Network security group

Vishu 1,576 Reputation points
2022-12-27T19:13:37.707+00:00

Requirement is to challenize traffic from jump host vm to all the other vms

There is one vnet, having jump host vm in one subnet(vm1) and the other vm(vm2) in the other subnet

If we try setting an nsg rule that the rdp for vm2 should happen through vm1 only and another rule(with a lesser priority) to deny all traffic, the rdp does ot work until we create another rule in between the above 2 to allow virtual network service tags. However the service tag rule is causing traffic to come to vm2 from other sources also besides jump host(vm1)

Please guide

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
0 comments No comments
{count} votes

Answer accepted by question author
  1. GitaraniSharma-MSFT 50,181 Reputation points Microsoft Employee Moderator
    2022-12-28T12:53:18.07+00:00

    Hello @Vishu ,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    I understand that you would like to allow RDP to all VMs in subnet2 via a jump host VM in subnet1 and deny all other traffic for subnet2 VMs.

    I recreated this setup in my lab and it works just fine.
    Below are the rules that I added to my Subnet2 NSG:

    274593-image.png

    I only created the below 2 rules:

    • Rule to allow inbound RDP traffic from my jump host VM in Subnet1 with higher priority (100).
    • Rule to deny all other traffic with lesser priority (1000).

    I'm able to RDP to my Subnet2 VM from my jump host VM in Subnet1 and unable to access it from any other subnets.

    Could you please re-check the NSGs that you have configured and make sure that there are no other NSGs on the network interfaces of the VM blocking the traffic?

    Kindly let us know if the above helps or you need further assistance on this issue.

    ----------------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.