通过VPN从本地资源访问Azure App Service RESTful端点的方案咨询
Absolutely! You can totally call your Azure App Service-hosted Web APIs through your existing Site-to-Site VPN instead of relying on public endpoints. This setup not only keeps your traffic off the public internet (boosting security) but can also cut down on latency for your local desktop app. Here’s how to make it work:
1. Integrate your App Service with your Azure VNet
First, enable VNet Integration for your App Service. This connects the app directly to the Azure virtual network linked to your Site-to-Site VPN, placing it within the private IP space your local network can reach via the VPN.
- Quick heads-up: VNet Integration is only supported on App Service Plans at the Basic, Standard, Premium V2/V3, Isolated, or Elastic Premium tiers—free or shared plans don’t support this feature.
2. (Optional but Highly Recommended) Set up a Private Endpoint
For stricter control (and to fully block public access to your API), create a Private Endpoint for your App Service. This assigns a private IP address from your Azure VNet to the App Service, making it accessible only from within the VNet (and your local network via the VPN).
- Once the private endpoint is active, you can disable the App Service’s public endpoint entirely in its network settings—ensuring no external public traffic can reach your API.
3. Configure DNS for Local Resolution
To make sure your local desktop app resolves the App Service’s domain to its private IP (instead of the public one), adjust your DNS setup:
- If using a private endpoint, Azure automatically creates DNS records in a private DNS zone. You can either configure your local DNS server to forward queries for the App Service’s domain to Azure DNS, or manually add the private IP-to-domain mapping to your local DNS.
- For basic VNet Integration (without a private endpoint), use a custom DNS server in your VNet or add a local DNS record pointing the App Service domain to its internal private IP.
4. Lock Down Access with Network Restrictions
Finally, tighten security by setting up Network Access Restrictions in your App Service’s settings. Create rules that only allow traffic from your local VPN’s IP range and/or your Azure VNet. This blocks any unauthorized public traffic from reaching your API.
Once all these steps are complete, your local desktop app will route requests to the Web API through the Site-to-Site VPN, completely bypassing the public internet.
内容的提问来源于stack exchange,提问作者Paul Witherspoon

