Home
%3CLINGO-SUB%20id%3D%22lingo-sub-369077%22%20slang%3D%22en-US%22%3EConnect%20to%20Azure%20SQL%20Database%20Managed%20Instance%20with%20Virtual%20Network%20peering%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-369077%22%20slang%3D%22en-US%22%3E%0A%20%26lt%3Bmeta%20http-equiv%3D%22Content-Type%22%20content%3D%22text%2Fhtml%3B%20charset%3DUTF-8%22%20%2F%26gt%3B%3CSTRONG%3EFirst%20published%20on%20MSDN%20on%20Oct%2026%2C%202018%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3E%20%3CSTRONG%3E%20How%20to%20connect%20with%20an%20existing%20VM%20to%20your%20Managed%20Instance%20Vnet%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CEM%3E%20This%20guide%20assumes%20you%20already%20have%20a%20deployment%20of%20a%20Managed%20instance%20in%20your%20subscription%20%3C%2FEM%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CSTRONG%3E%20Problem%20summary%3A%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CEM%3E%20Initially%2C%20you%20might%20%3CSTRONG%3E%20not%20%3C%2FSTRONG%3E%20want%20to%20deploy%20a%20new%20machine%20using%20the%20script%20in%20the%20%3CSTRONG%3E%20Getting%20Started%20%3C%2FSTRONG%3E%20section%20in%20your%20Managed%20Instance%20to%20connect%2C%20because%20you%20already%20have%20several%20deployed%20VMs%20and%20you%20don't%20want%20to%20deploy%20a%20new%20Virtual%20Machine%20and%20incur%20in%20additional%20costs.%20In%20this%20case%2C%20we%20could%20suggest%20you%20to%20peer%20your%20existing%20Virtual%20networks%20to%20your%20Managed%20Instance%20Virtual%20network%2C%20taking%20into%20account%20that%20you%20already%20have%20an%20existing%20Virtual%20network%20in%20the%20same%20regions%20as%20the%20one%20where%20your%20Managed%20Instance%20was%20deployed%20to.%20%3C%2FEM%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CSTRONG%3EExplanation%20of%20this%20guide%3A%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CEM%3E%20This%20guide%20was%20designed%20to%20guide%20our%20customers%20to%20be%20able%20to%20connect%20to%20their%20Managed%20Instance%20from%20a%20%3CSTRONG%3E%20Virtual%20Machine%20%3C%2FSTRONG%3E%20from%20a%20different%20%3CSTRONG%3E%20Virtual%20Network%20%3C%2FSTRONG%3E%20to%20their%20Managed%20Instance.%20The%20solution%20to%20this%20problem%20is%20by%20creating%20%3CSTRONG%3E%20Virtual%20Network%20Peerings%20%3C%2FSTRONG%3E%20.%20Why%20the%20peering%20needs%20to%20be%20both%20ways%3F%20Well%2C%20by%20design%2C%20network%20peering%20will%20only%20go%20A%20--%26gt%3B%20%3C%2FEM%3E%20%3CEM%3E%20B%20if%20you%20set%20it%20this%20way.%20If%20you%20don%E2%80%99t%20set%20B%20--%26gt%3B%20%3C%2FEM%3E%20%3CEM%3E%20A%2C%20then%20no%20response%20will%20be%20received%20resulting%20in%20several%20connectivity%20errors%20such%20as%20%3CSTRONG%3E%20SNI%20timeouts%20%3C%2FSTRONG%3E%20and%20%3CSTRONG%3E%20connection%20timeouts%20%3C%2FSTRONG%3E%20.%20Why%3F%20Well%2C%20if%20you%20think%20of%20it%20in%20terms%20of%20connectivity%2C%20we%20send%20some%20pre-login%20packets%20to%20the%20resource%20(Managed%20Instance)%3B%20taking%20into%20consideration%20that%20the%20flow%20is%20from%20A%20%3C%2FEM%3E%20%3CEM%3E%20--%26gt%3BB%2C%20B%20will%20not%20have%20a%20way%20to%20send%20back%20packets%20to%20A%2C%20therefore%20this%20would%20cause%20a%20loss%20in%20connectivity%20at%20the%20pre-login%20phase.%20Therefore%2C%20the%20%3CSTRONG%3E%20Virtual%20Network%20Peering%20%3C%2FSTRONG%3E%20must%20be%20set%20both%20ways%20A%20--%26gt%3B%20%3C%2FEM%3E%20%3CEM%3E%20B%20and%20B%20--%26gt%3B%20%3C%2FEM%3E%20%3CEM%3E%20A.%20%3C%2FEM%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20On%20your%20portal%2C%20create%20a%20new%20Virtual%20network.%20%3CBR%20%2F%3E%3CUL%3E%3CBR%20%2F%3E%3CLI%3EIt%20doesn%E2%80%99t%20matter%20if%20the%20Virtual%20network%20or%20the%20VM%20is%20in%20another%20resource%20group.%3C%2FLI%3E%3CBR%20%2F%3E%3CLI%3EIt%20is%20essential%20that%20you%20create%20this%20new%20virtual%20network%20and%20the%20VM%20in%20the%20same%20region%20as%20your%20Managed%20Instance.%3C%2FLI%3E%3CBR%20%2F%3E%3C%2FUL%3E%3CBR%20%2F%3E%20%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F89036i2209531955B4A675%22%20%2F%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20Create%20a%20new%20VM%20and%20attach%20it%20to%20this%20new%20Virtual%20network%20(ToMIVnet)%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F89037i4E34142C2CC80D51%22%20%2F%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F89038iE0D8B372EE2CBB54%22%20%2F%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20Once%20the%20VM%20is%20created%20and%20attached%20to%20the%20new%20virtual%20network%2C%20we%20will%20proceed%20to%20configure%20the%20Peerings%20between%20the%20two%20virtual%20networks.%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F89039i80C6BDCE3EC00684%22%20%2F%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CSTRONG%3E%20Setting%20A%20--%26gt%3B%20B%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F89040i287DCCBE608F0098%22%20%2F%3E%20%3CBR%20%2F%3E%3CUL%3E%3CBR%20%2F%3E%3CLI%3EClick%20on%20%2BAdd%3C%2FLI%3E%3CBR%20%2F%3E%3CLI%3EAdd%20a%20name%20to%20the%20peering%3C%2FLI%3E%3CBR%20%2F%3E%3CLI%3EChoose%20the%20virtual%20network%20you%20are%20going%20to%20peer%20it%20to%3C%2FLI%3E%3CBR%20%2F%3E%3CLI%3EHit%20the%20OK%20button.%3C%2FLI%3E%3CBR%20%2F%3E%3C%2FUL%3E%3CBR%20%2F%3E%20%3CA%20href%3D%22https%3A%2F%2Fmsdnshared.blob.core.windows.net%2Fmedia%2F2018%2F10%2FMI6_LI.jpg%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%20%3C%2FA%3E%20%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F89041iB611CB94389B99C1%22%20%2F%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CSTRONG%3E%20Setting%20A%20%26lt%3B--%20B%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F89042i3AA73681AFDF9EDC%22%20%2F%3E%20%3CBR%20%2F%3E%20%3CBR%20%2F%3E%20%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F89043i7836ED34F5AC3D3A%22%20%2F%3E%20%3CBR%20%2F%3E%3CUL%3E%3CBR%20%2F%3E%3CLI%3EDo%20the%20same%20as%20you%20did%20with%20A%2C%20but%20in%20B.%3C%2FLI%3E%3CBR%20%2F%3E%3CLI%3ENow%2C%20fire%20up%20your%20new%20VM%20in%20the%20external%20virtual%20network%20that%20is%20now%20peered%20to%20your%20Managed%20Instance%20Virtual%20network%2C%20install%20SQL%20Server%20Management%20Studio%20and%20try%20to%20connect%20to%20your%20Managed%20Instance.%3C%2FLI%3E%3CBR%20%2F%3E%3CLI%3ENow%2C%20at%20this%20step%2C%20you%20should%20be%20able%20to%20connect%20to%20your%20Managed%20Instance%20and%20manage%20it!%3C%2FLI%3E%3CBR%20%2F%3E%3C%2FUL%3E%0A%20%0A%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-369077%22%20slang%3D%22en-US%22%3EFirst%20published%20on%20MSDN%20on%20Oct%2026%2C%202018%20How%20to%20connect%20with%20an%20existing%20VM%20to%20your%20Managed%20Instance%20VnetThis%20guide%20assumes%20you%20already%20have%20a%20deployment%20of%20a%20Managed%20instance%20in%20your%20subscriptionProblem%20summary%3A%20Initially%2C%20you%20might%20not%20want%20to%20deploy%20a%20new%20machine%20using%20the%20script%20in%20the%20Getting%20Started%20section%20in%20your%20Managed%20Instance%20to%20connect%2C%20because%20you%20already%20have%20several%20deployed%20VMs%20and%20you%20don't%20want%20to%20deploy%20a%20new%20Virtual%20Machine%20and%20incur%20in%20additional%20costs.%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-369077%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Eazure%20sql%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Emanaged%20instance%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Emanaged%20instance%20connection%20time%20out%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EManagement%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EPeering%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Epre%20login%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Esni%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EVirtual%20Machine%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EVirtual%20Network%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Evirtual%20network%20peering%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Evnet%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft
First published on MSDN on Oct 26, 2018
How to connect with an existing VM to your Managed Instance Vnet

