Expose private link HTTPS and Non HTTPS ports from NGFW LB Sandwich

Chris Brien (CPower) 21 Reputation points
2022-01-11T19:04:49.987+00:00

My organization has decided to utilize private endpoint on all of our PaaS services when possible, with the end goal of filtering traffic through our NGFWs. We currently have a ELB and ILB sandwich configured which is currently servicing our internal communication requirements, but are looking to expose our private linked Azure functions apps to the internet to service some public web clients. My understanding is that we would need a Azure Application Gateway in front of the NGFWs to service these requests and translate them to our internal function apps.

I need to service these HTTPS requests as well as support legacy protocols including FTP, SFTP, etc into the Azure vNets. I am looking to see if my assumptions are correct, and if it is possible to have a Azure Application Gateway and a External Load balancer both sit in front of the NGFWs and service requests for both of these use cases.

Thanks for any assistance!

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
956 questions
Azure Private Link
Azure Private Link
An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.
461 questions
Azure Load Balancer
Azure Load Balancer
An Azure service that delivers high availability and network performance to applications.
402 questions
0 comments No comments
{count} votes

Accepted answer
  1. msrini-MSFT 9,256 Reputation points Microsoft Employee
    2022-01-12T12:14:35.59+00:00

    @Chris Brien (CPower) ,

    PLS can only be linked to a Standard Load balancer. You cannot link a PLS to an Application Gateway as of today.

    You can have NGFW as part of Load Balancer and Application gateway. But the Private Link traffic cannot be sent via Application gateway. That can only pass via Load Balancer.

    Hope this answers your question.

    Regards,
    Karthik Srinivas

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful