Before You Begin
Before you configure network settings for SQL Servers, make sure that your Azure environment meets the requirements listed in the following table. Some of the requirements, such as the peering connection between VNets and disabled public access to the SQL Server, change the network topology of your Azure subscription. Plan these changes in advance, as organization security policies may restrict them.
|
Requirement |
When Required |
Purpose |
|---|---|---|
|
Always |
The privatelink.blob.core.windows.net, privatelink.queue.core.windows.net and privatelink.database.windows.net zones hold the DNS records of the private endpoints. Veeam Backup for Microsoft Azure components use these records to resolve the endpoint names to private IP addresses. You can create the zones manually or instruct Veeam Backup for Microsoft Azure to create and manage them automatically. |
|
|
Always |
The worker configuration defines the Azure region and the VNet in which Veeam Backup for Microsoft Azure launches worker instances. Create the configuration in the same region where the protected SQL database resides and select a VNet for the worker instances. |
|
|
Always |
A virtual network link allows the resources of a VNet to resolve the records stored in a private DNS zone. Link the privatelink.blob.core.windows.net and privatelink.queue.core.windows.net zones to the VNet of the backup appliance and to the VNet selected for the worker instances. |
|
|
Peering connection between backup appliance VNet and worker VNet |
Always |
The peering connection allows the backup appliance and the worker instances to resolve the private endpoints that reside in the other VNet. Without the peering connection, you must create a separate set of private endpoints and private DNS zones in each VNet. Veeam Backup for Microsoft Azure does not use the peering connection to transfer backup data — the components exchange control messages through Azure Queue Storage. |
|
Private endpoints for Azure Blob Storage and Azure Queue Storage |
Always |
Veeam Backup for Microsoft Azure transfers backup data through the private endpoint for Azure Blob Storage and exchanges control messages through the private endpoint for Azure Queue Storage. The backup appliance has no direct connection to the worker instances, so Azure Queue Storage acts as a proxy that delivers worker readiness messages and job progress updates. Veeam Backup for Microsoft Azure creates the endpoints automatically at the first run of a backup policy, but you must configure DNS settings for them manually. |
|
Always |
When public access is disabled, the SQL Server becomes unavailable through the public network and accepts connections only through its private endpoint. |
|
|
Always |
A private endpoint grants worker instances access to the databases that you want to protect. Create a separate endpoint for every VNet to which worker instances are connected. If you plan to back up SQL databases through a staging server, create the endpoint for the SQL Server that acts as the staging server. |
|
|
Only if you create and manage the private DNS zones manually |
Add the private endpoint of the SQL Server to the privatelink.database.windows.net zone, create an 'A' record for it and link the zone to the VNets of the worker instances. Otherwise, the worker instances cannot resolve the name of the SQL Server to a private IP address. |
Considerations and Limitations
Before you start the deployment, review the following dependencies and limitations:
- Veeam Backup for Microsoft Azure does not create peering connections between VNets automatically — you must create the connection manually in the Microsoft Azure portal.
- When you create a private endpoint for the SQL Server, do not integrate the endpoint with a private DNS zone. Veeam Backup for Microsoft Azure requires the endpoint to use the private DNS zones that you created at step 1.
- To allow Veeam Backup for Microsoft Azure to update worker instances, the worker instances must have public access to the online Ubuntu repositories listed in section Ports.
- To store backups of SQL databases in repositories that reside in a private network, you must also configure network settings for storage accounts as described in section Configuring Network Settings for Storage Accounts.