<a id="clusters-connect-cloud"></a>

# Manage Networking for Confluent Cloud Connectors

This topic provides an overview of the networking features supported for fully
managed connectors in Confluent Cloud.

The following diagram summarizes networking features supported for fully managed
connectors. You can use it as the starting point when you determine the public
or private networking for fully managed connectors.

For Confluent Cloud networking details, see the [Cloud Networking docs](../../networking/overview.md#cloud-networking).

![image](connectors/networking/images/connector-networking.png)

<a id="connect-cloud-target-system-networking-supportability"></a>

## Target service networking supportability

The following table lists the networking supportability of the connectors with
links to associated setup guides.

| External Target Service                                                                                                                                                             | Confluent Cloud PNI Egress (AWS)                 | Confluent Cloud Private Link (AWS Dedicated & Enterprise)                                                                                                    | Confluent Cloud Private Link (Azure Dedicated & Enterprise)                                       | Confluent Cloud Private Link (Google Cloud Dedicated)                                      | Confluent Cloud Peering / Transit Gateway                                                                                                                                                                                                                                     | Confluent Cloud Public             |
|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------|
| Self-managed services                                                                                                                                                               | Yes                                              | [Yes](aws-eap-self-managed.md#cc-aws-eap-self-managed)                                                                                                       | [Yes](azure-eap-self-managed.md#cc-azure-eap-self-managed)                                        | Yes                                                                                        | Yes with DNS Forwarding: [AWS](../../networking/aws-dns-forwarding.md#dns-forwarding-ccloud-aws),<br/>[Azure](../../networking/peering/azure-peering.md#dns-forwarding-azure-peering),<br/>[Google Cloud](../../networking/peering/gcp-peering.md#dns-forwarding-gcp-peering) | Yes only if the endpoint is public |
| AWS first-party services<br/><br/>- S3<br/>- Kinesis<br/>- Lambda<br/>- DynamoDB<br/>- Cloudwatch<br/>- SQS                                                                         | Yes                                              | [Yes](aws-eap-1st-party.md#cc-aws-eap-1st-party)                                                                                                             | Yes only if the endpoint is public                                                                | Yes only if the endpoint is public                                                         | Yes                                                                                                                                                                                                                                                                           | Yes only if the endpoint is public |
| RDS                                                                                                                                                                                 | Yes                                              | [Yes](aws-eap-rds.md#cc-aws-eap-rds)                                                                                                                         | Yes only if the endpoint is public                                                                | Yes only if the endpoint is public                                                         | Yes                                                                                                                                                                                                                                                                           | Yes only if the endpoint is public |
| DocumentDB                                                                                                                                                                          | Yes                                              | [Yes](aws-eap-documentdb.md#cc-aws-eap-documentdb)                                                                                                           | Yes only if the endpoint is public                                                                | Yes only if the endpoint is public                                                         | Yes                                                                                                                                                                                                                                                                           | Yes only if the endpoint is public |
| OpenSearch                                                                                                                                                                          | Yes                                              | If private connectivity is required, use [OpenSearch Ingestion](https://www.confluent.io/blog/amazon-opensearch-ingestion-adds-support-for-confluent-cloud). | Yes only if the endpoint is public                                                                | Yes only if the endpoint is public                                                         | Yes                                                                                                                                                                                                                                                                           | Yes only if the endpoint is public |
| Azure first-party services<br/><br/>- Blob<br/>- Event Hubs<br/>- Service Bus<br/>- SQL Server<br/>- CosmoDB                                                                        | No                                               | Yes only if the endpoint is public                                                                                                                           | [Yes](azure-eap-1st-party.md#cc-azure-eap-1st-party)                                              | Yes only if the endpoint is public                                                         | Yes with [Azure DNS Forwarding](../../networking/peering/azure-peering.md#dns-forwarding-azure-peering)                                                                                                                                                                       | Yes only if the endpoint is public |
| Google Cloud first-party services<br/><br/>- Google Cloud Storage<br/>- BigQuery<br/>- Google Pub/Sub<br/>- Google Cloud Functions<br/>- Google Cloud Spanner CDC Source (Debezium) | No                                               | Yes only if the endpoint is public                                                                                                                           | Yes only if the endpoint is public                                                                | [Yes](gcp-eap-1st-party.md#cc-gcp-eap-1st-party)                                           | Yes only if the endpoint is public                                                                                                                                                                                                                                            | Yes only if the endpoint is public |
