You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何限制ASP.NET 4.7 Azure Web服务特定URL路径公网访问并允许VNet访问?

Hey there, let's break down your questions and troubleshoot the Application Gateway issue you ran into—this is a common scenario for securing internal API paths while keeping the rest of your site public.

1. General Approach to Restricting Public Access to Specific URL Paths in Azure Web Apps

There are two primary ways to lock down specific paths, depending on whether you're using Azure Application Gateway or relying on App Service's built-in features:

Option 1: Use App Service Access Restrictions (No Gateway Required)

Azure Web Apps have built-in access controls that let you restrict paths directly:

  • First, ensure your app has a default "Allow All" rule (this is the default, but double-check if you've modified rules before) with a low priority (like 1000).
  • Add a Deny rule with a higher priority (e.g., 100) targeting your restricted path(s)—use wildcards for broader matches, like /api/internal/*.
  • In the "Exceptions" section of this Deny rule, add your virtual network (VNet) via service endpoints or private links. This means only traffic from your VNet can bypass the Deny rule and access the restricted paths.
  • Pro tip: Classic ASP.NET 4.7 routing is case-sensitive, so make sure your path matches exactly what your API uses (e.g., /API/Internal/* won't match /api/internal/*).

Option 2: Use Azure Application Gateway (For Centralized Traffic Management)

If you're already using a gateway (and ran into issues), this is the way to go for centralized control. Here's how to set it up correctly, plus troubleshooting tips for your earlier failure.

2. Scenario: Public Site + VNet-Only Restricted Paths (Classic ASP.NET 4.7)

Your goal is to let the public access the entire site, but limit specific API paths to VNet traffic. Let's walk through the correct Application Gateway setup and fix why your previous attempt didn't work.

Step 1: Secure Your Web App to Only Accept Traffic from the Gateway

First, you need to ensure users can't bypass the gateway and access your Web App directly:

  • Go to your Web App's Networking > Access Restrictions.
  • Add an Allow rule with priority 100, and enter your Application Gateway's public IP address (or the entire subnet if the gateway is in a VNet).
  • Set the default rule to Deny—this forces all traffic to go through the gateway.

Step 2: Configure Application Gateway Path-Based Routing

Now set up the gateway to route traffic correctly and restrict the specific paths:

  1. Create Backend Pool: Add your Azure Web App to a backend pool. If your Web App uses VNet integration, ensure the gateway is in the same VNet (or a peered VNet) and that private endpoints are configured if needed.
  2. Create Two Routing Rules (Priority Matters!):
    • Rule 1 (High Priority: e.g., 10): Restricted Paths
      • Set the listener to your public frontend IP.
      • Use a Path-based routing rule, and enter your restricted path(s) (e.g., /api/internal/*).
      • Under Access Control List (ACL), add your VNet's IP range(s) as "Allow" entries, and set the default to "Deny". This blocks all public traffic to these paths.
      • Route the traffic to your Web App backend pool.
    • Rule 2 (Lower Priority: e.g., 20): Public Access Paths
      • Use a Path-based routing rule with the path /* (matches all other paths).
      • Set the ACL to "Allow All" to let public traffic through.
      • Route to the same Web App backend pool.

Why Your Previous Application Gateway Setup Might Have Failed

Here are the most common issues:

  • Incorrect Rule Priority: If your public /* rule had a higher priority than the restricted path rule, the gateway would match the public rule first, ignoring your restrictions. Always give restricted path rules higher priority.
  • Path Matching Issues: Gateway path rules are case-sensitive and require exact wildcard usage. For example, /api/internal won't match /api/internal/orders—use /api/internal/* to cover all subpaths.
  • Web App Access Restrictions Were Too Permissive: If your Web App allowed public traffic directly, users could bypass the gateway entirely. Always lock down the Web App to only accept gateway traffic.
  • Backend Pool Health Checks Failed: If the gateway can't reach your Web App (due to misconfigured health checks), it won't route traffic. Ensure health checks target a publicly accessible path like / or a dedicated health endpoint.
  • Incorrect VNet IP Range: Double-check that the IP range you added to the restricted rule's ACL matches your VNet's actual range (including subnets).

Bonus: Verify the Setup

Test the configuration to make sure it works:

  • From a public network: Try accessing the restricted path (should get a 403 Forbidden), then access a public path (should load normally).
  • From a VM in your VNet: Access the restricted path (should load successfully).

内容的提问来源于stack exchange,提问作者Michael Chudinov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 17:02:51