P2S VPN resolves to Private endpoint DNS but connects to Public IP for Storage account and blocked

Nagulan Sundararajan 0 Reputation points
2023-02-21T21:43:48.3833333+00:00

https://luke.geek.nz/azure/azure-point-to-site-vpn-and-private-dns-resolver/

I've created a VNET and added Custom DNS (Private DNS resolver)

  • Deployed a VM to iaas subnet
  • Private endpoint for storage account to pvtendpt subnet

User's image

  • Private DNS Resolver to dnsres subnet User's image

User's image

I can connect to the VM via P2S VPN but not to the storage account via private endpoint.

Local Machine connected via P2S VPN resolves private endpoint on nslookup but connects to public IP on ping but not the VM

User's image

User's image

Azure DNS
Azure DNS
An Azure service that enables hosting Domain Name System (DNS) domains in Azure.
743 questions
Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,687 questions
Azure Private Link
Azure Private Link
An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.
538 questions
{count} votes

1 answer

Sort by: Most helpful
  1. SaiKishor-MSFT 17,331 Reputation points
    2023-02-23T20:17:14.3933333+00:00

    @Nagulan s Thanks for reaching out to Microsoft Q&A.

    Looking at your setup, you have the following-

    1. Vnet
    2. Private DNS Zone with A record for storage
    3. Deployed a VM in the IAAS subnet

    However, you cannot get the local machine to connect to storage account via the private endpoint, you need the following resources-

    Please refer to the following image to see how this works-

    On-premises using Azure DNS

    This configuration can be extended for an on-premises network that already has a DNS solution in place.  The on-premises DNS solution is configured to forward DNS traffic to Azure DNS via a conditional forwarder. The conditional forwarder references the DNS forwarder deployed in Azure.

    Do you have a DNS solution on-premises that can forward this request to Azure DNS? Please refer below to see how this can be setup:

    On-premises forwarding to Azure DNS

    I see that you may not have a DNS forwarder deployed on-premises and/or in Azure to forward this request to Azure provided DNS to be able to resolve this. Please make sure you have this in place and let me know if that helps.

    Thank you!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.