| Snowflake                                                                                                                                                                           | No                                               | [Yes](../cc-snowflake-sink/cc-snowflake-sink-eap-aws.md#cc-snowflake-sink-eap-aws)                                                                           | [Yes](../cc-snowflake-sink/cc-snowflake-sink-eap-azure.md#cc-snowflake-sink-eap-azure)            | [Yes](../cc-snowflake-sink/cc-snowflake-sink-eap-gcp.md#cc-snowflake-sink-eap-gcp)         | Yes                                                                                                                                                                                                                                                                           | Yes only if the endpoint is public |
| MongoDB Atlas                                                                                                                                                                       | No                                               | [Yes](../cc-mongo-db-sink/cc-mongo-db-sink-eap-aws.md#cc-mongo-db-sink-eap-aws)                                                                              | [Yes](../cc-mongo-db-sink/cc-mongo-db-sink-eap-azure.md#cc-mongo-db-sink-eap-azure)               | [Yes](../cc-mongo-db-sink/cc-mongo-db-sink-eap-gcp.md#cc-mongo-db-sink-eap-gcp)            | Yes                                                                                                                                                                                                                                                                           | Yes only if the endpoint is public |
| Neo4j                                                                                                                                                                               | No                                               | [Yes](../cc-neo4j-sink/cc-neo4j-sink-eap-aws.md#cc-neo4j-sink-eap-aws)                                                                                       | Yes only for self-managed Neo4j instances on Azure                                                | Yes only for self-managed Neo4j instances on Google Cloud                                  | Yes                                                                                                                                                                                                                                                                           | Yes only if the endpoint is public |
| ElasticSearch                                                                                                                                                                       | No                                               | Yes                                                                                                                                                          | Yes only if the endpoint is public. Resource Alias is not currently supported by Confluent Cloud. | Yes                                                                                        | Yes                                                                                                                                                                                                                                                                           | Yes only if the endpoint is public |
| Salesforce                                                                                                                                                                          | No                                               | Yes                                                                                                                                                          | Yes                                                                                               | Yes                                                                                        | Yes                                                                                                                                                                                                                                                                           | Yes only if the endpoint is public |
| Splunk                                                                                                                                                                              | No                                               | Yes                                                                                                                                                          | Yes                                                                                               | Yes                                                                                        | Yes                                                                                                                                                                                                                                                                           | Yes only if the endpoint is public |
| Couchbase                                                                                                                                                                           | No                                               | Yes                                                                                                                                                          | Yes                                                                                               | No                                                                                         | No                                                                                                                                                                                                                                                                            | Yes only if the endpoint is public |
| ClickHouse                                                                                                                                                                          | Yes only for self-managed ClickHouse in your VPC | [Yes](../cc-clickhouse-sink-connector/cc-clickhouse-sink-eap-aws.md#cc-clickhouse-sink-eap-aws)                                                              | [Yes](../cc-clickhouse-sink-connector/cc-clickhouse-eap-azure.md#cc-clickhouse-sink-eap-azure)    | [Yes](../cc-clickhouse-sink-connector/cc-clickhouse-eap-gcp.md#cc-clickhouse-sink-eap-gcp) | Yes                                                                                                                                                                                                                                                                           | Yes only if the endpoint is public |

The following pages describe how to configure private egress connectivity for
connectors:

* [Use Private Network Interface on Confluent Cloud](../../networking/aws-pni.md#pni-overview-aws)
* [Use AWS Egress PrivateLink Endpoints](../../networking/aws-egress-privatelink.md#cloud-networking-privatelink-aws-egress)
* [Use Azure Egress Private Link Endpoints](../../networking/azure-egress-privatelink.md#cloud-networking-privatelink-azure-egress)
* [Use Egress Private Service Connect Endpoints](../../networking/gcp-egress-psc.md#cloud-networking-gcp-psc-egress)

