---
title: "Prerequisites for Amazon Route 53 Integration"
canonical: "https://docs.infoblox.com/space/NAIG/277546012/Prerequisites%20for%20Amazon%20Route%2053%20Integration"
format: markdown
---
Before you configure sync groups and sync tasks required for the Route 53 integration in NIOS, complete the following prerequisites:

> ⚠️ **Note**
> ⚠️ 
> ⚠️ In versions of NIOS prior to 9.0.4, the Cloud Sync service was termed as Cloud DNS Sync service.

- Ensure that you have installed the Cloud Network Automation license on the Grid Master. For information about licenses, refer to the *[Infoblox NIOS Documentation](https://docs.infoblox.com/)*.
- For NIOS version 9.0.4 and later:
  - Ensure that the Cloud Sync service is running on the Grid member that will perform the Route 53 sync task. For more information, see *[Starting and Stopping the Cloud Sync Service](#Starting_and_Stopping_Sync_Service)*.
  - Start the Cloud DNS Sync Service on the Grid member on which you want to synchronize the DNS data. For more information, see *[Starting and Stopping the Cloud Sync Service](#Starting_and_Stopping_Sync_Service)*. Note that the Cloud DNS Sync Service is supported from NIOS 8.6.3 onwards.
  - For the Route53 synchronization to function properly, ensure that your network firewall settings permit access to the below mentioned global STS endpoint and the regional STS endpoints specific to your region. This is crucial for establishing a connectivity between the NIOS appliance and your configured AWS accounts. For other regional endpoints, see the *[AWS STS Regions and endpoints](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_region-endpoints.html)* page.  
In the list, replace <region> with your AWS region. If you have deployed resources in multiple regions, make sure that all regional endpoints are accessible.
    - route53.amazonaws.com (primary Route 53 operations endpoint)
    - sts.amazonaws.com (global STS endpoint for authentication)
    - sts.<region>.amazonaws.com (regional STS endpoints specific to your region)
    - organizations.<region>.amazonaws.com (required for account discovery feature)
    - http://aws.amazon.com/  (general AWS endpoint access)  
  
Additionally, Infoblox recommends regularly checking the AWS documentation for the latest updates on endpoint changes to keep your network configuration current and ensure uninterrupted accessibility.
- Enable multi-account support in AWS and keep the role ARN (Amazon Resource Name) handy. For more information, see *[Setting up the AWS Environment for Multi-Account Synchronization](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/277742797)*.
- Set up AWS user accounts and record the AWS credentials for these accounts. You may need the credentials when configuring Route 53 sync tasks. For information about how to set up an AWS account, see the AWS documentation. You can also configure AWS accounts and credentials through Grid Manager, as described in *[Configuring AWS Access for NIOS Cloud Admins](https://infoblox-docs.atlassian.net/wiki/spaces/NAIG/pages/37454198)*.  
Note that all sync tasks in the same sync group are performed for the same AWS user account.
- If your deployment is on AWS GovCloud, enable the Route 53 synchronization as defined in the *[Enabling Route 53 Integration on the GOV Cloud](#Enabling_Route53_GOV_Cloud)* section.
- For the Route 53 synchronization to function properly, ensure that the time on the NIOS or vNIOS appliance is synchronized with the actual time. You can configure NTP servers on the NIOS appliance and enable the NTP service to synchronize time on the appliance. For information about how to set up the NTP server, refer to the* **[Infoblox NIOS Documentation](https://docs.infoblox.com/)*.
- Configure DNS resolvers on the Grid member that is synchronizing Route 53 data so the AWS API can reach the Route 53 endpoints. For information about how to configure DNS resolvers, refer to the * **[Infoblox NIOS Documentation](https://docs.infoblox.com/)**.*

# > Macro (anchor)

Adding an AWS Admin User (Amazon User) in NIOS

For the AWS management account that is set up in your AWS organization, you must create a parallel AWS admin user in NIOS by specifying the access key ID and secret access Key and associate it with an appropriate cloud API enabled NIOS admin account. The access key pair that you specify is used by NIOS to communicate with AWS through the cloud admin account.

