Networking

The Networking forum covers all aspects of Networking in Azure, including endpoints, load-balancing, network security, DNS, Traffic Manager, virtual networks, and external connectivity.

Virtual Network:

  • Service overview

  • Technical documentation

  • Pricing details

  • Traffic Manager:

  • Service overview

  • Technical documentation

  • Pricing details

  • Network Watcher:

  • Service overview

  • Technical documentation

  • Pricing details

  • If you have any feedback on any aspect of Azure relating to Networking, we’d love to hear it.

    • Hot ideas
    • Top ideas
    • New ideas
    • My feedback
    1. Enable NSG Flow Logs for secured Storage Accounts

      At the moment, it's apparently not possible to use NSG Flow Logs with secured Storage Accounts, even if the exception "Allow trusted Microsoft services to access this storage account" is enabled on the Storage Account.

      It would be really helpful if you could add the Network Watcher this list of trusted Microsoft servies, so we can use secured Storage Accounts to store our NSG Flow Logs on.

      127 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      4 comments  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    2. ARM Template support for NSG Flow logs

      Add support to configure NSG Flow logs using Azure Resource Manager template.

      The goal is to have Azure Policy to deploy NSG Flow Log configuration.

      Reference to Docs:
      https://docs.microsoft.com/en-us/azure/network-watcher/traffic-analytics-faq#can-i-configure-traffic-analytics-using-powershell-or-an-azure-resource-manager-template-or-client

      122 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      3 comments  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →

      Great news! ARM Template support for NSG Flow Logs and Traffic Analytics is now available in all regions.

      Useful links:
      1. Documentation: https://docs.microsoft.com/azure/network-watcher/network-watcher-nsg-flow-logging-azure-resource-manager
      2. Template Reference: https://docs.microsoft.com/azure/templates/microsoft.network/2019-11-01/networkwatchers/flowlogs
      3. Quickstart Template: https://azure.microsoft.com/en-in/resources/templates/101-networkwatcher-flowlogs-create/

      We will soon be releasing a QuickStart template to make using this feature easier. Stay tuned.

      Thanks for your patience and keep your feedback on the forums coming.

    3. ExpressRoute / On-Premises to VNET monitoring

      Add ability to monitor and store latency between Azure VNet and On-Premises network.

      We have an ExpressRoute circuit and would like to know how latency changes throughout a day, allowing us to possibly correlate it with other traffic.

      For example, to record a 15 second ICMP Ping round trip every 5 minutes would be a very good start.

      Bonus points: Tracking throughput would be nice too - think PsPing.exe

      41 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      2 comments  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    4. Add OMS integration for NSG Flog Logs

      Currently you can only send flow logs to a storage account. Add support for sending them to OMS.

      40 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      1 comment  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    5. Traffic Analytics in Canadian Region

      I would like Traffic Analytics available in Canadian Regions as we have a requirement of data sovereignty. Thus our networks and log analytics workspaces must remain in Canada

      25 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      completed  ·  2 comments  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    6. Need a way to collect traffic meta data

      Need to collect all network traffic related operation happening on a VM or at VPC. Following network details are expected to be fetched using Azure RM log analytics.
      1. Source IP
      2. Source Port
      3. Destination IP
      4. Destination Port
      5. Traffic Direction
      6. Protocol
      7. Action taken

      23 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      2 comments  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    7. Packet and Byte Count in NSG Flow Logs

      Adding packet and byte count to NSG flow logs would give it parity with a number of netFlow analysis tools. Analyzing flows by data transferred is much more useful than counting flows and provides much better insight into the network.

      While WireData may provide this additional data it is (1) not available everywhere, (2) provides data redundant to NSG Flow, and (3) requires agent to get the necessary data.

      13 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      completed  ·  0 comments  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    8. ExpressRoute Monitoring from multiples VNETs from different subscriptions

      I have a scenario where 8 VNETs, from 8 different subscriptions are connected to a single ER Circuit. Today, NPM needs that I create 8 different OMS Workspaces to be able to monitor each VNET individually. I wish that we could add VNETs from different Subscription in the same OMS Workspace/NPM Solution, and have a single pane to monitor them all.

      10 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      completed  ·  1 comment  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    9. NSG logs should show the IP address and port of the client on inbound traffic

      It shows the rule that blocked the request but doesn't show any details around the person trying to hit your resource.

      It shows the IP address of the Azure resource that they were trying to hit as well.

      It would be nice to see how much blocked traffic we're getting from a specific client for troubleshooting or for ensuring we don't have anyone trying to breach the network on that endpoint.

      7 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    10. Let IP flow verify show which NSG is matched.

      The current implementation of IP flow verify in network watcher shows the name of the rule that is matched for allowing/denying traffic. It doesn't show the name of the effective NSG itself (only the rule in an NSG). A useful addition would be to show the name of the NSG in additional to the matched rule. A click through to the NSG for instant changes would help as well.

      7 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    11. scheduled connectivity check

      Scheduled connectivity check
      Check functionality is fine. I want to get email when check is completed and failed. So we need recurring checks.

      6 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →

      Try out Connection Monitor and let us know what you think!

      Connection monitor enables scenarios like monitoring connectivity from a VM in a virtual network to a VM running SQL server in the same or different virtual network, over port 1433. Connection monitor provides you connection latency as an Azure Monitor metric, recorded every 60 seconds. It also provides you a hop-by-hop topology, and identifies configuration issues impacting your connection.

      https://docs.microsoft.com/en-us/azure/network-watcher/connection-monitor

    12. Add vnet peering to Topology diagram

      The vNet/Monitor/Diagram blade is great.
      However it would be better if it also included vNet peerings.
      Currently those are not shown on the diagram.
      Also it would be good to select multiple RGs (in case they have connected resources.

      4 votes
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      1 comment  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    13. When will the service be available in Asia Pacific regions?

      When will the service be available in Asia Pacific regions?

      1 vote
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      completed  ·  0 comments  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    14. 1 vote
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      0 comments  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    15. Provide option to trigger Alerts based on Network Watcher Connection Monitor result

      It would be useful if there is an option to trigger an Alert directly from the Network Watcher Connection Monitor when the result of a Monitor is UnReachable.

      1 vote
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      completed  ·  1 comment  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    16. traffic analytics dashboard not showing data after long time

      I enabled traffic analytics dashboard to get insights from NSGs and after one hour, I still don't see any data on the dashboard.
      when I open the dashboard, it doesn't show my log analytics workspace:
      "Looks like you do not have any Log Analytics workspace under the selected Log Anaytics subscriptions. Try changing the Log Analytics subscriptions selection."
      Is there anything I can try to fix it?

      1 vote
      Vote
      Sign in
      (thinking…)
      Sign in with: Microsoft
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      completed  ·  1 comment  ·  Network Watcher  ·  Flag idea as inappropriate…  ·  Admin →
    • Don't see your idea?

    Feedback and Knowledge Base