AWS Storage Gateway User Guide
Network and Firewall Requirements
For more information on activating and configuring a hardware appliance, see
Gateway Hardware Appliance (p. 24)
Allowing AWS Storage Gateway Access Through Firewalls and
Routers
Your gateway requires access to the following endpoints to communicate with AWS. If you use a firewall
or router to filter or limit network traffic, you must configure your firewall and router to allow these
service endpoints for outbound communication to AWS.
The following service endpoints are required by all gateways for control path (anon-cp, client-cp, proxy-
app) and data path (dp-1) operations.
anon-cp.storagegateway.
region
.amazonaws.com.cn:443
client-cp.storagegateway.
region
.amazonaws.com.cn:443
proxy-app.storagegateway.
region
.amazonaws.com.cn:443
dp-1.storagegateway.
region
.amazonaws.com.cn:443
The following service endpoint is required to make API calls.
storagegateway.
region
.amazonaws.com.cn:443
The Amazon S3 service endpoint, shown following, is used by file gateways only. A file gateway requires
this endpoint to access the S3 bucket that a file share maps to.
If your gateway can't determine the AWS Region where your S3 bucket is located, this endpoint defaults
to us-east-1.s3.amazonaws.com. We recommend that you whitelist the us-east-1 region in addition to
AWS Regions where your gateway is activated, and where your S3 bucket is located.
region
.s3.amazonaws.com.cn
The Amazon CloudFront endpoint following is required for Storage Gateway to get the list of available
AWS Regions.
https://d4kdq0yaxexbo.cloudfront.net/
A Storage Gateway VM is configured to use the following NTP servers.
0.amazon.pool.ntp.org
1.amazon.pool.ntp.org
2.amazon.pool.ntp.org
API Version 2013-06-30
19