Connecting your network for AWS DataSync transfers (original) (raw)

If you need an AWS DataSync agent, you must establish several network connections for a data transfer. The following diagram shows the three network connections in a DataSync transfer from a storage system (which could be on premises, in another cloud, or at the edge) to an AWS storage service.

Alt text should describe what's relevant about the image and end with a period.

1. Network connection between your storage system and agent

Your DataSync agent connects to your on-premises, other cloud, or edge storage system. For more information, see Network requirements for on-premises, self-managed, other cloud, and edge storage.

2. Network connection between your agent and DataSync service

There are a few aspects to connecting your agent to the DataSync service. First, you must connect your storage network to AWS. Second, your agent needs a service endpoint to communicate with DataSync.

Connecting your storage network to AWS

When using DataSync, consider the following options for connecting your storage network to AWS:

Choosing a service endpoint

Your agent uses a service endpoint to communicate with DataSync. For more information, see Choosing a service endpoint for your AWS DataSync agent.

3. Network connection between DataSync service and AWS storage service

To connect DataSync to an AWS storage service, you just have to make sure that the DataSync service can access your S3 bucket or file system. For more information, see Network requirements for AWS storage services.

Networking when you don't need a DataSync agent

For transfers that don't require a DataSync agent, you just have to make sure that the DataSync service can access the AWS storage services you’re transferring between. For more information, see Network requirements for AWS storage services.

How and where DataSync traffic flows through the network

DataSync has data plane and control plane traffic. Knowing how each of these flows through the network is important if you want to separate your DataSync traffic.

Network security for DataSync

For information about how your storage data (including metadata) is secured during a transfer, see AWS DataSync encryption in transit.