Azure-docs: NSG allowed on Gateway subnet but Portal says not?

Created on 12 Oct 2018  Â·  6Comments  Â·  Source: MicrosoftDocs/azure-docs

You can only deploy an Application Gateway into the subnet of type 'Gateway'. But on a Gateway Subnet, the option to configure a NSG is locked with a tooltip saying: "Assigning a network security group to a gateway subnet is not supported as virtual network gateway management and gateway connectivity may fail."
Am I missing something here?


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

application-gatewasvc cxp in-progress product-question triaged

Most helpful comment

@mrdfuse In my case I consciously wanted the gateway subnet to have the NSG as I need to whitelist some IPs. I believe the document is correct, so yes I supposed this issue being closed is accurate. The issue/bug is with the UI where it locks that and prevent users from assigning it.

Workaround for those who stumble across this issue is to use the CLI or Terraform to configure and you will be able to set the NSG on gateway subnet

All 6 comments

@mrdfuse App Gateways do not have the restriction of being deployed into gateway subnet, and you can put NSGs on the App Gateway Subnets.

We will now proceed to close this thread. If there are further questions regarding this matter, please tag me in your reply. We will gladly continue the discussion and we will reopen the issue.

@TravisCragg-MSFT This is a valid issue(could be a bug but not a documentation issue). Your documentation says it is valid but the UI(Portal) does not allow us to assign NSG to it.

capture1

My issue was about putting an NSG on a subnet created for an Application Gateway. My mistake was that I made the subnet of type Gateway, which is not necessary for an Application Gateway. In that respect Travis was right.

I'm not sure if your comment is relevant here, or even correct. If you have the same issue as me, try without creating a gateway subnet, but instead create a normal subnet for your Application Gateway.

@mrdfuse In my case I consciously wanted the gateway subnet to have the NSG as I need to whitelist some IPs. I believe the document is correct, so yes I supposed this issue being closed is accurate. The issue/bug is with the UI where it locks that and prevent users from assigning it.

Workaround for those who stumble across this issue is to use the CLI or Terraform to configure and you will be able to set the NSG on gateway subnet

@nloke Do you have an example or link to docs for how to do that?

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Favna picture Favna  Â·  3Comments

jamesgallagher-ie picture jamesgallagher-ie  Â·  3Comments

spottedmahn picture spottedmahn  Â·  3Comments

ianpowell2017 picture ianpowell2017  Â·  3Comments

monteledwards picture monteledwards  Â·  3Comments