Connecting a backup network
To use IBM® Cloud Sync to back up DNS data, connect a backup network from IBM NS1 Connect® to an Amazon Simple Storage Service (S3) bucket.
Before you begin
- A Cloud Sync subscription
- An Amazon Web Services (AWS) account with permissions to create policies and roles
- Amazon S3 as your storage service
- An Amazon S3 bucket with a unique name
About this task
Configuring a backup network is a multistep process that you complete in NS1 Connect and in AWS. If you need help on using AWS, refer to its help documentation.
Connect to an external network through which NS1 Connect backs up DNS data. Enter the account ID and the unique name of the Amazon S3 bucket.
Enable cross-account access to allow NS1 Connect to perform DNS actions in your AWS account. To do so, you create an identity access management (IAM) policy and role for the NS1 Connect account for Cloud Sync services. This helps ensure that NS1 Connect can perform certain actions on certain objects through a trusted role in the NS1 Connect account. NS1 Connect validates that the AWS account ID that you provide is for an account that you control. NS1 Connect can then verify that it can perform certain actions in your AWS account.
If you can't validate the network connection when you initially connect a network, you can validate it later. Only when the network connection is validated can Cloud Sync back up data from NS1 Connect to Amazon S3.
Connecting a backup network is a one-time setup for each Amazon S3 bucket.
Procedure
What to do next
If the connection was validated successfully, publish zones to the network to start backing up the DNS data. Every time a DNS change is made in NS1 Connect, Cloud Sync backs up the changes to Amazon S3.
If the Connection validated section of the Summary page showed an error, you must validate the connection. Otherwise, the DNS data isn't backed up to Amazon S3 even if you publish a zone to this network in NS1 Connect.
If you have other networks through which you want to back up data to AmazonS3, repeat the preceding steps for each network.