tencent cloud

Feedback

Overview

Last updated: 2023-03-03 15:07:47

    Overview

    When creating a migration, sync, or subscription task, you need to select different access types based on the deployment conditions of your source database. This document describes how to select an access type and prepare accordingly.
    

    Preparations

    Note
    Determine the access type in advance. For the same source and target databases, if an access type such as Public Network is selected and the connectivity verification is passed, you cannot switch to another access type such as Direct Connect; otherwise, an error will be reported during connectivity verification.
    If the source database is an IDC-based self-built database or a third-party cloud database, you can select Public Network generally. If you require a higher transfer performance, you can select VPN Access, Direct Connect, or CCN based on your actual network conditions.
    If the source database is a TencentDB instance, select Database.
    If the source database is a CVM-based self-built database, select Self-Build on CVM. However, if it is on the classic network, we recommend that you select Public Network as the classic network was deactivated on December 31, 2022.
    If the source database is based on a Lighthouse instance, select Public Network.
    Access Type
    Use Case
    Operation Guide
    Public Network
    The source database can be accessed through a public IP.
    The public network option cannot guarantee the transfer bandwidth and is applicable to scenarios with low requirements for the transfer performance.
    Manually add the SNAT IP of the DTS server to the allowlist (generally the firewall) of the self-built database as instructed in Adding DTS IP Address to Database Allowlist to connect the source database and DTS instance.
    Direct Connect/VPN Access
    The source database can be interconnected with VPCs through VPN Connections or Direct Connect.
    The network bandwidth of Direct Connect is guaranteed.
    Configure VPN-IDC interconnection as instructed in Direct Connect or VPN Access: Configuring VPN-IDC Interconnection.
    Manually add the SNAT IP of the DTS server to the allowlist (generally the firewall) of the self-built database as instructed in Adding DTS IP Address to Database Allowlist to connect the source database and DTS instance.
    CCN
    The source database can be interconnected with VPCs through CCN.
    Configure VPC-IDC interconnection through CCN as instructed in CCN Access: Configuring VPC-IDC Interconnection Through CCN.
    Manually add the SNAT IP of the DTS server to the allowlist (generally the firewall) of the self-built database as instructed in Adding DTS IP Address to Database Allowlist.
    Self-Build on CVM
    The source database is deployed in a CVM instance.
    Manually add the SNAT IP of the DTS server to the security group of the CVM instance as instructed in Adding DTS IP Address to Database Allowlist.
    VPC
    The source and target databases are both deployed in Tencent Cloud VPCs.
    Manually add the SNAT IP address of the DTS server to the security group of the source database as instructed in Adding DTS IP Address to Database Allowlist. To use the VPC access type, submit a ticket for application.
    Database
    The source database is a TencentDB instance.
    Manually add the SNAT IP address of the DTS server to the security group of the source database as instructed in Adding DTS IP Address to Database Allowlist.
    
    Note
    The source database may be exposed to certain security threats if the SNAT IP address of the DTS server is manually or automatically added to its security group or allowlist. Therefore, when performing such operations, you should take security protection measures like standardizing account password management, requiring authentication for API communication, and restricting unnecessary IP ranges. By using DTS, you acknowledge that you bear all risks associated with the use of the service. If you have a very low tolerance for risks when you use DTS, we recommend you choose Direct Connect, VPN, or VPC for access.
    After using DTS, we recommend that you delete the DTS IP address from the security group or firewall promptly.
    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support