Private link

Many companies connect to API Gateway (IONAPI) endpoints using their own Virtual Private Cloud (VPC) which Infor does not host or own. By default, a VPC connects to IONAPI endpoints directly over the public internet.

However, while this works fine in many cases, some companies have a stricter security policy which requires using a private connection from their VPC to IONAPI endpoints. To support this, CSSP provides a way to configure such a connection through AWS PrivateLink.

AWS PrivateLink works by providing a Service Endpoint which connects to IONAPI’s endpoints. Your VPC then connects to this Service Endpoint via AWS PrivateLink rather than connecting to IONAPI’s endpoints directly. This way, no data is ever transmitted over the public internet. This requires your VPC to be associated with an AWS Account ID for which a user with the Admin role can whitelist a Private Link connection through CSSP.