The access key pair is defined by Amazon and sent directly to each requesting AWS administrator, and must be copied manually. AWS requires the access keys to allow calls made to AWS using the AWS CLI, AWS SDKs, or direct HTTP calls.

To add an AWS admin user, complete the following steps:

1. On the **Administration** tab > **Cloud** tab, click the **Add** icon.
2. In *Add Cloud User Wizard > Step 1 of 1*, complete the following:
  - **Cloud Service Provider**: Select **AWS** from the drop-down list.
  - **Username**: Enter a username for the AWS user account.
  - **Access key ID**: Enter the Amazon IAM (Identity and Access Management) access key ID value associated with the AWS user account.  
All AWS API requests require an access key ID and a corresponding secret access key that NIOS uses to authenticate the sender of the request and verify the authenticity of the request message.
  - **Secret access key**: Enter the secret access key from the AWS user account.
  - **Amazon account**: Enter the account ID of the AWS user account that you have created in AWS.
  - **Mapped to NIOS user**: Each pair of access key ID and secret access key received by the AWS API Proxy must be assigned to a NIOS admin user with sufficient privileges. You can assign multiple AWS user accounts to a single NIOS cloud Admin user account with the required **cloud-api-only** NIOS group setting. Click the **Select** **NIOS User** button and complete the following:
    - In the *Select NIOS User* dialog box, find and select a NIOS admin user to map to this user account.
    - Click **OK**.
  - **GovCloud**: Select the check box if you want to enable the Route 53 service on the AWS GovCloud for this user.
3. Click **Save & Close**.

> ⚠️ **Note**  
> ⚠️ For multi-account synchronization of Route 53 data, you must enter the **Access key ID**, **Secret access key** and **Amazon account** values from the management account of your AWS organization.

# > Macro (anchor)

Enabling Route 53 Integration on the AWS GovCloud

If you have deployed vNIOS for AWS instances on the AWS GovCloud and want to synchronize DNS data with NIOS, you must enable Route 53 support for the AWS GovCloud.

1. On the **Administration** tab > **Cloud** tab, do one of the following:
  - Select an existing admin user and click the **Action** icon > **Edit**.  
*Cloud User Properties* dialog box for that user is displayed.
  - Click the **Add** icon, and then add an AWS admin user in the *Add Cloud User Wizard*. For more information, see *[Adding an AWS Admin User](#Adding_AWS_Admin_in_NIOS)*.
2. Select the **GovCloud** checkbox to enable the Route 53 integration feature for this user on the AWS GovCloud.
3. Click **Save & Close**.

# > Macro (anchor)

Starting and Stopping the Cloud Sync Service

To enable the synchronization of DNS data from multiple AWS accounts of an AWS organization to NIOS on a Grid member, the Cloud Sync service must be running on the member. The Cloud Sync service is supported for DNS synchronization only from NIOS 8.6.3 onwards.

In NIOS 9.0.4 and later, if the member is not assigned with any existing sync task, the service is automatically enabled when you create a sync task on the member.

> Macro (excerpt)
> 
> Before or after an upgrade to NIOS 9.0.4 or later, if you manually stopped the Cloud Sync service on a member for any reason, you must manually start the service for the dependent tasks such as DNS sync and/or vDiscovery to run.
> 
> To start the service:
> 
> 1. From the **Grid** tab, select **Grid Manager** tab > **Services** tab.
> 2. On the service bar, click the **Cloud Sync** service.
> 3. Select the member on which the Cloud Sync service must be enabled.
> 4. Expand the Toolbar and click **Start**.  
> The service takes a few minutes to start. Before running a Route 53 sync task, wait for the service status to show **Cloud Sync service is healthy**.
> 
> To stop the Cloud Sync service on a member, select the member checkbox, and then click **Stop** in the Toolbar.