%3CLINGO-SUB%20id%3D%22lingo-sub-1450899%22%20slang%3D%22en-US%22%3EAccessing%20On-Premise%20File%20Systems%20from%20Azure%20Logic%20Apps%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1450899%22%20slang%3D%22en-US%22%3E%3CDIV%20class%3D%22ember-view%22%3E%0A%3CDIV%20class%3D%22reader-article-content%22%3E%0A%3CP%3E%3CSTRONG%3EOverview%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EIn%20today's%20world%2C%20hybrid%20integration%20is%20prominent%20with%20many%20challenges%20on%20accessing%20on-premise%20resources%20on%20Cloud%20environment.%20Here%2C%20I%20thought%20of%20sharing%20my%20insights%20on%20available%20options%20to%20access%20On-Premise%20File%20Systems%20as%20many%20users%20have%20various%20concerns%20like%20Size%20limitations%20%2C%20access%20to%20storage%20accounts%20behind%20firewall.%20Let's%20see%20what%20are%20the%20options%20we%20have%20to%20access%20On-Premise%20file%20systems%20and%20how%20we%20can%20access%20them%20in%20Logic%20Apps.%3C%2FP%3E%0A%3CP%3EIt's%20as%20of%20my%20knowledge%20and%20there%20might%20be%20other%20ways%20to%20access%20On-Premise%20files%20through%20Express%20route%20%2C%20VNET%20peering%20and%20others.%20I%20am%20more%20over%20concentrating%20on%20the%20major%20concrete%20solutions%20we%20have%20at%20present%20in%20terms%20of%20respective%20services%2Fresources.%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EOn-Premise%20Data%20Gateway%3C%2FLI%3E%0A%3CLI%3EAzure%20File%20Share%20-%20File%20Sync%20service%20(How%20about%20when%20its%20behind%20firewall)%3C%2FLI%3E%0A%3CLI%3EExpress%20route%20%2C%20VNET%20peering%20with%20Integration%20Service%20Environment%20(ISE)%3C%2FLI%3E%0A%3CLI%3ESFTP%26amp%3B%20FTP%20servers%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EOn-Premise%20Data%20gateway%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOPDG%20is%20windows%20service%20which%20can%20be%20deployed%20in%20on-premise%20windows%20servers%20to%20access%20LOB%20systems%20on%20premise%20such%20as%20File%20Systems%20(Even%20Microsoft%20File%20over%20clustering%20is%20supported)%2C%20SQL%20Server%20%2C%20IBM%20MQ%20server%20%2C%20SAP%20etc.%20OPDG%20service%20underlying%20service%20is%20Azure%20Service%20Bus%20which%20is%20securely%20connects%20to%20the%20LOB%20systems%20on%20on-premise%20without%20opening%20additional%20firewalls%20and%20ports%20except%20the%20ports%20specific%20to%20LOB%20systems.%20OPDG%20service%20currently%20works%20for%20LogicApps%2CPower%20Apps%20and%20Power%20BI.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EPro's%3C%2FSTRONG%3E%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ENo%20need%20to%20open%20additional%20firewall%20and%20ports%3C%2FLI%3E%0A%3CLI%3EEasy%20to%20configure%20and%20doesn't%20need%20much%20effort%20%2COne%20gateway%20is%20enough%20o%20access%20all%20data%20sources%3C%2FLI%3E%0A%3CLI%3EFail%20over%20clustering%20for%20high%20availability%3C%2FLI%3E%0A%3CLI%3ECan%20be%20installed%20in%20any%20server%20with%20in%20the%20domain%20network%20has%20access%20to%20the%20resources%20but%20performance%20could%20be%20impacted.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CSTRONG%3ELimitations%3C%2FSTRONG%3E%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EAs%20it's%20underlying%20architecture%20is%20on%20Azure%20Service%20Bus%20%2C%20the%20request%20size%20limit%20is%20max%20of%202%20MB%20and%20Response%20limit%20is%208%20MB%20except%20for%20File%20systems%20which%20is%2030%20MB%20for%20all%20I%2FO%20operations%20except%20Create%20file%20which%20is%2030%20MB%3C%2FLI%3E%0A%3CLI%3EConnection%20timeout%20will%20be%2030%20seconds%3C%2FLI%3E%0A%3CLI%3EUser%20can%20be%20part%20of%20only%20one%20tenant%20directory%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CH3%20id%3D%22toc-hId-1172062587%22%20id%3D%22toc-hId-1172087322%22%3EAzure%20File%20Share-File%20Sync%20Service%3A%3C%2FH3%3E%0A%3CP%3EIn%20most%20of%20scenarios%2C%20we%20use%20Azure%20File%20Server%20for%20accessing%20the%20common%20tools%2C%20Config%20files%2C%20logs%20file%20etc..