MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.26k stars 21.43k forks source link

Details on the NSG rules? #100269

Closed Candelit closed 3 months ago

Candelit commented 2 years ago

Hi.

We are moving from AKS to CAE, and want to restrict access as much as possible in a zero trust spirit, only allowing what we have to. The section on NSG allow rules are to me unclear... Can you please make them a bit more...exact?

On the Inbound section, we get protocol, port and 'service tag'. But what is source and destination? Is the service tag for the source or the destination, or both? If destination, what then should be the source?

It would realy be nice to get superclear instructions on this since it is a super complex setup, and we can't have it failing on us.

There is also at the end of this section a mention of: 'If you are running HTTP servers, you might need to add ports 80 and 443. Adding deny rules for some ports and protocols with lower priority than 65000 may cause service interruption and unexpected behavior.'

The highest priority possible is 4096...so what does that mean? The 'add ports 80 and 443'? Where? To which rule?

The article would be better with one or two complete examples.

Lastly, even the part about UDRs is a bit unclear. Using custom user-defined routes (UDRs) or ExpressRoutes, other than with UDRs of selected destinations that you own, are not yet supported for Container App Environments with VNETs. Therefore, securing outbound traffic with a firewall is not yet supported. We use a default UDR that sends 0.0.0.0/+0 to our Palo Alto firewall, do we have to remove that from the CAE subnet or not?

Thanks // Thomas Odell Balkeståhl


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

YashikaTyagii commented 2 years ago

@Candelit Thanks for your feedback! We will investigate and update as appropriate.

SaibabaBalapur-MSFT commented 2 years ago

@Candelit Since this issue isn't directly related to improving our docs, and to gain a better understanding of your issue, I'd recommend working closer with our support team via an [Azure support request] (https://docs.microsoft.com/en-us/azure/azure-portal/supportability/how-to-create-azure-support-request). Or you can leverage our Q&A forum by posting your issue there so our community, and MVPs can further assist you in troubleshooting this issue or finding potential workarounds.

[Teams Q&A forum] (https://docs.microsoft.com/en-us/answers/topics/46488/office-teams-windows-itpro.html) for technical questions about the configuration and administration of Microsoft Teams on Windows. [Microsoft Teams Community forum] (https://answers.microsoft.com/en-us/msteams/forum?sort=LastReplyDate&dir=Desc&tab=All&status=all&mod=&modAge=&advFil=&postedAfter=&postedBefore=&threadType=All&isFilterExpanded=false&page=1

Candelit commented 2 years ago

Eh, sorry, but did you ever read my input? Its 100% relevant to improving Docs… The article today is unclear, unfinished and wrong. I tried to help you, me and every other customer is all.

I do not need help from support, where did you read that?

Regards Thomas

Sent from Outlook for iOShttps://aka.ms/o0ukef


From: Saibaba Balapur Hireka @.> Sent: Tuesday, October 25, 2022 7:23:05 AM To: MicrosoftDocs/azure-docs @.> Cc: Thomas @.>; Mention @.> Subject: Re: [MicrosoftDocs/azure-docs] Details on the NSG rules? (Issue #100269)

@Candelithttps://github.com/Candelit Since this issue isn't directly related to improving our docs, and to gain a better understanding of your issue, I'd recommend working closer with our support team via an [Azure support request] (https://docs.microsoft.com/en-us/azure/azure-portal/supportability/how-to-create-azure-support-request). Or you can leverage our Q&A forum by posting your issue there so our community, and MVPs can further assist you in troubleshooting this issue or finding potential workarounds.

[Teams Q&A forum] (https://docs.microsoft.com/en-us/answers/topics/46488/office-teams-windows-itpro.html) for technical questions about the configuration and administration of Microsoft Teams on Windows. [Microsoft Teams Community forum] (https://answers.microsoft.com/en-us/msteams/forum?sort=LastReplyDate&dir=Desc&tab=All&status=all&mod=&modAge=&advFil=&postedAfter=&postedBefore=&threadType=All&isFilterExpanded=false&page=1

— Reply to this email directly, view it on GitHubhttps://github.com/MicrosoftDocs/azure-docs/issues/100269#issuecomment-1289998239, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AES2L6JXFSAV43SJN7YQJ7DWE5VDTANCNFSM6AAAAAARK7HJK4. You are receiving this because you were mentioned.Message ID: @.***>

SaibabaBalapur-MSFT commented 2 years ago

@Candelit I have reopened this case and assign this to the document author so they can take a look at it accordingly.

craigshoemaker commented 3 months ago

Thanks for your feedback and your contribution to Azure docs.

Feedback for this repository is moving away from GitHub to a system specific to the Microsoft Learn platform. Issues for this repository will soon be disabled, and additional comments from GitHub will no longer be possible. However, we are now tracking and triaging this issue in the new feedback system.

To learn more about our feedback systems, please see Provide feedback for Microsoft Learn content.

please-close