Alternative to closing ports used by Azure Virtual Network Gateway

jimmy cao 20 Reputation points
2024-02-06T09:35:54.02+00:00

It is to my understanding that Azure Virtual Network Gateway requires some ports to be open for Azure infrastructure communucation and that there was no way to close said ports on the Network Gateway. My question is if there is an alternative or compensating control that can be applied to close the port (Azure firewall, NSG etc.)

I came accross these similar questions but was not able to find an answer

https://learn.microsoft.com/en-us/answers/questions/1382462/how-to-deny-traffic-on-port-20000-of-the-public-ip

https://learn.microsoft.com/en-us/answers/questions/1313000/disable-port-7999-8081-for-azure-vpn-gateway

https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-vpn-faq#gatewayports

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,556 questions
Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
674 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,491 questions
0 comments No comments
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 46,676 Reputation points Microsoft Employee
    2024-02-06T09:43:04.24+00:00

    @jimmy cao

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to know if there are any alternatives to make the opened ports of Azure VPN Gateway inaccessible.

    • Unfortunately, this is not feasible.
    • The ports are in listening state so that the platform can access it via these ports. If we were to block it using Azure Firewall or NSG, that would not help the case.
    • The documents and reference Q&A threads shared by you are correct.

    This is by design of the product and we cannot override this.

    Also, see : Gateway subnet considerations

    User's image

    Thanks,

    Kapil


    Please Accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer.

    2 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.