Home
%3CLINGO-SUB%20id%3D%22lingo-sub-737543%22%20slang%3D%22en-US%22%3EAzure%20Bastion%20-%20Access%20your%20Azure%20virtual%20servers%20without%20a%20public%20open%20RDP%20port%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-737543%22%20slang%3D%22en-US%22%3E%3CP%3EThere%20may%20be%20a%20valid%20reason%20why%20you%20need%20Remote%20Desktop%20Protocol%20(RDP)%20or%20Secure%20Shell%20(SSH)%20access%20to%20a%20virtual%20machine%20hosted%20in%20Microsoft%20Azure.%20Unfortunately%2C%20this%20means%20you%20either%20need%20to%20have%20ports%20like%203389%20open%20on%20a%20public%20IP%20address%20(and%20therefore%20discoverable%20to%20hacking%20attempts)%2C%20or%20you%20need%20to%20manage%20a%20separate%20%E2%80%9Cjump%20box%E2%80%9D%20as%20an%20interim%20step%20to%20route%20your%20connection%20through.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3ENow%20in%20public%20preview%2C%20Azure%20Bastion%20provides%20easy%2C%20secure%20remote%20access%20into%20Microsoft%20Azure%20VMs%20through%20the%20Azure%20Portal%20in%20a%20browser%2C%20without%20the%20need%20for%20those%20VMs%20to%20have%20a%20public%20IP%20address.%20This%20Platform%20as%20a%20Service%20offering%20is%20managed%20%26amp%3B%20updated%20by%20Microsoft%20and%20is%20configured%20per%20virtual%20network%20where%20your%20VMs%20reside.%20The%20Azure%20Bastion%20Host%20itself%20has%20a%20public%20IP%20address%20but%20only%20requires%20port%20443%20to%20be%20open%20for%20HTTPS.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAnd%20while%20the%20ease%20of%20setup%20and%20access%20will%20blow%20you%20away%20%E2%80%93%20wait%20until%20you%20see%20what%20is%20on%20the%20roadmap%3A%20seamless%20single%20sign-on%2C%20Azure%20Active%20Directory%20authentication%2C%20multi-factor%20authentication%2C%20support%20for%20native%20RDP%2FSSH%20clients%2C%20support%20for%20other%20Azure%20resources%20..%20and%20that%E2%80%99s%20just%20the%20start!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CU%3EThings%20to%20note%3A%3C%2FU%3E%3CBR%20%2F%3E%3CSTRONG%3EAccess%20during%20public%20preview%3C%2FSTRONG%3E%20%E2%80%93%20To%20see%20Azure%20Bastion%20as%20an%20option%2C%20you%E2%80%99ll%20need%20to%20use%20the%20Preview%20Microsoft%20Azure%20portal%20at%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FBastionHost%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2FBastionHost%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAvailable%20regions%3C%2FSTRONG%3E%20-%20Azure%20Bastion%20is%20currently%20available%20only%20in%20the%20following%20regions%3A%20West%20US%2C%20East%20US%2C%20West%20Europe%2C%20South%20Central%20US%2C%20Australia%20East%2C%20Japan%20East.%20It%20must%20be%20deployed%20in%20the%20same%20region%20as%20the%20vnet%20it%20is%20providing%20access%20to%20(that%20is%2C%20the%20same%20vnet%20that%20your%20VMs%20are%20using).%20If%20you%20have%20VMs%20deployed%20across%20more%20than%20one%20vnet%2C%20you%E2%80%99ll%20need%20an%20Azure%20Bastion%20host%20in%20each%20vnet.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EPricing%3C%2FSTRONG%3E%20%E2%80%93%20You%20will%20only%20be%20partially%20billed%20during%20the%20public%20preview%20(as%20public%20previews%20do%20not%20come%20with%20SLAs).%20%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fpricing%2Fdetails%2Fazure-bastion%2F%3FWT.mc_id%3Ditopstalk-blog-socuff%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EFull%20pricing%20is%20available%20here%3C%2FA%3E.%20%26nbsp%3BOnce%20deployed%2C%20Azure%20Bastion%20hosts%20are%20currently%20always%20on.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CU%3ESetting%20up%20Azure%20Bastion%3A%3C%2FU%3E%3CBR%20%2F%3E%E2%80%A2%20Following%20the%20instructions%20to%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fbastion%2Fbastion-create-host-portal%3FWT.mc_id%3Ditopstalk-blog-socuff%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3ECreate%20a%20bastion%20host%20(preview)%3C%2FA%3E%20was%20quite%20straightforward.%20You%E2%80%99ll%20find%20Bastion%20in%20the%20Azure%20Marketplace%2C%20or%20clicking%20Connect%20in%20an%20existing%20VM%20will%20prep-populate%20some%20network%20settings%20relevant%20to%20that%20VM.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20224px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F122156iC8535E07A7CE6DA9%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Bastion%20in%20Azure%20Marketplace.jpg%22%20title%3D%22Bastion%20in%20Azure%20Marketplace.jpg%22%20%2F%3E%3C%2FSPAN%3E%26nbsp%3B%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20413px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F122157iA687CAB7B5B32615%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22BastionOptionVMConnect.jpg%22%20title%3D%22BastionOptionVMConnect.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%E2%80%A2%20It%E2%80%99s%20important%20to%20check%20the%20configuration%20of%20your%20virtual%20network.%20The%20vnet%20address%20space%20sets%20the%20maximum%20amount%20of%20IP%20addresses%20available%20using%20%3CA%20href%3D%22https%3A%2F%2Fen.wikipedia.org%2Fwiki%2FClassless_Inter-Domain_Routing%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3ECIDR%20notation%3C%2FA%3E.