AWS Storage Gateway User Guide
Network and Firewall Requirements
Note
In some cases, you might deploy AWS Storage Gateway on Amazon EC2 or use other types of
deployment (including on-premises) with network security policies that restrict AWS IP address
ranges. In these cases, your gateway might experience service connectivity issues when the
AWS IP range values changes. The AWS IP address range values that you need to use are in the
Amazon service subset for the AWS Region that you activate your gateway in. For the current IP
in the
AWS General Reference.
Topics
•
•
Networking and Firewall Requirements for the AWS Storage Gateway Hardware Appliance (p. 17)
•
Allowing AWS Storage Gateway Access Through Firewalls and Routers (p. 19)
•
Configuring Security Groups for Your Amazon EC2 Gateway Instance (p. 20)
Port Requirements
AWS Storage Gateway requires certain ports to be allowed for its operation. The following illustrations
show the required ports that you must allow for each type of gateway. Some ports are required by all
gateway types, and others are required by specific gateway types. For more information about port
.
Common ports for all gateway types
The following ports are common to all gateway types and are required by all gateway types.
Protocol
Port
Direction
Source
Destination
How Used
TCP
443 (HTTPS)
Outbound
Storage
Gateway
AWS
For
communication
from AWS
Storage
Gateway to the
AWS service
endpoint. For
information
about service
endpoints,
.
TCP
80 (HTTP)
Inbound
AWS
Management
Console
Storage
Gateway
By local
systems
to obtain
the storage
gateway
activation key.
Port 80 is only
used during
activation of
the Storage
API Version 2013-06-30
13