Home
%3CLINGO-SUB%20id%3D%22lingo-sub-891147%22%20slang%3D%22en-US%22%3ELesson%20Learned%20%23110%20Azure%20SQL%20Managed%20Instance%20and%20Azure%20DNS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-891147%22%20slang%3D%22en-US%22%3E%3CP%3EI%20got%20this%20recent%20case%20where%20customer%20wanted%20to%20create%20a%20%3CSTRONG%3Etransaction%20replication%20from%20Azure%20SQL%20Managed%20instance%20to%20another%20SQL%20Server%20inside%20the%20same%20virtual%20network%3C%2FSTRONG%3E%2C%20but%20in%20a%20different%20subnet%2C%20but%20all%20inside%20Azure.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20413px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F135292i93B25C4FDCAE13AF%2Fimage-dimensions%2F413x247%3Fv%3D1.0%22%20width%3D%22413%22%20height%3D%22247%22%20alt%3D%222019-10-03_15h57_07.png%22%20title%3D%222019-10-03_15h57_07.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CDIV%20id%3D%22tinyMceEditorclipboard_image_0%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20id%3D%22tinyMceEditorclipboard_image_1%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAll%20communications%20that%20happens%20on%20Azure%20Network%20if%20not%20set%20a%20custom%20DNS%20will%20use%20%3CSTRONG%3EAzure%20DNS%3C%2FSTRONG%3E%20to%20resolve%20name%20of%20resources%20inside%20the%20network.%20However%20there%20is%20something%20very%20important%20in%20the%20documentation%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-network%2Fvirtual-networks-name-resolution-for-vms-and-role-instances%23azure-provided-name-resolution%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CFONT%20size%3D%222%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-network%2Fvirtual-networks-name-resolution-for-vms-and-role-instances%23azure-provided-name-resolution%3C%2FFONT%3E%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22padding-left%3A%2030px%3B%22%3E%3CFONT%20size%3D%222%22%3E%22%3CEM%3EAzure-provided%20name%20resolution%3C%2FEM%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%20style%3D%22padding-left%3A%2030px%3B%22%3E%3CFONT%20size%3D%222%22%3E%3CEM%3EAlong%20with%20resolution%20of%20public%20DNS%20names%2C%20Azure%20provides%20internal%20name%20resolution%20for%20VMs%20and%20role%20instances%20that%20reside%20within%20the%20same%20virtual%20network%20or%20cloud%20service.%20VMs%20and%20instances%20in%20a%20cloud%20service%20share%20the%20same%20DNS%20suffix%2C%20so%20the%20host%20name%20alone%20is%20sufficient.%20But%20in%20virtual%20networks%20deployed%20using%20the%20classic%20deployment%20model%2C%20%3CSTRONG%3Edifferent%20cloud%20services%20have%20different%20DNS%20suffixes.%20In%20this%20situation%2C%20you%20need%20the%20FQDN%20to%20resolve%20names%20between%20different%20cloud%20services%3C%2FSTRONG%3E.%20%3CSTRONG%3EIn%20virtual%20networks%20deployed%20using%20the%20Azure%20Resource%20Manager%20deployment%20model%2C%20the%20DNS%20suffix%20is%20consistent%20across%20the%20virtual%20network%2C%20so%20the%20FQDN%20is%20not%20needed%3C%2FSTRONG%3E.%20DNS%20names%20can%20be%20assigned%20to%20both%20VMs%20and%20network%20interfaces.%20Although%20Azure-provided%20name%20resolution%20does%20not%20require%20any%20configuration%2C%20it%20is%20not%20the%20appropriate%20choice%20for%20all%20deployment%20scenarios%2C%20as%20detailed%20in%20the%20previous%20table.%3C%2FEM%3E%22%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EConsider%20a%26nbsp%3BAzure%20Resource%20Manager%20deployment%20it%20would%20not%20be%20necessary%20to%20use%20FQDN%2C%20however%20the%20way%20that%20the%20deployment%20of%20Azure%20SQL%20Managed%20Instance%20happens%20%3CSTRONG%3Eit%20will%20not%20share%20the%20same%20DNS%20sufix%3C%2FSTRONG%3E%20and%20we%20can%20see%20connectivity%20errors%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20are%20some%20workarounds%3A%20use%20the%20%3CSTRONG%3Eprivate%20IP%3C%2FSTRONG%3E%20or%20the%20%3CSTRONG%3EFQDN%3C%2FSTRONG%3E%20of%20the%20SQL%20VM.%20The%20default%20DNS%20sufix%20is%20documented%20in%20same%20article%20above%20(%26nbsp%3B%3CFONT%20size%3D%221%202%203%204%205%206%207%22%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-network%2Fvirtual-networks-name-resolution-for-vms-and-role-instances%23name-resolution-that-uses-your-own-dns-server%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-network%2Fvirtual-networks-name-resolution-for-vms-and-role-instances%23name-resolution-that-uses-your-own-dns-server%3C%2FA%3E%3C%2FFONT%3E%20)%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22padding-left%3A%2030px%3B%22%3E%22%3CEM%3E%3CFONT%20size%3D%222%22%3EWhen%20you%20are%20using%20Azure-provided%20name%20resolution%2C%20Azure%20Dynamic%20Host%20Configuration%20Protocol%20(DHCP)%20provides%20an%20internal%20DNS%20suffix%20(%3CSTRONG%3E.internal.cloudapp.net%3C%2FSTRONG%3E)%20to%20each%20VM.%20This%20suffix%20enables%20host%20name%20resolution%20because%20the%20host%20name%20records%20are%20in%20the%26nbsp%3B%3CSTRONG%3Einternal.cloudapp.net%3C%2FSTRONG%3E%26nbsp%3Bzone.%20When%20you%20are%20using%20your%20own%20name%20resolution%20solution%2C%20this%20suffix%20is%20not%20supplied%20to%20VMs%20because%20it%20interferes%20with%20other%20DNS%20architectures%20(like%20domain-joined%20scenarios).%20Instead%2C%20Azure%20provides%20a%20non-functioning%20placeholder%20(reddog.microsoft.com).%3C%2FFONT%3E%3C%2FEM%3E%22%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20this%20test%20I%20will%20create%20a%20%3CSTRONG%3Elinked%20server%20from%20SQL%20MI%20to%20SQL%20VM%26nbsp%3B%3C%2FSTRONG%3Eand%20we%20can%20see%20that%20I%20was%20able%20to%20connect%20with%20success%20to%20%3CSTRONG%3EIP%3C%2FSTRONG%3E%20and%20%3CSTRONG%3EVM.internal.cloudapp.net%3C%2FSTRONG%3E%2C%20but%20failing%20to%20%3CSTRONG%3Esimple%20VM%20name%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F135452i71758AAE8B395C20%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%222019-10-03_11h38_41.png%22%20title%3D%222019-10-03_11h38_41.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20behavior%20is%20also%20documented%20at%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsql-database%2Fsql-database-managed-instance-custom-dns%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsql-database%2Fsql-database-managed-instance-custom-dns%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22padding-left%3A%2030px%3B%22%3E%22%3CFONT%20size%3D%222%22%3E%3CEM%3EAn%20Azure%20SQL%20Database%20Managed%20Instance%20must%20be%20deployed%20within%20an%20Azure%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-network%2Fvirtual-networks-overview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-linktype%3D%22relative-path%22%3Evirtual%20network%20(VNet)%3C%2FA%3E.%20There%20are%20a%20few%20scenarios%20(for%20example%2C%20db%20mail%2C%20linked%20servers%20to%20other%20SQL%20instances%20in%20your%20cloud%20or%20hybrid%20environment)%20that%20require%20private%20host%20names%20to%20be%20resolved%20from%20the%20Managed%20Instance.%20In%20this%20case%2C%20you%20need%20to%20configure%20a%20custom%20DNS%20inside%20Azure.%3C%2FEM%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%20style%3D%22padding-left%3A%2030px%3B%22%3E%3CFONT%20size%3D%222%22%3E%3CEM%3E%3CSTRONG%3ESince%20Managed%20Instance%20uses%20the%20same%20DNS%20for%20its%20inner%20workings%2C%20you%20need%20to%20configure%20the%20custom%20DNS%20server%20so%20that%20it%20can%20resolve%20public%20domain%20names%3C%2FSTRONG%3E.%3C%2FEM%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CDIV%20class%3D%22alert%20is-primary%22%20style%3D%22padding-left%3A%2030px%3B%22%3E%0A%3CP%20class%3D%22alert-title%22%20style%3D%22padding-left%3A%2030px%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22alert-title%22%20style%3D%22padding-left%3A%2030px%3B%22%3E%3CFONT%20size%3D%222%22%3E%3CEM%3EImportant%3C%2FEM%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%20style%3D%22padding-left%3A%2030px%3B%22%3E%3CFONT%20size%3D%222%22%3E%3CEM%3E%3CSTRONG%3EAlways%20use%20fully-qualified%20domain%20names%20(FQDN)%20for%20the%20mail%20servers%2C%20SQL%20Servers%2C%20and%20other%20services%20even%20if%20they%20are%20within%20your%20private%20DNS%20zone%3C%2FSTRONG%3E.%20For%20example%20use%26nbsp%3B%3CCODE%3Esmtp.contoso.com%3C%2FCODE%3E%26nbsp%3Bfor%20mail%20server%20because%20simple%26nbsp%3B%3CCODE%3Esmtp%3C%2FCODE%3E%26nbsp%3Bwill%20not%20be%20properly%20resolved.%3C%2FEM%3E%3C%2FFONT%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%22%3C%2FSPAN%3E%3C%2FP%3E%0A%3C%2FDIV%3E%0A%3CDIV%20id%3D%22tinyMceEditorclipboard_image_1%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-891147%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20DNS%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EManaged%20Instance%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EReplication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESQL%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