%20%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20my%20case%2C%20my%20existing%20vnet%20address%20space%20was%2010.0.0.0%2F24%2C%20allowing%20for%20256%20addressses%20(actually%20251%20%2B%205%20reserved%20for%20Azure).%20I%20already%20had%20a%20subnet%20configured%20called%20%E2%80%9Cdefault%E2%80%9D%20as%2010.0.0.0%2F26.%20This%20allows%20me%20to%20use%2059%20of%20those%20addresses%20(64%20-%205%20reserved%20for%20Azure)%20for%20things%20I%20configure%20to%20use%20that%20default%20subnet%20(like%20my%20VMs).%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAzure%20Bastion%20requires%20it%E2%80%99s%20own%20subnet%20named%20AzureBastionSubnet%20with%20a%20CIDR%20of%20at%20least%20%2F27%20(for%20future%20Auto%20Scale%20support).%20By%20configuring%20that%20new%20subnet%20to%20be%2010.0.0.64%2F27%2C%20I%E2%80%99m%20not%20conflicting%20with%20the%20IP%20addresses%20already%20reserved%20in%20the%20default%20subnet%2C%20and%20I%20still%20have%20more%20available%20addresses%20spare%20in%20the%20vnet%20address%20space.%20Your%20configuration%20may%20vary%2C%20but%20if%20you%20are%20getting%20a%20red%20error%20during%20your%20subnet%20configuration%2C%20it%E2%80%99s%20likely%20to%20mean%20that%20you%20need%20to%20increase%20the%20CIDR%20of%20the%20vnet%20address%20space%20(to%20allow%20for%20more%20addresses%20overall)%2C%20or%20your%20starting%20IP%20address%20number%20is%20too%20low%20and%20it%20conflicts%20with%20an%20existing%20address%20already%20in%20another%20subnet.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20781px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F122158i463DDA2CCE3332F4%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22BastionCreate.jpg%22%20title%3D%22BastionCreate.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20345px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F122159i9CB3D1843F3A598E%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22AzureBastionSubnet.jpg%22%20title%3D%22AzureBastionSubnet.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%E2%80%A2%20If%20your%20VMs%20only%20had%20existing%20public%20IP%20addresses%20for%20administrative%20RDP%2FSSH%20support%2C%20once%20Azure%20Bastion%20is%20configured%20and%20tested%20successfully%20you%20can%20disassociate%20the%20public%20IP%20address%20from%20the%20VM%20and%20then%20delete%20it.%20Just%20remember%20to%20leave%20the%20public%20IP%20address%20in%20place%20that%20is%20connected%20to%20your%20Azure%20Bastion%20host%20itself!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%E2%80%A2%20Because%20Bastion%20hosts%20are%20Azure%20resources%2C%20you%20can%20add%20tags%20to%20them%2C%20lock%20them%20to%20prevent%20accidental%20deletion%2C%20and%20export%20them%20as%20a%20.JSON%20template.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20885px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F122161iD69D58211D928C1F%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22BastionJSON.jpg%22%20title%3D%22BastionJSON.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%E2%80%A2%20I%20found%20connectivity%20to%20my%20VMs%20was%20fast%2C%20and%20the%20browser%20connection%20supports%20reading%20from%20my%20host%20PCs%20clipboard%20(text%20and%20images)%20once%20I%E2%80%99ve%20allowed%20it%2C%20but%20not%20the%20transfer%2Fcopy%20paste%20of%20any%20files%20from%20my%20PC%20to%20my%20virtual%20machines.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20301px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F122162i73039208453D8FCB%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22BastionClipboardAccess.jpg%22%20title%3D%22BastionClipboardAccess.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CU%3ETo%20learn%20more%3A%3C%2FU%3E%3CBR%20%2F%3EThe%20%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fblog%2Fannouncing-the-preview-of-microsoft-azure-bastion%2F%3FWT.mc_id%3Ditopstalk-blog-socuff%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Eofficial%20Azure%20Bastion%20announcement.%3C%2FA%3E%26nbsp%3BCheck%20out%20the%20comments%20to%20learn%20more%20about%20what%E2%80%99s%20on%20the%20roadmap.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fazure%2Fbastion%2F%3FWT.mc_id%3Ditopstalk-blog-socuff%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EAzure%20Bastion%20Documentation%26nbsp%3B%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EGo%20and%20explore%20this%20new%20feature%20and%20leave%20me%20a%20comment%20with%20your%20thoughts.%20Which%20roadmap%20features%20are%20the%20most%20important%20to%20you%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CEM%3E-Sonia%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-737543%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20413px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F122157iA687CAB7B5B32615%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22BastionOptionVMConnect.jpg%22%20title%3D%22BastionOptionVMConnect.jpg%22%20%2F%3E%3C%2FSPAN%3ETraditionally%2C%20administrative%20access%20to%20a%20server%20in%20Azure%20has%20required%20either%20open%20RDP%20or%20SSH%20ports%2C%20or%20managing%20a%20separate%20%22jump%20box%22.%20Now%2C%20Azure%20Bastion%20provides%20secure%2C%20managed%20remote%20access%20via%20the%20Azure%20Portal.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-737543%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

