Azure Firewall and outbound pings lost

John Wirtz 20 Reputation points
2024-07-09T15:56:54.6466667+00:00

outbound pings are allowed via policy, can see them leaving via the logs, no returned traffic comes back to complete the ICMP and the client behind the azure firewall shows timed out. what gives? do you have to specifically allow ICMP replies?

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
609 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 41,071 Reputation points Microsoft Employee
    2024-07-10T09:50:38.5133333+00:00

    @John Wirtz ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I see you are using Azure Firewall for inspecting traffic from VMs.

    Can you please provide more details on your environment?

    • Are you ICMP pinging a Public IP in Internet
    • Or Pinging another VM in the VNET from a VM in the same VNET via Azure Firewall?
    • Are you sure the destination is capable of responding to a ICMP Ping?
    • If you remove the Firewall from the routing, can you get a PING response back?
      • You can do this by adding a more specific route in the UDR such that the traffic directly goes to the destination.

    Cheers,

    Kapil

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful