary step of the wizard. In this case, do either of the following:
- Enable public IPv4 addressing for the subnet as described in AWS Documentation.
- Enable the private network deployment functionality, and configure specific VPC endpoints for the subnet to let Veeam Backup for AWS use private IPv4 addresses as described in section Enabling Private Network Deployment.
For the list of specific endpoints required to perform backup and restore operations, see Configuring Private Networks.
- Configure VPC endpoints as described in section Appendix C. Configuring Endpoints in AWS.
- At the Summary step of the wizard, review summary information and click Finish.
Related Topics