Is there a need to configure any port on Firewall for Azure Arc inbound connectivity?

CloudMan 20 Reputation points
2024-11-05T11:48:03.7733333+00:00

I want to know whether AzureArc extensions like AMA, WAC, ESU, HybridWorker etc need any inbound ports to be opened on Firewall? The outbound connectivity is public via the internet. Nothing configured for Inbound specifically. A lot of these extensions get deployed on the Azure Arc enabled on-prem servers. How do they get deployed when only outbound connectivity is enabled?

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
685 questions
{count} votes

Accepted answer
  1. Timmy Malmgren 1,521 Reputation points
    2024-11-05T14:40:52.5033333+00:00

    Hello

    Azure Arc is agent-based, so your Azure Arc enabled servers have an agent installed that will communicate/connect over 443 outbound (from the agent on the server) to your tenant/azure arc instance in Azure. If nothing specific is specified as inbound (i don't know any Azure Arc extension that does) it is all handled trough the outbound connection from the Agent on the server. This will handle evaluation of configurations and policy compliance for the server and deploy them if they do not match what is specified in Azure.

    For more in-depth information about the agent
    https://learn.microsoft.com/en-us/azure/azure-arc/servers/agent-overview

    For more in-depth about the network parts
    https://learn.microsoft.com/en-us/azure/azure-arc/servers/network-requirements?tabs=azure-cloud

    But like stated above you most likely only have to worry about the agent being able to communicate outbound on 443 to you Azure (internet) :)

    Hope this is helpful and remember shared knowledge is the best knowledge 😊

    Best Regards,

    Timmy Malmgren


    If the Answer is helpful, please click "Accept Answer" and upvote it as it helps others to find what they are looking for faster!

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.