Skip to main content

<Sample 2>

To ensure smooth operation of Enterprise Workloads, it is crucial to configure appropriate exclusions within your environment. We strongly recommend configuring exclusions for the Enterprise Workloads agent, Druva storage cluster URLs, and AWS S3 storage region URLs.

This article covers all the required configurations across two areas:

  • Step 1: Allow URLs in firewall rules.

  • Step 2: Ports and communication protocols.

Follow the below sections to identify your environment parameters and copy the required rules for each step.

Before You Begin

Your deployment region, agent version, and Azure usage determine which URL sections apply to your environment.

Determine your deployment region

Your deployment region determines which URLs you need to whitelist. To find your region:

  1. Log in to the Druva Cloud Platform console.

  2. Check the URL in your browser:

| If your console URL contains… | Your deployment region is… |

| :--- | :--- |

| `console.druva.com` | **US** |

| `ap1-console.druva.com` | **APAC** |

| `au-console.druva.com` | **Australia (AU)** |

If your console URL (address bar of the browser) contains…

Your deployment region is…

console.druva.com

US

ap1-console.druva.com

APAC

au-console.druva.com

Australia (AU)

Quickly check your region URLs

❗ Important

  • For existing customers
    If you have already excluded the IP ranges provided by Druva, add all the respective URLs for your region, and do not remove the IP address from your firewall rules.

  • For new customers:

    • You must exclude all the URLs for your region.

    • You must exclude *.druva.com URL in your firewall rules or Contact Support to get the list of IP ranges.

    • If you choose to exclude *.druva.com URL in your firewall rules, then by default all of the below listed URLs ending with druva.com domain are excluded.

    • You will still need to separately allow the AWS S3 storage URLs and Azure Storage URLs listed later in this document because they do not use the druva.com domain.

Deployment Scenarios and Required URLs

💡 New to Setup?

Refer the following matrix to check your Region (US, APAC, AU), Agent Version (v7.0.0+ vs v6.x) and Storage Setup. Locate your matching row in the matrix to see your required URL sections. If your setup isn't listed, refer to the individual regional sections to copy the URLs.

How to identify storage and agent version?

Navigate to Storage > Provisioned Storages on the Management Console to check the provisioned storage.


For more information on agent version, see Agents and Proxies.

Deployment

Region

Agent
Version

Storage
Provider

Allow URLs

Ports
Required


US


7.2


AWS

  • 443 (Outbound)

  • Workload-specific ports (see Ports section)


US


7.2


AWS + Azure

(with Azure SQL via Quantum Bridge)

  • 443 (Outbound)

  • Workload-specific ports (see Ports section)

US

6.x

AWS storage only

  • 443 (Outbound)

  • Workload-specific ports (see Ports section)

APAC

Any

Azure VMs (Azure Storage Only)

  • Open: Port <check with Engg. for any equivalent setting>

Step 1: Allow URLs in Firewall Rules

Important: You must add Common URLs and Storage Cluster URLs for your region. These are required for all customers. Depending on your setup, you may also need AWS S3 / Azure.

US Region Requirements

Common URLs (US)

You must allow the Common URLs for your deployment region.

login.druva.com
globalapis.druva.com
phoenix-globalapis.druva.com
phoenix.druva.com
downloads.druva.com
deviceapigw-phoenix.druva.com
backup-phoenix.druva.com
pub-devicemgmt-devicenotifier-dcp.druva.com
devicemgmt-reverseproxy-dcp.druva.com
dtp-c0-uksouth-phoenix.druva.com
vmacproxy-edge-vmacn.*-c0-us-east-1-phoenix\.druva\.com$

Configure the pattern, vmacproxy-edge-vmacn.*-c0-us-east-1-phoenix\.druva\.com$, to avoid any restore failure for application-aware backups. If you are not able to exclude this URL, then contact Support for the IP addresses.

Agent and Log URLs (US)

Allow both the primary FQDN and the Alias for each function. Both are required for reliable connectivity.

Purpose

FQDN

Alias

Log upload / download

https://dprod-devicestore-file.s3.us-east-1.amazonaws.com

https://druva-us0-devicefile-zqztwnudbwnx5u8j1bx4x6qbq8dmhuse1a-s3alias.s3.us-east-1.amazonaws.com

Agent upgrade

https://dprod-devicestore-package.s3.us-east-1.amazonaws.com

https://druva-us0-devicepack-mkpuot7uiirhb5wrphs1a9h946aeeuse1b-s3alias.s3.us-east-1.amazonaws.com

Storage Cluster URLs (US)

You must allow the Storage Cluster URLs only for the storage regions assigned to your account. If you are unsure which regions apply, navigate to Storage > Provisioned Storages on the Management Console and check it.

The URLs below represent Druva's regional storage clusters, each corresponding to a specific storage region and its associated storage service.

Storage Region

Storage Cluster URL

Storage Service URL

Northern Virginia (us-east-1)

dtp-c0-us-east-1-phoenix.druva.com

dtp-c0-dbs-us-east-1-phoenix.druva.com

Ohio (us-east-2)

dtp-c0-us-east-2-phoenix.druva.com

dtp-c0-dbs-us-east-2-phoenix.druva.com

Northern California (us-west-1)

dtp-c0-us-west-1-phoenix.druva.com

dtp-c0-dbs-us-west-1-phoenix.druva.com

Oregon (us-west-2)

dtp-c0-us-west-2-phoenix.druva.com

dtp-c0-dbs-us-west-2-phoenix.druva.com

Ireland (eu-west-1)

dtp-c0-eu-west-1-phoenix.druva.com

dtp-c0-dbs-eu-west-1-phoenix.druva.com

London (eu-west-2)

dtp-c0-eu-west-2-phoenix.druva.com

dtp-c0-dbs-eu-west-2-phoenix.druva.com

Paris (eu-west-3)

dtp-c0-eu-west-3-phoenix.druva.com

dtp-c0-dbs-eu-west-3-phoenix.druva.com

Stockholm (eu-north-1)

dtp-c0-eu-north-1-phoenix.druva.com

dtp-c0-dbs-eu-north-1-phoenix.druva.com

Frankfurt (eu-central-1)

dtp-c0-eu-central-1-phoenix.druva.com

dtp-c0-dbs-eu-central-1-phoenix.druva.com

São Paulo (sa-east-1)

dtp-c0-sa-east-1-phoenix.druva.com

dtp-c0-dbs-sa-east-1-phoenix.druva.com

Montreal (ca-central-1)

dtp-c0-ca-central-1-phoenix.druva.com

dtp-c0-dbs-ca-central-1-phoenix.druva.com

Hong Kong (ap-east-1)

dtp-c0-ap-east-1-phoenix.druva.com

dtp-c0-dbs-ap-east-1-phoenix.druva.com

Tokyo (ap-northeast-1)

dtp-c0-ap-northeast-1-phoenix.druva.com

dtp-c0-dbs-ap-northeast-1-phoenix.druva.com

Mumbai (ap-south-1)

dtp-c0-ap-south-1-phoenix.druva.com

dtp-c0-dbs-ap-south-1-phoenix.druva.com

Singapore (ap-southeast-1)

dtp-c0-ap-southeast-1-phoenix.druva.com

dtp-c0-dbs-ap-southeast-1-phoenix.druva.com

Sydney (ap-southeast-2)

dtp-c0-ap-southeast-2-phoenix.druva.com

dtp-c0-dbs-ap-southeast-2-phoenix.druva.com

UAE (me-central-1)

dtp-c0-me-central-1-phoenix.druva.com

dtp-c0-dbs-me-central-1-phoenix.druva.com

AWS S3 URLs (US)

Applies only to agents version 7.0.0 or later. Allow both the S3 FQDN and S3 Alias for each assigned storage region.

If your agent version is earlier than 7.0.0, skip this section.

For Enterprise Workloads agents version 7.0.0 or later, allow the following AWS S3 storage URLs to access storage during backups and restores. Ensure that you configure firewall rules to allow both FQDN and Alias URLs.

Storage Region

S3 FQDN

S3 Alias

Northern Virginia (us-east-1)

https://s3.amazonaws.com/

https://s3.us-east-1.amazonaws.com/

https://s3-1.amazonaws.com/

https://druvaphn-use1-3eshkjg74za3gfuc3rqj51ab5m8c1use1a-s3alias.s3.amazonaws.com/

https://druvaphn-use1-3eshkjg74za3gfuc3rqj51ab5m8c1use1a-s3alias.s3.us-east-1.amazonaws.com/

Ohio (us-east-2)

https://s3.amazonaws.com/

https://s3.us-east-2.amazonaws.com/

https://druvaphn-use2-kq757gh7ee4nmsdscs7fxn1frzmiwuse2a-s3alias.s3.amazonaws.com/

https://druvaphn-use2-kq757gh7ee4nmsdscs7fxn1frzmiwuse2a-s3alias.s3.us-east-2.amazonaws.com/

Northern California (us-west-1)

https://s3.us-west-1.amazonaws.com/

https://druvaphn-usw1-ak8kj98wzehr3qfiyepxt9ypq4yfrusw1a-s3alias.s3.us-west-1.amazonaws.com/

Oregon (us-west-2)

https://s3.us-west-2.amazonaws.com/

https://druvaphn-usw2-oxfxnrq6z6cjd5p7kbmefgzk6d73ausw2a-s3alias.s3.us-west-2.amazonaws.com/