%20In%20addition%20to%20that%20Microsoft%20provides%20the%20Azure%20File%20Sync%20service%20which%20can%20be%20deployed%20on%20your%20windows%20machined%20to%20mount%20the%20Azure%20File%20services%20on%20your%20on-premise%20file%20systems.%20So%20you%20can%20use%20the%20Azure%20File%20share%20when%20you%20would%20like%20to%20use%20the%20file%20systems%20on%20both%20Microsoft%20cloud%20and%20On-Premise.%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EBit%20difficult%20to%20configure%20as%20various%20components%20has%20to%20be%20setup%3C%2FLI%3E%0A%3CLI%3EEasy%20to%20mount%20on%20multiple%20windows%20servers%20to%20access%20common%20tools%20setup%20files%20etc..%3C%2FLI%3E%0A%3CLI%3EFile%20sync%20service%20does%20cache%20the%20Azure%20File%20server%20for%20quick%20access%20of%20the%20files%3C%2FLI%3E%0A%3CLI%3ELimits%20are%20bound%20to%20Azure%20File%20Share%20limits%20which%20is%20in%20TB's%20Tera%20bytes.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EHowever%2C%20I%20am%20not%20going%20to%20details%20about%20installation%20and%20configuration%20and%20quickly%20jump%20on%20how%20we%20could%20access%20these%20from%20Logic%20Apps.%3C%2FP%3E%0A%3CP%3EFirst%20thing%20that%20comes%20to%20out%20mind%20is%20security%20when%20we%20move%20data%20to%20cloud%20and%20accessing%20it%20from%20other%20Azure%20resources%20or%20any%20other%20clients.%20So%20storage%20account%20has%20Firewall%20settings%20along%20with%20the%20access%20keys%20or%20SAS%20keys%20for%20restricting%20the%20access%20and%20authorizing%20operations%20on%20storage%20account.%20When%20we%20consider%20this%20how%20could%20we%20access%20the%20storage%20accounts%20in%20Logic%20Apps%20which%20are%20behind%20the%20firewall%20and%20both%20are%20region%20same%20region.%20We%20can%20use%20the%20REST%20API's%20with%20SAS%20URL%20of%20Azure%20File%20Share%20to%20overcome%20this%20scenario%20as%20we%20won't%20be%20able%20to%20see%20the%20out%20of%20box%20connectors%20when%20they%20are%20in%20same%20region.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EISE%20Environment%3A%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3EDedicated%20environment%20isolate%20from%20multi%20tenant%20shared%20environment.%3C%2FP%3E%0A%3CP%3EISE%20environment%20as%20we%20know%20can%20be%20used%20to%20access%20the%20all%20resources%20with%20in%20same%20virtual%20network%20which%20can%20have%20Express%20route%20or%20VNET%20to%20peer%20configuration%20to%20access%20data%20resources%20in%20on-premise%20servers.%20It's%20pretty%20straight%20forward%20to%20access%20on-premise%20file%20systems%20using%20ISE%20version%20connectors.%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EDedicated%20resources%20will%20be%20allocated%20and%20isolate%20from%20the%20shared%20environment%3C%2FLI%3E%0A%3CLI%3EAll%20resources%20with%20in%20the%20same%20virtual%20network%20or%20access%20to%20other%20networks%20if%20peer%20networking%20or%20Express%20route%20established%20can%20be%20accessed%3C%2FLI%3E%0A%3CLI%3ECost%20is%20primary%20concern%20as%20its%20fixed%20amount%20respective%20to%20SKU's%20selected%3C%2FLI%3E%0A%3CLI%3EFlexibility%20to%20scale%20up%20and%20scale%20down%20with%20additional%20units%3C%2FLI%3E%0A%3CLI%3EExpose%20with%20Static%20IP%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CH3%20id%3D%22toc-hId--635391876%22%20id%3D%22toc-hId--635367141%22%3ESFTP%20%2FFTP%20server%3A%3C%2FH3%3E%0A%3CP%3EMost%20resilient%20approaches%20for%20accessing%20file%20servers%20hosted%20in%20either%20Windows%20or%20Linux%20servers%20through%20SFTP%2FFTP%20servers%20is%20pretty%20common%20scenario%20now.%20Using%20SFTP%2FFTP%20servers%20we%20can%20access%20the%20files%20of%20size%20upto%201%20GB%20with%20support%20of%20chunking.