Forum Discussion
How To Handle Dynamic IP Addresses Of Clients?
For dynamic home/ISP client IPs, I would avoid trying to maintain Azure Firewall source-IP allowlists. It becomes fragile quickly because the identity of the user and the network location are being mixed together.
The better pattern depends on what the users are accessing:
1. Admin access to VMs: use Azure Bastion or VPN/P2S rather than opening RDP/SSH through firewall rules.
2. Private app access: use VPN, Entra-aware reverse proxy/App Proxy, Private Access, or an app-level identity control.
3. Outbound from known clients to Azure resources: have users enter through a controlled egress point such as VPN or corporate proxy, then allow that stable egress.
4. Azure service access: use service tags/FQDN tags where applicable, but those solve Azure service destinations, not arbitrary user source IPs.
VNet peering is not a solution for random internet clients by itself. It connects VNets. For users with changing public IPs, you need a stable access path or identity-based access, not broader IP ranges.
Useful docs:
https://learn.microsoft.com/azure/vpn-gateway/point-to-site-about
https://learn.microsoft.com/azure/virtual-network/service-tags-overview
https://learn.microsoft.com/azure/firewall/service-tags