question

mdosolv-7869 avatar image
0 Votes"
mdosolv-7869 asked mdosolv-7869 commented

Does ASEv3 / Isolatedv2 still support Private Endpoint connectivity?

Hello,

We're working on a usecase that uses the ASEv3 for isolated app-hosting, now that it has become GA. It uses an Isolatedv2 serviceplan.
The usecase takes advantage of UDR for outbound connectivity on the subnet used for the ASE.

As the ASE itself requires a sizable subnet, and we have a requirement to significantly limit (routed) IP-footprint, we are looking to use Private Endpoint for selective disclosure of apps on other subnets. Peered connectivity to the apps is successful, however, connections to ASEv3-hosted apps over PE's currently fail.

Q: Are PE's still supported for ASEv3? I can find docs on PE's used on ASEv2 but nothing yet regarding v3.

Thanks!

azure-webapps
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

ryanchill avatar image
0 Votes"
ryanchill answered mdosolv-7869 commented

Hi @mdosolv-7869,

however, connections to ASEv3-hosted apps over PE's currently fail.

If you recreated your ASEv3 before 6/4, please check this guidance to see if private endpoint ASEv3 has been replaced. If it has, per the guidance, adjust your DNS entry to match the new IP. If this resolves your issue, you should've received a notification about this change. The email address it would've been sent to is on the Cost Management + Billing blade. Please let me know if this does or doesn't resolve your issue.

Are PE's still supported for ASEv3? I can find docs on PE's used on ASEv2 but nothing yet regarding v3.

I will get further clarification from the product group with regards to use of private endpoints inside ASEv3 and update this post with my findings.


EDIT: I've heard from the product group. Currently, ASEv3 doesn't support private endpoints. There is current work being done to add that support but not ETA for when to expect those changes.

· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Goodmorning @ryanchill,

Thank you for replying to me.

Please let me know if this does or doesn't resolve your issue.

The ASEv3 (and linked PE) are created (much) later than the specified date. We are aware of the DNS-addressing requirement pointing towards the ASE's internal IP.
Connecting directly to apps hosted on that address is working fine (what I referred to as "peered connectivity").

My question focuses solely on the usage of PrivateEndpoints on ASEv3/IsolatedV2. Both Portal and ARM instructions will let me setup PE's on ASEv3/IsolatedV2 and those endpoints even contain the configured hostnames of the apps on the ASEv3. To me, this indicates we are on the correct (and supported) way. ​For that matter I will be very interested what you can find out with the product group.

0 Votes 0 ·

Hi @mdosolv-7869 please see my edited post above.

0 Votes 0 ·

Thank you @ryanchill for clarifying.

1 Vote 1 ·