%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ESecure%20file%20transfer%20with%20SSH%20-2.0%20protocol%3C%2FLI%3E%0A%3CLI%3ETrigger%20file%20size%20limit%20is%2015%20MB%20and%20chunking%20doesn't%20support%20on%20trigger%20as%20expected%20by%20deign%3C%2FLI%3E%0A%3CLI%3EActions%20can%20be%20used%20to%20read%20data%20in%20streams%20of%2015%20to%2050%20MB%20chunks%20which%20can%20be%20set%20according%20to%20network%20speed.%20Limit%20is%20of%201%20MB%3C%2FLI%3E%0A%3CLI%3EConnection%20timeout%20is%2020%20seconds.%3C%2FLI%3E%0A%3CLI%3ENew%20filed%20to%20get%20the%20metadata%20of%20the%20files%20on%20both%20triggers%20and%20actions%20which%20can%20be%20suppressed%20in%20performance%20issues.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CSTRONG%3ERefrences%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EAzure%20File%20Share%20deployed%20in%20same%20region%20with%20firewall%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fazure%252Flogic-apps%252Flogic-apps-limits-and-config%2523message-size%26amp%3Bdata%3D02%257C01%257CVeeraReddy.Gangala%2540microsoft.com%257C51cc2db2df364377a08008d7f591efe0%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637247879493652666%26amp%3Bsdata%3DiJGhILqJyEM1LcmMSXG03opID3M4DtRqGqVtAEtLfic%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Flogic-apps%2Flogic-apps-limits-and-config%23message-size%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EAzure%20File%20Synch%3A%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CSTRONG%3ERelated%20to%20Azure%20File%20Sync%20and%20deployment%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E-ERR%3AREF-NOT-FOUND-%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-sync-files-deployment-guide%3Ftabs%3Dazure-portal%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-sync-files-deployment-guide%3Ftabs%3Dazure-portal%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fazure%252Fstorage%252Ffiles%252Fstorage-sync-files-planning%26amp%3Bdata%3D02%257C01%257CVeeraReddy.Gangala%2540microsoft.com%257C51cc2db2df364377a08008d7f591efe0%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637247879493662659%26amp%3Bsdata%3DLAi7SdohKYLlxCN5y5MofYYKCodRehuxMPDJ6Xchx5Y%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-sync-files-planning%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EHow%20to%20deploy%20Azure%20File%20Sync%3A%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fazure%252Fstorage%252Ffiles%252Fstorage-sync-files-deployment-guide%253Ftabs%253Dazure-portal%26amp%3Bdata%3D02%257C01%257CVeeraReddy.Gangala%2540microsoft.com%257C51cc2db2df364377a08008d7f591efe0%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637247879493672652%26amp%3Bsdata%3DUhN2ERbyo6pTWnTt0dTQHjdQE%252F3qArTOzr51nwVePVo%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-sync-files-deployment-guide%3Ftabs%3Dazure-portal%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EFAQs%20to%20Azure%20File%20Share%2FSyn%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fazure%252Fstorage%252Ffiles%252Fstorage-files-faq%2523azure-file-sync%26amp%3Bdata%3D02%257C01%257CVeeraReddy.Gangala%2540microsoft.com%257C51cc2db2df364377a08008d7f591efe0%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637247879493682653%26amp%3Bsdata%3D4hpwsSd1S6bwe01rbF536BdnZpH5YhdDjENT8TilGXk%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-files-faq%23azure-file-sync%3C%2FA%3E%3C%2FP%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3CDIV%20class%3D%22reader-flag-content__wrapper%20mb4%20clear-both%22%3E%26nbsp%3B%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1450899%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22introducingazurelogicapps_960.jpg%22%20style%3D%22width%3A%20960px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F197558i7AFC7FD880C7EC3A%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22introducingazurelogicapps_960.jpg%22%20alt%3D%22introducingazurelogicapps_960.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EAccessing%20On-Premise%20File%20Systems%20from%20Azure%20Logic%20Apps%3C%2FP%3E%3C%2FLINGO-TEASER%3E
Senior Member

Overview:

In today's world, hybrid integration is prominent with many challenges on accessing on-premise resources on Cloud environment. Here, I thought of sharing my insights on available options to access On-Premise File Systems as many users have various concerns like Size limitations , access to storage accounts behind firewall. Let's see what are the options we have to access On-Premise file systems and how we can access them in Logic Apps.

It's as of my knowledge and there might be other ways to access On-Premise files through Express route , VNET peering and others. I am more over concentrating on the major concrete solutions we have at present in terms of respective services/resources.

  • On-Premise Data Gateway
  • Azure File Share - File Sync service (How about when its behind firewall)
  • Express route , VNET peering with Integration Service Environment (ISE)
  • SFTP& FTP servers

 

On-Premise Data gateway:

 

OPDG is windows service which can be deployed in on-premise windows servers to access LOB systems on premise such as File Systems (Even Microsoft File over clustering is supported), SQL Server , IBM MQ server , SAP etc. OPDG service underlying service is Azure Service Bus which is securely connects to the LOB systems on on-premise without opening additional firewalls and ports except the ports specific to LOB systems. OPDG service currently works for LogicApps,Power Apps and Power BI.

 

Pro's:

  • No need to open additional firewall and ports
  • Easy to configure and doesn't need much effort ,One gateway is enough o access all data sources
  • Fail over clustering for high availability
  • Can be installed in any server with in the domain network has access to the resources but performance could be impacted.

Limitations:

  • As it's underlying architecture is on Azure Service Bus , the request size limit is max of 2 MB and Response limit is 8 MB except for File systems which is 30 MB for all I/O operations except Create file which is 30 MB
  • Connection timeout will be 30 seconds
  • User can be part of only one tenant directory

Azure File Share-File Sync Service:

In most of scenarios, we use Azure File Server for accessing the common tools, Config files, logs file etc.. In addition to that Microsoft provides the Azure File Sync service which can be deployed on your windows machined to mount the Azure File services on your on-premise file systems. So you can use the Azure File share when you would like to use the file systems on both Microsoft cloud and On-Premise.

  • Bit difficult to configure as various components has to be setup
  • Easy to mount on multiple windows servers to access common tools setup files etc..
  • File sync service does cache the Azure File server for quick access of the files
  • Limits are bound to Azure File Share limits which is in TB's Tera bytes.

However, I am not going to details about installation and configuration and quickly jump on how we could access these from Logic Apps.

First thing that comes to out mind is security when we move data to cloud and accessing it from other Azure resources or any other clients. So storage account has Firewall settings along with the access keys or SAS keys for restricting the access and authorizing operations on storage account. When we consider this how could we access the storage accounts in Logic Apps which are behind the firewall and both are region same region. We can use the REST API's with SAS URL of Azure File Share to overcome this scenario as we won't be able to see the out of box connectors when they are in same region.

 

ISE Environment: Dedicated environment isolate from multi tenant shared environment.

ISE environment as we know can be used to access the all resources with in same virtual network which can have Express route or VNET to peer configuration to access data resources in on-premise servers. It's pretty straight forward to access on-premise file systems using ISE version connectors.

  • Dedicated resources will be allocated and isolate from the shared environment
  • All resources with in the same virtual network or access to other networks if peer networking or Express route established can be accessed
  • Cost is primary concern as its fixed amount respective to SKU's selected
  • Flexibility to scale up and scale down with additional units
  • Expose with Static IP

SFTP /FTP server:

Most resilient approaches for accessing file servers hosted in either Windows or Linux servers through SFTP/FTP servers is pretty common scenario now. Using SFTP/FTP servers we can access the files of size upto 1 GB with support of chunking.

  • Secure file transfer with SSH -2.0 protocol
  • Trigger file size limit is 15 MB and chunking doesn't support on trigger as expected by deign
  • Actions can be used to read data in streams of 15 to 50 MB chunks which can be set according to network speed. Limit is of 1 MB
  • Connection timeout is 20 seconds.
  • New filed to get the metadata of the files on both triggers and actions which can be suppressed in performance issues.

Refrences:

Related to Azure File Sync and deployment:

https://docs.microsoft.com/en-us/azure/storage/files/storage-sync-files-deployment-guide?tabs=azure-...

https://docs.microsoft.com/en-us/azure/storage/files/storage-sync-files-planning

How to deploy Azure File Sync:

https://docs.microsoft.com/en-us/azure/storage/files/storage-sync-files-deployment-guide?tabs=azure-...

FAQs to Azure File Share/Syn

https://docs.microsoft.com/en-us/azure/storage/files/storage-files-faq#azure-file-sync