The Biggest Change To Azure No One Is Talking About!

preview_player
Показать описание
This Is The BIGGEST To Azure EVER! Default Outbound Internet Access will stop working September 30, 2025.

▬▬▬▬▬▬ C H A P T E R S 📲 ▬▬▬▬▬▬
00:00 Azure BIGGEST Change:
00:46 WHY Now?:
02:16 How It All Works:
03:22 Private Azure Subnets
05:05 Internet Access Options:
07:36 Build A Gateway:
10:16 Firewall Gateway:
11:28 Wrap Up:

▬▬▬▬▬▬ R E S O U R C E S 📡 ▬▬▬▬▬▬

▬▬▬▬▬▬ S U P P O R T 💰 ▬▬▬▬▬▬

#TheAzureAcademy #AzureNATGateway #AzureInternet
Рекомендации по теме
Комментарии
Автор

Thanks for the heads up!
We use NAT Gateway for client security requirements. Customers want to know which IPs our people are coming from.
If you have multiple public ips or prefixes assigned to your NAT Gateway, it does round robin (or is it random? can't recall but it changes) for any new outbound connections.
It's causing issues where we connect to a customers service (website, hosted desktop, etc) on one ip for auth and their service expects subsequent comm from that same ip BUT the next connection comes from a different ip in the natgw pool.
Otherwise, natgw has been really effective at its job.

anaveragehuman
Автор

It's a good move, I come from AWS background and was suprised how I had internet access by default in azure

eointhomas
Автор

Hey Dean, Great video as always :)
Are you aware of any documentation regarding this change in AVD deployment? I had a customer telling me they noticed NAT Gateway deployed automatically with their AVD. I've been chasing MS team to confirm how it'll be in cause all of a sudden there would be a responsibility of NatGateway resource back on customer. i.e. do we need DoS for that IP address ?

saeednouri
Автор

Honestly, I never understood why this wasn't the default behavior from the start. It always felt like an unnecessary risk.

benmitchell
Автор

The original announcement, and subsequent announcements, have said that this default outbound access will only be removed for new VMs in subnets created after September '25. So, unless somebody really messed up the communication, existing VMs and subnets should be fine.

macro
Автор

I have this set up today for some of my subnet to control the prefix. To my knowledge, one of my subnets are private so I'm confused why they and their limitations were such a focus here.

mcdonamw
Автор

Ok, the NAT Gateway allows outbound only and its stateful. Can you please explain, why you call this a "Zero Trust Model Network Device"? And what does that term even mean?

beatjunkies
Автор

wow! i had now idea.... this is great info 🙂

lwa.dev
Автор

We normally implement a firewall (azure or market place) will these be affected by the change?

keithbucknall
Автор

Good video, read about it a while ago. I've never heard of SNAT referred to as secure nat, i always thought it stood for source network address translation? Anyway, who cares, thanks for the video.

papajohnscookie
Автор

thanks for this, very useful. However I don’t believe NAT Gateway in combination with Azure Firewall is supported for Zone Redundant deployments. I learned this the hard way when I wanted to have a predictable IP address when making outbound SNAT connections through the Azure Firewall for 3rd party whitelisting purposes.

BuggageandGlitchage
Автор

how would you handle a zone redundant firewall with NAT gateway when you have to pin a NAT gateway to a particular zone? more of an issue if that zone fails.

jamiechilds
Автор

Hiding under the guise of "security"...is a new revenue generator for Microsoft.

gregstreuber
Автор

Instead of allowing whole subnet, how can I allow a single IP if I want to allow internet to a single VM in a subnet?

suvendupanda
Автор

Why is Azure copying Oracle Cloud and aws now? All these public-subnet vs Private Subnet and NAT Gateway along with Internet Gateway were Oracle's way (and AWS too)

syamantakpati
Автор

Ok NAT gateway is a good thing but it puts a ton of data processing costs on top...

moritz
Автор

There should be an option switch to turn it on and off. I dont want Outbound just going away the have to do all this stuff.

ApeZoneEntertainment
Автор

...where is the AVD book ... Walter wants 5 of those 🤩🤩🤩

Timmy-Hi
Автор

Why Aws kicks Azures Ass - private and public subnets has always been there. Seems weird not to do this.

dg
Автор

Is this a massive price rise by stealth?

jaaguitar
welcome to shbcf.ru