You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- Azure subscription - [create one for free](https://azure.microsoft.com/free/)
34
40
35
41
> [!IMPORTANT]
36
-
> Currently, portal console support, and persistence to firewall storage accounts are not supported.
37
-
> When using private link, you cannot export or import a cache that to a [storage account](/azure/storage/common/storage-network-security) that has firewall enabled.
42
+
> Currently, the [portal-based redis console](cache-configure.md#redis-console) is not supported with private link.
43
+
>
44
+
45
+
> [!IMPORTANT]
46
+
> When using private link, you cannot export or import data to a to a storage account that has firewall enabled unless you're using [managed identity to autenticate to the storage account](cache-managed-identity.md).
47
+
> For more information, see [How to export if I have firewall enabled on my storage account?](cache-how-to-import-export-data.md#how-to-export-if-i-have-firewall-enabled-on-my-storage-account)
38
48
>
39
49
40
50
## Create a private endpoint with a new Azure Cache for Redis instance
### How do I connect to my cache with private endpoint?
341
351
342
-
Your application should connect to `<cachename>.redis.cache.windows.net` on port `6380`. We recommend avoiding the use of `<cachename>.privatelink.redis.cache.windows.net` in configuration or connection string.
352
+
For **Basic, Standard, and Premium tier** caches, your application should connect to `<cachename>.redis.cache.windows.net` on port `6380`.
353
+
354
+
For **Enterprise and Enterprise Flash** tier caches, your application should connect to `<cachename>.<region>.redisenterprise.cache.azure.net` on port `10000`.
343
355
344
-
A private DNS zone, named `*.privatelink.redis.cache.windows.net`, is automatically created in your subscription. The private DNS zone is vital for establishing the TLS connection with the private endpoint.
356
+
A private DNS zone, named `*.privatelink.redis.cache.windows.net`, is automatically created in your subscription. The private DNS zone is vital for establishing the TLS connection with the private endpoint. We recommend avoiding the use of `<cachename>.privatelink.redis.cache.windows.net` in configuration or connection string.
345
357
346
358
For more information, see [Azure services DNS zone configuration](../private-link/private-endpoint-dns.md).
347
359
348
360
### Why can't I connect to a private endpoint?
349
361
350
-
- Private endpoints can't be used with your cache instance if your cache is already a VNet injected cache.
362
+
- Private endpoints can't be used with your cache instance if your cache is already using the VNet injection network connection method.
351
363
- You have a limit of one private link for clustered caches. For all other caches, your limit is 100 private links.
352
-
- You try to [persist data to storage account](cache-how-to-premium-persistence.md)where firewall rules are applied might prevent you from creating the Private Link.
364
+
- You try to [persist data to a storage account](cache-how-to-premium-persistence.md)with firewall rules and you're not using managed identity to connect to the storage account.
353
365
- You might not connect to your private endpoint if your cache instance is using an [unsupported feature](#what-features-arent-supported-with-private-endpoints).
354
366
355
367
### What features aren't supported with private endpoints?
356
368
357
369
- Trying to connect from the Azure portal console is an unsupported scenario where you see a connection failure.
358
-
- Private links can't be added to caches that are already geo-replicated. To add a private link to a geo-replicated cache: 1. Unlink the geo-replication. 2. Add a Private Link. 3. Last, relink the geo-replication.
370
+
- Private links can't be added to Premium tier caches that are already geo-replicated. To add a private link to a cache using [passive geo-replication](cache-how-to-geo-replication.md): 1. Unlink the geo-replication. 2. Add a Private Link. 3. Last, relink the geo-replication.
359
371
360
372
### How do I verify if my private endpoint is configured correctly?
361
373
@@ -378,7 +390,7 @@ To change the value in the Azure portal, follow these steps:
378
390
379
391
1. Select the **Enable public network access** button.
380
392
381
-
To change the value through a RESTful API PATCH request, use the following code and edit the value to reflect the flag you want for your cache.
393
+
You can also change the value through a RESTful API PATCH request. For example, use the following code for a Basic, Standard, or Premium tier cache and edit the value to reflect the flag you want for your cache.
0 commit comments