Azure定时触发函数无法访问防火墙后摄像头的网络配置求助
问题描述
我在Azure Function App中创建了一个Timer Trigger定时触发函数,通过HttpClient请求防火墙后方的摄像头快照。该摄像头可从公司办公网络访问,且已配置Azure使用办公网络,原本预期Azure能连接到摄像头。本地在办公网络环境测试时一切正常,但部署到Azure后功能失效。当前函数应用使用最低层级的消费计划,查阅资料后怀疑需要升级计划。
请问如何配置才能让函数应用使用可访问办公网络的Azure网络,从而连接到摄像头?我们暂不控制摄像头侧的防火墙,但可管控办公网络防火墙,希望能让Azure函数的请求看起来来自办公网络。
函数代码
using System; using System.Net; using System.Net.Http; using System.Threading.Tasks; using Azure.Storage.Blobs; using Azure.Storage.Blobs.Models; using Microsoft.Azure.WebJobs; using Microsoft.Extensions.Logging; namespace PlaygroundAzureFunctions { public class PictureToStorageFunnyTest { [FunctionName("PictureToStorage")] public async Task RunAsync([TimerTrigger("0 */5 * * * *")]TimerInfo myTimer, ILogger log) { log.LogInformation($"Timer trigger started executed at: {DateTime.Now}"); // Create an HttpClientHandler object and set to use default credentials HttpClientHandler handler = new HttpClientHandler(); var credCache = new CredentialCache(); var user = "User"; var secret = "Secret"; var domain = "urlToPictureAPI"; credCache.Add(new Uri(domain), "Digest", new NetworkCredential(user, secret)); handler.Credentials = credCache; // Create an HttpClient object HttpClient client = new HttpClient(handler); try { using HttpResponseMessage response = await client.GetAsync(domain); response.EnsureSuccessStatusCode(); byte[] responseBody = await response.Content.ReadAsByteArrayAsync(); // Above three lines can be replaced with new helper method below // string responseBody = await client.GetStringAsync(uri); //For Console printout test //Console.WriteLine(responseBody); //For local storage testing //File.WriteAllBytes("TestPicture.jpeg", responseBody); string Connection = Environment.GetEnvironmentVariable("AzureWebJobsStorage"); string containerName = Environment.GetEnvironmentVariable("ContainerName"); var blobClient = new BlobContainerClient(Connection, containerName); var blob = blobClient.GetBlobClient("TestPicture.jpeg"); var blobHttpHeader = new BlobHttpHeaders { ContentType = "image/jpeg" }; byte[] sourceData = responseBody; BinaryData uploadData = new BinaryData(sourceData); await blob.UploadAsync(uploadData, new BlobUploadOptions { HttpHeaders = blobHttpHeader }); log.LogInformation($"Picture Uploaded Successfully at: {DateTime.Now}"); } catch (HttpRequestException e) { //Console.WriteLine("Exception Caught!"); //Console.WriteLine("Message :{0} ", e.Message); log.LogInformation($"Exception Caught!\nMessage :{{0}} at: {DateTime.Now}", e.Message); } // Need to call dispose on the HttpClient and HttpClientHandler objects // when done using them, so the app doesn't leak resources handler.Dispose(); client.Dispose(); log.LogInformation($"Timer trigger ended executed at: {DateTime.Now}"); } } }
解决方案建议
- 升级函数计划:消费计划(Consumption Plan)不支持虚拟网络集成,必须升级到Premium计划(EP1/EP2/EP3)或专用App Service计划,这是实现办公网络访问的前提。
- 配置虚拟网络集成(VNet Integration):
- 在Azure门户进入你的Function App,选择“网络”->“虚拟网络集成”。
- 选择或创建要集成的Azure虚拟网络,确保该VNet已通过VPN网关或ExpressRoute与公司办公网络打通,让Azure资源能访问办公网络内的设备。
- 配置完成后,函数的出站流量会通过该VNet转发,请求源IP为VNet内地址或VPN/ExpressRoute网关IP,办公网络防火墙只需允许这些IP即可。
- 办公网络防火墙配置:
- 若使用VPN/ExpressRoute,将Azure VNet的地址段加入办公网络防火墙的允许列表;
- 若暂未搭建VPN/ExpressRoute,可将Premium/App Service计划的静态出站IP添加到办公网络防火墙的允许列表(消费计划无固定出站IP)。
- 让请求源匹配办公网络的进阶设置:
如需函数请求完全以办公网络IP出站,可在Azure VNet中配置NAT网关,将函数出站流量转换为办公网络认可的IP;或通过VPN网关的SNAT功能,让Azure侧流量以办公网络的公网/内网IP对外请求。
内容的提问来源于stack exchange,提问作者user19876549
相关产品推荐
相关产品推荐

