Matillion ETL IP's for on-premise sources

Hi all,

 

we are looking into Matillion ETL as a possible tool for some of our client projects. However right now we are not sure how a possible setup with on-premise data sources would look like.

The documentation does not yield any useful information so far, so I would like to ask it here.

 

So my hopes would be, that a Matillion ETL Instance will always keep it's IP address, so we are able to whitelist that address in the on-premise firewall?! Is this the case and way to go, or is Matillion offering something similar to Microsofts on-premise Gateways to establish a connection between the cloud and on-premise sources?

 

Thanks for any hints on that topic!

Mathias

Hi @MaMS​,

There are probably multiple ways of handling this. I can speak to AWS specifically but I am sure Azure is very similar but with different nomenclature. What most companies will do is create an AWS Private VPC with all the network infrastructure required for their use case. From there you have a couple options. You can use VPN tunnels, Direct Connect or just an internet connection from your on premise network into your AWS VPC. For security sakes I would personally steer you towards Direct Connect or VPN tunnels. This will build that bridge between the on premise network and AWS private network. Since Matillion is simply an Ec2 (virtual machine) in AWS you can setup roles and security groups to allow that instance to traverse the AWS VPC and gain access to on premise systems. This can further be secured by using on premise network hardware to allow specific traffic from the Matillion instance to specific servers and ports on those servers.

I hope this helps paint a better picture.

Hi @Bryan​ ,

thanks for your answer. I had the chance to also talk to one of Matillions Solution Engineers, who seconded your proposed solution.

So in short: Since your Matillion ETL is running in an EC2 instance in your AWS account, it is the best solution to just use the AWS Private VPC to connect your Matillion ETL with your on premise network.

From what I gathered, this should be doable for a first timer like me in under a day, provided that you have the necessary rights in the network.