The CommServe host, MediaAgent, and the proxy must all be able to communicate with each other by using one of the following connections:
- 
AWS Direct Connect - On premises components and the AWS instance are within the same network. No firewall configuration is required.
 - 
AWS VPN - Only available if the AWS instance is accessible through VPC. On-premises components and the AWS instance are within the same network. No firewall configuration is required.
 - 
If you do not use AWS Direct Connect or AWS VPN for communication between on-premises components and the AWS proxy, you can configure a firewall by using one of the following methods:
- 
If you use one proxy server and one Amazon RDS Virtualization client, then you can first configure a Commvault firewall connection between the on-premises components and the AWS proxy.
 - 
If you have multiple proxy servers or multiple Amazon RDS Virtualization clients, then you can configure a firewall. For more information, see Amazon RDS Protection Using Native Database Utilities Firewall.
 
 -