You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Application Proxy外部URL重定向至内部问题排查求助

Troubleshooting Azure Application Proxy (AAP) External URL Access Issues

Alright, let's break down the most common culprits that might be causing your external URL access failure, even with a running AAP connector. We'll start with the simplest checks and work our way up:

1. Verify Internal URL Reachability from the Connector Server

First things first—your connector needs to be able to reach the internal app directly from its host server.

  • Log into the server where you installed the AAP connector, open a browser, and try accessing http://test. If this fails, AAP can't reach it either.
    • Check for server-specific issues: Does the server require a proxy to access internal sites? Are there IE/Edge compatibility settings blocking the site? (The connector uses the server's default browser context for requests.)
    • Use command-line tools to test connectivity: Run Test-NetConnection test -Port 80 to confirm the server can establish a TCP connection to the internal app's port.

2. Validate AAP Application Configuration

Double-check your app settings in the Azure portal—small misconfigurations here are often the root cause:

  • Path Matching: Ensure the external URL's path aligns with the internal URL. If your internal app is at http://test (root path), the external URL should not have an extra path suffix (e.g., https://your-app.msappproxy.net instead of https://your-app.msappproxy.net/test).
  • Pre-Authentication Settings:
    • If you set pre-authentication to Azure Active Directory, confirm the user you're testing with is added to the app's access list (Go to Enterprise Applications > Your App > Users and groups). Missing permissions will throw an access denied error.
    • To rule out auth issues temporarily, switch pre-authentication to Pass-through and test the external URL again.
  • Kerberos Constrained Delegation (KCD): If your internal app uses Windows authentication, verify the Internal Application SPN is correctly set (it should match the SPN registered for your internal app's service account). For anonymous internal apps, this isn't required.

3. Troubleshoot the AAP Connector

Even if the portal shows "Running," the connector might have underlying connectivity issues:

  • Restart the connector service: Open Services on the connector server, find Azure AD Application Proxy Connector, right-click and select Restart. Wait a minute, then check the portal status again.
  • Confirm outbound network access: The connector needs unrestricted outbound access to *.msappproxy.net, login.microsoftonline.com, and other Azure endpoints over port 443. Use Test-NetConnection msappproxy.net -Port 443 to test this. If blocked, work with your network team to open these endpoints.

4. Check Internal DNS Resolution

The connector server must be able to resolve http://test to the correct internal IP:

  • Run ping test on the connector server. If it fails to resolve, add a host entry in the server's C:\Windows\System32\drivers\etc\hosts file mapping test to the app's IP, or fix your internal DNS configuration.

5. Rule Out Browser-Specific Issues

Sometimes the problem is on the client side:

  • Test the external URL with different browsers (Chrome, Edge, Firefox) to eliminate cache or extension conflicts.
  • Ensure your browser isn't using a proxy server that routes traffic away from AAP's endpoints.

内容的提问来源于stack exchange,提问作者Rincey_nz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:37:40