<a id="cloud-connect-egress-ip-address-range"></a>

## Egress IP address ranges

The following tabs provide network connectivity IP address details. Note that a
Connect node runs in the same VPC/VNet as the cluster the Connect node was
provisioned with. This is true for all cluster types (Basic, Standard, Enterprise, Dedicated, and Freight). For
Confluent Cloud networking details, see the [Cloud Networking docs](../../networking/overview.md#cloud-networking).

Public egress IP addresses are available on all the major cloud platforms. For
details, see [Public Egress IP Addresses for Confluent Cloud Connectors](../static-egress-ip.md#cc-static-egress-ips).

Public egress IP addresses are not supported with [Custom Connectors](../bring-your-connector/overview.md#cc-bring-your-connector).

### Public connectivity

The following information applies to a fully managed Sink or Source
connector connecting to an external system using a public IP address.

| Cluster network type            | Public IP address connectivity   | IP range used by the connector                                                                                                                     |
|---------------------------------|----------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------|
| Public Endpoint                 | Yes                              | A set of public egress IP addresses (see [Public Egress IP Addresses for Confluent Cloud Connectors](../static-egress-ip.md#cc-static-egress-ips)) |
| VPC Peering and Transit Gateway | Yes                              | Dynamic public IP/CIDR range from the cloud provider region where the Confluent Cloud cluster is located                                           |
| Private Link                    | Yes                              | Dynamic public IP/CIDR range from the cloud provider region where the Confluent Cloud cluster is located                                           |

### Private connectivity

The following information applies to a fully managed Sink or Source
connector connecting to an external system using a private IP address.

| Cluster network type            | Private IP address connectivity                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | IP range used by the connector                                                                                   |
|---------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------|
| PNI (AWS)                       | Yes. Egress routes (CIDR blocks) must be configured on the access point. [DNS Forwarding](#clusters-connect-cloud-dns) is required when a private DNS is in use.                                                                                                                                                                                                                                                                                                                                                           | The private IP address of the Elastic Network Interface (ENI) in the customer’s VPC                              |
| VPC Peering and Transit Gateway | Yes. [DNS Forwarding](#clusters-connect-cloud-dns) is required when a private DNS is in use.                                                                                                                                                                                                                                                                                                                                                                                                                               | The source IP address used is from the /16 CIDR range configured by the customer for the Confluent Cloud cluster |
| Private Link                    | AWS: Yes using [Egress PrivateLink Endpoint on AWS](../../networking/aws-egress-privatelink.md#cloud-networking-privatelink-aws-egress) <sub>[\*]</sub><br/><br/><br/><br/><br/>Azure: Yes using [Egress Private Link Endpoint on Azure](../../networking/azure-egress-privatelink.md#cloud-networking-privatelink-azure-egress) <sub>[\*]</sub><br/><br/><br/><br/><br/>GCP: Yes using [Egress Private Link Endpoint on Google Cloud](../../networking/gcp-egress-psc.md#cloud-networking-gcp-psc-egress) <sub>[\*]</sub> | The IP address of the load balancer which hosts the private link service                                         |
| Public Endpoint                 | No                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | N/A                                                                                                              |

<sub>[\*]</sub> The price premium will be $0.03/task/hour for Egress Private
Link Endpoints. For more information about Confluent Cloud connector pricing, see
[Confluent Pricinng](https://www.confluent.io/confluent-cloud/pricing).

<br/>

See the following cloud provider documentation for additional information:

* [Amazon Web Services IP address ranges](https://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.html)
* [Microsoft Azure IP address Ranges and Service Tags (PDF Download)](https://www.microsoft.com/en-us/download/details.aspx?id=56519)
* [Google Cloud IP address ranges](https://cloud.google.com/compute/docs/faq#find_ip_range)

<a id="clusters-connect-cloud-dns"></a>

## DNS zones

The Domain Name System (DNS) is the system used to translate URLs/Hostnames to
IP addresses, for example, `www.confluent.io` to `54.177.145.149`.

