Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Configuring Network Topologies, Gateways & Firewall Routes

Commvault
03/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


When convult components communicate or move data through a firewall, the network settings must be configured for each component. This is accomplished by configuring individual network settings for a specific client, or using network topologies where server group firewall configurations can be set for clients and infrastructure machines. There are several key configuration options available when configuring network routes. Connections between servers which can be restricted or blocked. The ports used to communicate through a firewall and routes which can be direct via a proxy or via a gateway. Convult components communicate using a traditional communication port as well as dynamic ports. If the system notices that the dynamic ports are blocked and therefore unavailable, it automatically encapsulates data transfers through a tunnel port. There is no need to configure any network topologies or network routes in the convult software. The only requirement is that the communication port 8400 and tunnel port 8403 are open and accessible between the components. Sometimes the default automatic tunneling ports cannot be used or they cannot be opened bidirectionally. If this is the case, network configurations must be used to define a different port or to set up specific communication settings. Convult software uses network topologies to simplify network configurations between server groups. The clients in the server groups can be the commserve server, media agents or client servers. By default there is a system created computer group called infrastructure that can be leveraged for network topologies containing the convult infrastructure components. Convult also utilizes smart groups that automatically groups machines based on their roles such as my commserve or my commserve and media agents. Let's look at the network topology types. A one-way network route is a direct connection with port restrictions where one side of a pair of communicating computers can establish a one-to-one connection towards the other on specific ports. A one-way network topology consists of two server groups. The first group is servers, which is the side that can initiate the connection. This is commonly the client servers. The second group is network gateways, where members of this group cannot initiate the connection. This is commonly the infrastructure machines. When creating a one-way network topology, the servers group has restricted communications on a specific port with the network gateways group. Direct connections are initiated with the network gateways group. These systems are in the untrusted networks such as the DMZ. When implementing the network topology, the network gateways group has blocked communication with the servers. A two-way network route is a direct connection with port restrictions where either side of a pair of communicating computers can establish a one-to-one connection towards the other on specific ports. A two-way network topology consists of a servers group and an infrastructure group, which contains the commserve infrastructure components. When implementing the two-way network topology, the servers have restricted communication on a specific port with the infrastructure machines. Infrastructure machines contains the commserve server and media agents. On the other side of the firewall, infrastructure machines have restricted communication on a specific port to the servers. The Commvault network gateway is a special configuration in which a dedicated Commvault agent is placed in a perimeter network that is configured to allow connections into the perimeter network. The network gateway authenticates, encrypts and allows the tunnel connections it accepts to connect the clients operating outside of the private network to clients operating inside of it. The Commvault network gateway supports NAT operations. Similar to a network gateway, a cascading network gateway configuration works where networks span multiple zones. In each zone, a dedicated Commvault agent is placed in the perimeter network that is configured to allow connections into the perimeter network. The cascading gateways communicate with each other and authenticate, encrypt and allow the tunnel connections between the zones. There are cases in which direct connectivity setups do not work. Consider the case of the commserve and media agents being located inside a company's internal network, with the entire network being exposed to the outside world through a single IP address. Typically, this IP address belongs to a firewall or gateway that works as a network address translation device for connections from the internal network to the outside. In scenarios like this, you can establish port forwarding at the gateway to forward connections received by specific gateway ports to clients on the internal network. You can then configure the client to open a direct connection to the port forwarder's IP address on a specific port to reach a particular internal server. This creates a custom route from the client towards the internal servers. A port forwarding gateway sends incoming connections to specific machines on the internal network based on the incoming connection's destination port number. Let's look at a short demonstration of how to create a network topology. I won't go through each type as the configuration steps and user experience are the same. Start by expanding Manage and selecting Network. Then, click the Network Topologies tile. This will show any topologies already configured. In the upper right, click Add Topology. Give it a name. Select whether the client type is servers or laptops. And then select your desired topology type. We'll create a cascading gateway topology. A diagram will show you the selected network type and the groups required. Click Next. Next, we'll select the client groups for each topology section. The servers, server gateways and network gateways. For the infrastructure machines, you can select manual client groups, automatic client groups such as infrastructure or smart groups such as MyCommServe or MyCommServe and Media Agents. By clicking the Advanced toggle switch, you can force configuration settings and change the port number and keep alive settings. Click Next to finally configure advanced options where you can select to encrypt traffic, choose the tunnel protocol and set the number of parallel data transfer streams. Click Submit. Your topology will be created and the configuration settings will be automatically pushed to the relevant servers.

