-
Notifications
You must be signed in to change notification settings - Fork 21.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Confusion around "Allow access to Azure services" option #13287
Comments
@andyce1010 Thanks for the feedback! We are currently investigating and will update you shortly. |
@andyce1010 Thanks for the feedback! I have assigned the issue to the content author to evaluate and update as appropriate. |
investigating... |
This appears to be a bug and a CSS case should be opened. No further action at this point in terms of changing the docs. @andyce1010 @Alberto-Vega-MSFT |
@andyce1010 if you don't have a Support plan, email AzCommunity@microsoft.com, and we will enable a one-time Support ticket for you. Please remember to include your Subscription ID, and a link to this issue. |
Ok thanks, I'll do that. Just to clarify, are you saying that a firewall rule should be required, even when the "enabled access from azure services" option is enabled? If that's the case, then is the information note I quoted above wrong? |
@andyce1010 To the best of my knowledge, the information note is correct and a firewall rule is not required from an Azure resource to another Azure resource |
Ah ok, thanks. In that case it's the flow diagram that's incorrect, as that shows Azure connections being subject to the database and server firewall rules. |
@andyce1010 I answered too quickly. When you create an Azure SQL server and DB using the Azure portal and click the checkbox for allowing Azure services, a firewall rule with an IP address of 0.0.0.0 is created. When you create your server and DB using an API, such as PowerShell, you have to create this firewall rule for this IP address yourself - as there is no checkbox. Sorry for the confusion. As such, the diagram is correct. I confused myself because, when I use the Azure portal and use the allow azure services checkbox, no other firewall rule is needed. |
#please-close |
Yes, thanks for the clarification. |
#please-close |
Hello,
According to the flow diagram, it looks like once you have "enabled access from azure services", then you still need to add firewall rules to the DB or server, to allow the azure services to connect. However the Information note that follow ("This option configures the firewall to allow all connections from Azure including connections from the subscriptions of other customers. When selecting this option, make sure your login and user permissions limit access to only authorized users.") makes it sound like azure services will bypass the firewall.
In practice I have found that azure services (I tested using a container instance) do indeed bypass the firewall. I can connect after enabling access from azure services, without adding any firewall rules.
Maybe the diagram should be updated to make this more obvious. Or is there a plan to make these firewall rules apply to azure connections too?
Document Details
⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.
The text was updated successfully, but these errors were encountered: