Azure-docs: Does "AzureCloud" IP range include all Azure IPs and tag like "Storage", "AppService"?

Created on 17 Apr 2019  Â·  10Comments  Â·  Source: MicrosoftDocs/azure-docs

  1. Does "AzureCloud" tag includes all Azure resources' public IP? If not, does it overlap (or include) with other tag such as "AppService"?
  2. What tag should Azure FrontDoor IPs belong to?
  3. Given a specific Azure IP, how can we identify which tag it belongs to?

I'm asking this because our customer thought whitelisting "AzureCloud" would whitelist all Azure IPs, but got problem that certain services got blocked (which works before when whitelisting "AzureCloud"), and found it's due to a set of new Azure IPs got blocked. Some of the IPs I found belongs to Azure Front Door and not in "AzureCloud" tag.


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

cxp product-question triaged virtual-networsvc

All 10 comments

Thanks for the question. We are currently investigating and will update you shortly.

@jinzejian

  1. You are correct, the AzureCloud tag is all azure public IP ranges, which includes many other service tags.
  2. If you would like to specify the Azure FrontDoor IP Ranges, you can find them Here.
  3. If you would like to figure out what tag it belongs to / what service it came from, you can match it to the IP Ranges and Service Tags list.

The IP Ranges and Service Tags list should contain everything you need.

Hi Travis, thanks for the information. Take "13.107.246.0/24" for example, it belongs to name" AzureFrontDoor.Frontend" and systemService "AzureFrontDoor", but I don't see such tag in NSG. Would you let me know what tag suites "13.107.246.0/24"?

Thanks.

@jinzejian Azure FrontDoor does not have a service tag at this time. It will be integrated into the Azure Cloud service tag in the near future, and get it's own service tag.

Thanks Travis for the reply. Which means "AzureCloud tag is all azure public IP ranges" is not entirely correct currently, right?

Also, which tag should these IP belongs to (or will belong to), I checked they do belongs to Azure
65.55.163.x

Thanks.

@jinzejian The published IP Ranges are in the JSON Doc. I am unsure outside of what is published there unfortunately.

Thanks Travis. Per "Azure FrontDoor does not have a service tag at this time. It will be integrated into the Azure Cloud service tag in the near future, and get it's own service tag." Do we have a ETA that can be shared with our customer?

@jinzejian Unfortunately no, I cannot state a time that it will be ready at this time.

We will now proceed to close this thread. If there are further questions regarding this matter, please tag me in your reply. We will gladly continue the discussion and we will reopen the issue.

Hello @jinzejian - we are currently working on enabling AFD service tag for NSG. Rough ETA is Q3'19. Thank you.

Noted, thanks @jispar !

Was this page helpful?
0 / 5 - 0 ratings