Service Access¶
Before connecting to Veeam Cloud Connect for the first time, network access must be enabled on both sides:
- Cloud4You must allow connections from the customer's public IP addresses,
- the firewall on the customer side must allow outbound connections to Cloud4You endpoints.
Submitting public IP addresses¶
Access to Veeam Cloud Connect endpoints is enabled for specified public IP addresses.
To activate the service, send Cloud4You all public IP addresses from which backups or replications will be sent to Veeam Cloud Connect.
IP addresses can be submitted:
- through the Cloud4You support system,
- by email to:
Support portal:
Provide all public IP addresses
If the environment uses multiple Internet connections, multiple locations, NAT, or a backup WAN connection, provide all public IP addresses from which a connection to Cloud4You may be established.
A connection from an address that has not been previously submitted and allowed may be rejected.
How do I determine which public IP address to submit?¶
Provide the IP address visible on the Internet side for the server or network from which Veeam Backup & Replication will connect to Cloud4You.
If Veeam is behind NAT, do not provide its private address, for example:
Provide the public IP address used by the NAT/firewall.
Example:
Veeam Backup Server
192.168.10.20
│
▼
Firewall / NAT
203.0.113.25
│
▼
Internet
│
▼
Cloud4You Veeam Cloud Connect
In this case, submit the following address to Cloud4You:
Required port¶
On the customer side, allow outbound TCP connections to:
The port must be reachable for the following endpoints:
Required communication:
| Direction | Protocol | Port | Destination |
|---|---|---|---|
| customer → Cloud4You | TCP | 6180 |
connect.cloud4you.pl |
| customer → Cloud4You | TCP | 6180 |
connect2.cloud4you.pl |
| customer → Cloud4You | TCP | 6180 |
connect4.cloud4you.pl |
Do not restrict the configuration to a single endpoint
The firewall should allow connections to all specified Cloud4You endpoints.
This allows the service to operate correctly during maintenance, infrastructure changes, or when an alternative endpoint is used.
Example firewall rule¶
The rule logic should look like this:
SOURCE:
Veeam Backup & Replication server
or the network from which the connection is established
DESTINATION:
connect.cloud4you.pl
connect2.cloud4you.pl
connect4.cloud4you.pl
PROTOCOL:
TCP
DESTINATION PORT:
6180
ACTION:
ALLOW
Prefer FQDN-based rules
If your firewall supports rules based on FQDN names, we recommend using endpoint names instead of hard-coding IP addresses.
This means that an IP address change on the Cloud4You side will not require a manual firewall rule update.
DNS resolution test¶
Before testing the port, verify that the Veeam server resolves the endpoint names correctly.
Windows PowerShell¶
Resolve-DnsName connect.cloud4you.pl
Resolve-DnsName connect2.cloud4you.pl
Resolve-DnsName connect4.cloud4you.pl
If the command returns an IP address, DNS resolution is working correctly.
Port 6180 test¶
On the Veeam server, you can test port availability using PowerShell.
connect.cloud4you.pl¶
connect2.cloud4you.pl¶
connect4.cloud4you.pl¶
A correct result should contain:
Example:
If the test returns False¶
Example:
Check the following in order:
- whether the public IP address has been submitted to Cloud4You,
- whether Cloud4You has confirmed that access has been enabled,
- whether the customer firewall allows TCP/6180,
- whether the connection is blocked by a UTM, IPS, or proxy device,
- whether the Veeam server is using the expected public IP address,
- whether DNS resolves the endpoint name correctly.
Public IP address change¶
If the public IP address used by the Veeam environment changes, submit the new address to Cloud4You.
This applies, among other things, to:
- changing the Internet provider,
- changing WAN addressing,
- migration to another location,
- deploying a new firewall,
- changing NAT,
- enabling a backup Internet connection,
- moving the Veeam server to another data center.
An IP change may interrupt connectivity
If Veeam starts connecting from a public IP address that has not been previously allowed on the Cloud4You side, access to the service may stop working.
What should I include in the request?¶
Example request:
Subject:
Enable access to Veeam Cloud Connect
Please enable access to the Veeam Cloud Connect service
for the following public IP addresses:
203.0.113.10
203.0.113.11
These addresses will be used by the Veeam Backup & Replication server
to send backups to Cloud4You.
If this is a change to an existing configuration, it is also worth indicating which old IP addresses will no longer be used.
Summary¶
Before configuring the Service Provider in Veeam, complete these three steps:
1. Submit all public IP addresses to Cloud4You
↓
support.cloud4you.pl
or support@cloud4you.pl
2. Allow TCP/6180 on your firewall to:
↓
connect.cloud4you.pl
connect2.cloud4you.pl
connect4.cloud4you.pl
3. Test connectivity:
↓
Test-NetConnection <endpoint> -Port 6180
Only after network access has been confirmed should you proceed with adding Cloud4You as a Service Provider in Veeam Backup & Replication.