---
name: framework-financial-services-satellite-architecture-connectivity-to-ibm-services
title: Connectivity to IBM Cloud services with Satellite Link
description: When using IBM Cloud services from workload components in your Satellite location, you should use Satellite Link functionality to facilitate secure access to the IBM Cloud services. Satellite Link endpoints provide a connection over a secure tunnel directly to private service endpoints.
last-updated: 2025-03-02
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/framework-financial-services?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Connectivity to IBM Cloud services with Satellite Link
{: #satellite-architecture-connectivity-to-services}

When using IBM Cloud services from workload components in your Satellite location, you should use [Satellite Link](https://cloud.ibm.com/docs/satellite?topic=satellite-link-location-cloud&format=markdown) functionality to facilitate secure access to the IBM Cloud services. Satellite Link endpoints provide a connection over a secure tunnel directly to private service endpoints.
{: shortdesc}

Inside a Satellite location, this private access can be accomplished by using a [Satellite Link endpoint](https://cloud.ibm.com/docs/satellite?topic=satellite-link-cloud-create&format=markdown#link-cloud) to map a TCP port on the control plane hosts to the IBM Cloud service private endpoint. The Link endpoint is a virtualized function that scales horizontally, is redundant and highly available, and spans all zones of your Satellite location.

Private service endpoints for IBM Cloud services should be used when you define cloud endpoints for your location.
{: important}

## Creating Satellite Link endpoints
{: #create-satellite-link-endpoints}

- Create Satellite Link endpoints for the IBM Cloud services that you need to consume from your Satellite location. For more information, see [Creating and managing link endpoints](https://cloud.ibm.com/docs/satellite?topic=satellite-link-cloud-create&format=markdown).

Cloud endpoints for your location use a TCP port on the control plane hosts. If the endpoint is supposed to be used by a component outside of your Red Hat OpenShift on IBM Cloud cluster deployed on your Satellite location, you need to allow network connectivity from the origin of that component to the port on the control plane.
{: important}

## Related controls in IBM Cloud Framework for Financial Services
{: #related-controls}

The following IBM Cloud Framework for Financial Services controls are most related to this guidance. However, in addition to following the guidance here, do your own due diligence to ensure you meet the requirements.


| Family              | Control                                           |
|---------------------|---------------------------------------------------|
| Access Control (AC) | [AC-20 Use of External Systems](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-20&format=markdown) |
| Security Assessment and Authorization (CA) | [CA-3 Information Exchange](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ca-3&format=markdown) |
| System and Communications Protection (SC)  | [SC-5 Denial-of-service Protection](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-5&format=markdown) \n [SC-7 Boundary Protection](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-7&format=markdown) \n [SC-7 (4) Boundary Protection &#124; External Telecommunications Services](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-7.4&format=markdown) \n [SC-7 (5) Boundary Protection &#124; Deny by Default - Allow by Exception](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-7.5&format=markdown) \n [SC-7 (10) Boundary Protection &#124; Prevent Exfiltration](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-7.10&format=markdown) |
{: caption="Related controls in IBM Cloud Framework for Financial Services [FSv2.0]" caption-side="top"}
{: #related-controls-fsv2.0}
{: tab-title="FSv2.0"}
{: tab-group="RelatedControls-1"}
{: class="simple-tab-table"}


| Family              | Control                                           |
|---------------------|---------------------------------------------------|
| Access Control (AC) | [AC-20 Use of External Information Systems](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-20&format=markdown) |
| Security Assessment and Authorization (CA) | [CA-3 System Interconnections](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ca-3&format=markdown) |
| System and Communications Protection (SC)  | [SC-5 Denial of Service Protection](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-5&format=markdown) \n [SC-7 Boundary Protection](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-7&format=markdown) \n [SC-7(4) Boundary Protection &#124; External Telecommunications Services](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-7.4&format=markdown) \n [SC-7 (5) Boundary Protection &#124; Deny By Default - Allow By Exception](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-7.5&format=markdown) \n [SC-7 (10) Boundary Protection &#124; Prevent Exfiltration](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-7.10&format=markdown) |
{: caption="Related controls in IBM Cloud Framework for Financial Services [FSv1.1]" caption-side="top"}
{: #related-controls-fsv1.1}
{: tab-title="FSv1.1"}
{: tab-group="RelatedControls-1"}
{: class="simple-tab-table"}


## Next steps
{: #next-steps}

- [Consumer connectivity to workload resources](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-satellite-architecture-connectivity-workload&format=markdown)