does azure cosmosdb service tag include physical partition ip ranges?

Zengbo Luo 0 Reputation points Microsoft Employee
2024-10-08T08:15:15.67+00:00

I added a NSG rules to block the outbound requests to cosmosdb but found out that only the requests to cosmosdb gateway has been blocked. The requests to physical pation still could go through. So does azure cosmosdb service tag include physical partition ip ranges?

Azure Cosmos DB
Azure Cosmos DB
An Azure NoSQL database service for app development.
1,678 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Vijayalaxmi Kattimani 415 Reputation points Microsoft Vendor
    2024-10-08T16:22:08.3+00:00

    Hi @Zengbo Luo,

    Welcome to the Microsoft Q&A Platform! Thank you for asking your question here.

    As i understand that you are trying to block the outbound requests to Cosmos DB using Network Security Group(NSG) rule.

    I would like to inform you that, The Azure Cosmos DB service tag only covers gateway traffic and do not include physical partition IP ranges. When you added a Network Security Group (NSG) rule to block outbound traffic to Cosmos DB using the service tag, you effectively blocked traffic to the gateway layer.

    Please refer to this link https://learn.microsoft.com/en-us/azure/virtual-network/service-tags-overview

    Hope this helps. Do let us know if you have any further queries.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

     

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.