An Azure relational database service.
You can configure a Private Link. With a private link clients can connect to the Private endpoint from the same virtual network, peered virtual network in same region, or via virtual network to virtual network connection across regions. Additionally, clients can connect from on-premises using ExpressRoute, private peering, or VPN tunneling.
With Private Link you do not need to use the IP-based firewall to allow access to any IP address.