Montreal (ca-central-1)

https://s3.ca-central-1.amazonaws.com/

https://druvaphn-cac1-acawpxxtj4ichfwxtxberrmj7w3jkcan1a-s3alias.s3.ca-central-1.amazonaws.com/

Frankfurt (eu-central-1)

https://s3.eu-central-1.amazonaws.com/

https://druvaphn-euc1-eiytn963i4jtmpue5xt1i9fdb9kjweuc1a-s3alias.s3.eu-central-1.amazonaws.com/

Ireland (eu-west-1)

https://s3.eu-west-1.amazonaws.com/

https://druvaphn-euw1-u39y9y4kon6oan1omsg9f9wjtmp4oeuw1a-s3alias.s3.eu-west-1.amazonaws.com/

London (eu-west-2)

https://s3.eu-west-2.amazonaws.com/

https://druvaphn-euw2-u8om1ejedb58a7oh4ad85p4qc7q3aeuw2a-s3alias.s3.eu-west-2.amazonaws.com/

Paris (eu-west-3)

https://s3.eu-west-3.amazonaws.com/

https://druvaphn-euw3-pswryckcmqamxuiicf7gjets9hafoeuw3a-s3alias.s3.eu-west-3.amazonaws.com/

Stockholm (eu-north-1)

https://s3.eu-north-1.amazonaws.com/

https://druvaphn-eun1-do7rfzp8s3xuz8nm7cwfjzcqbf3pgeun1a-s3alias.s3.eu-north-1.amazonaws.com/

São Paulo (sa-east-1)

https://s3.sa-east-1.amazonaws.com/

https://druvaphn-sa1-poghxe43kh71og6pghcfrzfuxziphsae1a-s3alias.s3.sa-east-1.amazonaws.com/

Hong Kong (ap-east-1)

https://s3.ap-east-1.amazonaws.com/

https://druvaphn-ape1-3qpd1n8aqdth45hba5ghxpceb9thkape1a-s3alias.s3.ap-east-1.amazonaws.com/

Mumbai (ap-south-1)

https://s3.ap-south-1.amazonaws.com/

https://druvaphn-aps1-kuia8bkbftwcbn4y8ihzdhck3y4zgaps3a-s3alias.s3.ap-south-1.amazonaws.com/

Singapore (ap-southeast-1)

https://s3.ap-southeast-1.amazonaws.com/

https://druvaphn-apse1-9k6pu5kyjr3813xemeo14r9dioukwaps1a-s3alias.s3.ap-southeast-1.amazonaws.com/

Sydney (ap-southeast-2)

https://s3.ap-southeast-2.amazonaws.com/

https://druvaphn-apse2-xifjr44ehwn4skab8xgg4kwzgg1qcaps2a-s3alias.s3.ap-southeast-2.amazonaws.com/

Tokyo (ap-northeast-1)

https://s3.ap-northeast-1.amazonaws.com/

https://druvaphn-apne1-3tzzk6pokwpj7o3c8r3cquw8ithxoapn1a-s3alias.s3.ap-northeast-1.amazonaws.com/

UAE (me-central-1)

https://s3.me-central-1.amazonaws.com/

https://druvaphn-mec1-hupms3wzwebgdbjgiyikzebx7mi84mec1a-s3alias.s3.me-central-1.amazonaws.com/

Region

Whitelisting URL

Live From

East US

druvaphn1eus.blob.core.windows.net

19 May 2025

Australia East

druvaphn1ae.blob.core.windows.net

19 May 2025

West US 2

druvaphn1wu2.blob.core.windows.net

26 May 2025

UK South

druvaphn1uks.blob.core.windows.net

26 May 2025

Germany West Central

druvaphn1gwc.blob.core.windows.net

APAC Region Requirements

Common URLs (APAC)

You must allow the Common URLs for your deployment region.

login.druva.com
globalapis.druva.com
phoenix.druva.com
downloads.druva.com
deviceapigw-ap1-phoenix.druva.com
backup-ap1-phoenix.druva.com
pub-devicemgmt-devicenotifier-ap1-dcp.druva.com
devicemgmt-reverseproxy-ap1-dcp.druva.com
vmacproxy-edge-vmacn.*-c0-ap-south-1-phoenix\.druva\.com$

Configure the pattern, vmacproxy-edge-vmacn.*-c0-ap-south-1-phoenix\.druva\.com$ to avoid any restore failure for application-aware backups. If you are not able to exclude this URL, then contact Support for the IP addresses.

Agent and Log URLs (APAC)

Allow both the primary FQDN and the Alias for each function. Both are required for reliable connectivity.

Purpose

FQDN

Alias

Log download

https://ap1-dprod-devicestore-file.s3.ap-southeast-1.amazonaws.com

https://druva-ap1-devicefile-gkztbhmogjger59x4d8qps3gomasnaps1a-s3alias.s3.ap-southeast-1.amazonaws.com

Agent upgrade

https://ap1-dprod-devicestore-package.s3.ap-southeast-1.amazonaws.com

https://druva-ap1-devicepack-4bkkqwrp4harurgb7hrocaya9cme4aps1b-s3alias.s3.ap-southeast-1.amazonaws.com

Storage Cluster URLs (APAC)

You must allow the Storage Cluster URLs only for the storage regions assigned to your account. If you are unsure which regions apply, navigate to Storage > Provisioned Storages on the Management Console and check it.

The URLs below represent Druva's regional storage clusters, each corresponding to a specific storage region and its associated storage service.

Storage Region

Storage Cluster URL

Storage Service URL

Singapore (ap-southeast-1)

dtp-c0-ap-southeast-1-ap1-phoenix.druva.com

dtp-c0-dbs-ap-southeast-1-ap1-phoenix.druva.com

Hong Kong (ap-east-1)

dtp-c0-ap-east-1-ap1-phoenix.druva.com

dtp-c0-dbs-ap-east-1-ap1-phoenix.druva.com

Mumbai (ap-south-1)

dtp-c0-ap-south-1-ap1-phoenix.druva.com

dtp-c0-dbs-ap-south-1-ap1-phoenix.druva.com

Sydney (ap-southeast-2)

dtp-c0-ap-southeast-2-ap1-phoenix.druva.com

dtp-c0-dbs-ap-southeast-2-ap1-phoenix.druva.com

Tokyo (ap-northeast-1)

dtp-c0-ap-northeast-1-ap1-phoenix.druva.com

dtp-c0-dbs-ap-northeast-1-ap1-phoenix.druva.com

UAE (me-central-1)

dtp-c0-me-central-1-ap1-phoenix.druva.com

dtp-c0-dbs-me-central-1-ap1-phoenix.druva.com

AWS S3 Storage URLs (APAC)

For Enterprise Workloads agents version 7.0.0 or later, allow the following AWS S3 storage URLs to access storage during backups and restores. Ensure that you configure firewall rules to allow both FQDN and Alias URLs.

The following table is for Enterprise Workloads agents version 7.0.0 or later.

Storage Region

S3 FQDN

S3 Alias

Hong Kong (ap-east-1)

https://s3.ap-east-1.amazonaws.com/

https://druvaphn-ape1-3qpd1n8aqdth45hba5ghxpceb9thkape1a-s3alias.s3.ap-east-1.amazonaws.com/

Mumbai (ap-south-1)

https://s3.ap-south-1.amazonaws.com/

https://druvaphn-aps1-kuia8bkbftwcbn4y8ihzdhck3y4zgaps3a-s3alias.s3.ap-south-1.amazonaws.com/

Singapore (ap-southeast-1)

https://s3.ap-southeast-1.amazonaws.com/

https://druvaphn-apse1-9k6pu5kyjr3813xemeo14r9dioukwaps1a-s3alias.s3.ap-southeast-1.amazonaws.com/

Sydney (ap-southeast-2)

https://s3.ap-southeast-2.amazonaws.com/

https://druvaphn-apse2-xifjr44ehwn4skab8xgg4kwzgg1qcaps2a-s3alias.s3.ap-southeast-2.amazonaws.com/

Tokyo (ap-northeast-1)

https://s3.ap-northeast-1.amazonaws.com/

https://druvaphn-apne1-3tzzk6pokwpj7o3c8r3cquw8ithxoapn1a-s3alias.s3.ap-northeast-1.amazonaws.com/

UAE (me-central-1)

https://s3.me-central-1.amazonaws.com/

https://druvaphn-mec1-hupms3wzwebgdbjgiyikzebx7mi84mec1a-s3alias.s3.me-central-1.amazonaws.com/

AU Region Requirements

Common URLs (AU)

You must allow the Common URLs for your deployment region.

au-login.druva.com
au-globalapis.druva.com
au-phoenix.druva.com
downloads.druva.com
au-deviceapigw-phoenix.druva.com
au-backup-phoenix.druva.com
au-pub-devicemgmt-devicenotifier-dcp.druva.com
au-devicemgmt-reverseproxy-dcp.druva.com

Agent and Log URLs (AU)

Allow both the primary FQDN and the Alias for each function. Both are required for reliable connectivity.

Purpose

FQDN

Alias

Log upload / download

https://au-audprod-devicestore-file.s3.ap-southeast-2.amazonaws.com

https://druva-au-devicefile-ni1pe37xditiu89brrmep38mkgmz4aps2a-s3alias.s3.ap-southeast-2.amazonaws.com

Agent upgrade

https://au-audprod-devicestore-package.s3.ap-southeast-2.amazonaws.com

https://druva-au-devicepacka-8uwp59g6gdffarqnszpjwa5j3bu6caps2b-s3alias.s3.ap-southeast-2.amazonaws.com

Storage Cluster URLs (AU)

You must allow the Storage Cluster URLs only for the storage regions assigned to your account. If you are unsure which regions apply, navigate to Storage > Provisioned Storages on the Management Console and check it.

The URLs below represent Druva's regional storage clusters, each corresponding to a specific storage region and its associated storage service.

Storage Region

Storage Cluster URL

Storage Service URL

Sydney

(ap-southeast-2)

dtp-c0-ap-southeast-2-au-phoenix.druva.com

dtp-c0-dbs-ap-southeast-2-au-phoenix.druva.com

AWS S3 Storage URLs (AU)

Applies only to agents version 7.0.0 or later. Allow both the S3 FQDN and S3 Alias for each assigned storage region.

If your agent version is earlier than 7.0.0, skip this section.

For Enterprise Workloads agents version 7.0.0 or later, allow the following AWS S3 storage URLs to access storage during backups and restores. Ensure that you configure firewall rules to allow both FQDN and Alias URLs.

The following table is for Enterprise Workloads agents version 7.0.0 or later.

Storage Region

S3 FQDN

S3 Alias

Sydney (ap-southeast-2)

https://s3.ap-southeast-2.amazonaws.com/

https://druvaphn-apse2-wq3hckoupwgrr8ioir1mx5nyci8aoaps2a-s3alias.s3.ap-southeast-2.amazonaws.com

Azure / Quantum Bridge URLs

Azure Storage URLs

Applies to Azure workloads only.

If you protect Azure workloads, allow the Azure Storage URLs for the applicable Azure regions in your environment.

Resource Region

Whitelisting URL

East US

druvaphn1eus.blob.core.windows.net

Australia East

druvaphn1ae.blob.core.windows.net

West US 2

druvaphn1wu2.blob.core.windows.net

UK South

druvaphn1uks.blob.core.windows.net

Germany West Central

druvaphn1gwc.blob.core.windows.net

Central India

druvaphn1inc.blob.core.windows.net

Transient Blob URLs for Azure SQLs

If you use Azure SQL or Azure Storage accounts (Files/Blob/Data Lake) with private access (via Quantum Bridge), allow the Transient Blob URLs.

Transient blob storage facilitates data transfer to and from Druva’s Quantum Bridge and must reside in the same Azure region as the source resource. Since we support both APAC and US deployments with globally distributed resources, we maintain separate infrastructure, including storage accounts tied to their respective regions. So, if you are an APAC customer with resources located in a U.S. region (e.g., East US), you may be directed to use a U.S.-based storage URL to ensure proper data transfer. For this, ensure these URLs are allowed in the Network Security Group during the creation of the Quantum Bridge.

Which column applies to me in the following table?

Use the column that matches your Druva deployment region (US or APAC), not the Azure resource region.

Resource Region

APAC deployment region URLs

US deployment region URLs

East US (eastus)

https://sql1ap1phoenixeus.blob.core.windows.net

https://sql1phoenixeus.blob.core.windows.net

Asia Pacific (southeastasia)

https://sql1ap1phoenixsea.blob.core.windows.net

https://sql1phoenixsea.blob.core.windows.net

North America (westus)

https://sql1ap1phoenixwus.blob.core.windows.net

https://sql1phoenixwus.blob.core.windows.net

Europe (uksouth)

https://sql1ap1phoenixuks.blob.core.windows.net

https://sql1phoenixuks.blob.core.windows.net

Europe (francecentral)

https://sql1ap1phoenixfc.blob.core.windows.net

https://sql1phoenixfc.blob.core.windows.net

Asia Pacific (australiacentral)

https://sql1ap1phoenixacl.blob.core.windows.net

https://sql1phoenixacl.blob.core.windows.net

Asia Pacific (australiaeast)

https://sql1ap1phoenixae.blob.core.windows.net

https://sql1phoenixae.blob.core.windows.net

Asia Pacific (australiasoutheast)

https://sql1ap1phoenixase.blob.core.windows.net

https://sql1phoenixase.blob.core.windows.net

South America (brazilsouth)

https://sql1ap1phoenixbrs.blob.core.windows.net

https://sql1phoenixbrs.blob.core.windows.net

North America (canadacentral)

https://sql1ap1phoenixcnc.blob.core.windows.net

https://sql1phoenixcnc.blob.core.windows.net

North America (canadaeast)

https://sql1ap1phoenixcne.blob.core.windows.net

https://sql1phoenixcne.blob.core.windows.net

Asia Pacific

(centralindia)

https://sql1ap1phoenixinc.blob.core.windows.net

https://sql1phoenixinc.blob.core.windows.net

North America (centralus)