TL;DR

  • Commvault uses port 8400 for communication and port 8403 for automatic tunneling when dynamic ports are blocked, requiring no additional network configuration in most environments.
  • Network topologies simplify firewall configurations by defining communication rules between server groups, with options for one-way routes (client-initiated only) and two-way routes (bidirectional).
  • Network gateways are dedicated agents placed in perimeter networks that authenticate, encrypt, and tunnel connections between external clients and internal infrastructure, supporting NAT operations.
  • Cascading gateway configurations enable secure communication across multiple network zones by chaining gateway agents that authenticate and encrypt tunnel connections between zones.

This technical tutorial provides a comprehensive walkthrough of Commvault network configuration options for managing communication between backup infrastructure components across firewalls and segmented networks. The video explains how Commvault components use both standard communication ports and dynamic ports for data transfer, with automatic tunneling capabilities that encapsulate traffic through port 8403 when dynamic ports are blocked. Administrators learn that network topology configuration is only necessary when default automatic tunneling cannot be used or when specific firewall rules require custom routing. The tutorial covers the key topology types available in Commvault, including one-way network routes where only one side can initiate connections (typically client servers connecting to infrastructure in untrusted zones like DMZs), and two-way network routes that allow bidirectional communication with port restrictions. Network gateways are explained as dedicated Commvault agents placed in perimeter networks that authenticate, encrypt, and tunnel connections between external and internal clients, with support for NAT operations. The video also addresses cascading gateway configurations for environments spanning multiple network zones, where gateways in each zone communicate with each other to maintain secure tunneled connections. Port forwarding scenarios are covered for situations where internal infrastructure is exposed through a single external IP address, allowing specific gateway ports to forward connections to internal servers. The demonstration portion walks through creating a cascading gateway topology in the Commvault interface, showing how to select client groups, configure infrastructure machines using manual groups or smart groups, and set advanced options including encryption, tunnel protocol selection, and parallel data transfer stream configuration.

Chapters

0:00 - Network Configuration Fundamentals
1:17 - When Configuration Is Required
2:04 - Network Topology Types
3:53 - Network Gateways
4:23 - Cascading Gateways
5:53 - Creating a Network Topology

Key Quotes

1:01 "There is no need to configure any network topologies or network routes in the convult software. The only requirement is that the communication port 8400 and tunnel port 8403 are open and accessible between the components."
1:33 "Convult software uses network topologies to simplify network configurations between server groups."
3:53 "The Commvault network gateway is a special configuration in which a dedicated Commvault agent is placed in a perimeter network that is configured to allow connections into the perimeter network."
4:05 "The network gateway authenticates, encrypts and allows the tunnel connections it accepts to connect the clients operating outside of the private network to clients operating inside of it."

Categories:
  • » Webinar Library » Commvault
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Network Configuration
  • Firewall Management
  • Network Topologies
  • Port Forwarding
  • Network Gateways
  • Tunneling
  • DMZ Architecture
  • Data Protection Infrastructure
  • Commvault Administration
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Configuring Network Topologies, Gateways & Firewall Routes

              XStreaminars (watch here)

              • Jul
                29

                Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                07/29/202601:00 PM ET
                More events

                Industry Events (watch there)

                • Aug
                  03

                  Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                  08/03/202611:00 AM ET
                  • Aug
                    06

                    Safeguarding Sensitive Data in the Era of AI Adoption

                    08/06/202604:00 AM ET
                    • Aug
                      06

                      Same Tactics, Enhanced Speed: AI Agents’ Impact on Identity Attacks

                      08/06/202602:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 07/29/2026
                        04:00 AM
                        07/29/2026
                        Real-Time Strategies for Protecting Against Prompt Injections
                        https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-protecting-against-prompt-injections/
                      • 07/29/2026
                        01:00 PM
                        07/29/2026
                        Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                        https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                      • 08/03/2026
                        11:00 AM
                        08/03/2026
                        Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                        https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                      • 08/06/2026
                        04:00 AM
                        08/06/2026
                        Safeguarding Sensitive Data in the Era of AI Adoption
                        https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-ai-adoption/
                      • 08/06/2026
                        02:00 PM
                        08/06/2026
                        Same Tactics, Enhanced Speed: AI Agents’ Impact on Identity Attacks
                        https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-speed-ai-agents-impact-on-identity-attacks/
                      • 08/07/2026
                        11:30 AM
                        08/07/2026
                        Refreshing Drinks and Essential Cybersecurity Strategies for the Season
                        https://www.truthinit.com/index.php/channel/2063/refreshing-drinks-and-essential-cybersecurity-strategies-for-the-season/
                      • 08/13/2026
                        12:00 PM
                        08/13/2026
                        Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                        https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                      • 08/19/2026
                        12:00 PM
                        08/19/2026
                        Becoming Agent Ready: Insights and Strategies with Cyera
                        https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version