You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure定时触发函数无法访问防火墙后摄像头的网络配置求助

问题描述

我在Azure Function App中创建了一个Timer Trigger定时触发函数,通过HttpClient请求防火墙后方的摄像头快照。该摄像头可从公司办公网络访问,且已配置Azure使用办公网络,原本预期Azure能连接到摄像头。本地在办公网络环境测试时一切正常,但部署到Azure后功能失效。当前函数应用使用最低层级的消费计划,查阅资料后怀疑需要升级计划。

请问如何配置才能让函数应用使用可访问办公网络的Azure网络,从而连接到摄像头?我们暂不控制摄像头侧的防火墙,但可管控办公网络防火墙,希望能让Azure函数的请求看起来来自办公网络。

函数代码
using System;
using System.Net;
using System.Net.Http;
using System.Threading.Tasks;
using Azure.Storage.Blobs;
using Azure.Storage.Blobs.Models;
using Microsoft.Azure.WebJobs;
using Microsoft.Extensions.Logging;

namespace PlaygroundAzureFunctions
{
    public class PictureToStorageFunnyTest
    {
        [FunctionName("PictureToStorage")]
        public async Task RunAsync([TimerTrigger("0 */5 * * * *")]TimerInfo myTimer, ILogger log)
        {
            log.LogInformation($"Timer trigger started executed at: {DateTime.Now}");
            // Create an HttpClientHandler object and set to use default credentials
            HttpClientHandler handler = new HttpClientHandler();
            var credCache = new CredentialCache();
            var user = "User";
            var secret = "Secret";
            var domain = "urlToPictureAPI";
            credCache.Add(new Uri(domain), "Digest", new NetworkCredential(user, secret));
            handler.Credentials = credCache;
            // Create an HttpClient object
            HttpClient client = new HttpClient(handler);

            try
            {
                using HttpResponseMessage response = await client.GetAsync(domain);
                response.EnsureSuccessStatusCode();
                byte[] responseBody = await response.Content.ReadAsByteArrayAsync();
                // Above three lines can be replaced with new helper method below
                // string responseBody = await client.GetStringAsync(uri);

                //For Console printout test
                //Console.WriteLine(responseBody);

                //For local storage testing
                //File.WriteAllBytes("TestPicture.jpeg", responseBody);
                

                string Connection = Environment.GetEnvironmentVariable("AzureWebJobsStorage");
                string containerName = Environment.GetEnvironmentVariable("ContainerName");
                var blobClient = new BlobContainerClient(Connection, containerName);
                var blob = blobClient.GetBlobClient("TestPicture.jpeg");
                var blobHttpHeader = new BlobHttpHeaders { ContentType = "image/jpeg" };

                byte[] sourceData = responseBody;
                BinaryData uploadData = new BinaryData(sourceData);
                await blob.UploadAsync(uploadData, new BlobUploadOptions { HttpHeaders = blobHttpHeader });
                log.LogInformation($"Picture Uploaded Successfully at: {DateTime.Now}");
            }
            catch (HttpRequestException e)
            {
                //Console.WriteLine("Exception Caught!");
                //Console.WriteLine("Message :{0} ", e.Message);
                log.LogInformation($"Exception Caught!\nMessage :{{0}} at: {DateTime.Now}", e.Message);
            }

            // Need to call dispose on the HttpClient and HttpClientHandler objects
            // when done using them, so the app doesn't leak resources
            handler.Dispose();
            client.Dispose();

            log.LogInformation($"Timer trigger ended executed at: {DateTime.Now}");
        }
    }
}
解决方案建议
  • 升级函数计划:消费计划(Consumption Plan)不支持虚拟网络集成,必须升级到Premium计划(EP1/EP2/EP3)或专用App Service计划,这是实现办公网络访问的前提。
  • 配置虚拟网络集成(VNet Integration):
    1. 在Azure门户进入你的Function App,选择“网络”->“虚拟网络集成”。
    2. 选择或创建要集成的Azure虚拟网络,确保该VNet已通过VPN网关或ExpressRoute与公司办公网络打通,让Azure资源能访问办公网络内的设备。
    3. 配置完成后,函数的出站流量会通过该VNet转发,请求源IP为VNet内地址或VPN/ExpressRoute网关IP,办公网络防火墙只需允许这些IP即可。
  • 办公网络防火墙配置:
    • 若使用VPN/ExpressRoute,将Azure VNet的地址段加入办公网络防火墙的允许列表;
    • 若暂未搭建VPN/ExpressRoute,可将Premium/App Service计划的静态出站IP添加到办公网络防火墙的允许列表(消费计划无固定出站IP)。
  • 让请求源匹配办公网络的进阶设置:
    如需函数请求完全以办公网络IP出站,可在Azure VNet中配置NAT网关,将函数出站流量转换为办公网络认可的IP;或通过VPN网关的SNAT功能,让Azure侧流量以办公网络的公网/内网IP对外请求。

内容的提问来源于stack exchange,提问作者user19876549

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 21:01:36