https://sql1ap1phoenixcus.blob.core.windows.net

https://sql1phoenixcus.blob.core.windows.net

Asia Pacific (eastasia)

https://sql1ap1phoenixea.blob.core.windows.net

https://sql1phoenixea.blob.core.windows.net

East US (eastus2)

https://sql1ap1phoenixeus2.blob.core.windows.net

https://sql1phoenixeus2.blob.core.windows.net

Europe (germanywestcentral)

https://sql1ap1phoenixgwc.blob.core.windows.net

https://sql1phoenixgwc.blob.core.windows.net

Middle East (israelcentral)

https://sql1ap1phoenixilc.blob.core.windows.net

https://sql1phoenixilc.blob.core.windows.net

Asia Pacific (japaneast)

https://sql1ap1phoenixjpe.blob.core.windows.net

https://sql1phoenixjpe.blob.core.windows.net

Asia Pacific (koreacentral)

https://sql1ap1phoenixkrc.blob.core.windows.net

https://sql1phoenixkrc.blob.core.windows.net

Asia Pacific (koreasouth)

https://sql1ap1phoenixkrs.blob.core.windows.net

https://sql1phoenixkrs.blob.core.windows.net

Central America (mexicocentral)

https://sql1ap1phoenixmxc.blob.core.windows.net

https://sql1phoenixmxc.blob.core.windows.net

North America (northcentralus)

https://sql1ap1phoenixncus.blob.core.windows.net

https://sql1phoenixncus.blob.core.windows.net

Europe (northeurope)

https://sql1ap1phoenixne.blob.core.windows.net

https://sql1phoenixne.blob.core.windows.net

Europe (norwayeast)

https://sql1ap1phoenixnwe.blob.core.windows.net

https://sql1phoenixnwe.blob.core.windows.net

Europe (polandcentral)

https://sql1ap1phoenixplc.blob.core.windows.net

https://sql1phoenixplc.blob.core.windows.net

Africa (southafricanorth)

https://sql1ap1phoenixsan.blob.core.windows.net

https://sql1phoenixsan.blob.core.windows.net

Africa (southafricawest)

https://sql1ap1phoenixsaw.blob.core.windows.net

https://sql1phoenixsaw.blob.core.windows.net

North America (southcentralus)

https://sql1ap1phoenixscus.blob.core.windows.net

https://sql1phoenixscus.blob.core.windows.net

Asia Pacific (southindia)

https://sql1ap1phoenixins.blob.core.windows.net

https://sql1phoenixins.blob.core.windows.net

Europe (swedencentral)

https://sql1ap1phoenixsdc.blob.core.windows.net

https://sql1phoenixsdc.blob.core.windows.net

Europe (switzerlandnorth)

https://sql1ap1phoenixszn.blob.core.windows.net

https://sql1phoenixszn.blob.core.windows.net

Middle East (uaenorth)

https://sql1ap1phoenixuan.blob.core.windows.net

https://sql1phoenixuan.blob.core.windows.net

Europe (ukwest)

https://sql1ap1phoenixukw.blob.core.windows.net

https://sql1phoenixukw.blob.core.windows.net

North America (westcentralus)

https://sql1ap1phoenixwcus.blob.core.windows.net

https://sql1phoenixwcus.blob.core.windows.net

Europe (westeurope)

https://sql1ap1phoenixwe.blob.core.windows.net

https://sql1phoenixwe.blob.core.windows.net

Asia Pacific (westindia)

https://sql1ap1phoenixinw.blob.core.windows.net

https://sql1phoenixinw.blob.core.windows.net

North America (westus2)

https://sql1ap1phoenixwus2.blob.core.windows.net

https://sql1phoenixwus2.blob.core.windows.net

North America (westus3)

https://sql1ap1phoenixwus3.blob.core.windows.net

https://sql1phoenixwus3.blob.core.windows.net

Next you must proceed to the Ports section to open the required ports for your workloads.

Step 2. Allow ports and communication protocols

Druva uses ports and communication protocols to ensure secure connections and communication during backup and restore operations.


📝 Note
Communication happens from a backup proxy to other parties on various ports. Here, the backup proxy is the communication initiator, which is unidirectional. These ports are used for outgoing (unidirectional) communication, not incoming communication. However, data in the form of a response can flow in the opposite direction. Standard system ports such as 22 (SSH) and 2049 (NFS-SERVER) are used for incoming requests.


VMware

Click to view the ports and protocols

Port

Communication protocol

Description

443

HTTPS+SSL

Druva uses Port 443 to establish a secure connection and communication between the following:

  • Backup Proxy to Druva Cloud

  • Backup Proxy to TurboTier

  • Backup Proxy to vCenter Server


📝 Note
Port 443 is required if the ESXi host is directly registered with Druva for backup. Backup proxy establishes connection with ESXi host over Port 443 only if it registered with Druva as Standalone ESXi. If the ESXi host is registered with Druva through vCenter Server, backup proxy communicates with the ESXi host over Port 902.


902

TCP/UDP

Druva uses port 902 to establish a connection between the backup proxy and ESXi host registered with Druva through vCenter Server.

By default, VMware uses the port 902 for the vixDiskLib connection (All Transport Modes). You must use the VixDiskLib to access a virtual disk. All operations require a VixDiskLib connection to access virtual disk data.

3542

HTTPS+SSL

For application-aware backups, the backup proxy uses VMware Tools to inject two executables and a few supporting files such as certificates into the guest OS of the virtual machine. When the executables run, they start guest OS processes called guestossvc and PhoenixSQLGuestPlugin . The backup proxy uses the opened port 3542 on the guest OS so that it can communicate with guestossvc to run SQL Server backups. Ensure that this port is open on the guest OS. In addition, the backup proxy should reach the virtual machine directly over IPv4.

The backup proxy also uses this port to restore databases to the virtual machine.

3545

HTTPS+SSL

For application-aware backups, the SQL executable service PhoenixSQLGuestPlugin queries the Microsoft VSS APIs to back up and restore SQL Server databases. The guestossvc service interacts with the PhoenixSQLGuestPlugin service using this port. The PhoenixSQLGuestPlugin service cannot directly communicate with the backup proxy.

3389/22

TCP/UDP

During the backup cycle, the backup proxy sends network packets to Windows virtual machines (where VMware tools are installed) on port 3389 to identify if the RDP port is open or not. For Linux virtual machines, the port is 22, which is used for SSH.

This is used for Disaster Recovery or DR restores.

123

UDP

Backup proxy accesses NTP server on Port 123 (UDP) for time synchronization.

443

HTTPS+TLS

Druva uses TLS 1.2 or a secure connection that happens between the following:

  • Backup proxy and Druva Cloud

  • Backup proxy and TurboTier

  • TurboTier and Druva Cloud

VMware ESX

Source

Type

Protocol

Port range

Target

Description

VMware Proxy

Custom

TCP

902

VMware ESX

Use port 902 to establish a connection between the Backup proxy and ESXi host registered with Druva through vCenter Server.

VMware Proxy

Source

Type

Protocol

Port range

Target

Description

Failback VM

HTTPS

HTTP

443

VMware Proxy

Failback VM connects to the VMware Proxy over HTTPS 443 port for sending Failback progress updates.

Disaster Recovery

Click to view the ports and protocols

AWS Proxy (Inbound rules)

Source

Type

Protocol

Port range

Target

Description

My IP

SSH

TCP

22

AWS Proxy

This is an optional inbound rule.
You can use this inbound rule to log into the AWS Proxy via SSH client such as Putty.

AWS Proxy ( Outbound rules)

Source

Type

Protocol

Port range

Target

Description

AWS Proxy

HTTPS

TCP

443

0.0.0.0/0

Use to communicate with Druva Cloud and AWS Services

Failover EC2 Instance

Linux Failover EC2 Instance (Inbound rules)

Source

Type

Protocol

Port range

Target

Description

My IP (Post DR Failover Job)

SSH

TCP

22

Failover EC2 Instance

This is an optional inbound rule. You can use this rule to log into the Failover EC2 Instance via SSH client such as Putty.

Destination VMware Network (Post DR Failback Job)

SSH

TCP

22

Destination VMware Failback VM

You need this inbound rule for DR Failback. Use this rule to transfer data during DR Failback from Failover EC2 Instance to VMware Failback VM.

Linux Failover EC2 Instance (Outbound rules)

Source

Type

Protocol

Port range

Target

Description

Failover EC2 Instance

All Traffic

ALL

ALL

Anywhere IPv4 (0.0.0.0)

Use this outbound rule for DR Failback.

Source

Type

Protocol

Port range

Target

Description

Failover EC2 Instance

SSH

TCP

22

Destination VMware Failback VM

You need this outbound rule for DR Failback. Use this rule to transfer data during DR Failback from Failover EC2 Instance to VMware Failback VM.

Failover EC2 Instance

DNS

TCP

53

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Failover EC2 Instance

DNS

UDP

53

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Failover EC2 Instance

LDAP

TCP

389

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Failover EC2 Instance

LDAPS

TCP

636

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Failover EC2 Instance

LDAP

UDP

389

Domain Controller Network

Use this outbound rule to log to the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job

Failover EC2 Instance

custom TCP

TCP

88

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Failover EC2 Instance

custom UDP

UDP

88

Domain Controller Network

Use this outbound rule to log to the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Windows Failover EC2 Instance (Inbound rules)

Source

Type

Protocol

Port range

Target

Description

Destination VMware Network

SMB

TCP

445

Failover EC2 Instance

Use this inbound rule for DR Failback. This connection is used to communicate with the Failover EC2 Instance Admin Share.

