Azure Premium Frontdoor linked to internal Load Balancer in front of Azure VM in private subnets not working

Alvin 25 Reputation points
2023-09-05T14:39:42.8866667+00:00

Hello,

Following this link https://video2.skills-academy.com/en-us/azure/frontdoor/standard-premium/how-to-enable-private-link-internal-load-balancer I implemented Azure front door premium with private link services linked to an internal load balancer in front of Azure Virtual machines in a private subnet, this appears not to be working. Any ideas on what I could be doing wrong?

Kindly note that this architecture works fine with a public load balancer and without the private link service.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,471 questions
Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
622 questions
Azure Private Link
Azure Private Link
An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.
484 questions
Azure Load Balancer
Azure Load Balancer
An Azure service that delivers high availability and network performance to applications.
420 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 39,446 Reputation points Microsoft Employee
    2023-09-12T13:10:56.5533333+00:00

    @Alvin

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to connect your application running behind ILB to AFD via Private Link Service.

    You informed us directly accessing the ILB did not work from a dummy VM in same VNET

    • Your backend(ILB) was not responding
    • I checked the configuration and isolated the issue being "Floating IP" enabled
    • Disabling this, made the ILB accessible from the dummyVM.

    Later, you wanted to access the ILB from one of the backend VMs of the ILB

    To make it accessible via Public Internet, we are leveraging AFD + Private Link.

    • In your case, if you were to confirm that accessing the ILB via DummyVM works fine, then I would say ILB set up is correct and is working as expected.
    • Now, we should troubleshoot why this would not work as a backend of AFD.
    • You informed us you are looking into the Private Link Service Subnet "Private endpoint network policy"

    Thanks,

    Kapil

    0 comments No comments

0 additional answers

Sort by: Most helpful