There may be a valid reason why you need Remote Desktop Protocol (RDP) or Secure Shell (SSH) access to a virtual machine hosted in Microsoft Azure. Unfortunately, this means you either need to have ports like 3389 open on a public IP address (and therefore discoverable to hacking attempts), or you need to manage a separate “jump box” as an interim step to route your connection through.


Now in public preview, Azure Bastion provides easy, secure remote access into Microsoft Azure VMs through the Azure Portal in a browser, without the need for those VMs to have a public IP address. This Platform as a Service offering is managed & updated by Microsoft and is configured per virtual network where your VMs reside. The Azure Bastion Host itself has a public IP address but only requires port 443 to be open for HTTPS.

 

And while the ease of setup and access will blow you away – wait until you see what is on the roadmap: seamless single sign-on, Azure Active Directory authentication, multi-factor authentication, support for native RDP/SSH clients, support for other Azure resources .. and that’s just the start!

 

Things to note:
Access during public preview – To see Azure Bastion as an option, you’ll need to use the Preview Microsoft Azure portal at https://aka.ms/BastionHost

 

Available regions - Azure Bastion is currently available only in the following regions: West US, East US, West Europe, South Central US, Australia East, Japan East. It must be deployed in the same region as the vnet it is providing access to (that is, the same vnet that your VMs are using). If you have VMs deployed across more than one vnet, you’ll need an Azure Bastion host in each vnet.

 

Pricing – You will only be partially billed during the public preview (as public previews do not come with SLAs). Full pricing is available here.  Once deployed, Azure Bastion hosts are currently always on.

 

Setting up Azure Bastion:
• Following the instructions to Create a bastion host (preview) was quite straightforward. You’ll find Bastion in the Azure Marketplace, or clicking Connect in an existing VM will prep-populate some network settings relevant to that VM.

Bastion in Azure Marketplace.jpg  BastionOptionVMConnect.jpg

 

• It’s important to check the configuration of your virtual network. The vnet address space sets the maximum amount of IP addresses available using CIDR notation.  

 

In my case, my existing vnet address space was 10.0.0.0/24, allowing for 256 addressses (actually 251 + 5 reserved for Azure). I already had a subnet configured called “default” as 10.0.0.0/26. This allows me to use 59 of those addresses (64 - 5 reserved for Azure) for things I configure to use that default subnet (like my VMs).

 

Azure Bastion requires it’s own subnet named AzureBastionSubnet with a CIDR of at least /27 (for future Auto Scale support). By configuring that new subnet to be 10.0.0.64/27, I’m not conflicting with the IP addresses already reserved in the default subnet, and I still have more available addresses spare in the vnet address space. Your configuration may vary, but if you are getting a red error during your subnet configuration, it’s likely to mean that you need to increase the CIDR of the vnet address space (to allow for more addresses overall), or your starting IP address number is too low and it conflicts with an existing address already in another subnet.

 

 

BastionCreate.jpg

AzureBastionSubnet.jpg

 

• If your VMs only had existing public IP addresses for administrative RDP/SSH support, once Azure Bastion is configured and tested successfully you can disassociate the public IP address from the VM and then delete it. Just remember to leave the public IP address in place that is connected to your Azure Bastion host itself!

 

• Because Bastion hosts are Azure resources, you can add tags to them, lock them to prevent accidental deletion, and export them as a .JSON template.

BastionJSON.jpg

 

• I found connectivity to my VMs was fast, and the browser connection supports reading from my host PCs clipboard (text and images) once I’ve allowed it, but not the transfer/copy paste of any files from my PC to my virtual machines.

BastionClipboardAccess.jpg

 

To learn more:
The official Azure Bastion announcement. Check out the comments to learn more about what’s on the roadmap.

 

Azure Bastion Documentation 

 

Go and explore this new feature and leave me a comment with your thoughts. Which roadmap features are the most important to you?

 

-Sonia