Destination VMware Network

Custom TCP

TCP

50000

Failover EC2 Instance

Use this inbound for DR Failback.
This connection is used to transfer data from Failover EC2 Instance to VMware Failback VM.

My IP (Post DR Failover Job)

RDP

TCP

3389

Failover EC2 Instance

This is an optional inbound rule for DR Failover.
You can use this connection to log into the Failover EC2 Instance via RDP clients.

This rule is not required for DR Failback.

Windows Failover EC2 Instance (Outbound rules)

Source

Type

Protocol

Port range

Target

Description

Failover EC2 Instance

All Traffic

ALL

ALL

Anywhere IPv4 (0.0.0.0)

Use this outbound rule for DR Failback.

Source

Type

Protocol

Port range

Target

Description

Failover EC2 Instance

DNS

TCP

53

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Failover EC2 Instance

DNS

UDP

53

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Failover EC2 Instance

LDAP

TCP

389

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Failover EC2 Instance

LDAP

UDP

389

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Failover EC2 Instance

Kerberos

TCP

88

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Failover EC2 Instance

Kerberos

UDP

88

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

Failover EC2 Instance

SMB

TCP

445

Domain Controller Network

Use this outbound rule to log into the Failover EC2 Instance using your domain credentials after the DR Failover job completes or during the DR Failback job.

AWS SQS Endpoint

Source

Type

Protocol

Port range

Target

Description

Private Subnet of the VPC

HTTPS

HTTPS

443

SQS Interface Endpoint

Make sure the Interface Endpoint allows 443 inbound rule. For more information, see Amazon ECS interface VPC endpoints (AWS PrivateLink).

Hyper-V

Click to view the ports and protocols

Port

Communication protocol

Description

443

TLS

Druva uses Port 443 to establish a secure connection and communication between

Backup agent and Druva Cloud.

Nutanix AHV

Click to view the ports and protocols

Port

Communication protocol

Description

9440

HTTPS+SSL

Druva uses Port 9440 to establish a secure connection and communication between the Backup Proxy and Prism.

3261/3260

TCP (iSCSI)

Port 3260 and 3261 uses the iSCSI protocol over TCP and is responsible for block-level storage communication between the proxy and the Nutanix cluster.

443

TLS

Backup Proxy to Druva Cloud.

443

TLS

Backup Proxy to S3 bucket.

Proxmox

Click to view the ports and protocols

Port

Communication protocol

Description

443

HTTPS+SSL

Druva uses Port 443 to establish a secure connection and communication between

Backup Proxy and Druva Cloud

File Server

Click to view the ports and protocols

Port

Communication protocol

Description

443

TLS

Druva uses Port 443 to establish a secure connection and communication between

Backup agent and Druva Cloud.

NAS

Click to view the ports and protocols

Port

Communication protocol

Description

443

TLS

Druva uses Port 443 to establish a secure connection and communication between

Backup proxy and Druva Cloud.

MS SQL Server

Click to view the ports and protocols

Port

Communication protocol

Description

443

TLS

Druva uses Port 443 to establish a secure connection and communication between

Backup agent and Druva Cloud.

Oracle PBS

Click to view the ports and protocols

Port

Communication protocol

Description

443

TLS

Druva uses Port 443 to establish a secure connection and communication between

PBS and Druva Cloud.

Oracle DTC

Click to view the ports and protocols

Port

Communication protocol

Description

443

TLS

Druva uses Port 443 to establish a secure connection and communication between

Backup agent and Druva Cloud.

SAP HANA

Click to view the ports and protocols

Port

Communication protocol

Description

443

TLS

Druva uses Port 443 to establish a secure connection and communication between

Backup agent and Druva Cloud.

20000 to 20100

Used for internal communication within the cluster

21000

Used for internal communication within the cluster

TurboTier

Click to view the ports and protocols

Port

Communication protocol

Description

443

TLS

Druva uses Port 443 to establish a secure connection and communication between

Backup agent, TurboTier agent, and Druva Cloud.

2049

TCP/UDP

This is the main Network File System (NFS) port used for core operations. All file access, directory browsing, and data transfer (reading and writing) between a client and server run directly over this port. For modern NFSv4, this is often the only port required.

111

TCP/UDP

This port is used by the rpcbind (or portmapper) service. In older NFS versions (v2/v3), it communicates the correct (and often dynamic) port numbers to the clients for other services, such as the one responsible for mounting.


📝 Note

Port 8082 is used for internal communications on the host for FS, NAS, Hyper-V, VMware, Oracle DTC, and MS SQL. If port 8082 is unavailable, other available ephemeral ports will be used.


Did this answer your question?