You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- Azure subscription - [create one for free](https://azure.microsoft.com/free/)
34
40
35
41
> [!IMPORTANT]
36
-
> Currently, portal console support, and persistence to firewall storage accounts are not supported.
37
-
> When using private link, you cannot export or import a cache that to a [storage account](/azure/storage/common/storage-network-security) that has firewall enabled.
42
+
> Currently, the [portal-based redis console](cache-configure.md#redis-console) is not supported with private link.
43
+
>
44
+
45
+
> [!IMPORTANT]
46
+
> When using private link, you cannot export or import data to a to a storage account that has firewall enabled unless you're using [managed identity to autenticate to the storage account](cache-managed-identity.md).
47
+
> For more information, see [How to export if I have firewall enabled on my storage account?](cache-how-to-import-export-data.md#how-to-export-if-i-have-firewall-enabled-on-my-storage-account)
38
48
>
39
49
40
50
## Create a private endpoint with a new Azure Cache for Redis instance
### How do I connect to my cache with private endpoint?
341
351
342
-
Your application should connect to `<cachename>.redis.cache.windows.net` on port `6380`. We recommend avoiding the use of `<cachename>.privatelink.redis.cache.windows.net` in configuration or connection string.
352
+
For **Basic, Standard, and Premium tier** caches, your application should connect to `<cachename>.redis.cache.windows.net` on port `6380`. A private DNS zone, named `*.privatelink.redis.cache.windows.net`, is automatically created in your subscription. The private DNS zone is vital for establishing the TLS connection with the private endpoint. We recommend avoiding the use of `<cachename>.privatelink.redis.cache.windows.net` in configuration or connection string.
343
353
344
-
A private DNS zone, named `*.privatelink.redis.cache.windows.net`, is automatically created in your subscription. The private DNS zone is vital for establishing the TLS connection with the private endpoint.
354
+
For **Enterprise and Enterprise Flash** tier caches, your application should connect to `<cachename>.<region>.redisenterprise.cache.azure.net` on port `10000`.
345
355
346
356
For more information, see [Azure services DNS zone configuration](../private-link/private-endpoint-dns.md).
347
357
348
358
### Why can't I connect to a private endpoint?
349
359
350
-
- Private endpoints can't be used with your cache instance if your cache is already a VNet injected cache.
360
+
- Private endpoints can't be used with your cache instance if your cache is already using the VNet injection network connection method.
351
361
- You have a limit of one private link for clustered caches. For all other caches, your limit is 100 private links.
352
-
- You try to [persist data to storage account](cache-how-to-premium-persistence.md)where firewall rules are applied might prevent you from creating the Private Link.
362
+
- You try to [persist data to a storage account](cache-how-to-premium-persistence.md)with firewall rules and you're not using managed identity to connect to the storage account.
353
363
- You might not connect to your private endpoint if your cache instance is using an [unsupported feature](#what-features-arent-supported-with-private-endpoints).
354
364
355
365
### What features aren't supported with private endpoints?
356
366
357
367
- Trying to connect from the Azure portal console is an unsupported scenario where you see a connection failure.
358
-
- Private links can't be added to caches that are already geo-replicated. To add a private link to a geo-replicated cache: 1. Unlink the geo-replication. 2. Add a Private Link. 3. Last, relink the geo-replication.
368
+
- Private links can't be added to Premium tier caches that are already geo-replicated. To add a private link to a cache using [passive geo-replication](cache-how-to-geo-replication.md): 1. Unlink the geo-replication. 2. Add a Private Link. 3. Last, relink the geo-replication.
359
369
360
370
### How do I verify if my private endpoint is configured correctly?
361
371
@@ -378,7 +388,7 @@ To change the value in the Azure portal, follow these steps:
378
388
379
389
1. Select the **Enable public network access** button.
380
390
381
-
To change the value through a RESTful API PATCH request, use the following code and edit the value to reflect the flag you want for your cache.
391
+
You can also change the value through a RESTful API PATCH request. For example, use the following code for a Basic, Standard, or Premium tier cache and edit the value to reflect the flag you want for your cache.
0 commit comments