You must be able to connect to the proxies and domains that are associated with your Metallic environment. Outbound network connectivity is needed for data transfer, device registration, and portal access.
Note:
Metallic does not support firewalls that use Server Name Indication (SNI).
If you have a Palo Alto Networks firewall and it is blocking Metallic network traffic, then you must configure the firewall to allow web browsing traffic from Metallic. For more information, see Palo Alto Firewalls.
For information on excluding Metallic service endpoints for your firewall, see the KB article "Network proxy information".
TCP 443 outbound must be open to access the following:
Metallic backup service (*.metallic.io)
Metallic storage (*.blob.core.windows.net)
Azure services (*.cloudapp.azure.com)
If applicable, your storage location in AWS (*.s3.amazonaws.com)
TCP 8400 and TCP 8403 must be open between the backup gateway and any on-prem data sources that you want to protect. Depending on the operation, either the client or the backup gateway can open a connection.
To back up on-prem VMware servers, the backup gateway must be able to access the VMware environment and components:
vSphere vCenter server: Port for web service (default: 443) must be opened. If vCenter is configured to use non-default ports, the non-default ports must also be opened.
vSphere ESX server: Ports for web service (default: 443) and TCP/IP (default: 902) must be opened for the vStorage APIs for data protection.
Note: If you use VMware Cloud on AWS (VMC) or Azure VMware Solution (AVS), there are no port requirements for the ESXi hosts.
To back up Hyper-V virtual machines (VMs), the Metallic VM proxy must be able to access the backup gateway on the port for the web service (default: 443).
Tenant computers must be able to connect to the following URLs (all URLs support HTTPS and can be accessed on port 443):
cloud.commvault.com (download software to install, update, or upgrade client computers)
downloadcenter.commvault.com (download software to install, update, or upgrade client computers)
https://time.akamai.com (fetch Akamai server time to generate Akamai token)
*.mapbox.com (provide location of the client or laptop, and fetches data such as city name)
*.skyhookwireless.com (provide location of the client or laptop, and fetches data such as city name)