VNET Flow Logs - Direction relative to interface or firewall rule?
VNET flow logs provide a direction defined as the following in the documentation: Flow direction: Direction of the traffic flow. Valid values are I for inbound and O for outbound. Flow logs are provided grouped by interface and then by firewall rule. …
VMSS Health Probe Showing Unhealthy Status Despite Whitelisting Wireserver IP 168.63.129.16
We are currently exploring the configuration of our production Virtual Machine Scale Sets (VMSS), which are behind an Azure Application Gateway. We have implemented a health extension check using the HTTP protocol on port 80. However, we are encountering…
Network watcher not working on FTD VM
I have a cisco FTD firewall running on a VM. When I go to extensions I see it shows AzureNetworkWatcherExtension is there. However when I go to use network watcher connection monitor I get an error it is not installed. Network Watcher VM extension…
Is it possible to ping 8.8.8.8 without a public IP associated with an Azure VM?
I am currently working with two Azure VMs (one running Linux and the other running Windows) that are located in the same virtual network. While I can access the internet from both machines (browsing, running sudo apt update, and using curl), I'm facing…
How to verify communication matrix established between 2 resource groups?
I have the resource group names and subnet IP range. I would like to verify if the communication is happening successfully between the 2 RGs. I dont have any other details like port etc.
I have created VPN Gateway and i want to provide VPN access to my Virtual machine. how can i do that?
I have created VPN Gateway and i want to provide VPN access to my Virtual machine. how can i do that? so that my application on my VM can be accessed by my vpn only. i have created point to site connection and downloaded vpn cline.
"Azure Virtual Wans - vwans | Connection Status of the HUb: NOT CONNECTED"
Hello, Hello, I tried to configure and set up a connection between two vwans. Below are the design details. Two Vnets in two different regions (Vnet-A and Vnet-B). VNEt-A: 10.40.0.0/24 | Vnet-B: 10.60.0.0.0/24 2. Two Virtual hubs (vHu-A:…
Network watcher log is disabled but provisioning state shows as failed. I can still see the logs being written to storage account whereas ideally it should be disabled.
I've configured the logs to be written to storage account whereas ideally it should be disabled. Even though status on Network Watcher states its disabled, the logs are being written continually. Can you help as to what changes are to be carried out to…
Not able to tick the checkbox "Enable traffic analytics" in the Flow log settings page
Not able to tick the checkbox "Enable traffic analytics" in the Flow log settings page. The checkbox appears enabled but I cannot tick the box. I was able to do the same action 1 month ago but not working now. Tried in Chrome and Edge browsers…
can't find "Network Diagnostic Tools" option under network watcher resource blade
can't find "Network Diagnostic Tools" option under network watcher resource blade
How to create NSG behind private endpoint and how can i enable flow logs for this NSG?
Hi team, I have two questions here on NSG: How can I create NSG behind private endpoints? Can I enable flow logs for NSG behind private endpoint? If yes, how can I do that?
(Vulnerabilities) NetworkWatcher
Question : Do we need to take action regarding these vulnerabilities, or will Microsoft handle the solutions? Vulnerability from Nessus Scanner. Findings : 202053 - Microsoft Azure Network Watcher VM Extension < 1.4.3320.1 Elevation of Privilege…
Unable to connect Fivetran with public IP to ADLS Gen2 in Vnet with Private end point
Hi, I'm encountering an issue while trying to connect Fivetran to ADLS Gen2 in the UK South region. Here are the details: I have configured ADLS Gen2 as a destination in Fivetran and completed the prerequisites, including creating an SPN with appropriate…
Unable to ping peered resource
I have deployed hub and spoke model, having one hub Vnet and one spoke Vnet through which connectivity is going good, but recently deployed and configured new Vnet with different address space and deployed one VM in it. I also did peering between new…
Verifying multiple network connections between MSFT datacenters?
What is the best way to evidence (to our auditors) that our datacenters are connected to each other via redundant fiber (i.e. mesh)? I am familiar with Azure AZs, but can't locate anything that I can provide that verifies that the datacenters in a…
Traffic latency between VNETs
Hello, what could be the reasons for the traffic latency from VNET1 to VNET2? The networks are located in the same region, and there is a connection between them. However, VNET2 uses a subnet with public addresses like 20.58.x.x (so that they are the…
Creation of a connection monitor between a vm and a vm scale set instance fails.
Greetings , I'm trying to create a connection monitor between a VM and VM scale set in sharing the same Subnet. Cases: the source is the Vm and the Destination whole Scale set has been selected . it works and tests are successful. the source is the Vm…
Is the reader role at the sub level could enable the traffic analytics in the same sub?
Is the reader role at the sub level could enable the traffic analytics in the same sub? Or we still need the contributor role to do so?
On-prem network access to Azure nested VM via site-to-site VPN
Azure VM with nested hv vm. Site-to-site VPN established between on-prem network and Azure. Nested VM can access the internet, the Azure VM, and the on-prem network. The Azure VM can communicate with the nested VM. On-prem can access…
Topology not appearing under network watcher monitoring
Hello - I'm trying to see my network topology. When I go into my network watcher resource, it doesn't appear under "Monitoring." Am I doing something wrong?