You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@@ -44,7 +44,7 @@ You can restrict public access to the private endpoint of your cache by disablin
44
44
45
45
> [!IMPORTANT]
46
46
> When using private link, you cannot export or import data to a to a storage account that has firewall enabled unless you're using [managed identity to autenticate to the storage account](cache-managed-identity.md).
47
-
> For more information, see [How to export if I have firewall enabled on my storage account?](cache-how-to-import-export-data.md#how-to-export-if-i-have-firewall-enabled-on-my-storage-account)
47
+
> For more information, see [How to export if I have firewall enabled on my storage account?](cache-how-to-import-export-data.md#how-to-export-if-i-have-firewall-enabled-on-my-storage-account)
48
48
>
49
49
50
50
## Create a private endpoint with a new Azure Cache for Redis instance
### How do I connect to my cache with private endpoint?
351
351
352
-
For **Basic, Standard, and Premium tier** caches, your application should connect to `<cachename>.redis.cache.windows.net` on port `6380`. A private DNS zone, named `*.privatelink.redis.cache.windows.net`, is automatically created in your subscription. The private DNS zone is vital for establishing the TLS connection with the private endpoint. We recommend avoiding the use of `<cachename>.privatelink.redis.cache.windows.net` in configuration or connection string.
352
+
For **Basic, Standard, and Premium tier** caches, your application should connect to `<cachename>.redis.cache.windows.net` on port `6380`. A private DNS zone, named `*.privatelink.redis.cache.windows.net`, is automatically created in your subscription. The private DNS zone is vital for establishing the TLS connection with the private endpoint. We recommend avoiding the use of `<cachename>.privatelink.redis.cache.windows.net` in configuration or connection string.
353
353
354
-
For **Enterprise and Enterprise Flash** tier caches, your application should connect to `<cachename>.<region>.redisenterprise.cache.azure.net` on port `10000`.
354
+
For **Enterprise and Enterprise Flash** tier caches, your application should connect to `<cachename>.<region>.redisenterprise.cache.azure.net` on port `10000`.
355
355
356
356
For more information, see [Azure services DNS zone configuration](../private-link/private-endpoint-dns.md).
357
357
358
358
### Why can't I connect to a private endpoint?
359
359
360
-
- Private endpoints can't be used with your cache instance if your cache is already using the VNet injection network connection method.
361
-
- You have a limit of one private link for clustered caches. For all other caches, your limit is 100 private links.
362
-
- You try to [persist data to a storage account](cache-how-to-premium-persistence.md) with firewall rules and you're not using managed identity to connect to the storage account.
360
+
- Private endpoints can't be used with your cache instance if your cache is already a VNet injected cache.
361
+
362
+
- On Premium tier caches, you have a limit of one private link for clustered caches. Enterprise and Enterprise Flash tier caches do not have this limitation for clustered caches. For all other caches, your limit is 100 private links.
363
+
364
+
- You try to [persist data to storage account](cache-how-to-premium-persistence.md) where firewall rules are applied might prevent you from creating the Private Link.
365
+
363
366
- You might not connect to your private endpoint if your cache instance is using an [unsupported feature](#what-features-arent-supported-with-private-endpoints).
364
367
365
368
### What features aren't supported with private endpoints?
366
369
367
370
- Trying to connect from the Azure portal console is an unsupported scenario where you see a connection failure.
368
-
- Private links can't be added to Premium tier caches that are already geo-replicated. To add a private link to a cache using [passive geo-replication](cache-how-to-geo-replication.md): 1. Unlink the geo-replication. 2. Add a Private Link. 3. Last, relink the geo-replication.
371
+
372
+
- Private links can't be added to caches that are already using [passive geo-replication](cache-how-to-geo-replication.md) in the Premium tier. To add a private link to a geo-replicated cache: 1. Unlink the geo-replication. 2. Add a Private Link. 3. Last, relink the geo-replication. (Enterprise tier caches using [active geo-replication](cache-how-to-active-geo-replication.md) do not have this restriction.)
369
373
370
374
### How do I verify if my private endpoint is configured correctly?
371
375
@@ -398,6 +402,7 @@ You can also change the value through a RESTful API PATCH request. For example,
398
402
}
399
403
400
404
```
405
+
401
406
For more information, see [Redis - Update](/rest/api/redis/Redis/Update?tabs=HTTP).
402
407
403
408
### How can I migrate my VNet injected cache to a Private Link cache?
0 commit comments