A public DNS server contains DNS records that can be resolved using the public
internet. A private DNS server contains DNS records that can only be resolved in
a private network, such as a VPC or an on-prem environment.

One way to check if a given hostname uses public DNS is running the `dig`
command with a public DNS resolver:

```bash
dig [DNS-server] <hostname>
```

`DNS-server` can be any public DNS server, such as Google DNS server
(`8.8.8.8`) and Cloudflare DNS server (`1.1.1.1`).

For example:

```bash
dig 8.8.8.8 www.confluent.io
```

Fully managed connectors in Confluent Cloud support the following types of DNS
zones/servers for resolving and accessing required endpoints.

|             | AWS                                                                                        | Azure                                                                                                   | Google Cloud                                                                                        |
|-------------|--------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------|
| Public DNS  | Supported                                                                                  | Supported                                                                                               | Supported                                                                                           |
| Private DNS | Supported with [DNS Forwarding](../../networking/aws-dns-forwarding.md#dns-forwarding-aws) | Supported with [DNS Forwarding](../../networking/peering/azure-peering.md#dns-forwarding-azure-peering) | Supported with [DNS Forwarding](../../networking/peering/gcp-peering.md#dns-forwarding-gcp-peering) |

<a id="clusters-connect-cloud-networking-troubleshoot"></a>

## Troubleshoot networking issues for fully managed connectors

This page describes common networking-related errors you may encounter when
creating connectors, and it provides checklists that can help you to
troubleshoot the issues.

### Issues with Peering or Transit Gateway

**Errors trying to connect via FQDN (fully qualified domain name) with publicly resolvable DNS**

* If able to directly connect to the private IP address, there is an issue when resolving DNS.
* If not able to connect to the private IP address:
  * Check the peering/Transit Gateway setup, routes, associated firewalls,
    security groups, and network access control lists.
  * Check **ports** and **protocol** settings.

**Errors trying to connect via FQDN with DNS that is not publicly resolvable**

* Check if DNS forwarding is correctly set up with the right IP address for the
  DNS server and is forwarding the needed domain name. For details, see
  [DNS Forwarding for AWS](../../networking/aws-dns-forwarding.md#dns-forwarding-aws-peering) or [DNS
  Forwarding for Azure](../../networking/peering/azure-peering.md#dns-forwarding-azure-peering).
* Check your DNS setup, peering/Transit Gateway setup, routes, associated
  firewalls, security groups, and network access control lists.
* Check **ports** and **protocol** settings.

### Issues with Private Link

**Errors related to a private endpoint when directly connecting to a private IP
address**

* Ensure that the Egress PrivateLink Endpoint is correctly set up. For details, see
  [Use AWS Egress PrivateLink Endpoints for Dedicated Clusters on Confluent Cloud](../../networking/aws-egress-privatelink.md#cloud-networking-privatelink-aws-egress).
* Check the associated firewalls, security groups, and network access
  control lists.
* Check **ports** and **protocol** settings.

**Errors related to a private endpoint when directly connecting to an FQDN**

* If the FQDN is publicly resolvable:
  * Ensure that the Egress PrivateLink Endpoint is correctly set up. For details, see
    [Use AWS Egress PrivateLink Endpoints for Dedicated Clusters on Confluent Cloud](../../networking/aws-egress-privatelink.md#cloud-networking-privatelink-aws-egress).
  * Check the associated firewalls, security groups, and network access
    control lists.
  * Check **ports** and **protocol** settings.
* If the FQDN is not publicly resolvable:
  * Ensure that the DNS record is set up for the Egress PrivateLink Endpoint. For
    details, see [Create a private DNS record in Confluent Cloud](../../networking/aws-egress-privatelink.md#aws-privatelink-egress-dns-records).
  * Check the associated firewalls, security groups, and network access
    control lists.
  * Check **ports** and **protocol** settings.
