%3CLINGO-SUB%20id%3D%22lingo-sub-1242197%22%20slang%3D%22en-US%22%3ELesson%20Learned%20%23125%3A%20Azure%20Storage%20Firewall%20and%20BCP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1242197%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20received%20some%20questions%20from%20our%20customers%20that%20they%20want%20to%20enable%20the%20firewall%20of%20their%20Azure%20Storage%20Account%20that%20they%20are%20using%20to%20import%20data%20using%20BCP.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20this%20article%20we%20are%20going%20to%20explain%20how%20it%20is%20possible%20to%20do%20it.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EFirst%20of%20all%2C%20we%20need%20information%20about%20the%20advantages%2Fdisadvantages%20when%20we%20enable%20Azure%20Storage%20Account%20firewall%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EIf%20you%20check%20the%20%3CSTRONG%3EAllow%20trusted%20Microsoft%20services%20to%20access%20this%20storage%20account%3C%2FSTRONG%3E%2C%20just%20only%20a%20few%20services%20reported%20in%20this%20URL%20would%20be%20able%20to%20connect%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Fcommon%2Fstorage-network-security%23exceptions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Fcommon%2Fstorage-network-security%23exceptions%3C%2FA%3E.%20Unfortunately%2C%20%3CSTRONG%3EAzure%20SQL%20Service%20is%20not%20among%20them%3C%2FSTRONG%3E%2C%20but%20SQL%20Azure%20DW%20(Synapse)%20yes.%20So%2C%20in%20this%20case%20using%20BULK%20INSERT%20would%20be%20not%20possible.%26nbsp%3B%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-60px%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Jose_Manuel_Jurado_1-1584733839252.png%22%20style%3D%22width%3A%20497px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F178536i5988085B7E7F5E89%2Fimage-dimensions%2F497x259%3Fv%3D1.0%22%20width%3D%22497%22%20height%3D%22259%22%20title%3D%22Jose_Manuel_Jurado_1-1584733839252.png%22%20alt%3D%22Jose_Manuel_Jurado_1-1584733839252.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EIf%20we%20used%20BCP%20command%20from%20a%20%3CSTRONG%3EVirtual%20Machine%20%3C%2FSTRONG%3E%26nbsp%3Bwe%20are%20going%20to%20have%20an%20Access%20Denied%20error%20message%20even%20if%20we%20check%20%3CSTRONG%3EAllow%20trusted%20Microsoft%20services%20to%20access%20this%20storage%20account%20%3C%2FSTRONG%3Eor%20adding%20the%20IP%20in%20the%20public%20firewall.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CSTRONG%3EWhat%20is%20the%20solution%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EAdded%20this%20storage%20account%20in%20the%20VNET%20of%20the%20Virtual%20Machine%20and%20BCP%20will%20work.%3C%2FLI%3E%0A%3CLI%3EIf%20you%20run%20the%20BCP%20command%20from%20OnPremises%2C%20you%20need%20to%20the%20IP%20in%20the%20firewall%20exceptions%20and%20BCP%20will%20work.%26nbsp%3B%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CSTRONG%3EHow%20to%20configure%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EIn%20order%20to%20have%20the%20best%20performance%2C%20my%20suggestion%20is%20to%20run%20BCP%20from%20the%20machine%20running%20in%20Azure.%3C%2FLI%3E%0A%3CLI%3ECreate%20an%20Azure%20Storage%20Account%20with%20File%20Share%20Option%20enabled.%26nbsp%3B%3C%2FLI%3E%0A%3CLI%3EEnable%20Azure%20Storage%20Account%20Firewall%2C%20adding%20the%20VNET%2FSUBNET%20of%20this%20Azure%20Virtual%20Machine.%26nbsp%3B%3C%2FLI%3E%0A%3CLI%3EMount%20the%20file%20share%20either%20OnPremises%20or%20in%20your%20Azure%20Virtual%20Machine%2C%20running%20the%20following%20commands%3A%26nbsp%3B%26nbsp%3B%3CUL%3E%0A%3CLI%3Enet%20use%20drivename%3A%20%5C%5Cmyfileshare.file.core.windows.net%5Cmybcpfiles%20%2Fu%3AAzure%5Cmyfileshare%20PrimaryKeyValue.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%20class%3D%22lia-indent-padding-left-60px%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Jose_Manuel_Jurado_0-1584734016314.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F178537i160B3CD972C737C6%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Jose_Manuel_Jurado_0-1584734016314.png%22%20alt%3D%22Jose_Manuel_Jurado_0-1584734016314.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EAnd%20from%20this%20point%20we%20could%20run%20BCP%20command%20using%20this%20drivername%20having%20the%20Azure%20Storage%20firewall%20enabled.%26nbsp%3B%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%20class%3D%22lia-indent-padding-left-60px%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Jose_Manuel_Jurado_0-1584734320063.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F178538iD15FD400DCCAC23F%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22Jose_Manuel_Jurado_0-1584734320063.png%22%20alt%3D%22Jose_Manuel_Jurado_0-1584734320063.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EEnjoy!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1242197%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20received%20some%20questions%20from%20our%20customers%20that%20they%20want%20to%20enable%20the%20firewall%20of%20their%20Azure%20Storage%20Account%20that%20they%20are%20using%20to%20import%20data%20using%20BCP.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20this%20article%20we%20are%20going%20to%20explain%20how%20it%20is%20possible%20to%20do%20it.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1243098%22%20slang%3D%22en-US%22%3ERE%3A%20Lesson%20Learned%20%23125%3A%20Azure%20Storage%20Firewall%20and%20BCP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1243098%22%20slang%3D%22en-US%22%3ENice%20post%3C%2FLINGO-BODY%3E

We received some questions from our customers that they want to enable the firewall of their Azure Storage Account that they are using to import data using BCP. 

 

In this article we are going to explain how it is possible to do it. 

 

First of all, we need information about the advantages/disadvantages when we enable Azure Storage Account firewall:

 

 

Jose_Manuel_Jurado_1-1584733839252.png

 

 

 

  • If we used BCP command from a Virtual Machine  we are going to have an Access Denied error message even if we check Allow trusted Microsoft services to access this storage account or adding the IP in the public firewall.

What is the solution:

 

  • Added this storage account in the VNET of the Virtual Machine and BCP will work.
  • If you run the BCP command from OnPremises, you need to the IP in the firewall exceptions and BCP will work. 

How to configure:

 

  • In order to have the best performance, my suggestion is to run BCP from the machine running in Azure.
  • Create an Azure Storage Account with File Share Option enabled. 
  • Enable Azure Storage Account Firewall, adding the VNET/SUBNET of this Azure Virtual Machine. 
  • Mount the file share either OnPremises or in your Azure Virtual Machine, running the following commands:  
    • net use drivename: \\myfileshare.file.core.windows.net\mybcpfiles /u:Azure\myfileshare PrimaryKeyValue.

Jose_Manuel_Jurado_0-1584734016314.png

  • And from this point we could run BCP command using this drivername having the Azure Storage firewall enabled. 

Jose_Manuel_Jurado_0-1584734320063.png

 

Enjoy!