Internet connectivity for Azure VM updates?

%3CLINGO-SUB%20id%3D%22lingo-sub-2417349%22%20slang%3D%22en-US%22%3EInternet%20connectivity%20for%20Azure%20VM%20updates%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2417349%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20two%20Windows%20Server%202019%20VMs%20in%20Azure%2C%20and%20both%20have%201x%20public%20IP%20address%2C%20and%201x%20private%20ip%20address.%20The%20private%20IP%20address%20is%20on%20a%20VNET%20that%20has%20no%20route%20out%20to%20the%20internet.%20These%20VMs%20were%20set%20up%20with%20the%20Automatic%20updates%20enabled%2C%20and%20I%20have%20seen%20on%20both%20VMs%20that%20Windows%20Update%20client%20has%20been%20updating%20the%20OS%20successfully.%20We%20have%20no%20internal%20WSUS.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20internet%20connectivity%20required%20for%20the%20Guest%20OS%20to%20perform%20updates%20from%20the%20Microsoft%20Updates%2C%20or%20is%20there%20connectivity%20provided%20via%20the%20internal%20Azure%20fabric%3F%20Basically%2C%20if%20we%20were%20to%20remove%20the%20public%20IP%20address%2C%20I%20assume%20the%20Windows%20Update%20client%20on%20the%20Guest%20OS%20would%20no%20longer%20be%20able%20to%20update%2C%20since%20the%20private%20IP%20has%20no%20way%20out%20to%20the%20internet%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDoes%20the%20same%20apply%20if%20we%20decided%20to%20use%20Azure%20Update%20Management%3F%20Reading%20the%20tech%20docs%20on%20Azure%20Update%20Management%2C%20I'm%20led%20to%20believe%20that%20would%20also%20need%20internet%20connectivity%20to%20the%20Azure%20Update%20Management%20endpoints%2C%20so%20would%20that%20mean%2C%20again%2C%20removing%20the%20public%20IP%20address%20would%20stop%20that%20working%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2417349%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECompute%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EVirtual%20Machine%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2420386%22%20slang%3D%22en-US%22%3ERe%3A%20Internet%20connectivity%20for%20Azure%20VM%20updates%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2420386%22%20slang%3D%22en-US%22%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1071379%22%20target%3D%22_blank%22%3E%40shamik-ghosh%3C%2FA%3E%20%2C%3CBR%20%2F%3E%3CBR%20%2F%3Ethis%20is%20a%20tricky%20but%20a%20tbh%20very%20good%20question.%20I%20searched%20a%20lot%2C%20but%20I%20didn't%20found%20a%20100%25%20clearly%20solution.%3CBR%20%2F%3EIf%20you%20have%20a%20Platform%20as%20a%20Service%20(PaaS)%20solution%2C%20this%20should%20work%20and%20there%20is%20no%20need%20of%20a%20public%20IP%20to%20get%20Updates%20(Just%20a%20guess).%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20you%20don't%20find%20further%20information%2C%20I%20would%20recommend%20you%20to%20%22pentest%22%20it.%20Next%20Tuesday%20is%20Patchday%2C%20so%20you%20can%20check%20if%20you%20get%20updates.%3CBR%20%2F%3E%3CBR%20%2F%3EMaybe%20not%20the%20best%20solution%20but%20maybe%20anyone%20else%20has%20an%20idea%20%3A)%3C%2Fimg%3E%3CBR%20%2F%3E%3CBR%20%2F%3EBest%20regards%2C%3CBR%20%2F%3ESchnittlauch%3CBR%20%2F%3E%3CBR%20%2F%3E%22First%2C%20No%20system%20is%20safe.%20Second%2C%20Aim%20for%20the%20impossible.%20Third%20no%20Backup%2C%20no%20Mercy%22%20-%20Schnittlauch%3CBR%20%2F%3E%3CBR%20%2F%3EMy%20answer%20helped%20you%3F%20Don't%20forget%20to%20leave%20a%20like.%20Also%20mark%20the%20answer%20as%20solved%20when%20your%20problem%20is%20solved.%20%3A)%3C%2Fimg%3E%3C%2FLINGO-BODY%3E
New Contributor

We have two Windows Server 2019 VMs in Azure, and both have 1x public IP address, and 1x private ip address. The private IP address is on a VNET that has no route out to the internet. These VMs were set up with the Automatic updates enabled, and I have seen on both VMs that Windows Update client has been updating the OS successfully. We have no internal WSUS.

 

Is internet connectivity required for the Guest OS to perform updates from the Microsoft Updates, or is there connectivity provided via the internal Azure fabric? Basically, if we were to remove the public IP address, I assume the Windows Update client on the Guest OS would no longer be able to update, since the private IP has no way out to the internet?

 

Does the same apply if we decided to use Azure Update Management? Reading the tech docs on Azure Update Management, I'm led to believe that would also need internet connectivity to the Azure Update Management endpoints, so would that mean, again, removing the public IP address would stop that working?

3 Replies
Hi @shamik-ghosh ,

this is a tricky but a tbh very good question. I searched a lot, but I didn't found a 100% clearly solution.
If you have a Platform as a Service (PaaS) solution, this should work and there is no need of a public IP to get Updates (Just a guess).

If you don't find further information, I would recommend you to "pentest" it. Next Tuesday is Patchday, so you can check if you get updates.

Maybe not the best solution but maybe anyone else has an idea :)

Best regards,
Schnittlauch

"First, No system is safe. Second, Aim for the impossible. Third no Backup, no Mercy" - Schnittlauch

My answer helped you? Don't forget to leave a like. Also mark the answer as solved when your problem is solved. :)
Internet connectivity is required for Azure Update Management, Azure Update Management, acts as the management later, updates aren't distributed directly via the Azure fabric.

You need to have a route out to the internet: 0.0.0.0/0 (it's a default route that should be there, unless it has been overwritten to point to a network appliance such as Azure Firewall, or directed to some kind of proxy). Azure Virtual Machines, don't need Public IP addresses to access the internet, theoretically, if the routes for the internet are there and nothing is blocking the traffic, even without a public IP - it should work.
@Luke Murray thanks for sharing your knowledge!