Do I need an Network Security Group to use a Standard SKU Public IP address to let internet access in, as the front end of an Application Gateway?

Ijaz M 206 Reputation points
2022-11-17T04:03:00.807+00:00

I have heard that an NSG is necessary for the Standard PIP to be used for scenarios as the NIC of a VM. Wonder if that applied to Application Gateway front end as well.

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,289 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,007 questions
0 comments No comments
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 41,071 Reputation points Microsoft Employee
    2022-11-17T05:46:54.823+00:00

    Hi @Ijaz M ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
    I understand that you would like to know if Public IP (Standard SKU) of App Gateway requires NSG or not.

    Any standard Public IP is closed to Internet by default.
    This is the case with App gateway too.

    Hence, you will be required to allow the ports via NSG in the App gateway subnet.

    Thanks,
    Kapil

    ----------------------------------------------------------------------------------------------------------------

    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful