Tutorial: Connect to a web app using an Azure Private Endpoint
Azure Private endpoint is the fundamental building block for Private Link in Azure. It enables Azure resources, like virtual machines (VMs), to communicate with Private Link resources privately.
In this tutorial, you learn how to:
- Create a virtual network and bastion host.
- Create a virtual machine.
- Create a webapp.
- Create a private endpoint.
- Test connectivity to web app private endpoint.
If you don't have an Azure subscription, create a free account before you begin.
Private Endpoint is available in public regions for PremiumV2-tier, PremiumV3-tier Windows web apps, Linux web apps, and the Azure Functions Premium plan (sometimes referred to as the Elastic Premium plan).
- An Azure subscription
Sign in to Azure
Sign in to the Azure portal.
Create a virtual network and bastion host
In this section, you'll create a virtual network, subnet, and bastion host.
The bastion host will be used to connect securely to the virtual machine for testing the private endpoint.
On the upper-left side of the screen, select Create a resource > Networking > Virtual network or search for Virtual network in the search box.
In Create virtual network, enter or select this information in the Basics tab:
Setting Value Project Details Subscription Select your Azure subscription Resource Group Select myResourceGroup Instance details Name Enter myVNet Region Select West Europe
Select the IP Addresses tab or select the Next: IP Addresses button at the bottom of the page.
In the IP Addresses tab, enter this information:
Setting Value IPv4 address space Enter 10.1.0.0/16
Under Subnet name, select the word default.
In Edit subnet, enter this information:
Setting Value Subnet name Enter mySubnet Subnet address range Enter 10.1.0.0/24
Select the Security tab.
Under BastionHost, select Enable. Enter this information:
Setting Value Bastion name Enter myBastionHost AzureBastionSubnet address space Enter 10.1.1.0/24 Public IP Address Select Create new. For Name, enter myBastionIP. Select OK.
Select the Review + create tab or select the Review + create button.
Create a virtual machine
In this section, you'll create a virtual machine that will be used to test the private endpoint.
On the upper-left side of the portal, select Create a resource > Compute > Virtual machine or search for Virtual machine in the search box.
In Create a virtual machine, type or select the values in the Basics tab:
Setting Value Project Details Subscription Select your Azure subscription Resource Group Select myResourceGroup Instance details Virtual machine name Enter myVM Region Select West Europe Availability Options Select No infrastructure redundancy required Image Select Windows Server 2019 Datacenter - Gen1 Azure Spot instance Select No Size Choose VM size or take default setting Administrator account Username Enter a username Password Enter a password Confirm password Reenter password
Select the Networking tab, or select Next: Disks, then Next: Networking.
In the Networking tab, select or enter:
Setting Value Network interface Virtual network myVNet Subnet mySubnet Public IP Select None. NIC network security group Basic Public inbound ports Select None.
Select Review + create.
Review the settings, and then select Create.
Create web app
In this section, you'll create a web app.
In the left-hand menu, select Create a resource > Storage > Web App, or search for Web App in the search box.
In the Basics tab of Create Web App enter or select the following information:
Setting Value Project Details Subscription Select your Azure subscription Resource Group Select myResourceGroup Instance details Name Enter mywebapp. If the name is unavailable, enter a unique name. Publish Select Code. Runtime stack Select .NET Core 3.1 (LTS). Operating System Select Windows. Region Select West Europe App Service Plan Windows Plan (West Europe) Select Create new. Enter myServicePlan in Name. Sku and size Select Change size. Select P2V2 in the Spec Picker screen. Select Apply.
Select Review + create.
Create private endpoint
In the left-hand menu, select All Resources > mywebapp or the name you chose during creation.
In the web app overview, select Settings > Networking.
In Networking, select Configure your private endpoint connections.
Select + Add in the Private Endpoint connections screen.
Enter or select the following information in the Add Private Endpoint screen:
Setting Value Name Enter mywebappendpoint. Subscription Select your subscription. Virtual network Select myVNet. Subnet Select mySubnet. Integrate with private DNS zone Select Yes.
Test connectivity to private endpoint
In this section, you'll use the virtual machine you created in the previous step to connect to the web app across the private endpoint.
Select Resource groups in the left-hand navigation pane.
On the overview page for myVM, select Connect then Bastion.
Select the blue Use Bastion button.
Enter the username and password that you entered during the virtual machine creation.
Open Windows PowerShell on the server after you connect.
nslookup <webapp-name>.azurewebsites.net. Replace <webapp-name> with the name of the web app you created in the previous steps. You'll receive a message similar to what is displayed below:
Server: UnKnown Address: 18.104.22.168 Non-authoritative answer: Name: mywebapp8675.privatelink.azurewebsites.net Address: 10.1.0.5 Aliases: mywebapp8675.azurewebsites.net
A private IP address of 10.1.0.5 is returned for the web app name. This address is in the subnet of the virtual network you created previously.
Open a web browser on your local computer and enter the external URL of your web app, https://<webapp-name>.azurewebsites.net.
Verify that you receive a 403 page. This page indicates that the web app isn't accessible externally.
In the bastion connection to myVM, open Internet Explorer.
Enter the url of your web app, https://<webapp-name>.azurewebsites.net.
Verify you receive the default web app page.
Close the connection to myVM.
Clean up resources
If you're not going to continue to use this application, delete the virtual network, virtual machine, and web app with the following steps:
From the left-hand menu, select Resource groups.
Select Delete resource group.
Enter myResourceGroup in TYPE THE RESOURCE GROUP NAME.
Learn how to create a Private Link service: