Azure公网负载均衡器NAT规则搭配NSG的RDP端口访问问题排查
Hey Alex, let's break down your Azure setup and the likely issues you're hitting with Network Watcher's IP Flow Verify tool.
First, a critical point about Azure Load Balancer (LB) NAT rules: when an external client connects to your LB's static PIP on port 12345, the LB forwards that traffic to your VM's private IP (10.2.2.2) on port 3389. However, the source IP seen by your NSGs is the client's original public IP, not the LB's PIP. This is why your current rules aren't working as expected.
Let's break down the problems with your existing NSG config:
- Subnet NSG Rule 100: You've set the source to the LB's PIP, but actual traffic comes from client IPs—this rule will never match incoming RDP traffic.
- Subnet NSG Rule 120: Targets IP 10.1.2.4 (not your VM's 10.2.2.2) and specifies source port 12345 (client traffic uses random source ports, not 12345). This rule is irrelevant to your setup.
- VM NIC NSG Rule 100: Again, you're using the LB's PIP as the source, which doesn't align with real traffic sources.
You need to create explicit allow rules that match the actual traffic flow. Here are two valid approaches:
Option 1: Subnet-Level NSG (Recommended for Centralized Management)
Add a high-priority allow rule to your subnet NSG:
- Priority: 90 (higher than your existing rules to ensure it's evaluated first)
- Source:
Internet(or restrict to specific client IP ranges for better security) - Source port range:
*(clients use random source ports) - Destination:
10.2.2.2/32(your VM's private IP) - Destination port range:
3389 - Protocol:
TCP - Action:
Allow
Option 2: VM NIC-Level NSG
If you prefer to manage rules directly on the VM's NIC, use the same rule parameters as above—just apply it to the VM's NSG instead of the subnet's.
To validate the fix, run IP Flow Verify with these settings:
- Direction: Inbound
- Target IP:
10.2.2.2(your VM's private IP) - Target port:
3389 - Source IP: Your local client's public IP (the one you'd use to connect via RDP)
- Source port:
*(or any random port like 50000) - Protocol:
TCP
This test should now show "Allowed" once your new NSG rule is in place.
Remember: Azure NSGs have a default inbound rule that denies all Internet traffic, so you must explicitly allow the traffic you need.
内容的提问来源于stack exchange,提问作者AlexB