I got this recent case where customer wanted to create a transaction replication from Azure SQL Managed instance to another SQL Server inside the same virtual network, but in a different subnet, but all inside Azure.

 

2019-10-03_15h57_07.png

 
 

 

All communications that happens on Azure Network if not set a custom DNS will use Azure DNS to resolve name of resources inside the network. However there is something very important in the documentation

https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-name-resolution-for-vms-and-...

 

"Azure-provided name resolution

Along with resolution of public DNS names, Azure provides internal name resolution for VMs and role instances that reside within the same virtual network or cloud service. VMs and instances in a cloud service share the same DNS suffix, so the host name alone is sufficient. But in virtual networks deployed using the classic deployment model, different cloud services have different DNS suffixes. In this situation, you need the FQDN to resolve names between different cloud services. In virtual networks deployed using the Azure Resource Manager deployment model, the DNS suffix is consistent across the virtual network, so the FQDN is not needed. DNS names can be assigned to both VMs and network interfaces. Although Azure-provided name resolution does not require any configuration, it is not the appropriate choice for all deployment scenarios, as detailed in the previous table."

 

Consider a Azure Resource Manager deployment it would not be necessary to use FQDN, however the way that the deployment of Azure SQL Managed Instance happens it will not share the same DNS sufix and we can see connectivity errors

 

There are some workarounds: use the private IP or the FQDN of the SQL VM. The default DNS sufix is documented in same article above ( https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-name-resolution-for-vms-and-...

"When you are using Azure-provided name resolution, Azure Dynamic Host Configuration Protocol (DHCP) provides an internal DNS suffix (.internal.cloudapp.net) to each VM. This suffix enables host name resolution because the host name records are in the internal.cloudapp.net zone. When you are using your own name resolution solution, this suffix is not supplied to VMs because it interferes with other DNS architectures (like domain-joined scenarios). Instead, Azure provides a non-functioning placeholder (reddog.microsoft.com)."

 

For this test I will create a linked server from SQL MI to SQL VM and we can see that I was able to connect with success to IP and VM.internal.cloudapp.net, but failing to simple VM name

2019-10-03_11h38_41.png

 

This behavior is also documented at https://docs.microsoft.com/en-us/azure/sql-database/sql-database-managed-instance-custom-dns

 

"An Azure SQL Database Managed Instance must be deployed within an Azure virtual network (VNet). There are a few scenarios (for example, db mail, linked servers to other SQL instances in your cloud or hybrid environment) that require private host names to be resolved from the Managed Instance. In this case, you need to configure a custom DNS inside Azure.

Since Managed Instance uses the same DNS for its inner workings, you need to configure the custom DNS server so that it can resolve public domain names.

 

Important

Always use fully-qualified domain names (FQDN) for the mail servers, SQL Servers, and other services even if they are within your private DNS zone. For example use smtp.contoso.com for mail server because simple smtp will not be properly resolved."