We are facing an issue with exposing Mosquitto MQTT running on private Azure Redhat Openshift to internet over TLS using Azure firewall . I think this will be relevant for any private openshift cluster running mosquitto. To access MQTT server the client needs to access it using hostname assigned to the Openshift passthrough router since it is using TLS as mentioned in this document https://developers.redhat.com/blog/2021/04/26/deploying-the-mosquitto-mqtt-message-broker-on-red-hat-openshift-part-2
We have successfully tested access to the MQTT service from a VM running on the same VNet as ARO using mosquitto_pub/sub client. The command is as below where the –host is very important as it allows Openshift passthrough router to determine the pod which hosts the service
$ mosquitto_pub -t foo -m "text" --cafile mosquitto_ca.crt
--insecure -u admin -P admin --host mosquitto.apps.my_domain --port 443
When we try to expose the service using Azure firewall, we are using DNAT rules to allow access from public internet. But DNAT rules don’t allow FQDN in the destination address. So we are forced to use the load balancer address of the cluster as the destination address. But this results is TLS error as SNI is not working using IP address. To enable SNI we somehow need to redirect using the hostname. Would anyone have idea on how to expose such passthrough routes via Azure Firewall? Is there any way Azure firewall could support FQDNs for target address for inbound traffic? We could as an alternative use App Gateway with Websocket protocol - but since this is non http traffic we wanted to use Azure firewall and also for its enhanced traffic control ability over app gateway. Any help much appreciated.