Azure App service not accessible with private endpoint within APIM/VM

Viewed 1340

I have configured my app serivce to be part of a subnet within a VNET.

Now i have integrated my app service with a private endpoint within the same VNET.

With the private endpoint integration, i'm now not able to access the app service (i.e. my API) on a public internet, where i'm getting 403 forbidden error. Which is an expected behaviour to restrict the access on the public network

But the issue is, i want to expose this API via APIM (which is internal) configured within a separate subnet in the same VNET, but i'm not not access the API now with the private endpoint IP address. I was hoping that the resources with in the VNET will be able to reach the App service using its private IP address

I also tried to configure a VM in a separate subnet with in the same VNET, but when i ping the API private IP from the VM, i'm getting request timedout.

Current there have not been any rules setup with NSG to restrict the subnets to talk between each other.

Please let me know how to expose the API with private endpoint via APIM which is also configured to be only internal

1 Answers

You also need to configure private dns zone as now your app's FQDN needs to be resolved to the private IP, instead of a public one.

https://docs.microsoft.com/en-us/azure/private-link/create-private-endpoint-powershell

Update:

Just want to add that app service cannot be accessed via the IP as it is assigned to the app service plan, which can be shared by other app services. The FQDN is required for app service plan to do L7 routing

Related