Azure Files/File Sync and Private Endpoints

%3CLINGO-SUB%20id%3D%22lingo-sub-1852074%22%20slang%3D%22en-US%22%3EAzure%20Files%2FFile%20Sync%20and%20Private%20Endpoints%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1852074%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20problems%20setting%20up%20Azure%20file%20sync%20with%20private%20endpoints%20that%20I%20can't%20find%20any%20details%20on.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20very%20simple%20subnet%20azure%20network%20with%20site%20to%20site%20VPN.%20There%20is%20a%20DNS%20server%20deployed%20in%20Azure%20and%20I'm%20using%20Private%20DNS%20as%20per%20the%20recommended%20setup.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EProblem%201%3C%2FP%3E%3CP%3EAzure%20Files%20with%20private%20endpoint.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFile%20Sync%20can%20not%20see%20or%20access%20the%20shares%20on%20the%20Storage%20account%20when%20private%20endpoint%20is%20created%20for%20the%20storage%20account.%20It%20works%20fine%20without%20a%20private%20endpoint.%3C%2FP%3E%3CP%3EThis%20is%20still%20the%20case%20when%20the%20firewall%20is%20set%20to%20All%20networks%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EProblem%202%3C%2FP%3E%3CP%3EAzure%20File%20Sync%20with%20private%20endpoint%3C%2FP%3E%3CP%3EMy%20on-prem%20server%20cannot%20communicate%20with%20the%20File%20Sync%20service%26nbsp%3Bacross%20site%20to%20site%20VPN%20when%20it%20is%20set%20up%20with%20a%20private%20endpoint%26nbsp%3B%3C%2FP%3E%3CP%3EDNS%20is%20correct%20and%20working%3C%2FP%3E%3CP%3EThe%20network%20tests%20fail%20with%20the%20following%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EDiscovery%20service%20connectivity%20result%3A%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3EResult%3A%20Fail.%20Error%3A%20A%20task%20was%20canceled.%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3EHostUri%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fxxxx.afs.azure.net%3A443%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fxxxx.afs.azure.net%3A443%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%3CSTRONG%3EManagement%20service%20connectivity%20result%3A%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3EResult%3A%20Fail.%20Error%3A%20A%20task%20was%20canceled.%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3EHostUri%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fxxxx.afs.azure.net%3A443%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fxxxx.afs.azure.net%3A443%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%3CSTRONG%3EMonitoring%20service%20connectivity%20result%3A%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3EResult%3A%20No%20response%20from%20monitoring%20agent%20process.%3C%2FSTRONG%3E%3CBR%20%2F%3E%3CSTRONG%3EHostUri%3A%20unknown%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can%20confirm%20that%20I%20can%20access%20those%20address%20on%20port%20443%20and%20receive%20a%20response%20from%20Telnet%2C%20so%20DNS%20and%20firewalls%20etc%20are%20fine.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAgain%20File%20Sync%20works%20fine%20before%20Private%20Endpoints%20are%20introduced.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20seem%20to%20be%20a%20lot%20of%20articles%20saying%20this%20is%20possible%20and%20supported%20but%20no%20documentation%20detailing%20setting%20these%20up%20with%20private%20endpoints.%20I%20feel%20like%20I'm%20missing%20something!!!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Regular Visitor

Hello,

 

I have problems setting up Azure file sync with private endpoints that I can't find any details on. 

 

I have a very simple subnet azure network with site to site VPN. There is a DNS server deployed in Azure and I'm using Private DNS as per the recommended setup.

 

Problem 1

Azure Files with private endpoint.

 

File Sync can not see or access the shares on the Storage account when private endpoint is created for the storage account. It works fine without a private endpoint.

This is still the case when the firewall is set to All networks,

 

Problem 2

Azure File Sync with private endpoint

My on-prem server cannot communicate with the File Sync service across site to site VPN when it is set up with a private endpoint 

DNS is correct and working

The network tests fail with the following 

Discovery service connectivity result:
Result: Fail. Error: A task was canceled.
HostUri: https://xxxx.afs.azure.net:443

Management service connectivity result:
Result: Fail. Error: A task was canceled.
HostUri: https://xxxx.afs.azure.net:443

Monitoring service connectivity result:
Result: No response from monitoring agent process.
HostUri: unknown

 

I can confirm that I can access those address on port 443 and receive a response from Telnet, so DNS and firewalls etc are fine.

 

Again File Sync works fine before Private Endpoints are introduced.

 

There seem to be a lot of articles saying this is possible and supported but no documentation detailing setting these up with private endpoints. I feel like I'm missing something!!!

1 Reply

@nlobass, it sounds like a disconnect somewhere in between. In order for connections to your storage account to go over your network tunnel, the fully qualified domain name (FQDN) of your storage account must resolve to your private endpoint's private IP address. To complete the configuration, you must forward the storage endpoint suffix to the Azure private DNS service accessible from within your virtual network.

More about that here.

Then do another test with:

nslookup <storage-account-name>.file.core.windows.net

It must properly resolve.