This guide assumes you already have a deployment of a Managed instance in your subscription

Problem summary:

Initially, you might not want to deploy a new machine using the script in the Getting Started section in your Managed Instance to connect, because you already have several deployed VMs and you don't want to deploy a new Virtual Machine and incur in additional costs. In this case, we could suggest you to peer your existing Virtual networks to your Managed Instance Virtual network, taking into account that you already have an existing Virtual network in the same regions as the one where your Managed Instance was deployed to.

Explanation of this guide:

This guide was designed to guide our customers to be able to connect to their Managed Instance from a Virtual Machine from a different Virtual Network to their Managed Instance. The solution to this problem is by creating Virtual Network Peerings . Why the peering needs to be both ways? Well, by design, network peering will only go A --> B if you set it this way. If you don’t set B --> A, then no response will be received resulting in several connectivity errors such as SNI timeouts and connection timeouts . Why? Well, if you think of it in terms of connectivity, we send some pre-login packets to the resource (Managed Instance); taking into consideration that the flow is from A -->B, B will not have a way to send back packets to A, therefore this would cause a loss in connectivity at the pre-login phase. Therefore, the Virtual Network Peering must be set both ways A --> B and B --> A.

On your portal, create a new Virtual network.

  • It doesn’t matter if the Virtual network or the VM is in another resource group.

  • It is essential that you create this new virtual network and the VM in the same region as your Managed Instance.




Create a new VM and attach it to this new Virtual network (ToMIVnet)





Once the VM is created and attached to the new virtual network, we will proceed to configure the Peerings between the two virtual networks.



Setting A --> B



  • Click on +Add

  • Add a name to the peering

  • Choose the virtual network you are going to peer it to

  • Hit the OK button.




Setting A <-- B





  • Do the same as you did with A, but in B.

  • Now, fire up your new VM in the external virtual network that is now peered to your Managed Instance Virtual network, install SQL Server Management Studio and try to connect to your Managed Instance.

  • Now, at this step, you should be able to connect to your Managed Instance and manage it!