Azure FW with VM NIC shows no internet access

Shola Lawani 531 Reputation points Microsoft Employee
2020-10-23T16:54:25.39+00:00

Hello Experts,

So I have a small lab environment with a hub (Azure FW) and two Spokes (with VMs). I'm redirecting all traffic 0.0.0.0/0 via the firewall using UDRs.

However, I have noticed that the VMs NIC (in the spokes vnet) in this set up indicates "No internet access", however, if I create an application rule to allow microsoft.com for instance I can still browse the site. My question, what is preventing the VM NIC from showing internet access, is there a rule in Azure FW that I haven't created

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
562 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,123 questions
{count} votes

2 answers

Sort by: Most helpful
  1. SUNOJ KUMAR YELURU 13,921 Reputation points MVP
    2020-10-25T03:25:12.45+00:00

    yes, you should allow azure FW rules that should allow internet access.

    https://learn.microsoft.com/en-us/azure/virtual-network/service-tags-overview

    1 person found this answer helpful.
    0 comments No comments

  2. Andreas Baumgarten 95,181 Reputation points MVP
    2020-10-25T09:57:09.55+00:00

    If I remember right the Windows Network Connectivity Status Indicator (NCSI) is running multiple tests to check if the client is connected to the internet.

    1. The following URL is used for the first test: https://www.msftconnecttest.com
    2. If the URL is reachable from the client a HTTP Get-Request for https://www.msftconnecttest.com/connecttest.txt is sent.
    3. If this is successfully, NCSI will try to resolve the DNS name dns.msftncsi.com.
    4. If the response is "131.107.255.255" the test is successful and the indicator in the Task Bar will show "Internet access".

    So you should add https://www.msftconnecttest.com to your white-list in the Firewall.


    (If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)

    Regards
    Andreas Baumgarten

    0 comments No comments